PRIVACY POLICY

Kaavalan Limited (trading as CyberCheck360)

Last updated: May 2026

This policy covers everything under the CyberCheck360 name: our website at cybercheck360.com, the Email Security Platform, the Threat Intelligence Platform, Email Link Security, Dynamic Threat Protection, our Gmail add-on, our Outlook add-in, and our Chrome and Firefox browser extensions.

If you have questions about anything in here, please email us at privacy@cybercheck360.com. We are a small team and we will get back to you properly.


A quick summary before we get into the detail

We are Kaavalan Limited, an Irish company that builds security tools under the CyberCheck360 brand. Our job is to help organisations spot and block phishing emails, malicious links, and other cyber threats before they cause damage.

To do that, we need to process certain information. This policy explains what we collect, why we collect it, who can see it, and what your rights are. We have tried to write it in plain language rather than legalese, because we think you deserve to actually understand it.

A few things worth knowing upfront:


Table of Contents

  1. What information do we collect?
  2. How do we use your information?
  3. What is our legal basis for processing your information?
  4. Who do we share your information with?
  5. Do we use cookies and tracking technologies?
  6. Do we use artificial intelligence?
  7. How long do we keep your information?
  8. How do we keep your information safe?
  9. Do we collect information from children?
  10. What are your privacy rights?
  11. Do-not-track signals
  12. Rights for US residents
  13. Google API services: user data disclosure
  14. Changes to this policy
  15. How to contact us
  16. How to access, update, or delete your data

1. What information do we collect?

Information you give us directly

When you create an account or get in touch with us, we collect:

Information collected through our products

What we collect depends on which product you use. Read the section that applies to you.

Our website and free tools

When you visit cybercheck360.com or use our free scanning tools without an account, we collect:

Email Security: Outlook add-in

When you open an email in Outlook with our add-in running, it checks that email for threats. It reads:

The add-in only looks at the email you have open in front of you. It does not read anything else in your inbox.

Email Security: Gmail add-on

Our Gmail add-on works in the same way as the Outlook version, but it connects to your Gmail account using four specific permissions that Google requires us to declare. Here is exactly what each permission does and does not allow:

PermissionWhat it allowsHow we use itWhat we never do with it
gmail.addons.executeRuns our add-on inside GmailOpens our panel when you click itNothing is read by this permission on its own
gmail.addons.current.message.metadataReads information about the email you have openWe read the routing headers, subject line, sender, recipients, and attachment details such as name, size, type, and fingerprintWe cannot and do not read the email body via this permission
gmail.addons.current.message.readonlyReads the full content of the email you have openWe use this to extract links from the email body locally, inside the add-on. Only the links are sent to our servers, not the email text. We also use this when you choose to report an email, but only after you give your explicit consent.The email body is never sent to our servers unless you actively choose to report the email and tick the consent checkbox
script.external_requestSends information to external servicesSends the extracted links and header data to our servers for analysisYour Google login token is never sent to our servers under any circumstances

The add-on is only active when you have our panel open on screen. It does not run in the background, it cannot access other emails in your inbox, and it has no access to your contacts, calendar, or any other Google data.

Reporting a suspicious email (both add-ins)

This is the only situation where we ever collect the full content of an email, and it only happens when you choose to report one.

Registered users can flag a suspicious email using the Report Email button inside the add-in. Before anything is submitted, you must tick a checkbox that reads:

"Email content will be shared with CyberCheck360 or your organisation's designated security provider for threat analysis."

If you tick that box and submit the report, we collect the full email including the body text, headers, sender and recipient details, the subject line, your written description of the issue, and any attachments if you chose to include them.

Who sees this reported email depends on how your organisation has set up their CyberCheck360 account. It may be reviewed by CyberCheck360, your organisation's own security team, or a third-party security provider your organisation works with.

Chrome and Firefox browser extensions

Our browser extension does two things that involve collecting data.

