Who we are
Cyber Ready Clinic is a Maryland 501(c)(3) nonprofit. This website is operated to share our programs and to let you sign up for updates, volunteer, mentor, or donate through linked services.
Definitions
- Service
- This website and the related applications operated by Cyber Ready Clinic, Inc.
- Personal data
- Data about a living individual who can be identified from that data, or from that data together with other information we hold or are likely to hold.
- Usage data
- Data collected automatically, either generated by use of the Service or by the infrastructure behind it, such as how long a page was open.
- Cookies
- Small files stored on your computer or mobile device.
- Data controller
- The person or organization that decides why and how personal data is processed. For this site, that is Cyber Ready Clinic.
- Data processor (service provider)
- A person or organization that processes data on the controller’s behalf. The vendors listed under Sub-processors are our processors.
- Data subject
- Any living individual whose personal data we hold.
Legal bases
Depending on the activity, we rely on: consent (for example when you check the box to agree to this policy and our Terms before submitting a form, or when you ask to receive email updates); contract / pre-contract steps when we need your details to respond to an inquiry; and legitimate interests in running a secure site (for example abuse prevention and rate limiting). We do not sell your personal information.
What we collect
- Newsletter: name and email when you use the signup form. We record the time and policy version when you consented.
- Volunteer / mentor inquiries: name, email, and any fields you choose to submit (for example county, specialties, message, profile link), plus consent timestamp and policy version.
- Client intake questionnaires: organization and contact details, free-text answers, and selections you submit. Responses are stored to follow up and prepare for consultations, with consent timestamp and policy version.
- Administrator accounts: name, email, and credentials for staff who sign in to the internal console (see our authentication provider and session cookies below).
- Technical data: we process IP addresses and browser metadata for security and abuse prevention (for example rate limiting). Rate-limit events use a hashed identifier and are deleted on a short rolling schedule (about one day) as described in our code documentation.
Cookies and similar technologies
We do not use third-party advertising networks. For reliability and security we may load first-party scripts from our hosting provider (for example aggregate traffic and performance metrics when the site runs on Vercel) and error-monitoring tools (for example Sentry) that help us fix bugs. Those tools are configured to minimize personal data (for example session replay is masked and tied to errors). The following first-party cookies (or similar storage) may also apply:
| Name / purpose | Type | Duration |
|---|
| Session / auth cookies for /admin (sign-in). Set by our application so administrators stay logged in. | Strictly necessary | Session or as configured by the auth system (typically days). |
| Hosting analytics / speed metrics (for example Vercel Web Analytics and Speed Insights) when the site is deployed on Vercel, aggregate page views and Core Web Vitals, not used for cross-site advertising. | Analytics / performance | Per vendor defaults (often session or short-lived). |
| Error monitoring (for example Sentry), technical diagnostics when something fails in the browser or server; may include a masked session replay when an error occurs. | Strictly necessary / security | Per vendor defaults. |
If we add additional marketing or cross-site tracking later, we will update this policy and, where required, ask for your consent before those tools run.
Sub-processors (vendors)
We use service providers to operate the site. They process data only to provide the service and under our instructions. Examples:
- Email delivery (for example transactional email when you use forms or password reset), currently Resend when configured.
- Hosting / infrastructure, the environment where the app and database run (for example Vercel or another host you choose).
- Observability: Sentry (error monitoring and diagnostics) and, when applicable, Vercel analytics or speed insights tied to hosting.
- Optional Google Sheets sync, if enabled in configuration, submission metadata may be appended to a spreadsheet you control.
Payment or donation checkout may occur on a third-party site; that provider’s privacy notice applies to the payment step.
International transfers
We are based in the United States. If you contact us from another country, your information may be processed in the U.S. Where required, we use appropriate safeguards (such as standard contractual clauses offered by vendors) for transfers from the EEA, UK, or Switzerland. Ask us for details if you need them for your records.
How we use it
We use submissions to respond to you, operate programs, and improve our services. Vendors process data only to provide the service (email delivery, hosting, optional Sheets).
Retention
We keep information only as long as needed for the purposes above and to meet legal, accounting, or insurance obligations. Indicative periods:
- Form submissions (newsletter, volunteer, mentor, questionnaires): retained for ongoing operations and program history unless you ask us to delete them, subject to legal holds.
- Abuse-prevention / rate-limit data: short rolling window (on the order of one day) before deletion.
- Backups: copies in backups may persist until those snapshots expire according to our host or backup rotation. We do not guarantee instant removal from every backup when you request deletion, but we will overwrite or exclude data on active systems and in the next backup cycle where practicable.
Security
We use HTTPS, access controls for admin areas, and reputable hosting. Database files are protected by the host environment; use encrypted disks and protected backups in production. No method of transmission over the Internet is 100% secure.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to certain processing. To exercise these rights, email info@cyberreadyclinic.com with a description of your request. We may need to verify your identity before processing. We respond within a reasonable time and as required by applicable law (often within about 30 days for many requests).
Administrator accounts: to delete an admin account or data tied to it, contact the same address. We will coordinate removal from our database and sessions where applicable.
California residents: we do not sell personal information as defined by the CCPA/CPRA. You may still contact us to exercise access or deletion rights as described above.
Email and unsubscribe
If you receive messages you no longer want, reply from the same address or write info@cyberreadyclinic.com with “unsubscribe” in the subject line. We will process reasonable requests as soon as we can.
Children
This site is not directed at children under 13. Do not submit a child’s personal information through our forms without appropriate consent.
When we disclose information
Beyond the vendors listed above, we may disclose personal information:
- To comply with law. If required to do so by law, or in response to a valid request by a public authority such as a court or a government agency.
- In a business transaction. If Cyber Ready Clinic is involved in a merger, acquisition, asset sale or similar transaction, personal data may be transferred as part of it. We would give notice here before your data became subject to a different privacy policy.
- To protect people and the Service. Where we reasonably believe disclosure is necessary to investigate or prevent wrongdoing, to enforce our Terms, or to protect the safety of users or the public.
- With your consent. For any other purpose we tell you about at the time.
Links to other sites
This site links to services we do not operate, including credential pages, payment and donation checkout, partner websites and press coverage. If you follow one of those links you are on that provider’s site, under their privacy policy, not ours. We have no control over their content or practices and we encourage you to read the policy of any site you visit.
California residents
We do not sell or share your personal information as those terms are defined by the California Consumer Privacy Act (CCPA/CPRA), and we have not done so in the preceding twelve months. We do not knowingly sell the personal information of anyone under 16.
If you are a California resident you may ask us for:
- the categories of personal information we have collected;
- the categories of sources it came from;
- the business purpose for collecting it;
- the categories of third parties we disclose it to, which for this site means the vendors listed under Sub-processors;
- a copy of the specific pieces of information we hold; and
- deletion or correction of that information.
We will not discriminate against you for exercising any of these rights. Email info@cyberreadyclinic.com to make a request. We may need to verify your identity first.
Under the California Online Privacy Protection Act (CalOPPA) we also confirm that you can visit this site anonymously; that this policy is linked from our footer with the word “Privacy” in the link; that we will post any changes to it on this page; and that you can change or remove your information by emailing the address above.
Do Not Track. We do not track visitors across third-party websites, so we do not respond differently to a Do Not Track browser signal.
Changes
We may update this page to reflect new practices or legal requirements. We will post the revised policy here and update the “last updated” date. If we make material changes to how we use personal data, we will describe them here and, where the law requires a new consent (for example for marketing), we will ask before continuing those uses.
← Back to home · Terms of use · Cookies