GRYHAT
Privacy Policy

Privacy Policy

This policy covers the CMMC Level 1 readiness assessment at this site. It describes exactly what the assessment collects, where it goes, and how to get it removed. Effective August 3, 2026.

Who we are

GRYHAT Cybersecurity, Mission Viejo, California. We provide CMMC training, readiness assessments, and compliance consulting to defense contractors. You can reach us atandy@gryhat.com or(714) 794-2803.

What we collect

Only what the assessment actually asks for, plus what your browser sends:

What we do not collect

No payment details, no government identifiers, and no account credentials. This form never asks for them and you should never enter them.

Do not paste actual Federal Contract Information, Controlled Unclassified Information, or system configuration details into the assessment. It asks only about the presence or absence of practices. It does not need, want, or handle the regulated data itself.

How we use it

We do not sell your personal information for money, and we do not use it for automated decision-making that produces legal effects. Your score is a readiness indicator you asked for, not a decision made about you.

Advertising and measurement

We advertise this assessment on Meta and LinkedIn. When you complete the assessment or request a report, those platforms are told that a conversion happened so we can tell which ads are working. Under California law that counts as “sharing” for cross-context behavioral advertising, and we would rather say so plainly than hide behind the fact that no money changes hands.

Two things limit it. First, we send conversion events and identifiers — never your assessment answers, your score, or which practices you failed. Those stay with us. Second, if your browser sends a Global Privacy Control signal, our tag manager does not load at all, so no advertising or measurement tags run for you. Most privacy browsers and extensions send GPC automatically. You can also opt out by emailing us.

Who processes it

Your submission is stored in a private, non-public blob store. It is not published, not listed, and not indexed. These are the only third parties that touch it:

ProcessorWhat they doLocation
VercelHosting and private blob storage for assessment submissionsUnited States
ResendDelivery of your gap report and related emailUnited States
PostHogProduct analytics — which steps of the assessment are completedUnited States
Google Tag ManagerLoads our measurement and advertising tagsUnited States
Meta, LinkedInAdvertising measurement — told that a conversion happened, so we can see which ads workUnited States
Cal.comScheduling, only if you choose to book a callUnited States

We will also disclose information where we are legally required to, or to protect our rights or the security of the service.

Your report link

Your gap report lives at a private URL containing a long random token. It is marked no-index so search engines do not list it, but anyone you forward the link to can open it — that is deliberate, so you can send it to your prime or your IT provider. Treat the link the way you would treat the report itself. Ask us and we will revoke it.

How long we keep it

Until you ask us to delete it, or twenty-four months after our last contact with you, whichever comes first. Deletion requests are honored regardless of where that clock is.

Your California privacy rights

Under the CCPA as amended by the CPRA, California residents have the right to know what personal information we hold, to request a copy of it, to correct it, and to have it deleted. You also have the right to opt out of the sharing described under “Advertising and measurement” above, and the right not to be discriminated against for exercising any of these rights.

We do not collect sensitive personal information as the CPRA defines it. In the preceding twelve months we have collected the identifiers, commercial information, and internet activity described above, from you directly, for the business purposes listed above.

To exercise any right, email andy@gryhat.com with the address you used. We will verify the request by replying to that address and will respond within 45 days. We honor Global Privacy Control signals where your browser sends them.

Security

Submissions are transmitted over TLS and stored in a private blob store that is not publicly readable. Access is limited to GRYHAT personnel who need it. No system is perfect, and we will not claim otherwise — if we learn of a breach affecting your information, we will notify you as required by California law.

Children

This is a business service and is not directed to anyone under 18. We do not knowingly collect information from minors.

Changes

If this policy changes materially we will update the effective date above and, where the change affects information we already hold, notify the address you gave us.

Contact

GRYHAT Cybersecurity · Mission Viejo, California
andy@gryhat.com ·(714) 794-2803