1About CyberEssentia
CyberEssentia provides cybersecurity assessment, scanning and compliance services designed to help organisations understand and improve their security posture, including their readiness for Cyber Essentials and related cybersecurity standards.
This Privacy Notice explains how we collect, use, store and protect personal and organisational information when you use the CyberEssentia website, CyberEssentia Scanner and associated services.
For the purposes of UK data protection law, the organisation responsible for the CyberEssentia service is:
CyberEssentia Ltd
United Kingdom
Website: cyberessentia.com
Email: info@cyberessentia.com
2Information we collect
Depending upon the services you use, CyberEssentia may process:
- Account information — including your name, business email address, organisation and account identifiers.
- Microsoft account information — such as your Microsoft Entra user identifier, display name and organisational information required to authenticate you and connect CyberEssentia to your Microsoft environment.
- Security and configuration information — including information about your organisation's Microsoft Entra ID and Microsoft 365 configuration, directory configuration, security policies, role-based access control settings and authentication methods where you have authorised CyberEssentia to access this information.
- Technical information — such as IP address, browser information, timestamps, application logs and security events.
- Assessment information — including scan results, compliance findings, security recommendations and information you provide when completing CyberEssentia assessments.
CyberEssentia only accesses Microsoft information covered by permissions that an authorised administrator has granted to the CyberEssentia Scanner.
3Microsoft Graph and Microsoft Entra access
CyberEssentia Scanner may connect to Microsoft services using Microsoft Graph APIs.
Depending upon the permissions approved by your organisation, CyberEssentia may be permitted to read information including:
- Basic user and organisational information
- Directory information
- Directory role and role-based access control settings
- Organisational security and configuration policies
- Users' authentication-method configuration
CyberEssentia uses this access to perform cybersecurity and compliance assessments and to generate findings and recommendations for the customer.
We do not use Microsoft Graph permissions to access information for advertising or marketing purposes.
We do not sell Microsoft account, directory, authentication or security configuration data.
CyberEssentia will not request write access to your Microsoft environment unless such functionality is explicitly introduced, explained to you and separately authorised.
4How we use your information
We process information where necessary to:
- Provide the CyberEssentia service
- Authenticate users
- Perform authorised security and compliance assessments
- Identify potential cybersecurity risks and configuration weaknesses
- Generate reports and recommendations
- Maintain and secure our service
- Provide customer support
- Administer customer accounts and subscriptions
- Comply with applicable legal and regulatory obligations
Where CyberEssentia processes personal data on behalf of a customer organisation, the customer may be the data controller and CyberEssentia may act as a data processor.
5Our legal basis for processing
Where UK GDPR applies, our legal basis will depend upon the circumstances and may include performance of a contract, legitimate interests, compliance with legal obligations or consent where appropriate.
Where CyberEssentia processes personal data solely on the instructions of a customer, we process that information as a processor on behalf of that customer.
6Data minimisation
CyberEssentia follows the principle of least privilege.
We aim to request only those Microsoft permissions and other information reasonably required to perform the relevant cybersecurity assessment.
Information obtained through Microsoft APIs is used only for the CyberEssentia functionality for which access was granted.
7Data storage and retention
We retain personal and organisational information only for as long as reasonably necessary to provide our services, meet contractual requirements, maintain appropriate audit records and comply with legal obligations.
Security assessment information and scan results may be retained for the duration of the customer's account and for a limited period afterwards where required for security, backup, audit or legal purposes.
Where technically and legally possible, customers may request deletion of their information.
8Sharing information
CyberEssentia does not sell personal information.
We may use carefully selected service providers to operate our infrastructure and deliver the CyberEssentia service. These providers may process information only where necessary to provide their services to us and are required to protect that information appropriately.
We may also disclose information where required by law or where reasonably necessary to protect the security, rights or property of CyberEssentia, our customers or others.
9International transfers
Where information is processed outside the United Kingdom, CyberEssentia will use appropriate safeguards required by applicable data protection legislation.
10Security
CyberEssentia uses appropriate technical and organisational measures designed to protect information against unauthorised access, alteration, disclosure, loss or destruction.
Access to customer security information is restricted to authorised systems and personnel where required for legitimate business purposes.
11Revoking Microsoft access
A customer's Microsoft 365 or Entra administrator may revoke CyberEssentia Scanner's access through Microsoft Entra ID.
Revoking access prevents CyberEssentia from making future requests to Microsoft using the revoked authorisation. Information previously obtained may continue to be retained where necessary under our retention policy or applicable legal requirements.
12Your data protection rights
Depending upon applicable law, individuals may have rights including access to personal information, correction of inaccurate information, deletion, restriction of processing, objection to processing and data portability.
Requests can be submitted to: info@cyberessentia.com
You also have the right to raise concerns with the UK Information Commissioner's Office.
13Changes to this Privacy Notice
We may update this Privacy Notice as CyberEssentia develops or where legal or regulatory requirements change. The current version will be published on our website with the date of the latest revision.