Privacy Policy
Effective date: [EFFECTIVE DATE]. This is a template pending legal review before production launch.
This policy explains what information My CISO Partner ("we," "us") collects through this website and our client portal, why, and what you can do about it. [LEGAL ENTITY NAME] is the entity responsible for this data — see Contact below.
Information we collect
We collect information you voluntarily submit:
- Contact form — name, email, company, company size, industry, and any message you provide.
- Booking a call — name, email, company, phone number, and any message you provide, plus the time you select.
- Any of our six free assessments (AI Governance, Cyber Risk, CISO Readiness, Compliance Readiness, Board Readiness, Cyber Insurance Readiness) — your email, optionally your name and company, and your answers, which we use to compute and send you your results.
- Client portal — if you're a client, whatever your organization's authorized members enter or upload (evidence documents, etc.), scoped to your organization only.
- Site analytics — only if you consent via the cookie banner (see "Cookies and analytics" below).
How we use your information
We use this information to respond to your inquiry, schedule calls, deliver assessment results, and — where you have not opted out — send relevant follow-up communications. We use client portal data solely to deliver the engagement you've contracted for. We do not sell your personal information to anyone.
Who we share it with
We use a small number of third-party service providers to run this platform, and share only what each one needs to do its job:
- Supabase — our database and authentication provider; stores the information above.
- Netlify — hosts this website and processes form/assessment submissions.
- SendGrid — sends transactional email (assessment results, follow-ups, booking confirmations).
- Anthropic — powers AI-assisted tools our consultants use internally (e.g. drafting assistance, meeting-note summarization) while serving an active engagement. A consultant reviews anything AI assists with before it reaches you — see our AI Disclaimer.
- Google Analytics — only if you consent to analytics cookies.
We do not share your information with data brokers or advertisers.
Cookies and analytics
We use Google Analytics to understand site usage. Analytics cookies and a first-party analytics beacon are only set after you provide consent via the cookie banner on this site — declining means no analytics tracking occurs. Assessment and form submissions themselves do not depend on any cookie. Session-level attribution (which pages you viewed before submitting an assessment) is only recorded if you've consented to analytics.
How long we keep your information
Security audit records are automatically deleted after 1 year. [OTHER DATA CATEGORIES — CONFIRM YOUR ACTUAL RETENTION PERIODS FOR LEAD, ASSESSMENT, AND CLIENT DATA AND STATE THEM HERE — see the internal data retention policy for the current status of this decision.]
Your rights
You may request access to, correction of, or deletion of your personal information by contacting us at the address below. [CONFIRM YOUR ACTUAL PROCESS AND TIMEFRAME FOR HONORING THIS — today this is handled manually rather than through a self-service tool.] Depending on where you live, you may have additional rights under applicable law (for example, California's CCPA/CPRA or the EU/UK GDPR) — [CONFIRM WHICH REGIMES ACTUALLY APPLY TO YOUR VISITOR BASE WITH COUNSEL].
Assessment and AI disclaimers
Our free assessments are self-reported and not a substitute for a formal risk assessment — see our Assessment Disclaimer. For how we use AI internally, see our AI Disclaimer.
Contact
Questions about this policy can be directed to [PRIVACY CONTACT EMAIL].
Note: this page is a template and requires review by qualified legal counsel before this site is used in production, particularly regarding applicable state and federal privacy law (e.g., CCPA) and, if relevant to your visitor base, GDPR obligations.