RightCyber
Skip to privacy notice
RightCyberBack to the assistant

Chatbot privacy

What happens to your question.

This notice covers the RightCyber Cyber Essentials AI assistant. It explains what the chatbot sends, what it does not save, and where OpenAI and hosting-provider processing still applies.

Last updated
Controller
RightCyber, United Kingdom
Privacy contact
info@rightcyber.co.uk

Scope and controller

RightCyber is the controller for the way this chatbot is provided and configured. This notice applies only to the assistant at this domain. The wider RightCyber website, purchases, account access, licensing, and product support are covered by the separate RightCyber website privacy notice.

The assistant provides general Cyber Essentials preparation guidance. It is not intended to collect client evidence, confidential records, incident material, or information about an identifiable person.

Information processed

Conversation content

When you send a message, the application processes its text and enough of the recent conversation to provide a contextual answer. The generated answer is streamed back to your browser. The chatbot has no file-upload feature.

Pilot access

During the protected pilot, the shared access password is checked on the server and is not written to the session. A strictly necessary, signed cookie records that the browser has passed the gate. It contains a version, issue and expiry times, and a random value; it does not contain a name, email address, or other user identity. It expires after eight hours.

Technical information

Requests necessarily include technical data such as an IP address, request headers, browser or device information, and timestamps. For production rate limiting, the application transforms its network-derived identifier with a keyed hash before sending a counter key to Upstash; Upstash does not receive the raw identifier from this application. A random request ID is also created for each chat request. The hosting provider processes traffic and service logs to deliver and secure the site.

Why we process it

RightCyber processes this information to:

  • answer the question you choose to submit;
  • maintain context within the current conversation;
  • control access during the pilot;
  • rate-limit misuse and protect the service; and
  • diagnose availability and security problems.

RightCyber relies on its legitimate interests in providing, protecting, and improving this optional business guidance service. The pilot cookie is used because it is strictly necessary to provide the protected service. RightCyber does not use chatbot content for advertising, sell it, or use it to make decisions with legal or similarly significant effects about you.

OpenAI and hosting

OpenAI API

RightCyber sends conversation content to the OpenAI API so a model can generate the answer. The request is configured withstore: false, so the application does not ask OpenAI to keep it as a saved response object. This is not the same as an approved Zero Data Retention arrangement.

OpenAI states that API inputs and outputs are not used to train or improve its models by default unless the API customer explicitly opts in. OpenAI also states that its default abuse monitoring logs may contain prompts and responses and may be retained for up to 30 days unless longer retention is required by law. Read OpenAI's current API data-controls documentation and business-data privacy information.

Vercel hosting

The production application runs on Vercel, which delivers the website and executes the chat function. Vercel states that it processes website traffic information such as end-user IP address, coarse location derived from IP, system configuration, diagnostics, and service logs. See the current Vercel privacy notice. The application does not deliberately write prompt or answer text to its own runtime logs.

Upstash rate limiting

Upstash Redis stores keyed-hash identifiers and counter values used to limit requests and protect the service. It does not receive prompts, answers, the pilot password, or a raw IP address from the application. See Upstash's current compliance and legal documentation.

OpenAI, Vercel, Upstash, and their subprocessors may process information outside the United Kingdom. Contact RightCyber if you would like information about the safeguards relevant to this processing.

Provider statements on this page were checked against the linked provider documentation on 14 August 2026. Provider terms and controls can change.

Storage and retention

  • In your browser: the visible conversation is held in page memory. Starting a new conversation, reloading, or closing the tab removes that browser copy.
  • By RightCyber: the application does not have a conversation database and does not deliberately persist prompts or answers. The pilot session cookie expires after eight hours.
  • For rate limiting: the application sets active Redis keys so per-client minute counters expire at the end of their fixed one-minute window; login-attempt counters at the end of their 15-minute window; and per-client daily and global usage counters at the end of the UTC day. Per-client and login counter keys use keyed-hash identifiers; no counter stores a raw IP address. These are live-key TTLs, not a promise that provider snapshots or backups are deleted at the same time. Upstash may retain operational snapshots or configured backups separately; the production deployment's plan-specific backup settings and retention must be confirmed before pilot use.
  • By OpenAI: the default abuse-monitoring period described above may be up to 30 days, subject to the exceptions in OpenAI's current documentation.
  • By the host: traffic and technical records are retained under the production hosting configuration and provider terms.

Selecting New conversation clears the browser view; it cannot erase records that a provider has already created under its retention rules.

Your choices and rights

You can use the assistant without entering a name or email address. You can also choose not to use it and instead consult the official NCSC resources or contact RightCyber in general terms.

Depending on the circumstances, UK data-protection law may give you rights to ask for access, correction, deletion, restriction or portability, and to object to processing. Email info@rightcyber.co.uk with a privacy request. Because the chatbot does not create an account or attach conversation content to an identity, RightCyber may not be able to identify an anonymous conversation from the information you provide.

You can also raise a concern with the UK Information Commissioner's Office. The ICO explains how to do this on its data-protection complaints page.

Contact and changes

Send privacy questions to info@rightcyber.co.uk. Do not email a conversation transcript, evidence, credentials, or private client material. Describe the issue in general terms.

RightCyber may update this notice when the chatbot, its providers, or their retention controls change. The date at the top identifies the current version.

Prefer not to use AI?

Official guidance remains available directly.
Open NCSC resources