CyBehave exists to help organisations build secure behaviour, culture, and resilience. The same values we ask champions to model - trust, privacy, openness, and security - are the values we hold ourselves to. This is the single home for every customer-facing policy, term, and disclosure across our products and services. Click any document to read it, see its version and last-updated date, and download a PDF for your records.
The privacy, cookie and AI policies that apply across the CyBehave marketing site (cybehave.com) and, where stated, the wider CyBehave group.
How CyBehave collects, uses, and protects personal data across cybehave.com and CyBehave Heroes.
Read document →What cookies cybehave.com uses, why, and how to manage them in your browser.
Read document →How CyBehave uses, governs and discloses AI as a business: our principles, internal and development use, providers, governance, and our position under UK and EU law.
Read document →The customer-facing policies, terms and disclosures that govern organisational use of the CyBehave Heroes platform (heroes.cybehave.com).
How CyBehave processes personal data, what rights data subjects have, and how to exercise them.
Read document →The contract governing organisational use of the CyBehave Heroes platform.
Read document →Which cookies and similar technologies the platform sets, why, and how to control them.
Read document →How the platform uses AI (Nudge coaching assistant, drafting and summaries), its EU AI Act classification, what data is sent, and the guardrails in place.
Read document →How the platform is built and operated to support customer DPIA, supplier review and information-security questionnaires.
Read document →The Article 28 UK GDPR processor agreement between CyBehave and the client organisation, including the Schedule of Processing.
Read document →The current list of third-party data processors that handle customer data under the platform DPA.
Read document →A public summary of our Data Protection Impact Assessment for the AI features in CyBehave Heroes.
Read document →CyBehave Athena is our upcoming agentic behavioural cybersecurity expert and coach. Its customer-facing policies, terms and disclosures will be published here ahead of launch.
This Privacy Policy explains how personal data is handled when an organisation uses the CyBehave Heroes platform ("the Platform") provided by CyBehave Ltd ("CyBehave", "we", "us"). It should be read alongside the Terms of Service and the Data Processing Agreement (DPA) that accompanies them, and the Security and Privacy by Design document published in the Trust Centre.
Processing under this Platform is subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
CyBehave Heroes is a multi-tenant B2B SaaS platform. Two distinct data-protection roles apply:
Where this Policy uses phrases such as "we process" or "we collect", it refers to processing in whichever of the above roles applies to the data category in question.
This Policy is addressed both to data subjects whose personal data is processed on the Platform (typically employees or contractors of a client organisation) and to client organisations carrying out their own privacy due diligence on the Platform.
The following categories are processed on the documented instructions of the client organisation that has onboarded you. The client organisation is the controller; CyBehave is the processor.
The lawful basis for this processing is determined by the client organisation in its role as controller (typically performance of an employment-related task or legitimate interests in running the programme). CyBehave does not determine that lawful basis on the client's behalf.
For the following categories CyBehave is the controller and is responsible for the lawful basis and your rights as a data subject:
We share data with the following sub-processors. The current authoritative list, including the country in which each sub-processor operates, the safeguards that apply to any international transfer and the date of any change, is published in the Trust Centre Sub-Processor Register.
We do not sell, rent, or share your personal data with any other third parties. Within the Platform, your Programme Leader can view your activity data, XP, badges and department as part of programme management; this is processing carried out by the client organisation in its role as controller.
All Platform data is hosted on IONOS infrastructure in the United Kingdom. Backups are stored in the same region. AI processing involves an international transfer to OpenAI, governed as set out in section 6 above.
The Platform supports a role-based recovery model during the 90-day retention window:
After 90 days, deactivated accounts and organisations are permanently and irreversibly deleted by automated process. Recovery is not possible after this point.
Under UK GDPR you have the right to: access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and to withdraw any consent you have given. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (the Platform does not make such decisions).
Where CyBehave is the processor, the primary contact for these rights is your organisation as controller; CyBehave will assist under the DPA. Where CyBehave is the controller (section 4), you may contact us directly at privacy@cybehave.com.
In-product self-service supports many of these rights directly: rectification via My Profile; access and portability by emailing privacy@cybehave.com or through your Programme Leader; objection to AI processing by opting out of Nudge from My Profile preferences; and human review of AI output via "Flag this response" on any Nudge reply.
The Platform uses strictly necessary cookies for authentication and session management only. We do not use tracking, advertising or analytics cookies. No cookie consent is required for strictly necessary cookies under UK GDPR, but we display a notice for transparency. See the Cookie Policy for full detail.
We implement appropriate technical and organisational measures including TLS 1.3 encryption in transit, AES-256 field-level encryption for sensitive data, JWT RS256 authentication, multi-factor authentication, role-based access controls, automated security audits, dependency scanning in the deployment pipeline and periodic independent penetration testing. The full set of controls is described in the Security and Privacy by Design document.
In its processor role, CyBehave will notify the client organisation of any personal data breach affecting that organisation's data without undue delay and in any event within seventy-two hours of becoming aware of the breach, in line with Article 33 UK GDPR and the DPA, and will provide the information the controller needs to assess and notify. In its controller role, CyBehave will make any breach notifications that fall on it directly.
The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect data from children.
We may update this Privacy Policy from time to time. Material changes will be communicated to Programme Leaders. The latest version is always available at /privacy and from the Trust Centre.
For privacy enquiries, data requests or complaints: privacy@cybehave.com. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. If your organisation is established outside the UK, you may also have the right to lodge a complaint with the supervisory authority in your jurisdiction.
Last updated: 2 June 2026. Version 2.1 (OpenAI disclosure aligned with AI Policy; audit-log retention shortened to 24 months; support-team escalation flow disclosed).
Version: 1.1 · Last updated: 13 June 2026 · Supersedes: v1.0 (17 May 2026)
Welcome to CyBehave Heroes ("the Platform"), a product of CyBehave Ltd ("CyBehave", "we", "us"). By creating an account and using the Platform, you ("you", "the Customer") agree to the following terms. If you do not agree, do not use the Platform.
1.1 By registering for an account, you confirm that you are authorised to act on behalf of your organisation and agree to these Terms and Conditions.
1.2 These terms apply to all users: Programme Leaders, Programme Team members, Security Team members, and Champions.
2.1 CyBehave Heroes is a multi-tenant SaaS platform for managing organisational Security Champion programmes. The Platform uses behavioural science frameworks (including, but not limited to, the COM-B model and the Behaviour Change Wheel) to support the development of evidence-based security culture.
2.2 Features include, but are not limited to, champion management, task assignment, pulse surveys, behavioural interventions, social network analysis, peer recognition, training courses, reporting, and gamification.
