Last Updated: September 15, 2026
This Privacy Policy is Ivy Cyber LLC’s privacy notice. It describes how ivycyber.com, including Ivy Cyber’s shop and commercial service pages, cryptopay.ivycyber.com, and Ivy Cyber’s commercial products, subscriptions, support, training, and enterprise services collect, use, protect, and retain personal information. In this Policy, “Ivy Cyber,” “we,” “our,” and “us” mean Ivy Cyber LLC.
PrivacySafe Foundation, Inc. is a separate 501(c)(3) nonprofit public charity. Foundation-operated public-interest services are outside the scope of this Ivy Cyber commercial Privacy Policy and are governed by the Foundation’s own privacy and terms documents. Ivy Cyber may provide contracted technical, hosting, infrastructure, security, administrative, or support services to the Foundation without thereby owning Foundation services, user data, charitable funds, or Foundation-controlled cryptocurrency wallets.
Note: For customer contract terms, subscriptions, warranties, returns, refunds, acceptable use, and other conditions governing Ivy Cyber products and services, please see our Terms of Service.
Account and data deletion: The public account and data deletion page provides the current procedures and distinguishes among PrivacySafe identities, Ivy Cyber storefront/customer accounts, and Foundation-operated PrivacySafe Social accounts.
Our Commitment To Privacy
At Ivy Cyber, we actively avoid collecting personal data unless it is absolutely necessary for secure transactions or technical operations. Our design principles emphasize privacy by default and data minimization. We proudly rely on Free/Libre and Open Source Software (FLOSS) to provide verifiable transparency in our platform and services. This ensures our users benefit from privacy-respecting tools that are community-vetted and ethically developed.
We do not sell or study your personal information. We collect what data is minimally necessary to conduct normal operations in the course of our business and for proper operation, diagnostics, and maintenance of our websites and applications. Privacy-rights requests may be sent to privacy@ivycyber.com.
Legal Bases and Regulatory Frameworks
Ivy Cyber processes personal information only when there is an appropriate purpose and legal basis. Depending on the context, processing may be necessary to perform a contract with you, comply with a legal obligation, protect security or other legitimate interests that are not overridden by your rights, or act on your consent. We apply data minimization, purpose limitation, storage limitation, security, and privacy-by-design principles to our operations.
GDPR and EEA/UK Privacy Rights
Where the EU General Data Protection Regulation (GDPR), UK GDPR, or related European data-protection law applies, our principal legal bases may include performance of a contract, compliance with legal obligations, legitimate interests such as fraud prevention, network and information security, service administration, and customer support, and consent where required. Individuals may also have the right to lodge a complaint with the data-protection authority responsible for their location.
Connecticut Data Privacy Act
Where the Connecticut Data Privacy Act (CTDPA) applies, Connecticut consumers may have rights to access, correct, delete, and obtain a portable copy of personal data, and to opt out of covered sales, targeted advertising, and certain profiling. Covered consumers also have a right to appeal a denial of a privacy-rights request. Ivy Cyber does not sell personal data or use personal data for targeted advertising. Where legally required, we also recognize applicable universal opt-out preference signals, including Global Privacy Control. If we deny a Connecticut privacy request, you may appeal by replying to our decision or writing to privacy@ivycyber.com with the subject “Privacy Appeal.”
Connecticut law also includes heightened protections for minors and sensitive data. Ivy Cyber does not use personal data collected under this Policy to train general-purpose large language models, does not sell minors’ personal data, and does not use minors’ personal data for targeted advertising.
California Privacy Rights
If the California Consumer Privacy Act (CCPA), as amended, applies to Ivy Cyber’s processing of your information, California residents may have rights to know, access, delete, and correct personal information, to opt out of covered sale or sharing, to limit certain uses of sensitive personal information, and to exercise those rights without discrimination. Ivy Cyber does not sell personal information or share it for cross-context behavioral advertising.
Canada and PIPEDA
Where Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) applies, Ivy Cyber is accountable for personal information under its control and uses contractual and technical measures when service providers process information on our behalf. Information processed in another jurisdiction may be subject to lawful access by courts, law-enforcement, or national-security authorities in that jurisdiction.
Legitimate Interests Assessment
Ivy Cyber maintains a Legitimate Interests Assessment (LIA) for processing activities that rely on legitimate interests. The current LIA appears at the end of this Policy. A Data Protection Impact Assessment (DPIA) or similar assessment is considered when a processing activity may create a high risk or when applicable law otherwise requires one; this Policy does not make a blanket determination that a DPIA can never be required.
