Sub-Processors and Data Processing Transparency
Cyber Tec Security Ltd (“CTS”) is committed to protecting personal data and maintaining transparency regarding the third-party technology providers used to support the delivery of our services.
This page provides information about the categories of service providers that may process personal data on behalf of CTS when delivering cybersecurity certification, security services, and business operations.
This information is provided in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Role of Cyber Tec Security
Cyber Tec Security Ltd may act as either:
Data Controller
Where CTS determines the purpose and means of processing personal data (for example internal operations, marketing or service administration).
Data Processor
Where CTS processes personal data on behalf of clients when delivering cybersecurity certification, assessment or consultancy services.
Where CTS acts as a processor, certain technology providers listed below may operate as sub-processors supporting the delivery of those services.
How We Select Technology Providers
CTS selects third-party providers based on:
- security and privacy controls
- contractual data protection commitments
- reliability and service capability
- regulatory compliance requirements
Where appropriate, Data Processing Agreements (DPAs) or equivalent contractual safeguards are in place with these providers.
Where personal data may be transferred outside the United Kingdom or European Economic Area, appropriate safeguards are implemented in accordance with UK GDPR requirements.
Categories of Technology Providers
CTS uses a range of technology solutions to support internal operations, communication, cybersecurity service delivery and certification activities.
These providers fall into the following categories.
Internal Business Operations
These tools support internal business administration, productivity and workforce management.
Examples include:
- SafeHR
- Canva
- Scribe
- Grammarly
- ChatGPT Business
- TestCandidates
- ActivTrak
- Keeper Security
- Adobe
- Usecure
- Loom
- Atlas-Hub (Citation)
- Datto
- RocketCyber
- Huntress
- AppRiver / OpenText
- Cisco OpenDNS
- Cisco Duo
- DNSFilter
- Exclaimer
- NordVPN
- OpenVPN / Connexa
- ThreatLocker
- Ninite Pro
- Cloudflare
- Google Accounts
These tools are primarily used for internal operations and security management.
Communications and Social Media Platforms
These services support communication with clients, partners and the wider public.
Examples include:
- Signal
- Microsoft Teams
- Zopier
- Zoom
Customer Relationship and Financial Systems
These platforms support client management, invoicing, payment processing and contractual administration.
Examples include:
- Microsoft 365 / Microsoft Azure
- HubSpot CRM
- Xero
- Apollo.io
- Stripe
- GoCardless
- Signable
Certification Scheme Platforms
Where CTS delivers certification services under external certification schemes, data may be processed through scheme-specific platforms operated by the scheme owner.
Examples include:
- Pervade (client assessment data platform)
- IASME Training and Certification Body Dashboard
- BlockMark Registry
These platforms are operated by the certification scheme owner and subject to their own data protection policies.
Assessment and Security Testing Platforms
CTS uses specialised tools when delivering cybersecurity services including vulnerability scanning, penetration testing and security assessments.
Examples include:
- Cyber Tec Security Partner Portal
- Qualys
- Tenable Nessus Professional
- Vonahi
- TeamViewer
- GoToAssist
- SiteGround Web Hosting
These systems may process limited client contact information and technical system data necessary to deliver cybersecurity services.
Data Protection Safeguards
CTS implements appropriate safeguards when working with third-party technology providers, including:
- contractual data protection obligations
- security assessments where appropriate
- access control and least privilege principles
- secure data transfer mechanisms
- Ongoing supplier review
CTS seeks to ensure that all third-party providers maintain appropriate technical and organisational measures to protect personal data.
Updates
The list of technology providers may change periodically as CTS improves its services and infrastructure.
This page may be updated from time to time to reflect those changes.
Contact
Questions regarding data protection, data processing or sub-processors can be directed to: [email protected]