We will not sell your data. 1600 Cyber is committed to protecting the privacy of its clients, training participants, website visitors, and business contacts. This Policy explains what data we collect, why we collect it, and your rights over it.
1. Data Controller Identity and Contact
1600 Cyber operates www.1600cyber.com and is the data controller for Personal Data collected through this website and through our client and training engagements.
Data Controller: 1600 Cyber GmbH (EU) and 1600 Cyber America (US), jointly doing business as 1600 Cyber.
EU Registered Office: Rossmarkt 21, 60311 Frankfurt am Main, Germany.
US Registered Office: 355 South Grand Avenue, Los Angeles, CA 90071, USA.
Data Protection Officer (DPO) / Privacy Contact: privacy@1600cyber.com. EU and UK residents may contact the DPO directly for all data protection enquiries.
EU Representative (GDPR Article 27): 1600 Cyber GmbH, Frankfurt, Germany. Contact: privacy-eu@1600cyber.com.
2. Who This Privacy Policy Covers
This Policy applies to Personal Data collected from the following categories of individuals:
- B2B clients and their employees, officers, and contractors who interact with 1600 Cyber in connection with consultancy, managed security, or advisory engagements;
- Individual training course buyers and corporate training participants who enrol in 1600 Cyber training programmes through the Platform or through Reed.co.uk;
- Website visitors who browse www.1600cyber.com;
- Business contacts, prospects, event attendees, and individuals who communicate with 1600 Cyber by email, telephone, or at industry events.
Where 1600 Cyber processes Personal Data on behalf of a B2B client as a data processor (for example, processing client employee data in the course of a security assessment), such processing is governed by the applicable Data Processing Agreement, not by this Policy.
3. What Personal Data We Collect and Why
3.1 Client and Engagement Data
- Contact information: names, job titles, business email addresses, telephone numbers, and business addresses of client contacts and authorised users.
- Contractual data: information contained in SOWs, proposals, and engagement letters, including scope of services, fees, and deliverable specifications.
- Technical data provided during security engagements: IP address ranges, system architecture information, and network diagrams provided by the Client for the purpose of scoping and performing security assessments. This data is treated as Client Confidential Information of the highest sensitivity.
3.2 Training and Course Data
- Enrolment data: name, email address, employer name, job role, and course selection.
- Learning data: course progress, assessment scores, completion status, and certification records.
- Payment data: billing name, address, and payment method details. Full card numbers are processed by our payment provider and are not stored by 1600 Cyber.
3.3 Website and Technical Data
- Log data: IP address, browser type and version, device type, operating system, and referring URL.
- Usage data: pages visited, time on page, navigation paths, and feature interactions.
- Cookie data: as described in Section 8 (Cookie Policy).
3.4 Marketing and Business Development Data
- Business contact data: name, title, company, email, and telephone of prospects and event contacts obtained with consent or under legitimate interests for B2B marketing.
- Communications data: records of email, telephone, and meeting interactions with prospects and clients.
4. Legal Basis for Processing (GDPR)
For individuals in the EEA, UK, or Switzerland, we process Personal Data on the following lawful bases under GDPR Article 6:
Contract (Article 6(1)(b)): Processing necessary to enter into or perform a contract with the Client or individual course buyer, including delivering training, issuing invoices, and providing support.
Legitimate Interests (Article 6(1)(f)): Processing for B2B marketing to existing and prospective business clients, fraud prevention, information security, improving our services, and maintaining business records. We conduct and document legitimate interest assessments (LIAs) for all legitimate interest processing. You may request details of our LIAs at privacy@1600cyber.com.
Legal Obligation (Article 6(1)(c)): Processing required to comply with German, EU, UK, or US legal obligations, including tax, accounting, anti-money-laundering, and export control requirements.
Consent (Article 6(1)(a)): Processing for consumer-facing marketing communications and non-essential cookies. Consent may be withdrawn at any time without affecting the lawfulness of prior processing.
5. How We Use Personal Data
- Delivering Services: managing engagements, providing consultancy output, delivering training, processing payments, and providing client support.
- Business communications: sending invoices, engagement updates, project communications, and service-related notifications.
