LEGAL
Privacy Policy
Effective date: June 16, 2026
Definitions
To keep this policy clear: Personal information (or personal data) means information that identifies, relates to, or could reasonably be linked to an identifiable individual. Processing means any action taken with that information — collecting, storing, using, sharing, or deleting it. A controller decides why and how personal information is used; a processor (or service provider) handles it on a controller's behalf and under their instructions. Client service data is information we access while delivering managed security services to a client.
Scope of this policy
cAIberOps LLC ("cAIberOps," "we," "us," or "our") provides managed cybersecurity services — including managed email security, endpoint protection, and related security services — to businesses and organizations. Protecting data is the core of our work, and we hold our own handling of it to the same standard. This Privacy Policy explains what information we collect, how we use and share it, how we protect it, and the choices and rights you have. It applies to our website (caiberops.com) and to information we receive while providing our services.
As a controller: For website visitors, prospective clients, and general business contacts, cAIberOps decides how and why personal information is used, and this policy governs it. As a processor/service provider: When delivering managed security services, we access and process data on behalf of our clients. In that role the client directs how their data is used, and our handling is governed by our service agreement and, where applicable, a Data Processing Agreement (DPA) or, for protected health information, a Business Associate Agreement (BAA). We use that data only to provide, support, and secure the contracted services.
Our data-protection principles
We handle personal information according to a few core principles. We process it lawfully, fairly, and transparently; collect it only for specific, legitimate purposes; limit it to what is reasonably necessary; work to keep it accurate and current; retain it only as long as needed; and protect it with appropriate administrative, technical, and physical safeguards.
Information we collect
We collect only what we need. Depending on your relationship with us, that may include:
- Identity and contact information — name, business email, phone, company, and similar details you provide.
- Inquiry details — number of users, your message, and anything you share when you contact us or request an assessment.
- Website and technical data — IP address, device and browser type, pages viewed, and referring source, collected automatically through cookies and similar technologies.
- Service data (for clients) — security telemetry and metadata from protected email systems and endpoints, such as threat indicators, alerts, logs, and the account and system information needed to detect, investigate, and respond to incidents.
- We do not seek to collect sensitive personal information except where necessary to deliver a contracted service or meet a legal obligation.
How we collect it
Directly from you (forms, email, calls, onboarding), automatically through your use of our website, and occasionally from trusted third parties such as marketing or business-information providers.
How we use information
To provide, operate, support, and improve our services; detect, investigate, and respond to threats and incidents; produce security reports for clients; respond to inquiries and provide support; send service communications and, where permitted, occasional business updates; protect our own systems; and meet legal, tax, and regulatory obligations. We do not sell personal information, and we do not use client service data for advertising.
A note on AI
Our services use AI-driven and behavioral technologies to detect and respond to threats — for example, identifying phishing or malicious activity. These tools support human-led security work; we do not use them to make automated decisions that produce legal or similarly significant effects on individuals.
Cookies and analytics
Our website uses cookies and similar technologies to make the site work, remember preferences, and understand usage (including through analytics tools such as Google Analytics). You can manage or disable cookies in your browser settings, though some features may not work as well without them.
How we share information
We do not sell your personal information. We share it only as needed, including with: technology and security platform providers that power our services (for example, Microsoft and Check Point) and other vendors supporting our website and operations, each under confidentiality and data-protection obligations and only for the purposes we specify; professional advisors (such as legal or accounting) where reasonably necessary; authorities or others when required by law or to protect rights, safety, and security; and a successor entity if cAIberOps is involved in a merger, acquisition, or sale of assets (we will require the recipient to honor this policy). We can provide clients a current list of the key service providers we rely on, on request.
Phone and text communications
If you give us your phone number, we may use it to respond to your inquiry and communicate about services you've requested. If we send any text (SMS) updates, message and data rates may apply, and you can opt out anytime by replying STOP. We do not share phone numbers for third-party marketing.
How we protect information
Safeguarding data is central to what we do. We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption of data in transit and at rest, multi-factor authentication, role-based and least-privilege access controls, monitoring, and ongoing security review. No system is perfectly secure, but we use recognized industry practices.
Data retention
We keep personal information only as long as needed for the purposes described here, to provide our services, to meet legal, tax, regulatory, or contractual obligations, and to resolve disputes or enforce agreements. Client service data is retained and disposed of according to the applicable service agreement, DPA, or BAA. When no longer needed, we securely delete or de-identify it.
Data breach notification
If a security incident affects personal information we're responsible for, we will act promptly to contain and investigate it and notify affected individuals and the appropriate authorities where required by law. When we process data on behalf of a client, we will notify the client without undue delay under our agreement so they can meet their own obligations.
Your privacy rights
Depending on where you live and the law that applies — including the Virginia Consumer Data Protection Act and the California Consumer Privacy Act (CCPA/CPRA), where applicable — you may have some or all of these rights:
-
to be informed about how your information is used (which this policy provides);
-
to access the personal information we hold about you;
-
to correct inaccurate or incomplete information;
-
to request deletion of your information;
-
to restrict or object to certain processing;
-
to receive a copy of your information in a portable format; and
-
to opt out of the sale or sharing of personal information (we do not sell personal information).
To exercise any of these, contact us using the details below. We will take reasonable steps to verify your identity and respond within the timeframe required by applicable law (generally within 30–45 days; we'll tell you if we need more time), at no charge for a reasonable request. For information we process on behalf of a client, we will forward your request to that client (the controller) and help them respond. We will never discriminate against you for exercising your rights.
Children's privacy
Our website and services are intended for businesses, not individuals, and are not directed to children. We do not knowingly collect personal information from children under 16 (or under 13 in the United States); if you believe a child has provided us information, please contact us.
Third-party websites
Our website may link to sites we don't operate. This policy doesn't cover them; please review their privacy policies.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we'll revise the "Effective date" above and, for material changes, provide additional notice where appropriate. Continued use of our website or services after an update means you accept the revised policy.
Contact us
Questions, concerns, or requests about your privacy: cAIberOps LLC — team@caiberops.com — (202) 602-6035 — McLean, Virginia.