CyberProfileCyberProfile Back to home

Last updated: August 21, 2026

Privacy Policy

This policy explains what personal data we process, for what purpose, on what legal basis, for how long, who we share it with and what rights you have over it. It is written to be understood, not to cover our backs.

1. Data controller

Gorka El Bochi Morillo (sole trader), tax ID 46099276P, registered address Carrer Romaní 15, 08184 Palau-solità i Plegamans (Barcelona), España, owner of CyberProfile (https://cyber-profile.com). Data protection contact: gorka@cyber-profile.com. Phone: +34 636 49 73 22.

We are not required to appoint a Data Protection Officer and have not done so. For anything relating to your data, the email address above is the direct channel to the controller.

2. What data we process

  • Account data: your email address and, if you sign in with Google, GitHub or LinkedIn, the identifier and public name that provider returns. We do not use passwords.
  • Profile data: whatever you choose to publish — name, photo, bio, experience, education, projects, certifications, languages and contact links.
  • Connected platform data: the public information of your account on HackTheBox, HackerOne, Bugcrowd, YesWeHack, GitHub, Credly, DockerLabs, The Hackers Labs, El Rincón del Hacker, ThePwnLab, BugBountyLabs, YouTube or LinkedIn — ranks, scores, machines solved, reports, badges, repositories and equivalent statistics.
  • Connection credentials: when a platform requires a token, it is stored encrypted (AES-256-GCM) and used server-side only. It is never displayed or sent to the browser.
  • Technical and usage data: pages visited, referring page, approximate country inferred from the connection, browser type and, in security logs, a truncated or hashed version of your IP address. The full IP address is not stored.
  • Employment data: if you enable "Open to opportunities", your availability information and any CV you choose to attach.
  • Communications: the messages you send us through contact forms or by email.

3. Where the data comes from

Most of the data comes from you. In addition, when you connect a platform we obtain information about you from that platform: either through its API with the authorisation you grant, or by reading the profile that is already public on its website.

We only collect data from a third party after you have connected that account and proved it is yours. We do not crawl or build profiles of people who have not signed up.

4. Purposes, legal basis and retention

Every processing activity has a specific purpose and its own legal basis. This table is the exact summary:

PurposeLegal basisRetention
Create and maintain your account, authenticate youPerformance of the contract (art. 6(1)(b) GDPR)While the account is active
Build and publish your professional profilePerformance of the contract (art. 6(1)(b))While the account is active
Connect platforms and sync your achievementsConsent given when connecting each account (art. 6(1)(a)), revocable by disconnecting itUntil you disconnect the platform or delete the account
Verify that an account is really yoursContract and legitimate interest in service integrity (art. 6(1)(b) and (f))While the verification remains valid
Show your profile to companies and enable contactExplicit consent when enabling "Open to opportunities" (art. 6(1)(a))Until you turn it off
Send you operational email (access codes, security alerts)Performance of the contract (art. 6(1)(b))Delivery log: 12 months
Send you product news and remindersLegitimate interest in informing our own users (art. 6(1)(f)), with an unsubscribe link in every emailUntil you unsubscribe
Measure site usage with a visitor identifierConsent in the cookie notice (art. 6(1)(a))14 months
Measure traffic in aggregate, without an identifierLegitimate interest in understanding service usage (art. 6(1)(f))14 months
Security, abuse prevention and audit loggingLegitimate interest in protecting the service (art. 6(1)(f)) and legal obligation where applicableAudit 24 months · access 12 months · sessions 13 months
Proof of cookie consentLegal obligation to demonstrate it (art. 7(1))24 months
Handle commercial enquiries from companiesPre-contractual measures at the request of the data subject (art. 6(1)(b))24 months

Where the legal basis is legitimate interest, we have assessed that our interest (keeping the service working, secure and improvable) does not override your rights, because the data is minimal, is not combined with third-party sources and you can always object. Ask us if you want the detail of that balancing test.

Once the account is closed, data is deleted except what we must keep by legal obligation (for example, invoicing) or what is already anonymised and no longer identifies you.