2.3 The Platform is an engagement and culture-development tool. It is not a safety-critical system, a real-time security control, an incident detection or response system, or a system of record on which the operation of your business depends. You acknowledge that the Platform is not critical to the continuity of your organisation's operations and agree not to treat it as such. This characterisation is relevant to the service levels and liability provisions below.
3.1 You are responsible for maintaining the confidentiality of your login credentials. Multi-factor authentication (MFA) is available and recommended. You must not share your account or allow unauthorised access.
3.2 Programme Leaders are responsible for the accuracy of organisational data and the management of users within their organisation.
4.1 The Platform operates a role-based access model. Role assignments are managed by Programme Leaders.
4.2 Programme Leaders have administrative control over their organisation's programme, including user management, feature configuration, and data exports.
4.3 Programme Team members assist with programme delivery.
4.4 Security Team members have read access to certain programme data and read/write access to the risk management module.
4.5 Champions participate in programme activities.
5.1 Your use of the Platform is subject to our Privacy Policy, which forms part of these terms.
5.2 The Platform collects and processes personal data necessary for service delivery, including name, email, role, department, activity data, XP scores, badge awards, peer kudos, survey responses, and login timestamps.
5.3 AI-powered features (summaries of programme data and in-app guidance and coaching) use OpenAI services with anonymised data. Full details are in the Privacy Policy and the AI Policy at section 15 below.
5.4 As between the parties, in respect of personal data processed through the Platform on your behalf, you are the controller, and CyBehave is the processor. A data processing addendum setting out the processing particulars is available on request and, where agreed, forms part of these terms.
6.1 The Platform includes gamification and recognition features (XP, tiers, badges, streaks, leaderboards, peer kudos, Champion of the Month). You acknowledge that these features measure participation and engagement only. They are not a measure of an individual's job performance, competence, or conduct, and tier promotions are automatic based on XP thresholds rather than any assessment by CyBehave.
6.2 You agree not to use Platform engagement data, whether viewed in the Platform or exported via the Reports page, as a basis for any hiring, promotion, discipline, performance review, pay, or termination decision about any individual. This obligation rests with you as the organisation deploying the Platform and is consistent with your responsibilities under the EU Artificial Intelligence Act (Regulation 2024/1689) and with section 15.6 below. CyBehave reserves the right to suspend access for any organisation found to be in material breach of this clause.
7.1 New organisations receive a 28-day free trial. After the trial, a paid subscription is required to continue using the Platform.
7.2 Subscriptions are seat-based and billed annually in advance. Cancellation takes effect at the end of the current annual billing period and no pro-rata refund is given for the unexpired part of that period, save as expressly stated in section 13.
7.3 Invoices are payable within 30 days of the invoice date. Subscriptions renew annually unless cancelled before the renewal date. If any undisputed sum is not paid by its due date, we may, without prejudice to our other rights, charge interest at the rate set by the Late Payment of Commercial Debts (Interest) Act 1998 and, after reasonable notice, suspend access until payment is received. Suspension for non-payment does not start the 90-day deactivation and recovery period in section 7.4, and your data is retained during any such suspension.
7.4 When an organisation or individual account is deactivated, the associated data is retained for 90 days in a recoverable state. Within this window: a deactivated organisation is reinstated by a CyBehave Support Administrator; a deactivated Champion account is reinstated by a Programme Leader or Programme Team member; a deactivated Security Team or Programme Team account is reinstated by a Programme Leader.
7.5 After 90 days, deactivated accounts and organisations are permanently and irreversibly deleted. Recovery is not possible after this point.
8.1 The Platform is provided on a commercially reasonable endeavours basis appropriate to a non-critical engagement tool. The service levels in this section are targets, not guarantees, and do not give rise to service credits, refunds, or any right of termination except as expressly stated in section 11.
8.2 Availability. We target an availability of 99.0% measured monthly, excluding the exclusions in section 8.3. We do not commit to 100% availability and you should not rely on the Platform for time-critical activity.
8.3 Excluded downtime. Scheduled maintenance; emergency maintenance; failures of third-party services outside our reasonable control (hosting, identity, email, AI); issues arising from your own systems or misuse; and force majeure events do not count as unavailability.
8.4 Support. Support is provided by email to support@cybehave.com during UK business hours (Monday to Friday, 9am to 5pm UK time, excluding public holidays). We do not operate a 24/7 helpdesk or telephone support line. We aim to acknowledge support requests within one business day.
| Priority | Description | Target response |
|---|---|---|
| P1 - Major | Platform broadly unavailable to most users | 1 business day |
| P2 - Significant | A core feature is unavailable; a workaround may exist | 2 business days |
| P3 - Minor | Limited or cosmetic issue; minimal impact on use | 5 business days |
8.5 Backups and recovery. We take regular backups and will use commercially reasonable endeavours to restore from the most recent available backup. We do not guarantee a specific recovery point or recovery time objective. You remain responsible for exporting and retaining your own copies of your data via the Reports page.
9.1 All intellectual property rights in the Platform are owned by, or licensed to, CyBehave Ltd, including the CyBehave Technique Library, training content, the behavioural frameworks, scoring models, algorithms, analytical and AI models, underlying research and know-how, and all software, designs, interfaces, text and graphics. No rights are transferred to you; you receive only the right to use the Platform during the Term.
9.2 Certain components may be used by CyBehave under licence from third parties and remain the property of the relevant third party.
9.3 Organisations retain ownership of their own data and may export it at any time via the Reports page.
10.1 The Platform may offer Private Preview and Public Preview features, provided "as is", which may be modified or removed without notice and carry no service level or availability commitment.
10.2 To the fullest extent permitted by law, we exclude all liability arising from preview features.
11.1 You must not use the Platform to store or transmit unlawful, harmful, or offensive content, attempt to gain unauthorised access to other organisations' data, or reverse engineer or interfere with the Platform.
11.2 Violation of these terms may result in immediate account suspension.
11.3 You are responsible for all use of the Platform under your account and will indemnify CyBehave against reasonable losses arising from your breach or misuse.
12.1 The Platform is provided "as is" and "as available". To the fullest extent permitted by law, we exclude all warranties not expressly set out in these terms.
12.2 We do not warrant that the Platform will be uninterrupted, error-free, or free of harmful components, or that it will meet your specific requirements.
13.1 Nothing in these terms limits liability for death or personal injury caused by negligence, fraud, or any other liability that cannot lawfully be limited.