Checking links you visit: when you click a link on a webpage, or type or paste a web address into your browser's address bar, that address is sent to our servers to be checked for threats. We do not monitor your browsing in the background. Scanning only happens when you take one of those two actions.

Checking pages for phishing: if you land on a webpage that contains a form, such as a login page, our extension takes a small sample of plain text from that page and sends it to our servers to check whether the page looks like a phishing attempt. We take text from the top of the page, the bottom of the page, and the first few hundred characters of the main content area. That is all. We do not collect any HTML code, any form field contents, anything you have typed, any passwords, or any session data.

This phishing check only runs when a form is detected on the page. It does not happen on every page you visit.

We also log sandbox sessions against your account when you open a link in our sandbox through the extension.

Basic link checking works without an account. The sandbox and reporting features require you to be registered.

Threat Intelligence Platform

Our Threat Intelligence Platform, which you can find at tip.cybercheck360.com, is a tool for security professionals to look up and track indicators of compromise. These are things like suspicious IP addresses, domains, URLs, and file hashes.

When you search for something: every time someone searches for an indicator, registered or not, we log the IP address the search came from. If you are logged in, your search is also linked to your account. This information is only visible to CyberCheck360 and is used to protect the platform from abuse and to maintain a record of who looked up what in the event of a security investigation. It is not shared with other platform users.

IOC lists: you can create lists of indicators to track and share.

How our threat data works: our threat intelligence is stored in our own database, which we keep updated from various security feeds. When you search for an indicator, the search goes to our database. We do not send your query to external providers in real time. The one exception is IP address lookups, where a standard DNS lookup is used to find the associated domain name. This is a routine part of how the internet works. The IP address is sent to public DNS servers and no personal information about you travels with it.

Third-party integrations: if you choose to connect a third-party threat intelligence provider using your own API key, then your searches in our platform will also be sent to that provider. What gets sent is the indicator you searched for and your own API key for that service. We store your API key on your account profile so the integration can run. We do not attach any personal information about you to these requests beyond the API key you provided.

Feedback and bug reports: when you report a bug, flag a false positive, or leave feedback, we collect your IP address, your account details, and what you wrote. Bug reports include a screenshot of the platform interface at the time of the report. Screenshots do not include any personal data beyond what you have entered into the platform yourself.

Email Link Security

Email Link Security is a feature organisations can enable where every link in incoming emails is automatically rewritten before it reaches anyone's inbox. When someone clicks a rewritten link, they are briefly routed through CyberCheck360 so we can check the destination before they arrive there.

Reading emails to rewrite links: our system reads incoming emails to find the links inside them. It reads the email body locally to find those links, but the body content is never sent to our servers. Only the links and some basic email details are extracted and processed.

What we collect from each email:

What we collect when someone clicks a rewritten link:

Every click from every user is recorded. This is a deliberate design decision. If a security incident happens and a malicious link was sent to the organisation, the security team needs to be able to find out exactly who clicked it and when. This click data is available to your organisation's administrators, their security team, and any third-party security provider managing the organisation's CyberCheck360 account (see Section 4).

Organisations can also quarantine emails containing links they believe are dangerous. This requires two people within the organisation to approve the quarantine before it takes effect.

A note on responsibility: when your organisation uses Email Link Security, Kaavalan Limited processes the data on your organisation's behalf. Your organisation is the one making decisions about how this feature is configured and who has access to the data (see Section 4). If you have questions about how your employer uses this feature, please ask them. If your organisation needs a formal data processing agreement with us, please get in touch at privacy@cybercheck360.com.

Dynamic Threat Protection

Dynamic Threat Protection connects to your organisation's firewall and automatically checks network traffic against our threat intelligence database. When a known threat is detected, it is added to a block list automatically.

To do this, the system receives log data from your firewall. These logs contain network-level information including IP addresses, port numbers, protocols, whether connections were allowed or blocked, and other standard fields that firewalls record.

