Last updated: August 21, 2026
Privacy Policy
This policy explains what personal data we process, for what purpose, on what legal basis, for how long, who we share it with and what rights you have over it. It is written to be understood, not to cover our backs.
1. Data controller
Gorka El Bochi Morillo (sole trader), tax ID 46099276P, registered address Carrer Romaní 15, 08184 Palau-solità i Plegamans (Barcelona), España, owner of CyberProfile (https://cyber-profile.com). Data protection contact: gorka@cyber-profile.com. Phone: +34 636 49 73 22.
We are not required to appoint a Data Protection Officer and have not done so. For anything relating to your data, the email address above is the direct channel to the controller.
2. What data we process
- Account data: your email address and, if you sign in with Google, GitHub or LinkedIn, the identifier and public name that provider returns. We do not use passwords.
- Profile data: whatever you choose to publish — name, photo, bio, experience, education, projects, certifications, languages and contact links.
- Connected platform data: the public information of your account on HackTheBox, HackerOne, Bugcrowd, YesWeHack, GitHub, Credly, DockerLabs, The Hackers Labs, El Rincón del Hacker, ThePwnLab, BugBountyLabs, YouTube or LinkedIn — ranks, scores, machines solved, reports, badges, repositories and equivalent statistics.
- Connection credentials: when a platform requires a token, it is stored encrypted (AES-256-GCM) and used server-side only. It is never displayed or sent to the browser.
- Technical and usage data: pages visited, referring page, approximate country inferred from the connection, browser type and, in security logs, a truncated or hashed version of your IP address. The full IP address is not stored.
- Employment data: if you enable "Open to opportunities", your availability information and any CV you choose to attach.
- Communications: the messages you send us through contact forms or by email.
3. Where the data comes from
Most of the data comes from you. In addition, when you connect a platform we obtain information about you from that platform: either through its API with the authorisation you grant, or by reading the profile that is already public on its website.
We only collect data from a third party after you have connected that account and proved it is yours. We do not crawl or build profiles of people who have not signed up.
4. Purposes, legal basis and retention
Every processing activity has a specific purpose and its own legal basis. This table is the exact summary:
| Purpose | Legal basis | Retention |
|---|---|---|
| Create and maintain your account, authenticate you | Performance of the contract (art. 6(1)(b) GDPR) | While the account is active |
| Build and publish your professional profile | Performance of the contract (art. 6(1)(b)) | While the account is active |
| Connect platforms and sync your achievements | Consent given when connecting each account (art. 6(1)(a)), revocable by disconnecting it | Until you disconnect the platform or delete the account |
| Verify that an account is really yours | Contract and legitimate interest in service integrity (art. 6(1)(b) and (f)) | While the verification remains valid |
| Show your profile to companies and enable contact | Explicit consent when enabling "Open to opportunities" (art. 6(1)(a)) | Until you turn it off |
| Send you operational email (access codes, security alerts) | Performance of the contract (art. 6(1)(b)) | Delivery log: 12 months |
| Send you product news and reminders | Legitimate interest in informing our own users (art. 6(1)(f)), with an unsubscribe link in every email | Until you unsubscribe |
| Measure site usage with a visitor identifier | Consent in the cookie notice (art. 6(1)(a)) | 14 months |
| Measure traffic in aggregate, without an identifier | Legitimate interest in understanding service usage (art. 6(1)(f)) | 14 months |
| Security, abuse prevention and audit logging | Legitimate interest in protecting the service (art. 6(1)(f)) and legal obligation where applicable | Audit 24 months · access 12 months · sessions 13 months |
| Proof of cookie consent | Legal obligation to demonstrate it (art. 7(1)) | 24 months |
| Handle commercial enquiries from companies | Pre-contractual measures at the request of the data subject (art. 6(1)(b)) | 24 months |
Where the legal basis is legitimate interest, we have assessed that our interest (keeping the service working, secure and improvable) does not override your rights, because the data is minimal, is not combined with third-party sources and you can always object. Ask us if you want the detail of that balancing test.
Once the account is closed, data is deleted except what we must keep by legal obligation (for example, invoicing) or what is already anonymised and no longer identifies you.