13.2 Subject to 13.1, we are not liable for indirect, special or consequential loss; loss of profit, revenue, business, contracts or anticipated savings; loss of goodwill; or loss or corruption of data beyond our backup-restoration obligation.
13.3 Subject to 13.1, our total aggregate liability is limited to the total fees actually paid in the 12 months immediately preceding the event giving rise to the claim. This is a single aggregate cap, not a per-claim cap.
13.4 Because billing is annual and in advance, fees counted towards the cap are those referable to the elapsed part of the current annual period plus fees paid for any earlier period within the preceding 12 months. The cap will not be less than one month's equivalent of the annual fee.
14.1 These terms apply for as long as you hold an active account or subscription (the "Term").
14.2 Only the following survive termination: accrued rights and unpaid sums; sections 9, 12, 13, 16 and 17; confidentiality for three years; data deletion duties and export rights for the 90-day recovery window; and any obligation that must survive as a matter of law.
14.3 We do not impose post-term audit rights or other continuing obligations beyond those listed in section 14.2.
15.1 The Platform's AI Policy is published at /ai-policy and is incorporated into these Terms by reference.
15.2 By enabling AI features for any user in your tenant, you acknowledge you have read the AI Policy and accept the responsibilities below.
15.3 When you enable AI features, your organisation is itself a "deployer" under the EU AI Act, responsible for deciding which roles have AI features enabled, informing your users, ensuring appropriate AI literacy (Article 4), reviewing AI-suggested outputs through human judgement, and communicating data subject rights requests to CyBehave.
15.4 Every AI feature is classified by us as limited risk under Article 50 of the EU AI Act, triggering transparency duties only. None are high-risk under Annex III or prohibited under Article 5.
15.5 The Heroes Platform uses OpenAI only. Data submitted to OpenAI's API is not used to train OpenAI's models. Anthropic appears as a CyBehave group sub-processor in the CyBehave AI Policy but is used only on the marketing site, not in the Heroes Platform.
15.6 You agree that AI outputs must not be used as the sole or principal basis for hiring, promotion, discipline, performance review, pay, or termination decisions. CyBehave reserves the right to suspend AI features for any organisation found to be in material breach of this clause.
15.7 Hard product boundaries: the Platform will not perform emotion recognition on workers, biometric categorisation, social scoring, training of any model on customer prompts or replies, or disclosure of one customer's data to another customer's AI features.
15.8 User rights are set out in section 13 of the AI Policy. You undertake not to suppress or work around these rights.
15.9 Material changes to the AI Policy will be communicated to Programme Leaders via in-app notification and reflected in the Changelog.
16.1 Force majeure. Neither party is liable for failure or delay caused by events beyond its reasonable control.
16.2 Changes to terms. We may update these terms; material changes will be communicated to Programme Leaders, and continued use constitutes acceptance.
16.3 Entire agreement and severability. These terms, with the Privacy Policy and AI Policy, are the entire agreement. Unenforceable provisions are modified or severed; the rest continue in force.
17.1 These terms are governed by the laws of England and Wales.
17.2 Any disputes are subject to the exclusive jurisdiction of the courts of England and Wales.
This Cookie Policy explains how CyBehave Heroes uses cookies and similar technologies. It applies to securitychampionsportal.com, heroes.cybehave.com, and any subdomain of cybehave.com on which the Heroes platform is served.
Cookies are small text files placed on your device by your browser when you visit a website. They are widely used to make websites work, or work more efficiently, and to provide reporting information to the site owner.
The Heroes platform uses cookies that fall into a single category: strictly necessary. These cookies are essential for the platform to function and cannot be switched off. You can configure your browser to block them, but parts of the platform will then not work.
| Cookie | Purpose | Lifetime |
|---|---|---|
| cybehave_heroes_session | Laravel session identifier. Keeps you signed in as you move between pages. | Session, with idle expiry of 120 minutes. |
| XSRF-TOKEN | Cross-site request forgery token. Protects forms and Livewire actions from forged submissions. | Session. |
| jwt_token | Authentication token (RS256 JWT) issued at sign-in. Used by the API layer to verify your identity. | Up to 24 hours, refreshed on activity. |
| cb_trusted_device | Records that this browser has passed multi-factor authentication, so we do not prompt for a code on every sign-in. Set only if you tick "trust this device" at the MFA challenge. | 30 days from last sign-in. |
| laravel_maintenance | Maintenance-mode bypass for platform administrators. Set only when an admin uses the bypass URL. | Cleared when maintenance mode ends. |
The platform uses your browser's localStorage for a small number of UI preferences (last-active programme, dismissed onboarding tour state, expanded panel state). These values stay on your device, are never transmitted to our servers, and contain no personal data. Clearing site data in your browser removes them.
UK and EU rules under PECR and the EU ePrivacy Directive require consent for non-essential cookies. Because the Heroes platform sets only strictly necessary cookies, no consent banner is required. If we add any non-essential cookie in future, we will introduce a consent mechanism before it is set and update this policy.
You can control and delete cookies through your browser. Most browsers let you refuse cookies, delete cookies already set, or be notified before a cookie is set. Detailed instructions for each major browser are at aboutcookies.org. Disabling the cookies listed in section 2 will prevent you from signing in to the Heroes platform.
We may update this policy from time to time. The current version is always available at /cookies. Material changes will be communicated to Programme Leaders through the in-app changelog.
Questions about cookies or any of our policies: privacy@cybehave.com.
Last updated: 8 May 2026. Version 1.0.
Last updated: 2 August 2026. Version 2.0. Supersedes v1.1 (2 June 2026). Aligned to Regulation (EU) 2026/1744; Annex III assessment restated in statutory language; provider role corrected; Article 50(2) content marking commitment added; individual-level measurement described in full at section 6; human review routing corrected; retention wording clarified.
This policy describes the AI features inside CyBehave Heroes (heroes.cybehave.com), how we classify them under the EU AI Act, what data leaves the platform, and who is responsible for what.
It sits beneath the CyBehave AI Policy at cybehave.com/ai-policy, which sets out our principles, our AI providers, our governance, and our position under UK and EU law. Classification is stated here rather than at group level, because classification under the Act attaches to a specific system and its intended purpose.
This policy, the Heroes Privacy Policy, and the Terms of Service form one set. Where they differ on a point of detail, the Terms of Service are the contractual instrument.
