Effective Date: May, 1st 2023
Company: Armada Cyber Defense LLC, d/b/a CyberComply
Contact: support@cybercomply.us | Office: (305) 306-1800

This Privacy Policy describes how CyberComply (“we,” “us,” or “our”) collects, uses, discloses, and protects personal information of subscribers and visitors (“you” or “your”) when using the CyberComply CMMC GRC SaaS platform (“Platform” or “Service”).

By using our Service, you consent to the practices described in this Privacy Policy.

1. Information We Collect

We collect limited categories of information in order to provide, maintain, and improve the Platform:

a. Information You Provide

  • Account Information: Name, email address, phone number, company name, and billing details.

  • Subscription Data: Plan type, payment history, and preferences.

  • Uploaded Content: Policies, procedures, reports, or other compliance-related materials you choose to store in the Platform (excluding CUI and FCI, which must not be uploaded).

  • Support Requests: Communications with our support team.

b. Automatically Collected Information

  • Log Data: IP address, browser type, operating system, access times, and activity within the Platform.

  • Cookies & Tracking Technologies: Session cookies, authentication tokens, and analytics tools to enhance usability.

c. Third-Party Sources

  • Payment processors (e.g., Stripe) for billing verification.

  • Cloud service providers (e.g., AWS) for secure hosting.

2. How We Use Information

We use your information for the following purposes:

  • Service Delivery: To provide access, authentication, and account management.

  • Compliance Management: To help you perform self-assessments, track compliance, and generate reports.

  • Customer Support: To respond to questions, troubleshoot issues, and provide updates.

  • Billing & Transactions: To process payments and manage subscription renewals.

  • Security & Legal Obligations: To detect fraud, enforce policies, and comply with applicable laws.

  • Product Improvement: To analyze usage patterns and improve functionality.

3. Data We Do Not Collect

  • Controlled Unclassified Information (CUI) and Federal Contract Information (FCI): The Platform is not designed to store or process CUI or FCI. Customers are strictly prohibited from uploading such data.

  • Classified Data: The Service cannot host or process classified or export-controlled information.

4. Data Sharing & Disclosure

We do not sell or rent personal information. We may share limited data only in the following cases:

  • Service Providers: With third parties who assist in hosting, payment processing, and technical operations.

  • Legal Compliance: When required by law, court order, or government regulation.

  • Business Transfers: In connection with a merger, acquisition, or asset sale.

  • Security & Protection: To prevent harm, fraud, or security risks to users or the Platform.

5. Data Security

  • Hosting Environment: The Platform is hosted on AWS FedRAMP High Enclave infrastructure to align with DoD compliance needs.

  • Encryption: Data is encrypted in transit (TLS/SSL) and at rest where applicable.

  • Access Control: Role-based access, audit logging, and multifactor authentication safeguard user accounts.

  • Retention: We retain user data only for as long as necessary to provide the Service or comply with legal obligations.

6. Data Retention & Deletion

  • Account data is retained for the duration of your subscription.

  • Upon termination or cancellation, data may be retained for up to 90 days to allow retrieval before secure deletion.

  • Certain transactional records may be retained longer for tax, audit, or legal compliance.

7. Your Rights & Choices

Depending on your jurisdiction, you may have the following rights:

  • Access & Portability: Request a copy of the information we maintain about you.

  • Correction: Request corrections to inaccurate or incomplete data.

  • Deletion: Request deletion of your account and related information (subject to legal retention requirements).

  • Opt-Out: Manage cookie preferences and marketing communications.

Requests can be submitted to support@cybercomply.us.

8. Children’s Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from minors.

9. International Users

The Platform is intended for use by U.S.-based defense contractors. If you access the Service from outside the United States, you are responsible for compliance with local laws.

10. Changes to This Policy

We may update this Privacy Policy periodically. Updates will be posted on this webpage with a revised effective date. Continued use of the Service constitutes acceptance of any changes.

11. Contact Us

If you have questions about this Privacy Policy or our data handling practices, please contact us:

CyberComply – Armada Cyber Defense LLC
Email: support@cybercomply.us
Office: (305) 306-1800

Privacy Policy