5. Your profile is public
CyberProfile exists to make your work visible. Your profile published at cyber-profile.com/u/your-name is accessible to anyone and may be indexed by search engines. Only what you add, or what comes from platforms you have voluntarily connected, is published.
Your email address is never shown on the public profile unless you add it yourself as a contact link. You can edit or delete any section at any time, and there are switches to hide entire sections.
6. Who else sees your data
We do not sell personal data, we do not share it for advertising purposes, and we do not use it to train models.
If you enable "Open to opportunities", your professional profile becomes accessible to the verified companies using the hiring platform. Those companies act as independent controllers from the moment they receive your data: it is up to them to inform you how they process it. We log every access so there is a trail, we limit which fields each company sees according to its plan, and we cut off access as soon as you withdraw consent.
Nobody can contact you through the platform if you have not enabled that option. Turning it off takes effect immediately.
7. Processors
To provide the service we rely on providers that process data on our behalf, under a data processing agreement pursuant to art. 28 GDPR:
| Provider | Service | Location |
|---|---|---|
| IONOS | Server where the platform runs | European Union |
| MongoDB (self-hosted) | Database, on the same server | European Union |
| Own mail server | Transactional email delivery | European Union |
| Resend | Fallback email delivery if the own server fails | European Union / USA |
| Stripe Payments Europe | Payments for business services | European Union |
| Sentry | Application error logging | European Union / USA |
| Cloudflare | Storage of uploaded files and anti-bot protection | European Union / USA |
In addition, if you choose to sign in with Google, GitHub or LinkedIn, that provider acts as an independent controller with respect to your account data with them.
8. International transfers
The core infrastructure (server, database and email) is hosted in the European Union. Some supporting providers may process data outside the European Economic Area.
In those cases the transfer relies on an adequacy decision of the European Commission or on the Standard Contractual Clauses it has approved, together with any supplementary measures required. You may request a copy of the safeguards applied.
9. Automated decisions
We automatically compute two indicators about your profile: a trust score, based on how many of your accounts are verified at source, and an indicative classification of your technical profile from the platforms and certifications you display.
Neither produces legal effects nor significantly affects you: they do not decide whether you get a job, do not block your account and do not restrict any functionality. They serve to sort results and to orient whoever looks at your profile. You can ask us to explain how yours was calculated and request a review.
10. Cookies and device storage
We use strictly necessary cookies for the service to work and, only with your consent, measurement and third-party cookies. Until you decide, nothing non-essential is installed.
The full inventory — name, purpose, duration and owner of every cookie — is in the Cookie Policy. From "Cookie preferences" in the footer you can change your decision at any time; when you withdraw a category we delete the corresponding cookies.
11. Security
- All traffic is encrypted (TLS) and platform credentials are stored encrypted with AES-256-GCM.
- Internal access to data is minimal and recorded in an audit log.
- IP addresses are stored truncated or as a keyed hash, never in plain text.
- We do not use passwords: access is by one-time code or through identity providers, which removes the risk of password leaks.
- No system is infallible. Should a breach occur that poses a risk to your rights, we will tell you and notify the supervisory authority within the legal deadlines.
12. Your rights
You can exercise at any time the rights of access, rectification, erasure, objection, restriction of processing and portability, as well as withdraw any consent you have given, without affecting the lawfulness of processing carried out beforehand. Write to gorka@cyber-profile.com from the address associated with your account and we will reply within one month at the latest.
Many of these rights you can exercise yourself, instantly: edit your profile, disconnect a platform, turn off "Open to opportunities", download your CV, change your cookie preferences or delete your account from settings. Deleting the account erases your data in cascade.
If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid) or with the supervisory authority of your country of residence.
13. Minors
The service is aimed at people over 16. If we detect an account belonging to someone below that age without the consent of a parent or guardian, we will delete it.
14. Changes to this policy
If we change this policy substantially, we will tell you by email or through a prominent notice on the platform before the change takes effect. The version in force is always the one published here, with its update date.
15. Contact
Gorka El Bochi Morillo, tax ID 46099276P, Carrer Romaní 15, 08184 Palau-solità i Plegamans (Barcelona), España. Email: gorka@cyber-profile.com. Phone: +34 636 49 73 22.