Heroes uses OpenAI models, served over the API, to power the following features.
| Feature | What it does | Who sees it |
|---|---|---|
| Nudge AI Chat | In-app coaching assistant answering questions on programme design, platform use, and behaviour change | All roles, where enabled |
| Nudge Comms Review | Behavioural review and rewrite suggestions on a draft the user has written | Champions, Programme Teams |
| Nudge Drafting | Generates communications and campaign content from a user prompt | Champions, Programme Teams |
| Nudge SNA Summary | Daily one-paragraph narrative summary of the Social Network Analysis dashboard | Programme Leaders |
| Nudge Theme Insights | Aggregated analysis of Nudge chat topics across the organisation | Programme Leaders |
| Intervention Retrospective Suggestion | Short next-step recommendation when a retrospective is filed | Programme Teams |
| Programme Summary | Periodic narrative summary of programme status | Programme Leaders |
No feature in this list assigns a task, allocates work, ranks one person against another, or produces an output about a named individual employee.
OpenAI is the only AI provider used inside Heroes. Anthropic is a CyBehave group sub-processor used on the marketing site; it is not used inside the platform and your organisation's data is not sent to it.
Risk score, XP, tier, streak, leaderboard rank, Security Culture Index, Wellbeing Score, SANS Maturity stage, programme coverage, and Social Network Analysis centrality measures are produced by deterministic formulae and by classical graph and psychometric computation.
These are not AI systems within the meaning of Article 3(1) of the EU AI Act, which requires a machine-based system that infers, from the input it receives, how to generate outputs. A published formula applied identically to identical inputs does not infer. The European Commission's guidelines on the definition of an AI system place simple statistical estimation and basic data processing outside the definition on the same reasoning.
The AI Act therefore does not reach these features. UK and EU data protection law does, and section 6 sets out how we handle them.
4.1 Prohibited practices (Article 5). No feature in Heroes falls within a prohibited practice. We do not deploy social scoring, exploitative manipulation, real-time remote biometric identification, predictive policing based solely on profiling, emotion recognition in the workplace, or biometric categorisation by sensitive attributes. The prohibitions added by Regulation (EU) 2026/1744, applying from 2 December 2026, concern content types Heroes does not generate.
4.2 Annex III. We assess that no Heroes AI feature falls within Annex III.
Point 4(b), employment and workers' management. This covers AI systems intended to be used to make decisions affecting the terms of a work-related relationship, promotion or termination; to allocate tasks based on individual behaviour or personal traits or characteristics; or to monitor and evaluate the performance and behaviour of persons in such relationships.
None of the features in section 2 is intended for any of those purposes. Nudge answers questions and drafts text. The SNA Summary, Theme Insights and Programme Summary describe programme-level and organisation-level patterns rather than individuals, and champion names are excluded from SNA summaries. The Retrospective Suggestion comments on an intervention, not on a person. No feature allocates a task, and no feature evaluates the work performance of an employee.
Point 3, education and vocational training. Heroes delivers champion development pathways. No AI feature determines access to training, evaluates a learning outcome, assigns a level, or monitors behaviour during an assessment. Where future functionality would do any of those things, it will be assessed before release and this policy updated.
We assert that these features fall outside Annex III by intended purpose. We do not rely on the Article 6(3) exemptions, and we note that those exemptions are unavailable to any system performing profiling of natural persons within the meaning of Article 4(4) GDPR.
Obligations for stand-alone Annex III systems apply from 2 December 2027 following Regulation (EU) 2026/1744. We reassess this classification at every material feature change and at each six-monthly review, and will publish an assessment under Article 6(4) if the conclusion changes.
4.3 Article 50 transparency. Every feature in section 2 carries transparency duties, which apply from 2 August 2026. We meet them through:
4.4 Our roles. For the features in section 2, CyBehave is the provider of the AI system placed on the market under its own name, and a deployer of the general-purpose AI models supplied by OpenAI. The customer organisation is the deployer of Heroes. We are not a provider of foundation models.
Champion Check-In, Team Pulse, and 360 Feedback collect ratings and reflections that the user voluntarily enters about themselves.
They do not infer emotional state from biometric data, text, voice, video, facial expression, or behavioural signals. Article 5(1)(f) prohibits inferring emotions in the workplace from biometric data. Asking a person how they feel and recording their answer is not inference, and is not within that prohibition.
We will not extend these features into voice, video, facial, or typing-pattern analysis. That is a hard boundary under section 12.
We describe this plainly because it is the question enterprise reviewers ask most often.
Heroes does hold individual-level data. XP, tier, streak, leaderboard rank, badge progress, pathway completion, and Champion of the Month are attached to named users. Individual responses to Check-In, Team Pulse, and psychometric instruments are held against the individual.
That constitutes profiling under Article 4(4) GDPR, where automated processing evaluates personal aspects of an individual. We do not claim otherwise. Our position is not that Heroes avoids individual-level measurement. It is that the measurement is consented, visible to the person it describes, derived from what that person does inside the platform and what they choose to report, and never used to assign work or judge job performance.
What we do not do:
Legal basis, transparency and rights for this processing are set out in the Heroes Privacy Policy. Individuals can see their own scores. Wellbeing Score responses are treated with the additional care described in the Privacy Policy.
Article 22 GDPR. No decision producing legal or similarly significant effects on an individual is made by automated means in Heroes.
Per Nudge interaction:
We do not send email addresses, phone numbers, risks, incidents, audit logs, individual psychometric responses, individual scores, or any data belonging to another organisation. Champion names are excluded from Nudge SNA Summaries, and personal names in free text are redacted where detected. Submitted data is not used to train OpenAI's models.
To CyBehave support, only when a user escalates a flagged response: the organisation name, the escalating role, the flag reference, and timestamps. The original message body is not included in the digest and is reviewed in-app under role-based access controls.
Article 25 note. A deployer that puts Heroes to a purpose we have not intended, in particular using it to evaluate work performance or to allocate tasks, may become a provider of a high-risk AI system in its own right and take on the corresponding obligations. The restrictions above exist to prevent that. We ask customers to raise any intended use that might approach them before implementing it.
Every AI surface carries a visible AI label. The Nudge shell shows a first-use explanation covering what Nudge does, what it sends to the model provider, and how to opt out. Generated content is marked. On request we will explain the general method by which a feature produced an output, including the model used and the inputs considered.
These are prohibited across the Heroes platform regardless of customer or user request, and no configuration can lift them:
You may also lodge a complaint with the Information Commissioner's Office at ico.org.uk or, in the EU or EEA, with your national data protection authority.
CyBehave notifies affected customer organisations within 72 hours of confirming a serious AI incident, as defined in the CyBehave AI Policy. This is separate from, and does not replace, any personal data breach notification obligation under the Data Processing Agreement.
Material changes are communicated to Programme Leaders via in-app notification and surfaced in the Changelog. The current version is always available at /ai-policy and from the Trust Centre. Superseded versions are retained and available on request.