- B2B marketing: contacting existing and prospective business clients about relevant services, events, and thought leadership content (on the basis of legitimate interests for B2B contacts, or consent where required).
- Platform improvement: analysing usage data to improve the functionality and content of www.1600cyber.com.
- Compliance: maintaining records required by applicable law and responding to lawful requests from regulatory authorities.
- Security: protecting 1600 Cyber systems, clients, and data against unauthorised access, cyberattacks, and fraud.
We do not use client engagement data or security assessment findings for any purpose other than delivering the agreed Services without explicit written consent.
6. Who We Share Personal Data With
We do not sell, rent, or lease your Personal Data. We share data only in the following circumstances:
- Sub-processors: Trusted third-party vendors providing services such as cloud hosting, learning management systems, payment processing, email delivery, and CRM. All sub-processors are subject to data processing agreements requiring appropriate data protection standards.
- Reed.co.uk: Where courses are listed and purchased through Reed, enrolment data is shared with Reed subject to Reed’s own privacy policy. Participants should review Reed’s privacy policy at reed.co.uk.
- Professional advisors: Legal counsel, accountants, and auditors who are bound by professional confidentiality obligations.
- Regulatory and law enforcement: Where required by applicable law, court order, or government authority.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with advance notice provided to affected individuals.
- Yours AI (1600 Cyber affiliate): 1600 Cyber and Yours AI share common ownership and infrastructure. Where a client or individual is referred between the two platforms, data sharing is limited to what is necessary for the referral purpose and is governed by appropriate internal data sharing agreements.
7. International Data Transfers
1600 Cyber operates across the EU (Germany) and the US. Data may be transferred between these jurisdictions and to sub-processors located in third countries.
For transfers from the EEA or UK to the US or other third countries lacking an adequacy decision, we rely on:
- Standard Contractual Clauses (SCCs) adopted by the European Commission under Regulation (EU) 2016/679, as updated;
- The EU-US Data Privacy Framework where applicable;
- Transfer Impact Assessments conducted prior to transfers to high-risk jurisdictions;
- Supplementary technical measures (including encryption and pseudonymisation) where assessed as necessary.
You may request details of applicable transfer safeguards by contacting privacy@1600cyber.com.
8. Cookie Policy
8.1 Our Approach to Cookies
We do not place non-essential cookies on your device without your prior, freely-given, specific, informed, and unambiguous consent as required by the GDPR and ePrivacy Directive. You can manage your cookie preferences at any time through our cookie settings panel. B2B website visitors are subject to the same cookie consent requirements as individual users.
8.2 Cookies We Use
- Strictly Necessary (no consent required): Session management, authentication, security, and cookie preference storage. Cannot be disabled as they are essential to Platform operation.
- Functional (consent required): Remembering your preferences, language settings, and login state between sessions.
- Analytics (consent required): Aggregated, anonymised data on how visitors use the Platform — page visits, navigation, and session duration. Used solely to improve Platform performance.
- Marketing / Targeting (consent required): Cookies that track visits across websites to deliver relevant advertising. Given our B2B focus, use of targeting cookies is limited and always requires your prior consent.
8.3 Managing Cookies
Update your preferences at any time through the cookie settings panel on our Platform, or through your browser settings. Note that disabling strictly necessary cookies will impair Platform functionality.
9. Data Retention
Client and engagement records: Duration of the client relationship plus 7 years (for tax, accounting, and legal purposes under German and US law).
Security assessment findings: As specified in the SOW; typically deleted or returned to the Client within 90 days of engagement close unless retention is required for legal proceedings.
Training and certification records: 7 years from completion (to support certificate verification requests).
Marketing contact data: Until you withdraw consent or opt out, or 3 years from last meaningful interaction, whichever is sooner.
Website log data: 12 months.
10. Your Data Protection Rights
10.1 Rights Under GDPR (EEA, UK, Switzerland)
You have the right to: access your Personal Data (Article 15); rectify inaccurate data (Article 16); request erasure where data is no longer necessary (Article 17); restrict processing in certain circumstances (Article 18); data portability in a structured, machine-readable format (Article 20); object to processing based on legitimate interests or for direct marketing (Article 21); and withdraw consent at any time without affecting prior processing (Article 7(3)).
