Legal & Compliance

Clear practices for a product built around employee records.

Review CyberPrimer’s privacy, security, commercial terms, data processing, accessibility, support boundaries, and service communications before enrolling an organization.

01

Privacy Policy

Information used, purposes, service providers, retention, and verified requests.

02

Security practices

Organization isolation, access controls, recovery, activity records, and responsible disclosure.

03

Terms of Service

Permitted use, customer responsibilities, evidence limitations, and support scope.

04

Refund Policy

The first-purchase refund window, cancellation rules, and request process.

05

Data Processing Agreement

Customer and CyberPrimer responsibilities for organization-controlled workforce data.

06

Cookie disclosure

Essential technologies used for authentication, security, preferences, and payment handoff.

07

Accessibility

Keyboard, contrast, responsive design, readable content, and how to report a barrier.

Data retention

Operational schedule pending final approval.

Training and evidence records follow the organization lifecycle and configured recovery workflow. Exact production retention periods remain to be finalized before paid launch and will then be reflected consistently in the Privacy Policy and DPA.

Service providers

Limited subprocessors support delivery.

Hosting and storage, Stripe, Resend, and Microsoft 365 may process only the information needed for their applicable function. Final processing locations and change-notification terms will appear in the execution-ready DPA.

Service communications

Operational notices stay distinct from guarantees.

CyberPrimer communicates material platform incidents and recovery status through registered manager contacts. The contractual incident-notification period remains pending final operational and legal review.