PRIVACY

Privacy Policy

CipherQuest Sàrl — Website Privacy Policy

Version 1.1 — Last updated: September 2026

This Privacy Policy explains how CipherQuest Sàrl ("CipherQuest", "we", "us" or "our") collects and processes personal data when you visit our website, contact us, submit a website form, receive marketing communications from us, or otherwise interact with us in a business context.

Scope of this Policy

This Policy applies to our public website and to our sales, marketing and business-relationship activities. It does not apply to personal data processed within the CQ Integrity platform (including CQ Vendor Risk, CQ IT Risk and CQ IT Asset Classification) on behalf of our customers. For that data, the customer is the data controller and CipherQuest acts as a data processor under the applicable SaaS Agreement and Data Processing Agreement. Customer users should refer to their organization's privacy notice.

Who we are

CipherQuest Sàrl

9 rue Louvigny

L-1946 Luxembourg

Grand Duchy of Luxembourg

RCS Luxembourg: B89100

Email: info@cipherquest.com

For the processing described in this Policy, CipherQuest Sàrl is the data controller unless otherwise stated.

CipherQuest has not appointed a Data Protection Officer, as it is not required to do so under Article 37 GDPR. Privacy inquiries may be sent to info@cipherquest.com.

Personal data we may collect

Information you provide directly, depending on how you interact with us:

•      Name and job title or role

•      Business email address

•      Company or organization

•      Telephone number, where provided

•      Country or location information, where requested

•      Information about your business requirements, cybersecurity, risk management or GRC needs

•      Product or service interests

•      Meeting preferences and availability

•      Information submitted through our website forms

•      Correspondence and other information you choose to provide to us

Information from other sources. We may also obtain limited business contact data from public sources (such as your company's website or professional networking sites such as LinkedIn), from business referrals, from events and conferences, or from third-party business-data providers. This is limited to professional contact and role information used for business development.

Technical information. Our website and its supporting technologies may also process technical information necessary to operate, secure and maintain the website (such as IP address, browser type, device information and pages visited). Further information about cookies and similar technologies is provided in our Cookie Policy.

Providing personal data is voluntary. However, if you do not provide the information requested in a form, we may be unable to respond to your request or arrange the interaction you have asked for.

How we use personal data

•      Respond to inquiries and requests

•      Discuss your business, cybersecurity, risk management or GRC requirements

•      Arrange meetings, demonstrations, reviews or other requested interactions

•      Assess eligibility for relevant CipherQuest programs or reviews

•      Provide information about our products and services where appropriate, including direct marketing communications (see below)

•      Manage existing or prospective business relationships

•      Operate, maintain, secure and improve our website and related systems

•      Prevent misuse, fraud or security incidents

•      Comply with applicable legal and regulatory obligations

•      Establish, exercise or defend legal claims

Legal bases for processing

Steps prior to entering into, or performance of, a contract — where processing is necessary to respond to a request, provide requested information or manage a contractual relationship.

Legitimate interests — where processing is necessary for legitimate business purposes, such as responding to business inquiries, business-to-business marketing to professional contacts, managing professional relationships, operating and securing our website and protecting our business, provided those interests are not overridden by your rights and freedoms. You have the right to object to processing based on legitimate interests at any time.

Legal obligation — where processing is required to comply with applicable law or regulatory requirements.

Consent — where applicable and where consent is the appropriate legal basis (for example, non-essential cookies or certain marketing communications). You may withdraw consent at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Marketing communications

We may send business-to-business marketing communications about CipherQuest products, services, events and insights to professional contacts, in accordance with the GDPR and the Luxembourg law of 30 May 2005 on electronic communications privacy. Where required, we will obtain your consent before sending electronic marketing.

You may opt out at any time by using the unsubscribe link in any marketing email or by contacting us at info@cipherquest.com. Opting out of marketing does not affect service or contractual communications.

