Privacy Policy
Last updated: January 2025
1. Introduction
Cyber Pantheon ("we," "our," or "us") is committed to protecting your privacy. As a cybersecurity firm specializing in penetration testing, security assessments, and advisory services, we understand the critical importance of data protection. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at cyberpantheon.us or engage our services.
Please read this policy carefully. By using our website or services, you consent to the practices described in this policy. If you disagree with any part of this policy, please do not use our services.
2. Information We Collect
2.1 Information You Provide
We collect information you voluntarily provide when you:
- Submit engagement applications: Name, email address, company name, job title, phone number, project details, and technical environment information
- Contact us: Name, email address, and message content through our contact forms
- Subscribe to communications: Email address and preferences
- Request proposals: Business information including company size, industry, security requirements, and budget ranges
- Participate in surveys or feedback: Responses and opinions provided
2.2 Information Collected Automatically
When you visit our website, we automatically collect:
- Usage data: Pages visited, time spent, click patterns, and navigation paths
- Device information: Browser type, operating system, device type, and screen resolution
- Technical data: IP address (anonymized where possible), referring URL, and connection type
- Cookies and similar technologies: Session identifiers, preference settings, and analytics cookies
2.3 Information From Third Parties
We may receive information about you from:
- Professional networking platforms (LinkedIn) when you connect with us
- Review platforms (Clutch) when you leave feedback about our services
- Business verification services to confirm company information
3. How We Use Your Information
We use collected information for the following purposes:
- Service delivery: To plan, execute, and report on security engagements
- Communication: To respond to inquiries and send service-related notifications
- Marketing: With your consent, to send newsletters and security insights
- Improvement: To analyze usage patterns and enhance service offerings
- Legal compliance: To fulfill contractual obligations and comply with applicable laws
- Security: To detect, prevent, and address fraud or unauthorized access
4. Handling of Client Engagement Data
⚠️ Important Notice for Security Engagements: As a penetration testing and security assessment firm, we handle sensitive client data during engagements with enhanced protections.
4.1 Data Retention for Engagement Materials
- Active engagements: Data retained for duration of project + 90 days
- Completed engagements: Final reports retained for 3 years unless contract specifies otherwise
- Raw testing data: Deleted within 30 days of final report delivery
- Client request: Earlier deletion available upon written request
4.2 Non-Disclosure Commitments
All client-specific information obtained during engagements is protected under confidentiality agreements. We never disclose client vulnerabilities without explicit written permission.
5. Information Sharing and Disclosure
We do not sell your personal information. We may share data only in these circumstances:
5.1 Service Providers
We share data with trusted third parties who assist our operations, including cloud infrastructure providers, email service providers, and analytics platforms. All vendors are bound by contractual data protection requirements.
5.2 Legal Requirements
We may disclose information when required by law, subpoena, court order, or government regulation.
5.3 Business Transfers
In the event of merger, acquisition, or asset sale, your information may be transferred as part of the transaction. You will be notified via email or prominent website notice at least 30 days before any transfer.
6. Data Security Measures
Given our expertise in cybersecurity, we implement robust security measures:
- Encryption: TLS 1.3 for data in transit; AES-256 encryption for data at rest
- Access controls: Role-based access and multi-factor authentication
- Audit logging: Comprehensive logging of access to sensitive data
- Staff training: Regular security awareness training for all team members
- Incident response: Documented procedures for potential data breaches
7. Your Rights and Choices
Depending on your location, you may have the following rights:
- Access: Request copies of personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data
- Opt-out: Unsubscribe from marketing communications at any time
- Withdraw consent: Withdraw previously given consent
To exercise these rights, contact us at privacy@cyberpantheon.us. We respond to all requests within 30 days.
8. Cookies and Tracking Technologies
We use essential, analytics, and preference cookies to enhance your experience. You can manage cookie preferences through your browser settings. Disabling essential cookies may affect website functionality.
9. Contact Us
For privacy-related inquiries, contact our Data Protection Officer:
Cyber Pantheon
Email: privacy@cyberpantheon.us
General Inquiries: hello@cyberpantheon.us
Response Time: Within 5 business days