AI policy and AI feature queries: ai@cybehave.com. Privacy queries: privacy@cybehave.com.
Last updated: 2 August 2026. Version 2.0.
This document forms an integral part of the Data Processing Agreement (DPA) between CyBehave Ltd and the client organisation (the "Controller"). It is the schedule of technical and organisational measures referenced in Section 5 and Schedule 1.G of the DPA, and the measures described here are the measures CyBehave maintains under Article 32 UK GDPR in its processor role.
It is also published as a standalone document so that prospective customers and data subjects can review the platform's security and privacy posture before signing the Terms of Service, and so the Controller can use it to support its own DPIA, supplier review and information-security questionnaires.
The Terms of Service is the master contract, incorporating the Privacy Policy, AI Policy, Cookie Policy and DPA by reference. The DPA is the Article 28 processor agreement. This document is the schedule of technical and organisational measures referenced by the DPA. The Sub-Processor Register is the live appendix referenced by Section 6 and Schedule 1.F of the DPA. Where these documents differ on contractual detail, the Terms of Service prevail; where they differ on the processing of tenant personal data, the DPA prevails.
CyBehave Heroes is a multi-tenant SaaS platform for managing organisational Security Champion programmes, operated by CyBehave Ltd. The controls described in this document apply to the production service.
The Controller is the controller of the personal data of the individuals it onboards. CyBehave acts as a processor in respect of that tenant personal data, processing it only on documented instructions under the DPA. CyBehave acts as a controller in its own right for a limited set of categories (contract and billing record, platform-wide audit logs, authentication and account-security metadata, aggregated and anonymised analytics, and direct communications with the Controller's nominated primary contact), which fall outside the DPA and are governed by the Privacy Policy.
The platform is designed against the seven foundational principles set out by the ICO for Privacy by Design: proactive not reactive; privacy as the default; privacy embedded into design; full functionality (positive-sum, with k-anonymity thresholds on team-level reporting); end-to-end lifecycle protection; visibility and transparency; and respect for user privacy.
All customer data is stored and processed in the United Kingdom. The current list of sub-processors, their country of operation, and the safeguards that apply to any international transfer is published in the Trust Centre Sub-Processor Register.
Personal data is retained for the duration of the Controller's subscription and within the Privacy Policy retention windows. Deactivated accounts and organisations enter a ninety-day recoverable window and are then permanently and irreversibly deleted. Erasure requests are processed within thirty days of approval, subject to the cooling-off period. Backups age out on a defined schedule.
The platform supports access and portability (in-app export or via the privacy address), rectification (user-editable profile fields), erasure (on request, subject to lawful-basis carve-outs), and objection/restriction (optional processing such as AI coaching can be turned off without losing core access).
The platform is hosted in a single UK region with an automated daily backup and frequent transactional log shipping, supporting point-in-time recovery. Deployments are atomic and reversible, supporting same-day rollback. Recovery time and recovery point objectives are defined in the contract Service Level Schedule.
Static analysis runs as part of the deployment pipeline; high-severity issues block release. Dependency vulnerabilities are reviewed before every release and out-of-band when a critical advisory is published. Targeted application-security review is performed on every significant feature.
CyBehave maintains an incident response process covering detection, triage, containment, eradication, recovery and post-incident review. Personal data breach notification follows Section 8 of the DPA: CyBehave notifies the Controller without undue delay and within seventy-two hours of becoming aware. In its processor role, CyBehave does not transfer the obligation to notify supervisory authorities or data subjects; that remains with the Controller, and CyBehave provides the information needed to do so.
Controls are designed in line with the UK GDPR, the Data Protection Act 2018, the NCSC Cloud Security Principles and the OWASP Application Security Verification Standard. Formal certifications, where held or in progress, are listed in the Trust Centre as they are issued.
Privacy enquiries, data requests, supplier review and DPIA support: privacy@cybehave.com. Security enquiries (vulnerability disclosure, incident notifications, security questionnaires): support@cybehave.com.
Last updated: 2 June 2026. Version 1.0.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between CyBehave Ltd ("CyBehave", the "Processor") and the client organisation that has subscribed to the CyBehave Heroes platform (the "Controller"). It governs the processing of personal data carried out by CyBehave on the Controller's behalf in connection with the Platform.
This DPA reflects Article 28 of the UK GDPR and the Data Protection Act 2018, and should be read alongside the Privacy Policy and the Security and Privacy by Design document.
In respect of Tenant Personal Data, the Controller is the controller and CyBehave is the processor. CyBehave is a controller in its own right for the categories described in section 4 of the Privacy Policy, which fall outside this DPA and are governed by the Privacy Policy.
CyBehave shall process Tenant Personal Data only on the documented instructions of the Controller, including with regard to transfers to a third country, unless required to do otherwise by UK or EU law. The Controller's documented instructions are those in the Terms of Service, this DPA, Schedule 1, and any other instructions agreed in writing. The Controller's configuration of the Platform also constitutes a documented instruction. CyBehave shall immediately inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.
CyBehave shall ensure that personnel authorised to process Tenant Personal Data have committed themselves to confidentiality. Access is granted on a need-to-know basis and is logged.
CyBehave shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 UK GDPR. The current set of measures is described in the Security and Privacy by Design document, including encryption in transit and at rest, tenant isolation, role-based access control, multi-factor authentication, immutable audit logging, dependency scanning, and a documented incident response process. CyBehave may update the measures provided any update does not materially reduce protection.
The Controller authorises CyBehave to engage the sub-processors listed in the Sub-Processor Register as at the effective date, and grants general authorisation for additional or replacement sub-processors subject to the procedure in this section. CyBehave shall notify the Controller at least thirty days before a change takes effect, through the Register and to the nominated primary contact. The Controller may object on reasonable grounds during that period; if unresolved, the Controller may terminate the affected portion of the Platform for cause. CyBehave imposes obligations on each sub-processor no less protective than this DPA and remains fully liable for sub-processor performance.
Taking into account the nature of the processing, CyBehave shall assist the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to data subject rights requests. Where a Data Subject contacts CyBehave directly, CyBehave forwards the request to the Controller without undue delay and does not respond itself unless instructed or required by law. The Platform provides in-product self-service for many rights.
CyBehave shall notify the Controller without undue delay and within seventy-two hours of becoming aware of a Personal Data Breach affecting Tenant Personal Data. The notification will include, to the extent known, the nature of the breach, likely consequences, measures taken or proposed, and the CyBehave security contact. In its processor role, CyBehave does not itself notify the ICO or affected Data Subjects; that obligation remains with the Controller, with reasonable assistance from CyBehave.