This product can be set up in two ways:

A note on responsibility: as with Email Link Security, your organisation is the data controller for all firewall log data in a managed deployment. We process it only on their instructions (see Section 4).

Bug reports across all products

When you report a bug through any CyberCheck360 product, we collect a screenshot of the interface you were using, your IP address, your account details, and your description of the problem. Screenshots only capture our interface. They do not include any email content, webpage content, or firewall data.

The sandbox

When you open a URL or file in our sandbox:

Things we never collect


2. How do we use your information?

We use the information we collect to:


3. What is our legal basis for processing your information?

This section is required under GDPR for users in the EU and UK. If you are in the US or another region, the relevant section is further down.

We only process your information when we have a lawful reason to do so. Depending on what we are doing and why, we rely on one of the following:

Where we process data on behalf of an organisation customer, for example in Email Link Security or managed Dynamic Threat Protection deployments, we are acting as a data processor. The organisation is the data controller and their instructions and contract with us govern how the data is handled.

If you are in Canada, we rely on express or implied consent as appropriate, or on the exceptions that Canadian privacy law permits.


4. Who do we share your information with?

We do not sell personal data.

Here is every situation where your information might be shared with someone outside of Kaavalan Limited:

When you search for an IOC, the indicator itself (the IP address, domain, URL, or file hash) is submitted to third-party threat intelligence providers to check its reputation and return an accurate verdict. No account details, IP address, username, or any other information that could identify you or your organisation is included in these requests. The specific providers used may vary depending on your subscription plan. See Section 1 for full details on what data is collected from each product.


5. Do we use cookies and tracking technologies?

Yes. Our website uses cookies and similar tracking technologies. Under GDPR and the ePrivacy Directive, we are required to tell you exactly what we use, why we use it, and to ask for your consent before anything other than strictly necessary cookies are placed on your device.

We manage all tracking through Google Tag Manager. The tags we currently have configured are listed below, grouped by purpose.

Strictly necessary

These are required for the website and platform to function. They do not track you for advertising or analytics purposes and they do not require your consent.

ToolWhat it does
Termly Cookie ConsentManages your cookie preferences and remembers your choices
Session cookiesKeep you logged in and protect against cross-site request attacks
Usage limit cookiesTrack your free sandbox session count for the day

Analytics and performance

These help us understand how people use our website so we can improve it. They only run if you have accepted analytics cookies.

ToolWhat it does
Google Analytics GA4Tracks page views, session duration, traffic sources, and general usage patterns. IP addresses are anonymised before we see them.
Google TagThe base configuration tag that connects our site to Google's measurement services
Cloudflare InsightsCollects performance data such as page load times and error rates to help us keep the site running smoothly
Microsoft ClarityRecords anonymised session behaviour including mouse movements, clicks, and scroll depth so we can understand how people interact with our pages. Clarity is configured to mask form fields, so anything you type into a form is not captured.

Marketing and advertising

These are used to measure the performance of our advertising campaigns and to show relevant ads to people who have visited our website. They only run if you have accepted marketing cookies. Our advertising platforms are not all running live campaigns at the time this policy was published, but the following tools are configured and will be subject to your consent before they fire.

ToolWhat it does
LinkedIn Insight TagTracks conversions from LinkedIn ads and enables us to reach people with similar profiles to our visitors on LinkedIn
Facebook (Meta Pixel)Tracks conversions from Meta ads across Facebook and Instagram and enables retargeting
Google Ads ConversionTracks when someone takes an action after clicking one of our Google Ads
Reddit PixelTracks conversions from Reddit ads and enables retargeting on Reddit

CRM and contact tracking

ToolWhat it doesWhen it fires
HubSpotTracks form submissions and contact activity to help our team follow up with people who have expressed interest in our productsOnly on pages where a contact form is present, not across all pages

All marketing, analytics, and CRM tags are managed through our cookie consent banner. None of them should activate before you have made a choice. If you have concerns about how consent is applied on our website, please get in touch at privacy@cybercheck360.com.