5. Your profile is public

CyberProfile exists to make your work visible. Your profile published at cyber-profile.com/u/your-name is accessible to anyone and may be indexed by search engines. Only what you add, or what comes from platforms you have voluntarily connected, is published.

Your email address is never shown on the public profile unless you add it yourself as a contact link. You can edit or delete any section at any time, and there are switches to hide entire sections.

6. Who else sees your data

We do not sell personal data, we do not share it for advertising purposes, and we do not use it to train models.

If you enable "Open to opportunities", your professional profile becomes accessible to the verified companies using the hiring platform. Those companies act as independent controllers from the moment they receive your data: it is up to them to inform you how they process it. We log every access so there is a trail, we limit which fields each company sees according to its plan, and we cut off access as soon as you withdraw consent.

Nobody can contact you through the platform if you have not enabled that option. Turning it off takes effect immediately.

7. Processors

To provide the service we rely on providers that process data on our behalf, under a data processing agreement pursuant to art. 28 GDPR:

ProviderServiceLocation
IONOSServer where the platform runsEuropean Union
MongoDB (self-hosted)Database, on the same serverEuropean Union
Own mail serverTransactional email deliveryEuropean Union
ResendFallback email delivery if the own server failsEuropean Union / USA
Stripe Payments EuropePayments for business servicesEuropean Union
SentryApplication error loggingEuropean Union / USA
CloudflareStorage of uploaded files and anti-bot protectionEuropean Union / USA

In addition, if you choose to sign in with Google, GitHub or LinkedIn, that provider acts as an independent controller with respect to your account data with them.

8. International transfers

The core infrastructure (server, database and email) is hosted in the European Union. Some supporting providers may process data outside the European Economic Area.

In those cases the transfer relies on an adequacy decision of the European Commission or on the Standard Contractual Clauses it has approved, together with any supplementary measures required. You may request a copy of the safeguards applied.

9. Automated decisions

We automatically compute two indicators about your profile: a trust score, based on how many of your accounts are verified at source, and an indicative classification of your technical profile from the platforms and certifications you display.

Neither produces legal effects nor significantly affects you: they do not decide whether you get a job, do not block your account and do not restrict any functionality. They serve to sort results and to orient whoever looks at your profile. You can ask us to explain how yours was calculated and request a review.

10. Cookies and device storage

We use strictly necessary cookies for the service to work and, only with your consent, measurement and third-party cookies. Until you decide, nothing non-essential is installed.

The full inventory — name, purpose, duration and owner of every cookie — is in the Cookie Policy. From "Cookie preferences" in the footer you can change your decision at any time; when you withdraw a category we delete the corresponding cookies.

11. Security

  • All traffic is encrypted (TLS) and platform credentials are stored encrypted with AES-256-GCM.
  • Internal access to data is minimal and recorded in an audit log.
  • IP addresses are stored truncated or as a keyed hash, never in plain text.
  • We do not use passwords: access is by one-time code or through identity providers, which removes the risk of password leaks.
  • No system is infallible. Should a breach occur that poses a risk to your rights, we will tell you and notify the supervisory authority within the legal deadlines.

12. Your rights

You can exercise at any time the rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw any consent you have given, without affecting the lawfulness of processing carried out beforehand. Write to gorka@cyber-profile.com from the address associated with your account and we will reply within one month at the latest.

Many of these rights you can exercise yourself, instantly: edit your profile, disconnect a platform, turn off "Open to opportunities", download your CV, change your cookie preferences or delete your account from settings. Deleting the account erases your data in cascade.

If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid) or with the supervisory authority of your country of residence.

13. Minors

The service is aimed at people over 16. If we detect an account belonging to someone below that age without the consent of a parent or guardian, we will delete it.

14. Changes to this policy

If we change this policy substantially, we will tell you by email or through a prominent notice on the platform before the change takes effect. The version in force is always the one published here, with its update date.

15. Contact

Gorka El Bochi Morillo, tax ID 46099276P, Carrer Romaní 15, 08184 Palau-solità i Plegamans (Barcelona), España. Email: gorka@cyber-profile.com. Phone: +34 636 49 73 22.