Privacy Policy
Effective Date: June 23, 2026
1. Introduction
Welcome to Cyber Recaps. This Privacy Notice explains how Cyber Recaps ("we," "us," or "our") collects, uses, shares, and protects your personal information when you interact with our services ("Services"), which include visiting our website (https://cyberrecaps.com) and subscribing to our newsletter.
For the purposes of the General Data Protection Regulation (GDPR) and other applicable data protection laws, the data controller is Cyber Recaps, a business operated from Israel. This means we are responsible for deciding how and why your personal information is processed. Our servers and primary hosting infrastructure are located in the United States. This Privacy Notice applies globally to all users of our Services.
2. What Personal Information We Collect and How
We collect personal information in the following ways:
a. Information You Provide to Us Directly
Subscription Information: When you subscribe to our newsletter, you provide us with your email address. This information is collected and processed by our third-party email service provider, MailerLite. To comply with our legal obligations and document your consent, we also automatically collect associated metadata, which may include your IP address, the timestamp (date and time) of your subscription, and the source of the subscription (e.g., the specific form on our website).
b. Information We Collect Automatically
When you visit our website, we automatically collect certain technical information:
Log and Device Information: Our servers (hosted by DigitalOcean) and security services (provided by Cloudflare) automatically collect log data. This may include your IP address, browser type and version, operating system, device information, referring URLs, and the dates and times of your visits.
Usage and Analytics Information: We use Burst Statistics, a privacy-first analytics tool that runs directly on our own website. Burst is cookie-free by default and does not collect any personally identifiable information (PII). All the data it collects (such as pages viewed, referral sources, device type, and country) is aggregated and anonymized, and is stored locally in our own website's database. This data is not transmitted to or shared with any third-party analytics company. It cannot be used to identify you.
Site Verification and Performance Data: We use Google Search Console to verify our site ownership with Google and to monitor our site's performance in Google search results (e.g., which queries bring users to our site). This data is aggregated by Google and is not used to track individual user behavior on our site.
3. Our Purposes and Lawful Bases for Processing
Under the GDPR, we are required to have a valid legal justification, known as a "lawful basis," for each way we process your personal information. We rely on the following lawful bases:
Consent: We process your information when you have given us clear, affirmative permission for a specific purpose.
Legitimate Interests: We process your information when it is necessary for our legitimate interests (or those of a third party), and your interests and fundamental rights do not override those interests. This includes activities like securing our website and understanding how our services are used to improve them.
Legal Obligation: We may process your information where it is necessary for compliance with a legal obligation to which we are subject.
The following table provides a detailed summary of our processing activities, the purposes they serve, and the corresponding lawful basis under GDPR.
Table 1: Summary of Data Processing Activities, Purposes, and Lawful Bases
Processing Activity | Categories of Personal Data Processed | Purpose of Processing | Lawful Basis (under GDPR) |
|---|---|---|---|
Newsletter Delivery | Email Address, IP Address, Subscription Timestamp & Source | To fulfill your request to subscribe and to send you the daily cybersecurity newsletter. | Consent (Art. 6(1)(a) GDPR). You provide this consent when you actively subscribe. |
Security & Performance Monitoring | IP Address, Browser Type, Device Information, Timestamps | To protect our website and services from malicious traffic, prevent fraud, investigate security incidents, and ensure the stability and performance of our infrastructure. | Legitimate Interests (Art. 6(1)(f) GDPR). Our legitimate interest is in maintaining the security and operational integrity of our Services. |
Website Analytics | Aggregated & Anonymized Data (e.g., page views, referral source, country), stored locally on our own infrastructure. No cookies or PII are collected. | To understand how visitors interact with our website, analyze performance, identify popular content, and improve the user experience. | Legitimate Interests (Art. 6(1)(f) GDPR). Our legitimate interest is in improving our service and understanding its performance without collecting personal data. |
4. How and With Whom We Share Your Information
We do not sell your personal information. However, to provide our Services, we must share information with certain trusted third-party service providers.
Email Delivery Provider: We use MailerLite to manage our mailing list and deliver our newsletter to you.
Infrastructure and Security Providers: Our website is hosted on servers provided by DigitalOcean and protected by security services from Cloudflare. These providers may process log data (including IP addresses) to maintain security and performance.
Website Analytics: Our website analytics are collected and stored locally on our own infrastructure using the Burst Statistics plugin. This analytics data is not shared with any third-party analytics provider.
Search Engine Monitoring: We use Google Search Console to monitor our site's performance in search results. This tool does not receive personal data about visitors from our site.
We may also disclose your information if required to do so by law or in the good faith belief that such action is necessary to comply with a legal obligation.
5. Cookies and Tracking Technologies
a. Our Approach to Cookies
We take a minimalist, privacy-first approach to cookies.
Analytics (Cookie-Free): Our analytics tool, Burst Statistics, is configured to run without cookies and does not use any persistent identifiers to track you.
Strictly Necessary Cookies: We may use cookies that are essential for the website to function and cannot be switched off. For example, our security provider (Cloudflare) may place a cookie (e.g., __cflb, __cf_bm) to identify trusted web traffic and mitigate attacks. These cookies do not track you for marketing or analytics.