COPPA (Children’s Online Privacy Protection Act) Statement
Ivy Cyber’s commercial websites and services are not directed to children under 13, and we do not knowingly collect personal information from children under 13 without legally sufficient authorization. If you have reason to believe a child has provided personal information to Ivy Cyber in a manner covered by COPPA, please contact privacy@ivycyber.com. Some Ivy Cyber products, contracts, purchases, or learning activities may require participants to be at least 18 or to have the legal capacity or authorization required for the transaction.
Your Rights
Depending on your location and applicable law, you may have rights regarding your personal information, including:
- Access: request information about personal data we hold about you and, where applicable, obtain a copy.
- Correction: request correction of inaccurate or incomplete personal data.
- Deletion: request deletion of personal data, subject to legal and operational exceptions.
- Restriction or objection: ask us to restrict certain processing or object where applicable.
- Portability: request eligible data in a portable, machine-readable form.
- Consent withdrawal: withdraw consent where consent is the legal basis for processing.
- Opt-out rights: opt out of covered sale, targeted advertising, sharing, or significant-effect profiling where applicable. Ivy Cyber does not currently sell personal data or use it for targeted advertising.
- Non-discrimination: exercise applicable privacy rights without unlawful discrimination.
To exercise a privacy right, contact privacy@ivycyber.com. We may need to verify your identity and may retain limited information necessary to document and fulfill the request. If applicable law gives you a right to appeal our decision, you may reply to the decision or email the same address with the subject “Privacy Appeal.” EEA and UK individuals may also lodge a complaint with their competent supervisory authority.
Account Deletion and Separate Account Contexts
PrivacySafe identities at privacysafe.xyz, privacysafe.me, and privacysafe.gg are intentionally separate from Ivy Cyber storefront, billing, and payment accounts. A PrivacySafe username is not, by itself, an Ivy Cyber customer or payment identifier. Ivy Cyber does not routinely maintain a mapping between those identity and storefront contexts. They can be associated when a user or customer voluntarily provides information that links them, such as in a purchase, billing, support, or deletion request.
PrivacySafe uses a zero-knowledge design for supported encrypted content. Users control the keys required to access that content, and Ivy Cyber does not possess the private keys needed to inspect, recover, or selectively identify encrypted messages, files, or records. Deleting a PrivacySafe identity and its associated key material is permanent and irreversible.
Deleting information that Ivy Cyber holds outside encrypted PrivacySafe content, such as storefront records, support correspondence, or other information voluntarily supplied to Ivy Cyber, is a different process from deleting content inside a zero-knowledge PrivacySafe account. Storefront and transaction records may also remain subject to the retention requirements described later in this Policy.
The current procedures for PrivacySafe deletion, Ivy Cyber storefront/customer-account deletion, data-only requests, and PrivacySafe Social export, migration, and account deletion are maintained on the account and data deletion page. PrivacySafe Social is operated by PrivacySafe Foundation, Inc. and uses the Foundation privacy contact identified on that page.
How do we secure data?
All information transmitted to IvyCyber.com is encrypted using cryptographic protocols and tools. User information is subject to a network of internal controls. Staff are required to undergo training on the handling and processing of data. We perform audits on a consistent basis and review our security measures in response to changes in the industry and new legal requirements. All PrivacySafe subscription services utilize a zero-knowledge architecture and strong end-to-end encryption of data in transit and at rest, ensuring that only end users control their encryption keys. For more information about these PrivacySafe subscription services, which are fully distinct products with data protection unique to those offerings, please refer to “PrivacySafe Subscription Services” below.
Cookies
Cookies on this site are essential for software functionality and are not advertising or tracking cookies. Functions include logging your browser into a registered account and saving your preferences for future visits.
Account Information
If you create an Ivy Cyber customer, subscription, affiliate, support, or Learning Commons account, we may ask for information such as a username, email address, name, password, billing or shipping information where needed, and other information necessary to provide the relevant service.
Passwords are stored in a cryptographic form appropriate to the system rather than as readable passwords. Account identifiers, email addresses, and optional profile information may be visible to other participants only when the relevant service requires that visibility, such as a class roster or discussion area. We recommend that users avoid placing sensitive personal information in optional profile fields.
