Privacy Policy
Last updated: 6 July 2026 · Effective: 30 June 2026
This Privacy Policy explains how Secure In Security (“SIS,” “we,” “us,” or “our”) collects, uses, and protects information when you visit secureinsecurity.com (the “Site”) and use our cybersecurity educational resources. It also describes the choices and rights you have, including under the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA).
By using the Site, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the Site.
1. Who we are
Secure In Security publishes educational cybersecurity content, reference material, and training resources for security professionals. For the purposes of the GDPR, Secure In Security is the data controller for personal data processed through the Site. You can reach us using the details in the Contact us section below.
2. Information we collect
2.1 Information you provide to us
We collect personal information only when you choose to provide it. Currently, this is limited to:
- Email. If you subscribe to updates, we collect your email address (and any name you choose to provide) so we can send you the content you requested. You can unsubscribe at any time using the link in any email.
2.2 Information collected automatically
When you visit the Site, certain information is collected automatically by us and by our analytics provider, including:
- Usage and device data — pages viewed, time on page, referring page, approximate location (derived from IP), browser type, operating system, and device type.
- Log data — standard server logs that may include a truncated or anonymized IP address and request timestamps.
- Cookie and identifier data — as described in the Cookies section.
We do not knowingly collect special categories of data (such as health, biometric, or political data), and we ask that you not submit such information to us.
3. Cookies & similar technologies
Cookies are small text files placed on your device that help websites function and provide information to site owners. We also use similar technologies such as pixels and local storage. We use the following categories of cookies:
- Strictly necessary cookies — required for the Site to function (for example, security, load balancing, and remembering cookie-consent choices). These cannot be switched off in our systems.
- Analytics cookies — help us understand how visitors use the Site so we can improve it (see Analytics).
- Functional cookies — remember preferences such as your newsletter or consent choices.
- Advertising cookies — described in Advertising.
3.1 Cookies we use
The table below lists the main cookies and technologies on the Site. Exact names and durations set by third parties may change; this list is representative.
| Cookie / technology | Provider | Purpose | Type / duration |
|---|---|---|---|
| cookie_consent | Secure In Security | Stores your cookie-consent preferences | Necessary / up to 12 months |
| _ga | Google Analytics | Distinguishes unique users | Analytics / up to 2 years |
| _ga_<ID> | Google Analytics (GA4) | Persists session state for GA4 | Analytics / up to 2 years |
| _gid | Google Analytics | Distinguishes users (short-term) | Analytics / 24 hours |
| _gat | Google Analytics | Throttles request rate | Analytics / 1 minute |
| Advertising cookies | Google AdSense & partners | Serve and measure ads (when ads are active) | Advertising / varies |
3.2 Managing cookies
Where required by law (including for visitors in the EU, UK, and similar jurisdictions), we request your consent before setting non-essential cookies, and you can change or withdraw your choice at any time through our cookie banner or settings link. You can also control cookies through your browser settings and delete cookies already stored. Blocking some cookies may affect how the Site works.
4. How we use information
We use the information described above to:
- operate, maintain, and secure the Site;
- deliver the content and newsletter you request;
- understand and improve how our educational resources are used;
- measure and, where applicable, display advertising;
- detect, prevent, and address technical issues, fraud, or abuse; and
- comply with our legal obligations.
We do not sell your personal information, and we do not use it for automated decision-making that produces legal or similarly significant effects.
5. Legal bases for processing (GDPR/UK GDPR)
If you are in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases:
- Consent — for non-essential cookies, analytics, advertising, and sending you our newsletter. You may withdraw consent at any time.
- Legitimate interests — for operating and securing the Site and understanding aggregate usage, balanced against your rights.
- Legal obligation — where we must process data to comply with applicable law.
6. Analytics
We use Google Analytics (GA4), a web-analytics service provided by Google, to understand how visitors interact with the Site. Google Analytics uses cookies and similar identifiers to generate aggregated reports about Site usage. Information generated about your use of the Site may be transmitted to and stored by Google.
