Privacy notice
What we collect when you contact us, and what happens to it.
Last updated July 26, 2026. Effective from the same date.
Who we are
This site is operated by Cybermint LLC, a North Carolina limited liability company trading as Backstop Cyber, at backstopcyber.com. We decide what happens to the information described below, and we are responsible for it.
For anything on this page — including a request to delete what we hold about you — use the contact form on the home page and say so in the message. It reaches the same inbox and a person reads it. We have not appointed a Data Protection Officer; nothing in the law that currently applies to us requires one.
What we collect
This site has no analytics, no advertising tags, no tracking pixels, no session recording and no third-party embeds other than the anti-spam widget described below. There is exactly one place where you can give us personal data: the contact form on the home page.
Information you type into the contact form
- Name — so we know who we are replying to.
- Work email address — so we can reply. This is set as the reply-to address on the notification we receive.
- Company — so we can scope realistically.
- Role — optional.
- What brings you here — one of a fixed set of options, so the enquiry reaches the right person.
- Your message — free text, up to 4,000 characters. Please do not paste credentials, live findings, customer data, protected health information, or anything else you would not want sitting in an ordinary email inbox. If you need to share sensitive detail, say so in the message and we will agree a secure channel first.
Information collected automatically when you submit
- Your IP address, taken from Cloudflare's
CF-Connecting-IPheader. It is used to rate-limit submissions and is included in the notification email so that abuse can be traced. - An anti-spam token issued by Cloudflare Turnstile, which we verify with Cloudflare and then discard. We do not store it.
- Ordinary edge request logs generated by Cloudflare in the course of serving the site, which may include IP address, user agent, timestamp and requested URL. These are Cloudflare's standard logs, retained under Cloudflare's own policy.
We do not collect special category data, we do not buy or enrich contact data from third parties, and we do not sell or share personal data for cross-context behavioural advertising.
Why we collect it
- To answer your enquiry
- The whole purpose of the form. You sent us a business enquiry and we are replying to it.
- To keep the form usable
- Rate limiting and Turnstile verification exist to stop automated abuse of our own systems. Nothing collected for that purpose is used for anything else.
- To keep a record if we do business
- If your enquiry becomes an engagement, the correspondence becomes part of the engagement record and is kept for as long as the relationship and any subsequent tax or contractual obligation requires. We keep them for seven years, which is the common US practice for records tied to an invoice.
We do not use your details for marketing. We do not add you to a mailing list. If we ever want to, we will ask you first and it will be a separate opt-in.
Who processes it on our behalf
Three third parties touch a contact form submission. All three act on our instructions under their standard terms, and none of them is permitted to use your message for their own purposes.
- Cloudflare, Inc.
- Hosts and serves this site (Cloudflare Pages), runs the serverless function that receives your submission (Pages Functions), and provides the Turnstile anti-spam check. Cloudflare therefore processes your IP address, your request metadata, and — transiently, in memory, at the moment of submission — the contents of the form. Cloudflare's own privacy documentation is at cloudflare.com/privacypolicy. Turnstile is a privacy-preserving alternative to a CAPTCHA: it does not use cookies for tracking purposes and Cloudflare states that it does not use the data for behavioural profiling.
- Resend (Plus Five Five, Inc.)
- Delivers the notification email from our contact function to our inbox. Resend therefore processes the full contents of your submission in the course of transmitting and logging that email. Resend's privacy documentation is at resend.com/legal/privacy-policy.
- Google LLC (Google Workspace)
- Hosts the mailbox that receives the notification, so Google stores the full contents of your message for as long as we keep the email. Google's privacy documentation is at policies.google.com/privacy, and the terms covering business use of Workspace are at workspace.google.com/terms. Google does not use Workspace content for advertising.
All three are US companies and your submission is processed in the United States. Backstop Cyber serves US clients and this site is directed at a US audience. If you are contacting us from outside the United States, send your message knowing it will be stored and read in the US.
How long we keep it
- Enquiries that do not become engagements are kept for 12 months from your last message, then deleted from the inbox and from Resend's logs where deletion is available to us.
- Enquiries that become engagements are retained as part of the engagement record for seven years.
- Rate-limiting records are held in memory only, for ten minutes, and are never written to storage.
- Turnstile tokens are verified and discarded within the same request. They are never stored.
- Cloudflare edge logs are retained under Cloudflare's policy, not ours.
Your choices, and how to use them
North Carolina does not currently have a comprehensive consumer data privacy statute of the kind in force in California, Virginia, Colorado and a growing number of other states. We are therefore offering the following as a matter of policy rather than because a statute compels us — and if you are covered by a law that does give you these rights, we will honour it on the same terms.
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Do that through the contact form, choosing "Other" and saying what you want. We will action it within 30 days. We may ask you to confirm your identity, which in practice means replying from the address you originally wrote in from.
Deletion is genuinely straightforward here, because there is no database. An enquiry exists as an email in an inbox and as a record in Resend's sending log. Asking us to delete it means those two things get deleted, and we will tell you when it is done.
We do not sell your information, we do not share it for advertising, and we do not use it to build a profile of you. There is nothing here to opt out of.
If you think we have handled your information badly, tell us first — we would rather fix it. If that does not resolve it, you can contact the North Carolina Department of Justice Consumer Protection Division, or the Federal Trade Commission at reportfraud.ftc.gov.
Security
The site is served over HTTPS only, with HSTS and a strict Content Security Policy. The contact function validates and length-caps every field server-side, escapes all input before it is placed into the notification email, and verifies the anti-spam token with Cloudflare before anything is sent onward. API credentials are held as Cloudflare environment secrets and are not present in the repository or in any file served to your browser.
None of that makes an ordinary email inbox a secure channel. Treat the contact form as you would treat an email to a stranger, and do not send us anything sensitive through it.
If we ever discover that information you sent us has been exposed, we will tell you directly and without waiting to be asked, as soon as we understand what happened and what it means for you — and in any case within 72 hours of confirming it. We will also comply with the North Carolina Identity Theft Protection Act where it applies. Given that this site holds no database and no credentials, the realistic exposure is a compromise of the receiving mailbox rather than of this website.
Changes to this notice
If we change how any of this works, we will update this page and change the date at the top. Material changes affecting people who have already contacted us will be notified directly where we can reasonably do so.