CyBehave shall provide reasonable assistance with DPIAs under Article 35 and prior consultation under Article 36 where necessary and relating to processing under this DPA. The Security and Privacy by Design document and the Sub-Processor Register are made available for this purpose, and a completed supplier security questionnaire is available on request.
On termination of the Terms of Service, CyBehave shall, at the Controller's choice, return or delete all Tenant Personal Data, save where storage is required by law. The Platform supports a ninety-day recoverable window for deactivated organisations; at the end of that window, data is permanently and irreversibly deleted. The Controller may request an export at any time during the subscription. After permanent deletion, recovery is not possible.
CyBehave shall make available all information necessary to demonstrate compliance with Article 28 UK GDPR and this DPA. CyBehave will contribute to a Controller's audit on at least thirty days' written notice, no more than once in any twelve-month period (except after a confirmed breach), during normal business hours, without disrupting the Platform or compromising other customers' security, and at the Controller's cost. CyBehave may decline access to information that would compromise other customers' security or is subject to legal privilege.
Tenant Personal Data is hosted in the United Kingdom. Where a sub-processor is located outside the UK, CyBehave shall ensure an appropriate Article 46 safeguard is in place, including the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, together with any required supplementary measures.
The liability of each party under this DPA is subject to the liability provisions in the Terms of Service.
This DPA takes effect when the Controller accepts the Terms of Service and remains in force for as long as CyBehave processes Tenant Personal Data on the Controller's behalf. Termination of the Terms of Service automatically terminates this DPA, subject to surviving obligations relating to return and deletion of data, confidentiality and audit.
In the event of conflict between the Terms of Service and this DPA in relation to the processing of Tenant Personal Data, this DPA prevails. CyBehave may update this DPA provided any update does not materially reduce protection; material updates are communicated to the nominated primary contact at least thirty days before they take effect.
This DPA is governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction.
Data protection enquiries, audit and DPIA support: privacy@cybehave.com. Security enquiries, vulnerability disclosure, breach notifications and security questionnaires: security@cybehave.com.
A. Subject matter. The processing of Tenant Personal Data by CyBehave as processor on behalf of the Controller in connection with the operation of the CyBehave Heroes platform for the Controller's Security Champion programme.
B. Duration. For the duration of the Controller's subscription, plus the ninety-day recoverable window following deactivation, after which Tenant Personal Data is permanently and irreversibly deleted.
C. Nature and purpose. Hosting, storing, organising, structuring, retrieving, consulting, transmitting, disseminating within the Controller's tenant, restricting, erasing and destroying Tenant Personal Data for the purpose of running the Controller's Security Champion programme, including account management, programme task tracking, gamification, 360 feedback, social network analysis, survey and Team Pulse administration, community posts, risk reporting, intervention design, programme communications and AI-assisted coaching where enabled.
D. Categories of personal data. Account data (name, work email, job title, department, location, organisation name); activity data (login timestamps, task completions, survey responses, badge awards, XP scores, tier progression, login streaks, peer kudos); profile data (bio, skills, avatar, influence-network mappings, 360 feedback responses); content data (community posts, risk reports, intervention designs, communication drafts, Nudge AI conversations); technical data (IP address at sign-in, session tokens, MFA state). The Platform does not collect special category personal data, payment card data, advertising identifiers or device fingerprints.
E. Categories of data subjects. Champions and other named users, Programme Team members, Security Team members and Programme Leaders, typically employees, contractors or other authorised personnel of the Controller.
F. Sub-processors. As set out in the Sub-Processor Register, and as updated from time to time in accordance with section 6.
G. Security measures. As described in the Security and Privacy by Design document, including encryption in transit and at rest, tenant isolation, role-based access control, multi-factor authentication, immutable audit logging, automated retention enforcement, dependency scanning and a documented incident response process.
Last updated: 22 May 2026. Version 1.0.
The following third-party data processors support the delivery of the CyBehave Heroes platform.
| Sub-processor | Purpose | Location | Data categories | Contract |
|---|---|---|---|---|
| ActiveCampaign LLC (Postmark) | Transactional email delivery (invitations, MFA codes, password resets, billing notices, programme broadcasts) | USA (EU SCCs in place) | recipient_email, email_subject, email_body, bounce_events | May 2026 |
| GitHub Inc. | Source-code hosting and CI/CD | USA | no_customer_data | Sep 2024 |
| Intuit Limited (QuickBooks) | Accounting and invoicing - raising and processing purchase-order invoices for subscription billing | United Kingdom (contracting entity); USA processing under the UK International Data Transfer Addendum and Standard Contractual Clauses | billing_contact, company_name, billing_address, vat_number, purchase_order_reference, invoice_history | Aug 2026 |
| IONOS SE | Cloud hosting platform for the website and application platform | United Kingdom | all_application_data | Sep 2024 |
| OpenAI, OpCo LLC | AI coaching assistant (Nudge) - chat completion only, no training | USA | chat_messages, org_name, user_role | Sep 2025 |
| Stripe Payments Europe, Ltd. | Card payment processing for subscription payments (excludes the purchase order route) | Ireland (UK/EU data processing) | billing_contact, payment_reference, card_token, last_four_digits, invoice_history | Jul 2026 |
| Tide Platform Ltd. | Business banking and payment processing for subscription invoices | United Kingdom | billing_contact, payment_reference, invoice_history | Apr 2026 |
The Sub-Processor Register is the live appendix referenced by Section 6 and Schedule 1.F of the DPA. CyBehave notifies the Controller of any intended addition or replacement of a sub-processor at least thirty days before the change takes effect.
Last updated: 5 August 2026. Version 1.2.
This is a public summary of the Data Protection Impact Assessment (DPIA) that CyBehave maintains for the AI features in the CyBehave Heroes platform. It is provided to support customer due diligence, supplier review and DPIA work by controllers. Operational and security-sensitive detail has been omitted; the full assessment is available to customers under NDA on request.
We carried out a DPIA because the AI features process personal data of identifiable workplace users, generate written suggestions that can influence engagement and intervention decisions, transmit a minimised set of data to a sub-processor outside the UK and EEA, and use generative AI, a relatively new technology. Conducting a DPIA is consistent with UK GDPR Article 35 and with our transparency duties under Article 50 of the EU AI Act.
We do not classify these features as high risk under the EU AI Act. There is no biometric identification, no emotion recognition, no social scoring and no automated employment decision-making. Our Terms of Service explicitly prohibit using AI outputs as the sole or principal basis for hiring, promotion, discipline, pay or termination decisions.