Advertising Cookies: We do not use any third-party advertising cookies or tracking pixels.
b. Your Choices and Consent
Our website does not use any tracking, analytics, or advertising cookies. Therefore, no cookie consent banner is required or displayed. The only cookies we may use are "Strictly Necessary" for core functionality, such as security. You do not need to take any action to opt out of tracking, as no tracking occurs.
6. Data Retention
We retain personal information for no longer than is necessary for the purposes for which it was collected.
Subscriber Information: We retain your email address and associated subscription data in MailerLite for as long as you remain an active subscriber. If you unsubscribe, your email will be moved to a suppression list to honor your opt-out request.
Security and Server Logs: We retain security and server logs (which may contain IP addresses) for a rolling period of 180 days for security analysis and incident investigation.
Website Analytics Data: All analytics data we collect via Burst Statistics is aggregated and anonymized from the moment of collection and is stored locally on our own infrastructure. We may retain this anonymized trend data indefinitely to analyze long-term service performance.
7. Data Security
We are committed to protecting the security of your personal information. We implement reasonable technical and organizational measures designed to protect your information from unauthorized access, use, or destruction. This includes relying on the robust security infrastructure of our service providers (DigitalOcean, Cloudflare, MailerLite) and using encryption for data in transit (HTTPS).
However, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee its absolute security.
8. International Data Transfers
Your personal information may be transferred to, stored, and processed in countries other than your country of residence, particularly the United States, where our servers and many of our third-party service providers are located.
We take appropriate steps to ensure that transfers of personal information are in accordance with applicable law. When we transfer personal information from the European Economic Area (EEA), the UK, Switzerland, or Israel to countries that have not been deemed to provide an adequate level of data protection (like the United States), we rely on the following legal mechanisms:
Adequacy Decisions: Our business is operated from Israel, a country recognized by the European Commission as providing an adequate level of data protection.
The EU-U.S. Data Privacy Framework: For transfers to our service providers in the United States, we verify their certification under the EU-U.S. Data Privacy Framework (DPF).
Standard Contractual Clauses (SCCs): Where the DPF is not applicable, we implement Standard Contractual Clauses (SCCs) in our contracts with third-party service providers.
9. Your Privacy Rights and Choices
Depending on your geographic location and applicable law, you may have the following rights:
a. How to Exercise Your Rights
To exercise any of the rights described below, please email contact[@]cyberrecaps[.]com. We will respond within the timeframes required by law.
b. Your General Rights
Opt-Out of Marketing Communications: You can unsubscribe from our newsletter at any time by clicking the "unsubscribe" link provided in every email.
c. Rights for Residents of the EEA, UK, and Switzerland (under GDPR)
You have the right to Access, Rectification, Erasure ("Right to be Forgotten"), Restrict Processing, Data Portability, and the Right to Object to processing.
d. Rights for Residents of California (under CCPA/CPRA)
If you are a California resident, you have the following rights:
The Right to Know: The right to request that we disclose the categories and specific pieces of personal information we have collected about you.
The Right to Delete: The right to request the deletion of personal information we have collected from you, subject to certain exceptions.
The Right to Correct: The right to request the correction of inaccurate personal information we maintain about you.
The Right to Opt-Out of Sale or Sharing: We do not "sell" or "share" your personal information as defined by the CCPA/CPRA. We do not use third-party advertising cookies or tracking pixels.
The Right to Non-Discrimination: The right not to be discriminated against for exercising any of your CCPA/CPRA rights.
e. Right to Lodge a Complaint
You have the right to lodge a complaint about our data processing activities with your local data protection authority.
10. Third-Party Services and Links
Our website and newsletter may contain links to external websites, advertisements, and affiliate partners that are not operated by us.
Our Policy on Affiliate Links: We may use affiliate links. When you click on such a link, it is a simple outbound link. We do not install any tracking pixels or cookies on our site on behalf of these partners. Any data collection that occurs will only happen after you have landed on the third-party's site, subject to their own privacy policy.
We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites.
For your convenience, here are links to the privacy policies of our key service providers:
- MailerLite: https://www.mailerlite.com/legal/privacy-policy
- Google (for Search Console): https://policies.google.com/privacy
- Cloudflare: https://www.cloudflare.com/en-gb/privacypolicy/
- DigitalOcean: https://www.digitalocean.com/legal/privacy-policy
11. Our Privacy Philosophy & User Recommendations
We have drafted this Privacy Notice to be as clear and accurate as possible. We are committed to our users' privacy and view it as a core principle of our service. If you find any errors in this policy or have suggestions for improvement, please contact us at contact[@]cyberrecaps[.]com.
We actively encourage you to take control of your own privacy. We recommend using privacy-enhancing tools, such as browser-based ad blockers or privacy-focused browsers like Brave.
For subscribing to our newsletter, we also recommend using email alias services (such as those provided by ProtonMail, SimpleLogin, or Apple's "Hide My Email") to protect your primary email address.
12. Children's Privacy
Our Services are not intended for or directed at individuals under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have, we will take steps to delete that information promptly.
13. Changes to This Privacy Notice
We may update this Privacy Notice from time to time. When we do, we will update the "Effective Date" at the top. If we make material changes, we will notify you in advance, such as by email or a notice on our website.
14. Contact Us
If you have any questions, comments, or concerns about this Privacy Notice or our data practices, please contact us at:
Cyber Recaps Email: contact[@]cyberrecaps[.]com Location: Israel Website: https://cyberrecaps.com