Legal

Privacy Policy.

How CyberDre collects, uses and protects your personal data, in line with the EU General Data Protection Regulation (GDPR).

Effective date: August 21, 2026 · Analytics, cookie and reporting sections added

1. Who we are (data controller)

CyberDre ("CyberDre", "we", "us", "our") is a regulatory cyber pipeline engine for cybersecurity providers, founded by Nick Dre. For the purposes of the GDPR, CyberDre is the data controller of personal data collected through cyberdre.co.

Contact: audit@cyberdre.co (general) · compliance@cyberdre.co (data protection queries)

2. What personal data we collect

When you use a form on this website (contact form, free pipeline audit request, or a consent checkbox), we may collect:

  • Full name / first name
  • Work email address
  • Company name and website
  • Country / target market
  • Message content and any information you choose to share (offer, sector, monthly pipeline goal, etc.)
  • Metadata: submission source (which page/form), date and time

We do not knowingly collect special category data (Art. 9 GDPR) and ask that you do not submit such data through our forms.

We also process technical information through cookies and analytics technologies, described in section 3 below.

3. Cookies, analytics and advertising technologies

3.1 Strictly necessary

These are required for the website to function or to respect a choice you have made. They do not require consent under the ePrivacy Directive, and they do not track you across other websites.

  • NEXT_LOCALE — a cookie that remembers your language preference. Duration: 12 months.
  • cd_consent — a browser local-storage entry that records your own cookie choice, so we do not ask again on every page. Duration: 12 months, after which we ask again.

3.2 Analytics — with your consent

With your consent, CyberDre uses Google Analytics 4, provided by Google Ireland Limited, to understand how this website is used and to measure the performance of our content. Google Analytics 4 sets first-party cookies, including _ga and _ga_<container id>.

Depending on your consent choice, the information processed may include:

  • Page URLs visited and referral information (how you reached the site)
  • Device and browser information
  • Approximate location, derived from a truncated IP address — we do not receive your full IP address
  • Timestamps and session duration
  • Interactions with pages and buttons: opening the portfolio viewer, downloading the portfolio PDF, reaching the pipeline audit section, clicking an audit email link, submitting a form, and your cookie choice itself
  • A pseudonymous identifier that allows two visits to be recognised as the same browser

Google Signals is disabled on our property, we do not enable advertising personalisation, and we do not link analytics data to any identifier you give us through a form. We run no advertising campaigns, so no advertising audience is built from this data.

Legal basis: your consent — Art. 6(1)(a) GDPR and Art. 5(3) of the ePrivacy Directive.

3.3 Consent Mode and what happens before you choose

Google Consent Mode v2 is implemented on this website, in its basic form. Until you accept, analytics_storage, ad_storage, ad_user_data and ad_personalization are all set to denied, and no Google script is requested at all — Google Tag Manager and Google Analytics are only downloaded once you have consented. Before that point no analytics cookie is written, no client identifier is stored, and no request is made to a Google server from this website. If you choose "Essential only", or if you withdraw your consent, that stays true.

3.4 Advertising technologies

CyberDre does not currently operate any advertising, retargeting or conversion-tracking technology on this website. There is no LinkedIn Insight Tag and no Meta Pixel. If we deploy one, this policy will be updated before it loads and your consent will be requested for it.

3.5 Changing or withdrawing your choice

Non-essential technologies are not activated until the required consent has been obtained. You can change or withdraw your consent at any time — it is as easy to withdraw as it was to give:

Cookie settings

Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. You can also block or delete cookies in your browser settings.

4. How we use your data (purpose and legal basis)

  • To respond to your inquiry or audit request — legal basis: steps taken at your request prior to entering a contract (Art. 6(1)(b) GDPR).
  • To send the follow-up communications you explicitly opted into (pipeline audit results, cybersecurity growth insights) — legal basis: your consent (Art. 6(1)(a) GDPR), given via the checkbox on our forms.
  • To improve our services and prevent abuse of our forms — legal basis: our legitimate interest (Art. 6(1)(f) GDPR), balanced against your rights.

You may withdraw consent at any time by emailing compliance@cyberdre.co or using the unsubscribe link in any email. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

5. Who receives your data (processors and recipients)

We use the following processors. Each processes data only on our documented instructions:

  • Make.com — workflow automation that receives your form submission via webhook and routes it to our other tools.
  • Airtable — stores your submission in our internal website_leads records (name, email, company, message, source, date).
  • Slack — internal notification only; a summary of your submission is posted to a private CyberDre team channel so we can respond promptly.
  • Google Ireland Limited (Google Analytics 4 and Google Tag Manager) — website usage measurement, only where you have consented. Google does not receive the personal data you submit through our forms.
  • Netlify — hosting provider that serves this website and processes standard server request data.
  • Supermetrics — reporting tool with read-only access to our Google Analytics 4 property. It retrieves the analytics data described in section 3.2 so we can report on it. It has no access to our forms, our CRM, or any data you send us directly.

We do not sell your personal data. We do not share it with any party outside this list except where required by law.

6. International data transfers

Make.com, Airtable, Slack, Netlify, Google and Supermetrics may process data on servers located outside the European Economic Area, including the United States. Where this occurs, transfers are safeguarded by Standard Contractual Clauses (SCCs) approved by the European Commission, or an equivalent adequacy mechanism, as implemented by each provider. Google LLC is certified under the EU–US Data Privacy Framework.

7. Data retention

  • Contact/audit requests: up to 24 months from your last interaction, or until you request deletion, whichever is sooner.
  • Marketing consent records: until you withdraw consent, plus a reasonable period to evidence consent was given.
  • Google Analytics 4 user-level and event-level data: 14 months, configured in our Google Analytics property. Aggregated reporting data is retained by Google for longer and cannot be attributed to an individual.
  • Your cookie choice (cd_consent): 12 months, after which we ask again.

After the retention period, your data is deleted or anonymized.

8. Your rights under the GDPR

Subject to applicable conditions and exceptions, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten")
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time
  • Lodge a complaint with your national data protection supervisory authority

To exercise any of these rights, email compliance@cyberdre.co. We will respond within one month, as required by Art. 12(3) GDPR.

9. Security

We apply appropriate technical and organizational measures — access controls, encrypted transmission, restricted processor access — to protect your data against unauthorized access, loss or misuse. No system is 100% secure; if we become aware of a breach affecting your data, we will notify you and the relevant supervisory authority as required by Art. 33–34 GDPR.

10. Children

Our services are intended for business professionals (B2B) and are not directed at, nor do we knowingly collect data from, individuals under 16.

11. Changes to this policy

We may update this policy to reflect changes in our practices or legal requirements. The effective date above will be updated accordingly, and material changes will be highlighted on this page.

12. Contact

Questions about this policy or your data: compliance@cyberdre.co
General inquiries: audit@cyberdre.co

CyberDre does not provide legal advice. This policy describes our own data practices — it is not legal guidance for your business.