The customer organisation is the controller for the personal data of the individuals it onboards. CyBehave Ltd is the processor operating the Platform. OpenAI acts as a sub-processor providing the underlying AI model. Full detail of these roles is set out in the Privacy Policy and the Data Processing Agreement.
The DPIA covers the AI features described in the AI Policy: Nudge AI chat, communications review, social network analysis (SNA) summary, theme insights, intervention retrospective suggestion, and programme summaries. Each feature calls a third-party AI model over an encrypted connection and returns text to authenticated users within a single customer tenant.
Nudge AI chat is provided as part of the contracted service (Article 6(1)(b)). The analytical features (communications review, SNA summary, theme insights, retrospective suggestion and programme summary) rely on legitimate interests (Article 6(1)(f)), balanced against the data minimisation we apply. Our legitimate interests assessment concludes that the impact on individuals is low because direct identifiers are not transmitted, AI outputs are advisory rather than determinative, and a per-user opt-out is available. No special category data is intentionally processed, and the Platform is a workforce product not directed at children.
Several layers of minimisation are applied before any data leaves our environment:
The data involved is limited to: a role label; the organisation name (chat only); free-text the user chooses to type; and aggregated behavioural and engagement metrics. Direct identifiers and special category data are not sent to the AI model. The Platform does not process children's data.
AI model inference involves a transfer to OpenAI in the United States. Transfers are governed by the EU-US Data Privacy Framework where applicable, with Standard Contractual Clauses as a fallback, and the UK International Data Transfer Addendum for UK exporters. Our transfer impact assessment concludes the transfer is lawful and the residual risk acceptable, on the basis that no direct identifiers and no special category data are transferred, the payload is minimised, data is encrypted in transit, and submitted data is not used to train the provider's models.
The DPIA assesses a set of risks to individuals and the controls that reduce them. In summary:
AI usage telemetry is retained for 12 months and then automatically purged. Nudge conversation content is kept for the life of the conversation, can be deleted by the user from the Nudge interface, and is removed under the 90-day deactivation window described in the Privacy Policy. Short-lived caches expire automatically. Backups follow the platform-wide backup schedule.
The rights mechanism described in the Privacy Policy covers AI processing. Users can access their own AI conversation history, delete their Nudge conversations in-app, object to AI processing through a per-user opt-out in their profile, and request human review of any AI output using "Flag this response".
After mitigations, the residual risk to individuals is assessed as low to medium-low across the assessment. AI outputs in CyBehave Heroes are advisory, scoped to a single tenant, do not drive automated decisions about individuals, and are subject to human override through per-user opt-out, response flagging and the contractual prohibition on HR use. Processing may proceed, and prior consultation with the supervisory authority is not required. The DPIA is reviewed at least annually and whenever an AI feature materially changes.
DPIA, supplier review and due-diligence requests: privacy@cybehave.com. AI feature queries: ai@cybehave.com.
Public summary. Last updated: 20 June 2026. Version 1.0. The full DPIA is available to customers under NDA.
CyBehave is a behavioural cybersecurity research organisation and SaaS platform provider registered in England and Wales. Contact: privacy@cybehave.com.
We process personal data under the following legal bases under UK GDPR:
We do not sell your personal data. We share data only with service providers under data processing agreements and with law enforcement where legally required. All data is stored on UK-based infrastructure.
Platform account data is retained for the duration of your account and for 90 days following deletion. Contact form submissions are retained for 12 months. Financial records are retained for 7 years in accordance with legal requirements.
Under UK GDPR you have the right to: access your personal data; correct inaccurate data; request erasure; restrict or object to processing; data portability; and to withdraw consent. Contact privacy@cybehave.com to exercise any right. You may also complain to the Information Commissioner's Office (ICO).
We use strictly necessary cookies for session management. Optional analytics cookies are only set with your consent. See our Cookie Policy for full details.
Privacy queries: privacy@cybehave.com. General enquiries: see the Contact page on cybehave.com.
Last updated: 1 May 2026. Version 1.0.
Cookies are small text files placed on your device when you visit a website. They allow the site to remember your preferences and understand how you use it.
These cookies are essential for the platform to function. They are set in response to your actions such as logging in or filling in a form and cannot be disabled.
| Cookie | Purpose | Expires |
|---|---|---|
| cybehave_session | Maintains your logged-in session | Session |
| cb_admin | Admin authentication token | Session |
We use our own analytics system - aggregate and anonymised, not shared with third parties. Only set with your consent.
| Cookie | Purpose | Expires |
|---|---|---|
| cb_visitor | Anonymous visitor tracking for our own analytics | 30 days |
You can control and delete cookies through your browser settings. Disabling strictly necessary cookies will prevent you from logging in to Heroes. Browser guides are available for Google Chrome, Mozilla Firefox, Apple Safari, and Microsoft Edge.
Questions: privacy@cybehave.com.
Last updated: 1 May 2026. Version 1.0.
Last updated: 2 August 2026. Version 2.0. Supersedes v1.0 (1 May 2026). Restructured as an organisational policy: product feature detail and per-product risk classification now sit in each product AI policy; internal use, AI-assisted development, procurement, the AI System Register and AI literacy added; aligned to Regulation (EU) 2026/1744.
CyBehave Ltd is a behavioural cybersecurity research organisation and SaaS provider registered in England and Wales, company number 16819297.
This is our organisational AI policy. It sets out the principles we hold ourselves to, how we use AI inside the business, who our AI providers are, how we govern AI decisions, and where we sit under UK and EU law.
It does not describe the AI features inside any individual product. Each CyBehave product publishes its own AI policy covering its feature inventory, its risk classification under the EU AI Act, the data sent to model providers, retention, and the split of responsibility between CyBehave and the customer:
Where this policy and a product AI policy differ on a point of product detail, the product policy governs. Where a product policy is silent, this policy applies. Where either differs from the applicable Terms of Service, the Terms of Service are the contractual instrument.
Classification under the EU AI Act attaches to a specific system and its intended purpose. It cannot be asserted once for a whole company. We therefore publish the method here and the result in each product policy.
For every AI feature we build, we record:
The result is held in our internal AI System Register and summarised in the relevant product policy.
4.1 Marketing site (cybehave.com).
Content substantially generated by AI carries a visible indication. Where we publish text intended to inform the public on a matter of public interest, we disclose AI generation in line with Article 50(4).