Website forms

When you submit information through a CipherQuest website form, we use the information to respond to the specific request and to manage the related business interaction. Our website may include forms for discussing requirements, arranging meetings, reviewing customer value or adoption, and assessing eligibility for specific programs or reviews.

Please provide only information that is relevant to your request. Do not submit sensitive personal information unless specifically requested and necessary for the relevant purpose.

Recipients and service providers

Personal data may be accessible to authorized CipherQuest personnel who require it for the purposes described in this Policy.

We use service providers that support the operation, hosting, security, communication or functionality of our website and business systems. These fall into the following categories:

•      Website hosting and content management (currently Squarespace)

•      Email and business productivity services

•      Customer relationship management (CRM) and marketing tools

•      Meeting scheduling and video conferencing services

•      Website analytics services, subject to your cookie preferences

Such providers process personal data on our behalf, only on our instructions, and are bound by data processing agreements in accordance with Article 28 GDPR.

We may also disclose personal data to professional advisers (lawyers, accountants, auditors), to competent authorities where required by law, and to a successor entity in the event of a merger, acquisition or reorganization of our business.

We do not sell personal data.

International data transfers

Some service providers may process data outside the European Economic Area, including in the United States. Where personal data is transferred to a country outside the EEA, we rely on one of the following safeguards: an adequacy decision of the European Commission (including the EU-U.S. Data Privacy Framework for certified organizations); Standard Contractual Clauses adopted by the European Commission, supplemented where necessary by additional measures; or another lawful transfer mechanism under Chapter V GDPR. You may request further information about the safeguards applied by contacting us.

Data retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected. As a guide:

  • Inquiries and form submissions that do not lead to a business relationship: up to 24 months after our last contact

  • Prospect and marketing contact data: until you opt out or for 36 months after our last meaningful interaction, whichever is earlier

  • Customer and contractual relationship data: for the duration of the relationship plus the applicable statutory limitation period (generally 10 years for accounting records under Luxembourg law)

  • Website technical data and analytics: server-level technical data is retained by our hosting provider, Squarespace, for the period necessary for security and operational purposes. Where you consent to analytics cookies, the resulting aggregated site-usage statistics are retained in our website analytics for the lifetime of the website. Analytics cookies persist on your device for up to two years unless you delete them or withdraw consent. See our Cookie Policy for details.

Data security

CipherQuest applies appropriate technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss or destruction, consistent with our own cybersecurity practice. No website, transmission method or information system can, however, be guaranteed to be completely secure.

Automated decision-making

We do not use personal data to make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.

Children

Our website and services are directed at businesses and professionals and are not intended for individuals under the age of 16. We do not knowingly collect personal data from children.

Your data protection rights

Subject to the conditions and limitations of applicable data protection law, you have the right to:

•      Access your personal data

•      Request correction of inaccurate or incomplete personal data

•      Request deletion of your personal data

•      Request restriction of processing

•      Object to processing based on legitimate interests, and object at any time to direct marketing

•      Receive certain personal data in a portable format

•      Withdraw consent where processing is based on consent

To exercise your rights, contact us at info@cipherquest.com. We will respond within one month, extendable by two further months where necessary for complex requests. We may request information necessary to verify your identity before responding.

Complaints

If you have concerns about how we process your personal data, we encourage you to contact us first so that we can address your request. You also have the right to lodge a complaint with the Luxembourg supervisory authority, or with the supervisory authority of your habitual residence or place of work:

Commission nationale pour la protection des données (CNPD), 15 boulevard du Jazz, L-4370 Belvaux, Grand Duchy of Luxembourg — https://cnpd.public.lu

Third-party websites

Our website may contain links to third-party websites. Their processing of personal data is governed by their own privacy practices and policies. CipherQuest is not responsible for the privacy practices of third-party websites.

Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in our website, business practices, technology or applicable legal requirements. The latest version, with its effective date, will be published on this page. Material changes will be indicated at the top of the Policy.

Related documents

Cookie Policy · Legal Notice