You can update your preferences at any time by clicking Cookie preferences in the footer of our website. Full details are in our Cookie Policy at cybercheck360.com/cookie-policy/.


6. Do we use artificial intelligence?

Yes, in one specific and limited way.

When you use our Chrome or Firefox extension and visit a webpage that contains a form, such as a login page, our extension checks whether that page might be a phishing site. To do this, it takes a small sample of plain text from the top of the page, the bottom of the page, and the beginning of the main content area. That text is sent to our servers and then to an AI model for classification.

We use OpenAI's API for this. We have not named a specific model version here because the model we use may change over time. What will not change is that OpenAI is the provider, and that the following apply regardless of which model is running:

To be specific about what we do send:

This only runs when a form is detected on a page. It does not happen on every page you visit.


7. How long do we keep your information?

Data typeRetention period
Email headers, extracted links, threat verdicts12 months
Browser extension scan logs12 months
Threat Intelligence Platform search logs12 months
TIP public commentsKept while your account is active. Removed within 30 days of account deletion.
TIP integration API keysKept while your account is active. Removed within 30 days of account deletion.
Email Link Security metadata and click logs12 months
Dynamic Threat Protection firewall logs (managed deployments)As agreed in your organisation's contract with us
Sandbox session logs12 months
Files opened in the sandboxDeleted immediately when the session ends, without exception
Reported email content (where you consented)12 months
Bug reports and screenshots12 months
Account informationWhile your account is active, plus 30 days after closure
Website analyticsPer Google Analytics settings (anonymised)

When you delete your account or cancel your subscription, all your associated data is deleted within 30 days.


8. How do we keep your information safe?

Security is our business, and we hold ourselves to the same standards we ask of our customers.

No system is completely unbreakable. While we take every reasonable precaution, we cannot guarantee absolute security. We recommend you access our services only from secure networks and devices.


9. Do we collect information from children?

No. Our services are designed for business use and are not intended for anyone under 18. We do not knowingly collect data from children. If you think we have accidentally received data from someone under 18, please contact us at privacy@cybercheck360.com and we will delete it promptly.


10. What are your privacy rights?

EEA, UK, and Ireland

Under GDPR and UK GDPR, you have the right to:

To use any of these rights, email privacy@cybercheck360.com. We will respond within 30 days.

You can also complain to the Data Protection Commission (Ireland) at dataprotection.ie, or to the supervisory authority in your own country. If you are in Switzerland, contact the Federal Data Protection and Information Commissioner.

South Africa

Under the Protection of Personal Information Act 4 of 2013 (POPIA), you have the right to access, correct, and delete your personal information. Complaints can be directed to the Information Regulator at inforegulator.org.za.

Nigeria

Under the Nigeria Data Protection Act 2023, you have equivalent rights. Complaints can be directed to the Nigeria Data Protection Commission at ndpc.gov.ng.

Managing your account

You can update your account details in your account settings. If you want to close your account, contact us and we will process the deletion within 30 days.

Opting out of marketing emails

Every marketing email we send includes an unsubscribe link. You can also email privacy@cybercheck360.com to opt out. We will continue to send service-related messages even if you opt out of marketing.


11. Do-not-track signals

Some browsers have a Do Not Track setting that sends a signal to websites asking them not to track you. There is currently no agreed industry standard for how websites should respond to these signals, so we do not act on them at this time. If that changes, we will update this policy.


12. Rights for US residents

This section applies to residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Montana, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia.

What categories of personal information do we collect?