Ivy Cyber’s Learning Commons may use different free-software classroom, conferencing, or course-delivery systems over time. The privacy principles in this Policy apply to Ivy Cyber-controlled learning environments regardless of the particular software used.
IP Logging and Session Metadata
We record the IP address and browser application used during login. Logged-in sessions are available for your review and revocation in your account settings. The latest IP address is stored for up to 12 months. Server logs, including IP addresses of every request, may also be retained.
Moderation
We may compare IP addresses to detect ban evasion or other violations of our policies. Moderation actions may be taken to protect the integrity of our learning environments and community standards.
Communication
The email address you provide may be used to send notifications about class interactions, account activity, or administrative updates. Your email may also be used to respond to inquiries or requests related to your enrollment or account.
Email Inquiries and Retention
If you choose to contact us via email or support form, the contents of your message may be stored as long as necessary to fulfill your request, resolve disputes, or meet legal requirements. We never sell or disclose your messages. Once your inquiry is addressed, we retain only what is essential for compliance or audit purposes. You may request deletion of any correspondence at any time by emailing privacy@ivycyber.com.
Network Information and Retention
We make a good faith effort to:
- Retain server logs containing IP addresses for no more than 90 days.
- Retain IP addresses associated with registered users for no more than 12 months.
These network logs are separate from encrypted user content and contain no decryptable user data.
Geographic Information
We use the static and open source MaxMind GeoLite geographic IP database to perform regional lookups for shopping cart functionality, service diagnostics, and high-level metrics. This data is never used to identify individual users and is aggregated, optimized for privacy, and widely used across open source projects. GeoLite is utilized by our self-hosted Plausible instance privacysafe.click and further anonymized as described in “Website Metrics” below.
PrivacySafe Subscription Services
Ivy Cyber publishes and supports commercial PrivacySafe subscription offerings, including Gold identities at @privacysafe.me, Platinum identities at @privacysafe.gg, and Enterprise deployments using an approved customer domain. PrivacySafe Silver at @privacysafe.xyz is a free Foundation-supported offering and is governed by the PrivacySafe Foundation Privacy Policy except where Ivy Cyber acts as a technical service provider.
PrivacySafe commercial subscription services use a zero-knowledge design and strong end-to-end encryption for supported private content. For encrypted content protected by user-controlled keys, Ivy Cyber is not intended to have the technical ability to decrypt the content. Users are responsible for safeguarding credentials, recovery material, and encryption keys. Account deletion and loss of keys may be irreversible.
Paid PrivacySafe synchronization storage may by default be hosted in Ontario, Canada through 3NSoft. Managed alternatives may be available in the United States or Iceland (EEA), and enterprise deployments may use other agreed regions or providers in the European Union or Asia-Pacific. The selected region and any additional contractual safeguards may be specified in the applicable order, subscription description, or enterprise agreement.
Retention of encrypted subscription data depends on account status, technical backup cycles, contractual commitments, legal obligations, and the selected service. Where a specific retention period is material to a paid service, it will be stated in the applicable service description or agreement rather than implied to be identical for every account.
Affiliate Program Participation
Users who register for the Affiliate Program at https://ivycyber.com/affiliate must provide minimal personal information to enable account creation and commission metrics. This may include:
- Full name
- Email address
- Username or display name
- Country or region (for payment eligibility)
- Preferred payout method (e.g., PayPal address)
Affiliate accounts are subject to strict privacy protections and must abide by our Terms & Conditions.
Limited Data Visibility
Affiliates may access their own referral metrics via a private dashboard. All affiliate dashboard URLs are unique, hidden, and accessible only by the assigned affiliate user and Ivy Cyber administrators. These dashboards are never publicly discoverable or indexable.
To protect the privacy of customers, affiliates may only view the following data about referred orders:
- Randomized order identifier (non-sequential and not linked to the order ID in our internal systems)
- Order date (not timestamp)
- Order total
- Order discount amount applied via the affiliate coupon
Affiliates do not have access to:
- Customer name, email address, or location
- Order time or shipping method
- Current order status (pending, failed, etc.)
- Customer IP address or device metadata
- Product list or itemized details of order (“More” column)
- Shipping or tax amounts
Affiliates are notified via email when an order is refunded or cancelled about any changes to commission metrics and payouts.
