1. Who we are
SIA CyAdviso, registered in Latvia (reg. no. 40203253216, EU VAT LV40203253216), Riga, Latvia, EU (the “Controller”).
Contact: info@cyadviso.com.
2. What data we process and why
2.1. DORA self-assessment lead form
On the homepage we offer a free 3-minute DORA readiness self-assessment. The score itself runs entirely in your browser — no data leaves your device. If you choose to receive the detailed gap report by email, we collect your work email address and the score / answers you submitted.
- Purpose: sending you the gap report you requested and a short follow-up about engagement options.
- Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in responding to a request for information you initiated. You can object at any time by replying “unsubscribe” to any email.
- Retention: we keep the email and submission for up to 24 months, after which the record is deleted unless we’ve started a commercial engagement with you.
- Processors: HubSpot stores the request in our CRM and Resend delivers the requested report email on our behalf. We do not sell or rent the data, and we do not disclose the assessment answers to advertising platforms.
2.2. Direct contact (email, Cal.com)
If you email us or book a discovery call, we process the data you provide for the purpose of replying. Cal.com, our booking provider, processes the booking on our behalf as a sub-processor; see their privacy notice for details.
2.3. Business email we send to you
We contact professionals at licensed EU and UK financial entities about ICT risk and regulatory topics relevant to their role. We do this on the basis of our legitimate interest (Article 6(1)(f) GDPR) in offering a professional service to the people responsible for that work, and we write to your work address only, never a personal one. Where we hold your address, it came from a public register, your professional profile, or a business data provider.
- We measure whether the message was opened and whether links in it were clicked. Our sending tool includes a small image in the message for this purpose. It tells us that the message was opened, roughly when, and from which broad location and device type. It does not read your mailbox, your reply, or anything else on your device.
- Why we measure it: to stop contacting people who are not interested and to keep volume low. A message left unopened twice is not followed by a third.
- How to switch the measurement off: reply with the words no tracking. We will disable it for your address and still answer you normally. Most email clients block these images by default in any case, and blocking them costs you nothing.
- How to stop hearing from us: every message carries a one-click unsubscribe, and you can also simply reply unsubscribe. We act on it immediately and permanently, and we do not ask for a reason.
- Retention: open and click records are kept for up to 12 months and then deleted. Unsubscribe records are kept for longer, because that is how we make sure we do not contact you again.
You may object to this processing at any time under Article 21 GDPR, including to the measurement described above, without giving reasons. We will stop.
2.4. First-party and cookieless analytics
We use a self-hosted endpoint at /api/track for CTA clicks, form submissions and technical error reports, and Vercel Speed Insights to measure page loading speed. These layers set no analytics cookies and count no visits. The Google tags described in section 2.5 also run cookieless until you opt in; the optional third-party analytics and advertising cookies are described there.
- No cookies are set for analytics. No cross-site tracking.
- IP addresses are truncated to /24 (IPv4) before storage, so individuals cannot be re-identified.
- We honour browser-level Do Not Track (DNT) and Global Privacy Control (GPC) signals — when either is set, no analytics events are recorded for your visit.
- Legal basis: Art. 6(1)(f) GDPR — legitimate interest in measuring how the site performs without identifying visitors.
2.5. Google measurement and advertising cookies
Google Tag Manager, which carries Google Analytics 4 and Google Ads conversion measurement, loads on every page. Until you select Accept optional it runs in Google Consent Mode with storage denied: it sets no cookies, stores nothing on your device and reads nothing from it, and sends only aggregate, cookieless signals that carry no identifier for you. Advertising click identifiers are redacted from those signals while storage is denied.
Beyond that, the banner asks about two purposes separately, and you may allow either one without the other:
- Analytics. Google Analytics 4 begins setting its measurement cookies, and Microsoft Clarity is loaded for aggregate session replay and heatmaps.
- Advertising. Google Ads conversion measurement begins setting its cookies, and the Meta Pixel (Facebook / Instagram audience and conversion measurement), the LinkedIn Insight Tag (LinkedIn audience and conversion measurement) and HubSpot (marketing analytics and visitor tracking) are loaded.
A purpose you have not allowed sets nothing and loads nothing. If you refuse both, none of those five scripts is ever loaded and the Google tags stay in cookieless mode. Withdrawing a purpose you previously allowed reloads the page so the scripts for it stop running.
- Providers: Google Ireland Limited / Google LLC (Tag Manager, Ads); Meta Platforms Ireland Limited / Meta Platforms Inc. (Meta Pixel — Facebook and Instagram measurement); LinkedIn Ireland Unlimited Company / LinkedIn Corporation (Insight Tag — LinkedIn measurement); Microsoft Ireland Operations Limited / Microsoft Corporation (Clarity — aggregate session replay and heatmap analytics); HubSpot Ireland Limited / HubSpot, Inc. (HubSpot — marketing analytics and visitor tracking).
- Purposes: measuring submitted lead forms, completed booking events, aggregate campaign performance and how pages are used.
- Legal basis: for the cookies and for the Meta, LinkedIn, Clarity and HubSpot tags, your consent under Art. 6(1)(a) GDPR. You may refuse or withdraw consent at any time without affecting access to the site. For the cookieless Consent Mode signals described above, which neither store nor read anything on your device, Art. 6(1)(f) GDPR: legitimate interest in measuring aggregate campaign and page performance.
- Conversion events: the site may send non-sensitive event names such as
lead_email_captureandcal_booking_completeto Google Tag Manager. We do not intentionally send your email address or DORA assessment answers to Google through these events.
Your choice is stored for up to one year in the strictly necessary cy_consent cookie, which records one flag per purpose (for example v2.a1.m0 means analytics allowed, advertising refused). It holds nothing else and identifies no one. Use the button below to review or change either purpose at any time.
2.6. Professional outreach on LinkedIn
We may contact professionals at EU-regulated financial firms (such as electronic money institutions, payment institutions and crypto-asset service providers) on LinkedIn — by connection request, direct message, or InMail — where their professional role makes our vCISO and DORA advisory directly relevant to their work.
- Data we process: your name, professional role, employer, and the public professional signal that prompted us to reach out (for example, a role change or a post you published). We may also add your work email address, obtained from a public register or a business data provider, so that we can continue a conversation by email. We do not process anything about your private life, and we do not sell or share your data with third-party marketing platforms.
- Purpose: introducing relevant expertise to a defined professional audience.
- Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in offering role-relevant professional services, balanced against your rights. You have the right to object at any time under Art. 21 GDPR.
- Opt-out: tell us you are not interested (a reply is enough) and we stop immediately and add you to our suppression list across all our channels.
- Retention: if you do not respond, we delete your record within 12 months unless a commercial engagement has begun.
3. Your rights under the GDPR
You have the right to:
- access the personal data we hold about you;
- have it corrected or deleted;
- restrict or object to processing;
- have your data transferred to another controller;
- lodge a complaint with the Latvian Data State Inspectorate (www.dvi.gov.lv) or the supervisory authority in your EU Member State.
To exercise any of these rights, email info@cyadviso.com. We respond within 30 days.
4. International transfers
We use service providers including Cal.com (booking), HubSpot (CRM and, with consent, website measurement), Resend (transactional email) and Vercel (hosting and cookieless page-speed measurement). Where a provider processes data outside the EEA, the transfer is covered by an applicable adequacy decision, EU Standard Contractual Clauses, or another lawful transfer mechanism.
5. Changes to this notice
We may update this notice when we change how we handle data. The “Last updated” date at the top tracks the most recent material revision.
6. Related
See also our terms of use and imprint.