4.2 Product development. We use AI-assisted coding tools in the development of CyBehave products. AI-generated code is reviewed by a human before merge on the same basis as any other contribution. Credentials, secrets, customer data and production data are not provided to AI coding tools. Dependencies suggested by AI tools are verified against the package registry before adoption. AI-assisted development is in scope for our secure development practices and for supplier assurance questionnaires.
4.3 Internal business operations. Staff and contractors may use approved AI assistants for drafting, research, summarisation and analysis. Customer personal data, platform production data, and material received under confidentiality from a third party must not be entered into a general-purpose AI assistant that is not an approved sub-processor for that purpose. Output relied on externally is verified before use. New AI tools require approval under section 8 before they touch any CyBehave or customer data.
4.4 Research. Our research programmes, including SHIELD and Behavioural Convergence Theory, examine how behavioural science frameworks apply to human and to agentic AI behaviour. AI tools may be used for literature review, data analysis, drafting and visualisation, with authorship and interpretation remaining with the named researchers. Research involving human participants follows separate ethics, consent and data protection processes approved before recruitment, and where the work forms part of doctoral study, under the ethics governance of the sponsoring institution. Participant data is not entered into AI tools unless the approved ethics protocol expressly permits it. We do not conduct research on AI systems in ways that would breach the safety or acceptable use policies published by the underlying model provider.
We use established providers under contractual data processing terms. The authoritative list, including processing purpose, location and transfer safeguards, is the Sub-Processor Register in this Trust Centre. In summary:
Provider terms exclude API inputs from being used to train the underlying models by default. We select providers on stated data handling commitments, hosting location and transfer safeguards appropriate to UK GDPR, published safety and acceptable use policies, and operational security posture.
We do not train our own foundation models on customer or user data. Where we develop AI features in-house, training and tuning use synthetic data, public datasets, or data we hold explicit rights to use. Changes to the register are reflected in the Trust Centre and communicated to customers in line with the Data Processing Agreement.
6.1 EU AI Act. Regulation (EU) 2024/1689 (the AI Act) was amended by Regulation (EU) 2026/1744 (the Digital Omnibus on AI), which entered into force on 27 July 2026. The dates we plan against are:
| Date | What applies |
|---|---|
| 2 February 2025 | Article 5 prohibited practices; general provisions |
| 2 August 2025 | Obligations on providers of general-purpose AI models |
| 2 August 2026 | Article 50 transparency obligations; national market surveillance and enforcement powers |
| 2 December 2026 | Article 50(2) machine-readable marking for systems placed on the market before 2 August 2026; new Article 5 prohibitions covering non-consensual intimate imagery and AI-generated child sexual abuse material |
| 2 August 2027 | National regulatory sandboxes operational |
| 2 December 2027 | Obligations for stand-alone high-risk systems under Annex III |
| 2 August 2028 | Obligations for high-risk systems embedded in products under Annex I |
We treat 2 December 2027 as a planning date rather than a start date. Where a product would be affected, the assessment work is done in advance and published in that product's policy. As an SME we may rely on the proportionate measures available under the Act, including simplified technical documentation and proportionate quality management requirements. We do not treat that as a reduction in substantive obligations.
6.2 Our roles under the Act. We hold different roles for different systems and record them per feature.
We are not a provider of foundation models.
6.3 United Kingdom. The UK has no single statutory equivalent to the AI Act. We align with UK GDPR and the Data Protection Act 2018, enforced by the ICO, including its guidance on AI and data protection and on automated decision-making and the right to human review; the five cross-sectoral AI principles of safety, security and robustness, appropriate transparency and explainability, fairness, accountability and governance, and contestability and redress; the Equality Act 2010, to avoid AI-driven outcomes that produce unlawful discrimination; and NCSC guidance on the secure development and deployment of AI systems. Where EU AI Act standards are stricter than UK requirements, we apply the EU standard as our baseline. Where the UK introduces statutory AI legislation, we will reassess this policy.
The following are prohibited across all CyBehave properties and products, regardless of customer or user request, and no configuration can lift them:
Ownership. This policy is owned by the CyBehave AI Governance function. Every AI feature has a named human owner recorded in the AI System Register.
AI System Register. We maintain an internal register covering every AI feature across all CyBehave products and internal uses. Each entry records the intended purpose, the model and provider, the Article 3(1) determination, the Annex I and Annex III assessment, the Article 50 determination, our role, the data sent to the provider, the named owner, and the date of last review.
Approving new AI use. A new AI feature, tool, or provider is approved before it touches CyBehave or customer data. Approval requires a completed register entry, a data protection assessment where personal data is involved, and confirmation of the provider's training-data and retention terms.
Review. This policy and the register are reviewed at least every 6 months, and additionally whenever we introduce or materially change an AI feature, add or replace an AI provider, applicable law or regulatory guidance changes, or an incident or near-miss prompts review. A change in EU AI Act application dates is an explicit trigger.
Article 4 of the AI Act, as amended by Regulation (EU) 2026/1744, requires providers and deployers to take measures supporting the development of AI literacy among staff and others operating AI systems on their behalf. We meet this through induction covering our AI principles, this policy and the approved tool list; role-specific guidance for engineering, research and customer-facing staff; an annual refresh, with additional briefing whenever a new AI feature or provider is introduced; and a record of completion held with the AI System Register.
We support customer AI literacy through product documentation, though responsibility for literacy among a customer's own staff rests with that customer as deployer.
By default, content submitted to AI-powered features on our properties is not used to train third-party AI models. Where AI features process personal data we apply the same legal bases, retention rules and security controls described in our Privacy Policy. We minimise the personal data sent to AI providers and, where feasible, send only anonymised, aggregated, or synthetic inputs.
A serious AI incident means confirmed disclosure of personal data through an AI feature, a confirmed cross-tenant data leak, a confirmed jailbreak that produced policy-violating content visible to a user, output that caused or could reasonably cause harm to a person, or receipt of a regulatory notice concerning our AI use.
We notify affected customer organisations within 72 hours of confirming a serious AI incident, alongside any separate obligation to notify a supervisory authority under UK GDPR. Incidents are recorded against the AI System Register entry and reviewed at the next governance cycle.
In addition to your rights under UK GDPR, described in the Privacy Policy:
Contact ai@cybehave.com or privacy@cybehave.com. You may also raise concerns with the ICO at ico.org.uk or, in the EU or EEA, with your national data protection authority.
Material changes are reflected in the version number and last-updated date, published in the Trust Centre, and communicated to registered customers by email. Superseded versions are retained and available on request.
AI policy and AI feature queries: ai@cybehave.com. Privacy queries: privacy@cybehave.com. General enquiries: see the Contact page on cybehave.com.
Last updated: 2 August 2026. Version 2.0.