Referral Links
When a user clicks on a referral link to visit the Ivy Cyber website, a temporary browser cookie is generated to:
- Automatically apply the affiliate coupon/promo code at checkout
- Attribute the completed purchase to the referring affiliate
This temporary cookie:
- Is only used for affiliate commission metrics and storefront functionality
- May persist for up to 24 hours if no order is placed
- Is automatically deleted as soon as an order is completed
- May only be reset or recreated if a user clicks on an existing or new referral link
These cookies are essential for software functionality and comply with EU General Data Protection Regulation (GDPR).
Affiliate Data Retention, Controls and Removal
Affiliate-related data is retained only as long as necessary to fulfill our operational and accounting requirements. You may request data removal at any time by contacting privacy@ivycyber.com.
Affiliate activity is monitored by Ivy Cyber to mitigate against deception, abuse, fraud, and misuse of the referral system. Metrics are aggregated and anonymized whenever possible. Participation in the Affiliate Program is governed by our Terms & Conditions.
Hosting Providers and International Processing
Ivy Cyber uses a combination of self-hosted systems and contracted infrastructure providers. Hosting locations depend on the service. Ivy Cyber’s commercial websites and administrative systems may be hosted in the United States, while paid PrivacySafe synchronization storage may be hosted in Ontario, Canada by default or in another managed region selected for the service.
When personal information is transferred across borders, we use safeguards appropriate to the circumstances and applicable law. For EEA-origin personal data, Canada may be used where the European Commission’s adequacy framework applies to the relevant commercial organization; other transfers may rely on contractual or other lawful safeguards. Iceland is within the European Economic Area. Enterprise customers using other regions will receive region and transfer information through the applicable service documentation or agreement.
Information stored or processed in another country may be subject to the laws of that jurisdiction, including lawful access by courts, law-enforcement, or national-security authorities.
Learning Commons
Ivy Cyber may provide classes, workshops, asynchronous coursework, live sessions, and related educational activities through a Learning Commons environment using free-software and other selected technical systems. The particular classroom or conferencing software may change over time. We collect only information reasonably needed to enroll participants, provide course access, communicate about the activity, maintain security, and administer the learning environment.
Conduct on Learning Platforms
By enrolling in courses or participating in workshops and live events through Ivy Cyber, users agree to maintain respectful, lawful, and ethical conduct within our learning environments.
- Engage in discussions and coursework with courtesy and professionalism.
- Respect the privacy of instructors and fellow students and comply with applicable copyright, software-licensing, confidentiality, and course-material restrictions.
- Refrain from harassment, abuse, discriminatory language, or disruptive behavior.
- Do not share access credentials or distribute restricted course content without permission.
- Do not doxx or disclose another person’s identity, personal information, or demographic information without authorization.
Moderation or access-control actions may be taken to protect participants, systems, and the integrity of the learning environment. Contract and conduct requirements for Learning Commons activities are governed by the Ivy Cyber Terms of Service.
Payments and Third-Party Processing
Ivy Cyber accepts commercial payments through Stripe and may also offer PayPal or Venmo. Depending on the checkout configuration and your location, Stripe may make card, bank debit, ACH, or other supported payment methods available. Ivy Cyber does not need to receive or store complete card or bank-account credentials when those credentials are entered directly into a payment provider’s payment flow.
Payment providers process payment information under their own privacy terms. We receive transaction information needed to fulfill and account for an order, which may include customer identifiers, payment status, transaction identifiers, amount, currency, billing details, fraud or risk results, and limited payment-method information. We do not list occasional in-person processors in this online Policy unless they become part of our ordinary online processing; when an in-person processor is used, the processor is identified at or before the transaction where practical.
For current provider privacy information, see:
Cryptocurrency Payments
The current Ivy Cyber cryptocurrency payment page is https://ivycyber.com/crypto. The payment methods described there are for Ivy Cyber commercial purchases. Cryptocurrency donations to the separate PrivacySafe Foundation, Inc. 501(c)(3) nonprofit public charity are governed by the Foundation and should use https://privacysafe.foundation/crypto. Ivy Cyber may safeguard Foundation-controlled wallets under a technical and security support arrangement, but Foundation donations are not Ivy Cyber commercial revenue.
Ivy Cyber offers multiple cryptocurrency payment paths. A cryptocurrency invoice generated as part of an ordinary Ivy Cyber order is still associated with the relevant order and may therefore be connected with customer and transaction information already supplied to Ivy Cyber. Current in-cart options may include Bitcoin (BTC), Dogecoin (DOGE), Ethereum (ETH), Litecoin (LTC), Monero (XMR), Solana (SOL), Tether on Ethereum (USDT_ERC20), and USD Coin (USDC).