Submit requests to privacy@1600cyber.com. We respond within 30 days (extendable by 60 days for complex requests with notice). We will verify your identity before fulfilling requests. No fee is charged for reasonable requests. You have the right to complain to your local supervisory authority: in Germany, the Berliner Beauftragte für Datenschutz; in the UK, the Information Commissioner’s Office (ico.org.uk).
10.2 Rights Under California Law (CCPA / CPRA)
California residents have the right to: know what Personal Information we collect and how we use it; delete Personal Information (subject to exceptions); correct inaccurate Personal Information; opt out of the sale or sharing of Personal Information (1600 Cyber does not sell Personal Information); limit use of Sensitive Personal Information; and be free from discrimination for exercising CCPA/CPRA rights. Submit requests to privacy@1600cyber.com. We respond within 45 days (extendable by 45 days with notice).
10.3 B2B Contact Opt-Out
Business contacts who receive B2B marketing communications may opt out at any time by clicking the unsubscribe link in any email or by contacting privacy@1600cyber.com. We will action opt-out requests within 10 business days.
Your California Privacy Rights (CPRA Notice)
Right to Opt-Out of the Sale or Sharing of Personal Information
Under the California Privacy Rights Act (CPRA), California residents have the right to opt-out of the “sale” or “sharing” of their personal information to third parties, including sharing for cross-context behavioral advertising.
1600 Cyber does not sell your personal data for money. However, like many online services, we may share certain information with analytics and advertising partners to improve your experience and show you relevant content. This sharing may be considered a “sale” or “sharing” under California law.
How to Exercise Your Right to Opt-Out
You can exercise your right to opt-out immediately through any of the following methods:
- Do Not Sell or Share button: Use the button below to opt this browser out of the sale and sharing of your personal information.
- Global Privacy Control (GPC): We recognize Global Privacy Control opt-out preference signals. If your browser transmits a GPC signal, our system will automatically opt you out of tracking on this device.
- Email request: Email privacy@1600cyber.com with the subject line “CPRA Do Not Sell/Share Request.”
Once you submit your request or disable tracking, we will stop selling or sharing your personal information within 15 business days.
Click below to opt this browser out of the sale and sharing of your personal information under the CCPA/CPRA.
Additional California Rights
In addition to the right to opt out of sale and sharing, California residents have the rights described in Section 10.2 above (right to know, delete, correct, limit use of Sensitive Personal Information, and non-discrimination). We will not deny goods or services, charge different prices, or provide a different level of quality because you exercised your CCPA/CPRA rights.
Authorized Agents
You may designate an authorized agent to submit CPRA requests on your behalf. We will require written authorization from you and verification of your identity before acting on the request.
11. Security Measures
1600 Cyber implements appropriate technical and organisational security measures including: TLS 1.2+ encryption in transit; AES-256 encryption at rest; role-based access controls; regular penetration testing of our own infrastructure; security awareness training for all personnel; incident response procedures; and 72-hour Personal Data breach notification to relevant supervisory authorities under GDPR Article 33. Given the nature of our business as a cybersecurity firm, we hold our own security posture to the standards we recommend to our clients.
12. Children’s Privacy
Our services are directed to business professionals and adult individual learners. We do not knowingly collect Personal Data from: (a) individuals under 13 years of age (COPPA); or (b) individuals under 16 years of age without verifiable parental consent (GDPR). If you believe a minor has provided us with Personal Data, contact privacy@1600cyber.com and we will promptly delete it.
13. Updates to This Privacy Policy
We may update this Policy periodically. Material changes will be notified by email and posted on the Platform with at least 30 days’ advance notice. The effective date will be updated with each revision. Prior versions are available on request.
14. Contact and Complaints
Privacy and data protection enquiries:
- Email: privacy@1600cyber.com
- EU DPO: Rossmarkt 21, 60311 Frankfurt am Main, Germany
- US Privacy: 355 South Grand Avenue, Los Angeles, CA 90071, USA
If you are not satisfied with our handling of your request, you have the right to lodge a complaint with your local data protection authority.