Privacy Policy
Dead Cyber Society Privacy Notice
Last updated: 19 August 2026
Website: deadcybersociety.org
1. About this Privacy Notice
Dead Cyber Society (“DCS”, “we”, “us” or “our”) is committed to protecting the privacy, security and dignity of people who use our website, educational resources and community services.
This Privacy Notice explains:
- what personal information we collect;
- why we collect and use it;
- our lawful bases for processing it;
- who may have access to it;
- when information may be shared;
- how long we keep information;
- how we protect information; and
- the data-protection rights available to you.
We aim to collect only the personal information reasonably necessary to operate DCS, protect our users, maintain security and provide our services.
Because DCS provides services that may be accessed by young people, we take additional measures to protect children’s privacy and provide age-appropriate information about how personal information is used.
2. Who is responsible for your information?
For data-protection purposes, the controller responsible for personal information processed through this website is:
Dead Cyber Society
Country: United Kingdom
If you have questions about this Privacy Notice or how DCS handles your personal information, please contact us using the privacy contact above.
3. Information we may collect
The information DCS processes depends on how you use the website.
Website visitors
We may process technical information necessary to operate and secure the website, including:
- IP address;
- date and time of requests;
- requested pages or resources;
- browser type;
- operating system;
- device and request information;
- security events;
- login attempts;
- server and application logs; and
- information required to detect malicious, abusive or fraudulent activity.
We do not claim that a website can obtain a device’s hardware MAC address through ordinary internet traffic. Where device-related information is processed, this refers to information technically available to the website or its security systems.
Registered members
When you create or maintain an account, we may process information such as:
- username;
- email address;
- account identifiers;
- display name or profile information you choose to provide;
- age or age-group information where required for eligibility and safeguarding;
- account preferences;
- Daylight or After Dark theme preference;
- registration and account status;
- community activity;
- moderation history; and
- security information associated with the account.
We will not ask members to provide unnecessary personal information merely to complete their profile.
Community activity
When you participate in DCS community features, we may process:
- posts;
- comments;
- reactions;
- reports;
- uploaded content;
- moderation actions;
- communications sent to authorised DCS staff;
- timestamps; and
- other information necessary to operate and safeguard the community.
Information you publish in a community area may be visible to other people who have access to that area.
You should not publish information that unnecessarily identifies you or another person.
Anonymous community features
DCS may provide features that appear anonymously to other community members, including anonymous journal or confession features.
Anonymous to the community does not necessarily mean anonymous to DCS.
Where technically and operationally necessary for safeguarding, abuse prevention or legal purposes, DCS may retain an internal link between anonymous content and the account that submitted it.
Access to information capable of revealing the author of protected anonymous content is strictly restricted and must not be used merely to satisfy curiosity or identify someone publicly.
DCS may access that information where reasonably necessary for safeguarding, serious abuse investigation, security, legal compliance or protection of a person.
Reports and safeguarding information
If you report harassment, abuse, exploitation, grooming, threats, self-harm concerns, sextortion, stalking or another safety issue, the information you provide may contain sensitive personal information about you or another person.
This may include:
- usernames and account identifiers;
- descriptions of incidents;
- screenshots or other evidence;
- communications;
- dates and times;
- information about alleged offenders;
- information concerning children;
- information concerning physical or mental wellbeing; and
- other information you voluntarily provide.
Please provide only information that is relevant to the concern being reported.
DCS will restrict access to safeguarding information according to role and operational need.
DCS is a peer-support and educational organisation. It is not a substitute for the police, emergency services, legal representation, medical services or professional mental-health care.
Contact forms and correspondence
If you contact DCS, we may process:
- your name;
- email address;
- username;
- the content of your message;
- attachments you provide; and
- information necessary to respond to your enquiry.
Volunteers, Academy applicants and other applicants
Where you apply to volunteer, undertake training or participate in another DCS programme, additional information may be collected.
Where appropriate, a separate privacy notice or just-in-time privacy information will be provided when that information is collected.
4. Children’s information
Protecting children and young people is a particularly important part of DCS’s privacy and safeguarding approach.
Where DCS provides services for under-18s, we aim to:
- collect only information reasonably necessary to provide and safeguard the service;
- use high-privacy settings by default;
- keep adult and under-18 community environments separated;
- restrict access to children’s information;
- avoid unnecessary location information;
- provide clear, age-appropriate explanations of how information is used; and
- consider the best interests of the child when designing features involving personal information.
Where parental or guardian information or consent is required, DCS may process information necessary to administer and record that process.
DCS may also operate safeguarding procedures for circumstances in which seeking parental involvement could itself create or increase a risk to a young person. Such cases must be handled carefully and according to DCS safeguarding procedures and applicable law.
Children and young people have data-protection rights in their own right.
A separate Young People’s Privacy Guide will provide this information in simpler language.