We configure Analytics to limit the data collected where feasible (for example, IP anonymization/truncation). You can prevent Google Analytics from using your data by installing the Google Analytics Opt-out Browser Add-on, by declining analytics cookies in our consent banner, or by managing cookies in your browser. For more information, see Google’s Privacy Policy and How Google uses information from sites that use its services.
7. Advertising
Secure In Security is preparing to support the Site through Google AdSense. When advertising is enabled:
- Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this Site and/or other sites.
- Google’s use of advertising cookies enables it and its partners to serve ads to you based on your visit to this Site and/or other sites on the Internet.
- In addition to Google, other third-party vendors and ad networks may serve ads on the Site. These third parties may place and read cookies on your browser, or use web beacons (pixels) and similar technologies, to collect information as a result of ad serving on the Site. Advertising cookies served through Google products may be set under Google-owned domains such as
doubleclick.netorgoogle.com. - You may opt out of personalized advertising by visiting Google Ads Settings. You can also opt out of some third-party vendors’ use of cookies for personalized advertising at aboutads.info (US) or youronlinechoices.eu (EU/UK).
Once advertising is live, we will update this policy to identify the ad networks active on the Site and, where those vendors offer them, link to their privacy policies and cookie opt-out mechanisms. Where required, advertising cookies are set only after you provide consent through our cookie banner. For more information about how Google manages data in its advertising products, see Google’s Advertising policies.
8. How we share information
We do not sell your personal information. We share information only as follows:
- Service providers — trusted processors who help us operate the Site, such as our hosting provider, email/newsletter platform, and analytics provider (Google). They may process data only on our instructions.
- Advertising partners — when advertising is active, as described in Advertising.
- Legal and safety — where required by law, regulation, legal process, or to protect the rights, property, or safety of SIS, our users, or others.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy.
9. Data retention
We retain personal data only for as long as necessary for the purposes described in this policy, after which it is deleted or anonymized:
- Analytics data — retained according to our Google Analytics configuration (for example, up to 14 months), in aggregated or pseudonymized form.
- Server logs — retained for a limited period for security and troubleshooting.
10. Your privacy rights
10.1 EEA / UK (GDPR)
If you are in the EEA or UK, you have the right to: access your personal data; request correction or erasure; restrict or object to processing; data portability; and withdraw consent at any time (without affecting prior processing). You also have the right to lodge a complaint with your local data-protection authority — in the UK, the Information Commissioner’s Office (ICO).
10.2 California (CCPA/CPRA)
If you are a California resident, you have the right to: know what personal information we collect and how it is used and shared; request access to and deletion of your personal information; correct inaccurate information; and opt out of the “sale” or “sharing” of personal information. We do not sell your personal information, and we do not share it for cross-context behavioral advertising except as you consent to through advertising cookies. We will not discriminate against you for exercising any of these rights.
10.3 How to exercise your rights
To exercise any of these rights, contact us using the details in the Contact us section. We will respond within the timeframe required by applicable law. To protect your privacy, we may need to verify your identity before acting on a request. You may use an authorized agent where permitted by law.
11. International data transfers
We are based in the United States, and our service providers (including Google) may process data in the United States and other countries. Where personal data is transferred out of the EEA or UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an applicable adequacy/Data Privacy Framework mechanism. By using the Site, you understand that your information may be processed in countries whose data-protection laws may differ from those of your country.
12. Data security
We use reasonable technical and organizational measures — including HTTPS encryption in transit and access controls — to protect personal data. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Children’s privacy
The Site is intended for cybersecurity professionals and is not directed to children. We do not knowingly collect personal data from anyone under the age of 16 (or the minimum age in your jurisdiction).
14. Third-party links
The Site may link to third-party websites and resources that we do not control. This policy does not apply to those sites, and we encourage you to review their privacy policies.
15. Do Not Track
Some browsers offer a “Do Not Track” (DNT) signal. Because there is no common industry standard for DNT, the Site does not currently respond to DNT signals. You can still manage tracking through our cookie banner and the opt-out tools described above.
16. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page and, where appropriate, provide additional notice. Your continued use of the Site after changes take effect constitutes acceptance of the updated policy.
17. Contact us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:
Secure In Security
Email: secureinsecurity@proton.me
Web: secureinsecurity.com/contact