For customers who prefer to minimize disclosure to conventional payment processors, Ivy Cyber also operates a self-hosted cryptocurrency checkout at cryptopay.ivycyber.com. Current BTCPay Server options include Bitcoin over the Lightning Network, Monero, Litecoin, and Dogecoin. This route can reduce the personal and payment information shared with conventional processors, but it does not guarantee anonymity. Blockchain visibility, wallet behavior, network metadata, information already supplied to Ivy Cyber, and the selected cryptocurrency all affect privacy.
Bitcoin Lightning payments may also be arranged through Radar.chat at ivycyber@radar.cash. Other cryptocurrency payment methods may be arranged directly with Ivy Cyber. For privacy-sensitive payment questions, contact support@ivycyber.com using our published GPG key where appropriate.
Transactional Data Retention
Ivy Cyber storefront/customer accounts may contain a username or email address, billing and shipping details, order and subscription history, support history, tax information, discounts, and payment or transaction metadata. These records are distinct from zero-knowledge PrivacySafe identity data and are governed by the storefront and transaction-retention rules below.
Ivy Cyber retains transaction and order data only as long as reasonably necessary for order fulfillment, customer support, subscription administration, fraud prevention, accounting, tax, chargeback, dispute, security, and other legal or operational requirements. Data associated with storefront accounts and orders is removed, anonymized, or obfuscated when it is no longer needed for those purposes.
- Inactive storefront accounts: retained for 12 months; accounts that have not logged in or placed an order during that period may be deleted and related orders may be anonymized as guest orders.
- Pending orders: retained for 1 week, then removed when abandoned.
- Failed orders: retained for 1 week, then removed.
- Cancelled orders: retained for 1 month, then removed where no longer required.
- Refunded orders: retained for 12 months, after which personally identifying information may be obfuscated when no longer required.
- Completed orders: retained for 12 months, after which personally identifying information may be obfuscated when no longer required.
- Ended subscriptions: retained for 12 months, after which personally identifying information may be obfuscated when no longer required.
- Payment-processor metadata: processor identifiers and similar transaction metadata may be retained for up to 12 months, subject to accounting, tax, chargeback, fraud-prevention, dispute, processor, and legal requirements.
We do not intentionally store complete card numbers, bank-account credentials, or card security codes in ordinary Ivy Cyber storefront records. Those credentials are processed by the selected payment provider under its own terms and privacy notice.
Embedded Content
We avoid loading third-party content unless necessary. Where feasible, we embed videos using self-hosted players or privacy-respecting frontends such as Invidious for YouTube. In cases where this is not technically feasible or would significantly hinder accessibility or user experience, we may embed third-party content (e.g., YouTube, Vimeo) directly. When doing so, we make a good faith effort to minimize privacy impact and inform users when external content may subject them to third-party data collection.
PrivacySafe Foundation and PrivacySafe Social
Current PrivacySafe Foundation public-interest services are governed by the Foundation’s own Privacy Policy and Terms of Use. PrivacySafe Social is operated by PrivacySafe Foundation, Inc. and is hosted in the European Union, on infrastructure in France through a hosting provider organized in Portugal. Because federation, moderation, account portability, and public posting create service-specific privacy considerations, PrivacySafe Social also maintains a dedicated Privacy Policy and Terms of Use.
Website Metrics
Ivy Cyber uses a self-hosted instance of the privacy-oriented Plausible analytics software at privacysafe.click. It is used for high-level traffic measurement, site reliability, broad usage trends, and technical performance. We do not use it for behavioral advertising, cross-site profiling, or persistent advertising identifiers, and Plausible analytics does not require tracking cookies.
For daily unique-visitor measurement, the analytics system derives a short-lived identifier from the website domain, the visitor’s IP address and User-Agent, and a salt that changes each day, then passes those values through a hash function:
hash(daily_salt + website_domain + ip_address + user_agent)
The raw IP address and User-Agent used to calculate that analytics identifier are not retained as raw fields in the Plausible analytics dataset. The salt is rotated and discarded every 24 hours, which prevents the same analytics identifier from following a visitor from one day to the next and materially limits the ability to reverse the identifier back to the underlying network information.
This analytics process is separate from ordinary web-server, security, abuse-prevention, or authentication logs described elsewhere in this Policy. Those operational logs may contain network information for the limited periods stated in our Network Information and Retention section. Geographic reporting for high-level site metrics may use the static MaxMind GeoLite database locally rather than sending the visitor’s IP address to a separate geolocation service.
Link Shortening Service
Ivy Cyber communications may use psafe.ly, a PrivacySafe Foundation-supported link-shortening service. Aggregate click counts and limited technical logs may be used for service operation, abuse prevention, and diagnostics. The Foundation’s Privacy Policy governs the service itself; this Policy governs any personal information Ivy Cyber receives or uses after a person follows a link to an Ivy Cyber property.
Information Sharing
We do not sell personal information and do not share it for targeted advertising. We disclose personal information only when reasonably necessary for the purposes described in this Policy, including to service providers that perform functions on our behalf, payment providers selected by the customer, shipping or fulfillment providers where needed, professional advisers, and government or legal authorities where disclosure is required or permitted by law.
We may disclose information when we reasonably believe disclosure is appropriate to prevent or investigate fraud, abuse, security incidents, or unlawful activity; protect the integrity of our systems; enforce our agreements; establish, exercise, or defend legal claims; or protect the rights, property, or safety of users, Ivy Cyber, or others. Service providers are expected to use information only for the services they provide to us and subject to applicable contractual and legal safeguards.
Data Breach Notification
We maintain incident-response procedures and will provide notices to affected individuals, regulators, or other parties when required by applicable breach-notification or data-protection law. The timing and content of a notice depend on the nature of the incident, the information involved, the risk presented, and the law governing the event.
Disclaimer of Warranty
THERE IS NO WARRANTY FOR SOFTWARE, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE SOFTWARE “AS IS” WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE SOFTWARE IS WITH YOU. SHOULD THE SOFTWARE PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
Limitation of Liability
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL ANY PARTY BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE SOFTWARE (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE SOFTWARE TO OPERATE WITH ANY OTHER SITE OR SOFTWARE), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
Governing Law and Dispute Resolution
These Terms are governed by the laws of the State of Connecticut, United States, without regard to its conflict of laws principles. If a dispute arises between you and Ivy Cyber relating to these Terms, the use of our Services or Products, or any related issue, we aim to resolve it fairly and efficiently. Most concerns can be resolved informally by contacting our team at legal@ivycyber.com.
If informal resolution is not possible, you may choose to resolve the dispute through final and binding arbitration or by pursuing a claim in a court of competent jurisdiction located in New Haven County, Connecticut. Arbitration, if selected, will be conducted by a mutually agreed provider using procedures designed to minimize cost and complexity.
Nothing in this section prevents either party from seeking injunctive or equitable relief in court when appropriate, especially in matters involving copyright, trademarks, software licensing, trade secrets, confidential information, or misuse of services. We do not require users to waive their rights to participate in a class action or collective proceeding. However, we ask that individual disputes be attempted in good faith before collective legal action is considered.
Changes To This Policy
We may update this Policy as our services, processing activities, or legal obligations change. The “Last Updated” date identifies the current version. When applicable law requires additional notice, consent, or another choice before a materially different use of personal information, we will provide it. Notice of significant changes may also be made through our websites or social media channels:
- Mastodon: https://privacysafe.social/@IvyCyber
- Twitter X: https://x.com/@IvyCyberEd
- Bluesky: https://bsky.app/profile/ivycyber.com
Contact Information
Business Address:
Ivy Cyber LLC
1204 Main St Num 1197
Branford, CT 06405-3787
+1 (929) 748-7233
Legitimate Interests Assessment (LIA)
Assessment Date: September 5, 2026
Next Review Date: September 5, 2027, or earlier if material processing changes
Why We Publish This
At Ivy Cyber, we treat privacy as a core principle, not just a legal obligation. While the General Data Protection Regulation (GDPR) allows companies to conduct Legitimate Interests Assessments (LIAs) privately, we publish ours to ensure that our users, partners, and regulators understand how and why we process personal data.
We believe transparency fosters trust. Publishing this assessment demonstrates our commitment to data minimization, privacy by design, and ethical software development. It outlines our rationale, safeguards, and intent as we carry out necessary operations across our educational, media, and privacy technology platforms.
1. Purpose Test
What is the purpose of the processing?
Ivy Cyber processes minimal personal data to operate, maintain, and secure its services. This includes:
- User authentication and login security
- Administrative communication (e.g., account and enrollment notifications)
- Abuse prevention and moderation enforcement
- Collection of high-level, privacy-respecting metrics via a self-hosted instance of Plausible
- Order and subscription processing
- Security diagnostics and fraud detection
Is there a legitimate interest behind the processing?