5. Why we use personal information
Depending on the circumstances, DCS may process personal information to:
- provide and administer the website;
- create and manage accounts;
- provide community functionality;
- maintain separation between adult and under-18 environments;
- provide educational and support resources;
- respond to enquiries;
- receive and investigate reports;
- moderate community content;
- protect users from abuse;
- address safeguarding concerns;
- prevent spam, fraud and malicious activity;
- secure accounts and website infrastructure;
- investigate security incidents;
- enforce community rules;
- maintain appropriate records;
- establish, exercise or defend legal claims;
- comply with legal obligations; and
- improve the safety, accessibility and reliability of our services.
We will not use personal information for an incompatible new purpose without considering our data-protection obligations and providing additional information where required.
6. Our lawful bases
UK data-protection law requires us to have a lawful basis for processing personal information.
Depending on the processing activity, DCS may rely upon:
Contract
Where processing is necessary to provide a service you have requested or to administer your membership under applicable terms.
Legitimate interests
Where processing is reasonably necessary for legitimate purposes such as:
- website and account security;
- preventing abuse and fraud;
- community moderation;
- maintaining service integrity;
- responding to enquiries; and
- protecting DCS and its users.
Where we rely on legitimate interests, we must consider those interests against your rights and interests.
Legal obligation
Where processing is necessary for DCS to comply with an applicable legal obligation.
Consent
Where we specifically ask for and rely upon your consent.
Where consent is the lawful basis, you may withdraw that consent.
Vital interests
In exceptional circumstances, information may be processed where necessary to protect someone’s life.
Some safeguarding information may constitute special category personal data. Where special category information is processed, DCS must also identify an appropriate additional condition under data-protection law.
DCS must document the precise lawful basis and, where relevant, special-category condition for each processing activity in its internal data-processing records.
7. Security and fraud prevention
DCS uses technical and organisational security measures intended to protect the website and its users.
Security systems may process information such as:
- IP addresses;
- login attempts;
- request information;
- browser or device characteristics;
- suspected attack activity;
- security events; and
- server/application logs.
This information may be used to detect or investigate:
- unauthorised access;
- account compromise;
- malicious requests;
- spam;
- fraud;
- attempts to circumvent restrictions;
- ban evasion;
- attacks against the website; and
- other security incidents.
Access to detailed security information, including raw IP addresses and sensitive security logs, is restricted.
Security information will not be made publicly available.
8. Images and uploaded files
Images and other files can contain hidden metadata, including information about the device used to create them and, in some circumstances, location information.
Users should avoid uploading files containing unnecessary location or identifying metadata.
Where technically practical, DCS may remove certain metadata from uploaded community images as an additional privacy safeguard.
However, users should not rely solely on automated metadata removal when handling particularly sensitive material.
9. Cookies and similar technologies
DCS may use cookies and local browser storage for purposes including:
- maintaining login sessions;
- account security;
- remembering user preferences;
- remembering Daylight or After Dark theme selection;
- maintaining essential website functionality; and
- other functions described in our Cookie Notice.
Some WordPress functionality may set cookies when users log in, manage content or use other website features.
Where non-essential cookies or similar technologies require consent, DCS will seek that consent before using them.
Further information will be available in our Cookie Notice.
10. Embedded content and external services
Some pages may contain content or services provided by third parties, such as videos or externally hosted resources.
When third-party content is loaded, the provider may receive technical information such as your IP address and browser information and may use cookies or similar technologies.
Where practical, DCS will minimise unnecessary third-party tracking and use privacy-enhancing configurations.
External services operate under their own privacy policies.
11. Security and anti-spam services
DCS may use security and anti-spam services to protect the website.
At the date of this notice, DCS uses Wordfence as part of its security arrangements.
Such services may process technical information required to identify malicious activity, protect accounts or prevent spam.
The precise processors and services used by DCS should be maintained in an internal data-processing and third-party supplier register.
12. Gravatar
If DCS enables Gravatar functionality, an anonymised value derived from an email address may be sent to the Gravatar service to determine whether a profile image is associated with that address.
If Gravatar is not used on the live DCS website, this section should be removed.
13. Who may see your information?
Access to personal information is restricted according to role and operational need.
Depending on the information concerned, access may be available to appropriately authorised:
- site owner;
- administrators;
- moderators;
- safeguarding personnel;
- technical/security personnel; or
- service providers acting on DCS’s behalf.
Access to one category of information does not automatically give a staff member access to every other category.
Particularly sensitive information should have stricter access controls.
14. When we may share information
DCS does not sell personal information.
We may disclose information where reasonably necessary to:
- provide a service;
- operate website infrastructure;
- investigate or respond to serious abuse;
- protect the security of DCS;
- protect a person from serious harm;
- obtain professional legal or safeguarding advice;
- establish, exercise or defend legal rights;
- comply with a valid legal requirement; or
- cooperate appropriately with law-enforcement or safeguarding authorities.
A request from another person or organisation does not automatically entitle them to information.
Where appropriate, DCS will assess the legal basis and necessity of a disclosure before providing personal information.
15. Service providers
DCS relies on third-party providers to operate parts of its infrastructure.
