Privacy policy

Last updated: March 2026 · Effective immediately
Plain language summary: We collect the minimum data needed to run your account and track learning progress. We don't sell data, don't run ads, don't use tracking cookies, and don't share your information with anyone except the infrastructure needed to operate the service. All data is processed in the EU.

1. Who we are

modularCISO ("we", "us", "our") operates the website modularciso.com. We provide cybersecurity training and tools for security professionals.

For data protection inquiries, contact us at: privacy@modularciso.com

2. What data we collect

Account data (provided by you)

OAuth data (if you use social login)

If you sign in with Google, GitHub, or LinkedIn, we receive your name, email address, and profile picture from the provider. We do not store access tokens or request ongoing access to your provider account.

Usage data (generated automatically)

Page view counts

We count how often each lesson and tool page is opened, so we can see which material is actually read. Each record contains four things: the date, the page path, whether the reader was signed in, and a count. It contains no user ID, no IP address, no browser details, no session identifier and no cookie, and it is written server-side — there is no script in your browser doing it. Nothing in that data can be traced back to a person, including by us.

What we do NOT do

The honest summary, in one paragraph

No advertising trackers and no third-party analytics. After you sign in we keep a session cookie, security logs that include your IP address and browser, per-lesson progress, and an invisible watermark tied to your account in the curriculum text. Separately we keep aggregate page counts that identify nobody. Cloudflare, which hosts the site, processes standard request data on our behalf as our infrastructure provider. One detail for anyone who reads our security headers: our Content Security Policy still permits Cloudflare's privacy-friendly analytics script (static.cloudflareinsights.com). It is not enabled — no such script is served on any page today — and the allowance exists only so we could turn it on without a policy change. If we ever do, this paragraph gets updated first. Our policy also still allows inline scripts ('unsafe-inline'), which weakens it: Cloudflare's bot-management platform injects an inline script carrying a token that changes on every request, so it cannot be allowlisted by hash or nonce, and removing the allowance would disable that protection. The reasoning is set out in full in our vulnerability disclosure policy. That is the complete list — if you find something on this site that contradicts it, please tell us, because that would be a bug in either the site or this page.

3. Why we process your data

4. Who has access to your data

Infrastructure providers

We do not sell, rent, or share your personal data with any other third parties. We do not use your data for advertising or profiling purposes.

5. Where your data is stored

Your data is stored on Cloudflare's infrastructure with EU data processing configured. All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Password hashes use PBKDF2-SHA256 with 100,000 iterations — the platform maximum (see the note above).

6. How long we keep your data

7. Your rights under GDPR

As a data subject in the EU, you have the following rights:

To exercise any of these rights, use the self-service tools in your account settings or email privacy@modularciso.com.

8. Cookies

We use a single cookie:

We do not use analytics cookies, advertising cookies, or any third-party tracking cookies.

9. Children

modularCISO is not directed at individuals under 16 years of age. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it promptly.

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email to registered users and noted on this page with an updated "last updated" date. Continued use of the service after changes constitutes acceptance.

11. Contact

For privacy-related inquiries, data protection requests, or complaints:

Email: privacy@modularciso.com

If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD).