Legal

Privacy Policy

Last updated: 2 June 2026

1. Who we are

Fortify is a product of Blue Cipher Ltd(“we”, “us”, “our”). We are the data controller for the personal information collected through this website.

If you have any questions about this policy or how we handle your data, please contact us at jason@bluecipher.co.uk.

2. What data we collect and why

Assessment conversation

When you complete the digital resilience assessment, your responses are sent to the Claude AI model (provided by Anthropic) to generate your personalised report. We store the conversation in our database solely for the purpose of producing your report. We do not use your assessment responses for any other purpose.

Name and email address

At the end of the assessment you provide your name and email address so we can deliver your report. We store this information in our database and in our CRM system (HubSpot).

We will also use your contact details to reach out personally to discuss your results. For free tier users, this typically means a short conversation to walk through your findings and explore whether a deeper engagement would be useful. For paid tier users, we use your contact details to arrange the follow-on sessions included in your package.

We will never send you unsolicited marketing emails, add you to a mailing list, or contact you about anything unrelated to your assessment and its results.

Report data

The scores, findings, and actions from your report are stored in our database and attached to your contact record in our CRM system. This allows us to provide context if we follow up with you, and helps us understand the general patterns and needs of our users (in aggregate only).

Usage and security data

We collect IP addresses for rate limiting and bot protection purposes. These are not linked to your identity and are not retained beyond the session.

3. Legal basis for processing

We process your personal data on the following bases under UK GDPR:

  • Consent — you tick a box at the point of submitting your email address, confirming you agree to your data being stored and used to deliver your report and for a consultant to contact you to discuss your results.
  • Legitimate interests — we have a legitimate interest in protecting our service from abuse (rate limiting and bot protection) and in understanding aggregate usage patterns to improve our product.

You may withdraw your consent at any time by contacting us at jason@bluecipher.co.uk. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

4. What we do not do

  • We do not sell your personal data to any third party.
  • We do not share your data with any third party for their own marketing purposes.
  • We do not use your data to train AI models. Anthropic does not use data submitted via the Claude API to train its models.
  • We do not make automated decisions that produce legal or similarly significant effects about you.

5. Third-party processors

We use the following trusted third-party services to operate Fortify. Each acts as a data processor on our behalf and is bound by appropriate data processing agreements.

ProviderPurposeLocation
AnthropicAI model for assessment and report generationUSA
SupabaseDatabase (sessions, messages, reports)EU
VercelApplication hosting and deliveryUSA / EU
ResendTransactional email deliveryUSA
HubSpotCRM — contact and report recordsUSA
CloudflareBot protection (Turnstile)USA / EU
UpstashRate limiting (IP-based, transient)EU

Transfers to providers outside the UK/EU are covered by Standard Contractual Clauses or equivalent adequacy mechanisms.

6. Cookies and similar technologies

Essential cookies

These are strictly necessary for the service to function and cannot be switched off. They include a technically necessary cookie placed by Cloudflare Turnstile (our bot protection service) during the security check. This cookie does not track you across websites and does not persist after your session ends.

Analytics cookies

We may use analytics cookies to understand how people use Fortify and to improve the service. These are only set if you choose “Accept all” in the cookie preference banner shown on your first visit. You can change your preference at any time by clearing your browser's local storage, or by contacting us.

We do not use advertising or cross-site tracking cookies. Your cookie preference is stored locally in your browser and is not sent to our servers.

7. How long we keep your data

We retain your name, email, and report data for as long as it is needed to provide our services and to follow up with you about your results. If you ask us to delete your data, we will do so promptly (see your rights below). Assessment conversation data is retained only as long as needed to generate your report.

8. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erasure — request that we delete your data
  • Restrict how we process your data in certain circumstances
  • Data portability — receive your data in a structured, machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, email us at jason@bluecipher.co.uk. We will respond within one month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

9. A note on assessment content

The assessment is designed to discuss your business operations and technology — not individuals. Please avoid sharing personal data about staff, customers, or third parties during the conversation. Any such data shared incidentally is processed solely to generate your report and is not used for any other purpose.

10. Changes to this policy

We may update this policy from time to time. The date at the top of the page will always reflect the most recent version. Material changes will be notified by email if you have provided one.