Yes. Our legitimate interests include:
- Delivering and securing educational and software services
- Fulfilling purchase and subscription orders
- Ensuring lawful and respectful participation in learning environments
- Preventing abuse, spam, and service degradation
- Meeting obligations under GDPR, CTDPA, CCPA where applicable, PIPEDA where applicable, and other relevant law
2. Necessity Test
Is the processing necessary for the intended purpose?
Yes. The processing we perform is essential to the secure and functional operation of our systems. Specifically:
- IP addresses are logged briefly to support login, session management, and abuse prevention
- Cookies are used solely for session persistence and interface preferences
- No behavioral profiling, fingerprinting, or advertising trackers are used
- User data is never sold or shared for marketing purposes
We avoid third-party scripts and tracking mechanisms wherever possible. However, there are three limited exceptions:
- Order Fulfillment: When users complete purchases, payment interfaces may connect to Stripe, PayPal, or Venmo as selected by the customer. These are necessary for payment authorization and fraud prevention. Ivy Cyber does not store or process full payment credentials.
- Affiliate Discounts: When users complete purchases with an affiliate discount coupon or referral link, anonymized metrics about the order are retained in an Affiliate Portal. These are necessary for affiliate commissions and payouts and the affiliate has no access to customer identity, location, or product details.
- Embedded Content: Where possible, we embed videos using self-hosted players or privacy-respecting frontends (e.g., Invidious for YouTube). In some cases, embedded third-party content (e.g., YouTube or Vimeo) is used when self-hosting is not feasible or would negatively affect accessibility, compatibility, or user experience. We make a good faith effort to inform users when external content may impact their privacy.
Can less intrusive means be used to achieve the purpose?
We have already implemented the least intrusive methods available. These include:
- Use of free software and self-hosted infrastructure where practical, including privacy-oriented metrics at privacysafe.click
- No use of third-party analytics platforms, CDN-based trackers, or advertising beacons
- Anonymized metrics to facilitate affiliate discounts
- Cryptographic data handling and minimal storage durations
- Direct-wallet and self-hosted cryptocurrency payment options that can reduce reliance on conventional payment processors
3. Balancing Test
Would individuals reasonably expect this data to be processed?
Yes. We make our data processing practices clear in our publicly available Privacy Policy (https://ivycyber.com/privacy) and Terms & Conditions (https://ivycyber.com/terms). Users interact with Ivy Cyber in contexts (e.g., education, privacy software, media) where secure processing of minimal data is reasonable and expected.
What is the nature of the data being processed?
We process only:
- Basic account information (e.g., email, username)
- Session metadata (e.g., IP address, browser user-agent)
- Order-related details (e.g., purchased item, discount information, payment method and transaction metadata from Stripe, PayPal/Venmo, or a selected cryptocurrency payment route)
- Aggregated geographic data (used for currency selection, regional pricing, and high-level metrics)
We use the static and open source MaxMind GeoLite geographic IP database to perform regional lookups for shopping cart functionality, service diagnostics, and high-level metrics. This data is never used to identify individual users and is aggregated, optimized for privacy, and widely used across open source projects. We do not collect sensitive categories of data (e.g., health, biometrics, racial/ethnic identity) unless explicitly required for user-submitted inquiries, and only then with purpose-limited retention.
Could the processing cause unwarranted harm or intrusion?
Unlikely. Ivy Cyber designs all services with minimalism and cryptographic protections in mind. We do not track behavior, profile users, or engage in targeted advertising. Payment and embedded content are handled transparently, and optional where possible.
Are safeguards in place?
Yes. Ivy Cyber has implemented:
- TLS encryption across all services
- Role-based access control for internal systems
- Self-hosted software infrastructure whenever feasible
- Data minimization in design and operation
- Anonymized metrics collection
- Limited use of external scripts only at payment or explicit user request
- Staff training and periodic audits
Conclusion
For the processing activities identified in this assessment, Ivy Cyber concludes that the stated legitimate interests are narrowly scoped and are supported by the safeguards described above. We avoid unnecessary data collection, implement strong safeguards, and review these practices regularly. Publishing this assessment is part of our broader mission to develop and promote privacy-respecting digital infrastructure.
Signed by:
Sean O’Brien
Chief Executive Officer
Ivy Cyber LLC