These may include:
- website hosting;
- security providers;
- email services;
- backup services;
- anti-spam services; and
- other technical suppliers.
DCS should maintain records identifying what information each provider receives, why it receives it, where processing takes place and what contractual protections apply.
16. International transfers
Some service providers may process information outside the United Kingdom.
Where UK data-protection law restricts an international transfer, DCS will use an appropriate lawful transfer mechanism or other permitted basis.
The final version of this section will be completed following review of DCS’s hosting, email, security, backup and other service providers.
17. How long we keep information
DCS does not intend to retain personal information indefinitely merely because storage is technically possible.
Different information requires different retention periods.
Our retention schedule will take account of:
- the reason the information was collected;
- safeguarding requirements;
- security requirements;
- legal obligations;
- dispute or legal-claim periods;
- the sensitivity of the information; and
- whether continued retention remains necessary and proportionate.
Indicative categories include:
Account information: retained while an account remains active and for a defined period afterwards where necessary for security, safeguarding, dispute resolution or legal purposes.
Community content: retained while published or otherwise required for the operation and integrity of the community, subject to moderation, deletion and data-protection rights.
Moderation records: retained according to DCS’s moderation and safeguarding retention schedule.
Safeguarding records: retained only for as long as justified by safeguarding, legal and accountability requirements.
Security logs: retained for a limited period appropriate to security monitoring, incident investigation and legal requirements.
Contact correspondence: retained for as long as reasonably necessary to resolve the enquiry and meet any related legal or operational requirement.
Precise retention periods must be finalised in the DCS Data Retention Schedule before this notice is treated as final.
18. Account deletion
Deleting an account does not necessarily mean that every record associated with that account can immediately be erased.
DCS may need to retain limited information where there is a valid legal reason, including:
- safeguarding records;
- serious moderation or abuse records;
- security records;
- information necessary to prevent serious misuse or ban evasion;
- records necessary for legal claims; or
- information DCS is legally required to retain.
Where continued identification is no longer necessary, DCS should consider deletion, anonymisation or other appropriate measures.
19. Your data-protection rights
Depending on the circumstances and lawful basis involved, you may have rights including:
- access – to ask for a copy of personal information held about you;
- rectification – to ask us to correct inaccurate or incomplete information;
- erasure – to ask us to delete information in certain circumstances;
- restriction – to ask us to restrict processing in certain circumstances;
- objection – to object to certain processing;
- data portability – to receive certain information in a portable format where the legal requirements apply;
- withdrawal of consent – where processing relies on consent; and
- rights relating to certain automated decisions and profiling.
These rights are not absolute and different rights apply in different circumstances.
Children have data-protection rights as well as adults.
To exercise a data-protection right, contact:
ashleigh@deadcybersociety.org
We may need to verify your identity before disclosing or changing personal information.
20. Your right to object
Where DCS processes your personal information on the basis of legitimate interests, you may have the right to object to that processing.
If you object, we will consider your circumstances and the legal requirements applying to the processing.
21. Automated decision-making
DCS does not currently intend to make decisions producing legal or similarly significant effects about members solely through automated processing.
Automated systems may assist with matters such as:
- spam detection;
- security monitoring;
- abuse detection; or
- content prioritisation.
Where an automated tool flags activity, this does not necessarily mean that a person has violated DCS rules.
If DCS introduces significant automated decision-making or profiling in future, this notice and the relevant safeguards must be reviewed before that processing begins.
22. Data breaches
DCS maintains procedures for responding to suspected personal-data breaches.
Where a breach creates a risk requiring notification under applicable data-protection law, DCS will notify the appropriate authority and, where legally required, affected individuals.
23. Complaints
If you are concerned about how DCS has handled your personal information, please contact us first so that we can investigate:
ashleigh@deadcybersociety.org
You also have the right to complain to the UK’s data-protection regulator, the Information Commissioner’s Office (ICO).
Information about making a complaint is available from the ICO.
24. Changes to this Privacy Notice
We will review this Privacy Notice as DCS develops.
If we make a significant change to how personal information is used, we will provide appropriate notice before beginning the new processing where required.
The current version and date will always be published on this page.
25. Further privacy information
This Privacy Notice should be read alongside:
- Young People’s Privacy Guide – to be created;
- Cookie Notice – to be created;
- Community Rules;
- Safeguarding Policy – where applicable;
- Terms of Use / Membership Terms; and
- any specific privacy information shown when particular information is collected.
Our privacy principles
Dead Cyber Society aims to follow these principles when handling personal information:
Collect less. Protect more. Explain clearly. Restrict access. Keep information only when justified. Put people’s safety and dignity first.
Who we are
Our website address is: https://deadcybersociety.org.
Media
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
Cookies
If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
Who we share your data with
If you request a password reset, your IP address will be included in the reset email.
How long we retain your data
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
What rights you have over your data
If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
Where your data is sent
Visitor comments may be checked through an automated spam detection service.
Comments
When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.