CategoryDescriptionCollected?
A. IdentifiersEmail address, IP address (anonymised for analytics; logged for TIP searches and click tracking), account name, session identifiersYes
B. Personal information (California Customer Records)Name, email address, organisation, billing informationYes
C. Protected characteristicsGender, age, race, ethnicity, national originNo
D. Commercial informationSubscription plan, transaction and payment recordsYes
E. Biometric informationFingerprints, facial recognition, voiceprintsNo
F. Internet or network activityURLs visited on user action via browser extension; IOCs searched in TIP; link click events in Email Link Security; firewall log data in managed DTP deployments (processed as data processor on behalf of the organisation)Yes
G. Geolocation dataApproximate location from IP address only. No GPS or precise location.Yes
H. Electronic or sensory informationScreenshots of our interface for bug reports only. No email or webpage content is captured.Yes
I. Professional informationOrganisation name and job title, if provided during registrationYes
J. Education informationStudent records or directory informationNo
K. InferencesWe do not build user profiles or draw inferences for advertisingNo
L. Sensitive personal informationHealth, biometric, financial credentials, or other sensitive categoriesNo

How long do we keep each category?

Do we sell your personal information?

No. We have never sold personal information and we will not do so.

Your rights

You have the right to know what personal information we have about you, access a copy of it, correct inaccuracies, request deletion, receive your data in a portable format, and not be discriminated against for exercising these rights. You also have the right to opt out of targeted advertising, sale of data, or profiling that produces significant effects.

To exercise any of these rights, email privacy@cybercheck360.com. We will respond within 45 days. You may appoint an authorised agent to make a request on your behalf, with your written and signed permission.

If we decline your request, you may appeal by emailing us. If your appeal is denied, you may complain to your state attorney general.

California Shine the Light: we do not share personal information with third parties for their direct marketing purposes. California residents may ask us to confirm this once per year, free of charge, by emailing privacy@cybercheck360.com.


13. Google API services: user data disclosure

This section is required by Google's OAuth verification process and applies specifically to users of the CyberCheck360 Gmail add-on. If anything here conflicts with another part of this policy, this section takes priority for Google API data.

The short version

We use Google's permissions only to provide you with the email security service you can see and use within the add-on. We do not use your Google data for advertising. We do not build profiles from it. We do not share it except as described here and in Section 4.

Kaavalan Limited's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.

What data do we access?

Only data from the single email you currently have open, and only while our add-on panel is visible on your screen. The full scope table is in Section 1 under the Gmail add-on heading.

How do we use it?

To check email headers for signs of spoofing, to find and analyse links for threats, to support the reporting feature when you give your explicit consent, and to manage sandbox sessions.

Who can see it?

Your organisation's administrators and designated security providers, as described in Section 4. We do not send your Google API data to any external threat intelligence provider in real time. Threat verdicts come from our own internal database.

How do we store it and keep it safe?

All data is stored within the European Economic Area. Security measures are described in Section 8. We never store your Google login credentials or session tokens. Those stay within Gmail.

How long do we keep it?

Section 7 has the full retention table — 12 months for most data types. You can request deletion at any time by emailing privacy@cybercheck360.com. You can also remove our access to your Gmail account at any time through myaccount.google.com/permissions.


14. Changes to this policy

We may update this policy when we launch new products, when the law changes, or when we change how we handle data. If we make a significant change, we will email registered users at least 14 days before the change takes effect. The date at the top of this page shows when it was last updated.


15. How to contact us

Kaavalan Limited (trading as CyberCheck360)

Email: privacy@cybercheck360.com

Address: 21, The Academy Building, Dublin, D12 H024, Ireland

If you are in the EEA or UK and you are not happy with how we have handled your data, you have the right to complain to the Data Protection Commission (Ireland) at dataprotection.ie, or to the supervisory authority in your country.


16. How to access, update, or delete your data

You can update your account information at any time by logging into your account settings.

To request a copy of your data, correct something, or ask us to delete your information, email privacy@cybercheck360.com with your account email address and a description of what you need. We will verify your identity and respond within 30 days, or within 45 days for requests under US state privacy laws.


Kaavalan Limited (trading as CyberCheck360) | Registered in Ireland | ISO 27001:2022 certified | GDPR compliant
Privacy Policy v5.1 | Effective May 2026 | cybercheck360.com/privacy/