Legal & Privacy
Privacy, explained with clarity.
This notice explains how CyberSift Limited collects, uses and protects personal data when you visit Tutela, contact us, start a trial or use the Tutela service.
Last updated: 17 August 2026CyberSift Limited respects your privacy and processes personal data in accordance with the EU General Data Protection Regulation (“GDPR”), the laws of Malta and other applicable data-protection legislation.
1. Scope and controller
This Privacy Policy applies to tutela-security.com, the Tutela registration environment at trial.tutela.cybersift.io, and related communications where CyberSift Limited determines how and why personal data is processed.
The data controller is:
Company registration number: C 86708
15, Sali, Triq Iz-Zebbuga
Iklin IKL 1960, Malta
General enquiries: [email protected]
Data Protection Officer: [email protected]
Tutela is a CyberSift product. Where a CyberSift customer uses Tutela to process personal data relating to its own organisation, staff, customers or systems, that customer may be the controller and CyberSift may act as its processor.
2. Personal data we collect
Website and technical data
When you use our websites, we may receive your IP address, browser and device information, referring pages, pages viewed, timestamps, security logs, consent choices and online identifiers. Where permitted, these may include advertising and cross-domain parameters such as GCLID, GBRAID, WBRAID, UTM parameters and Google linker identifiers.
Contact and enquiry data
If you contact us, request information or submit a form, we may collect your name, business contact details, organisation, role, telephone number, message and related correspondence.
Trial, account and subscription data
When you start a Tutela trial or create an account, we collect the information requested during registration and account setup, such as your name, business email address, telephone number, organisation, login details, subscription information and records of your acceptance of applicable terms.
Service and support data
We may process information you provide through Tutela, including account settings, support requests, authorised user information, monitored asset or network information and security-related data needed to deliver and protect the service. Please do not provide personal data that is not necessary for your use of Tutela.
Marketing and preference data
We may record whether you wish to receive marketing communications, your communication preferences, unsubscribe requests and cookie-consent choices.
3. Why we use personal data
Where we rely on legitimate interests, we consider the impact on your rights and use personal data only where those interests are not overridden by your rights and freedoms.
4. Cookies, analytics and advertising
We use strictly necessary technologies to operate and secure the websites. Subject to your consent, we may also use analytics and advertising technologies to understand website use, measure campaigns and improve our communications.
These services may include Google technologies such as Google Ads conversion measurement and, where enabled, Google Analytics. Because the registration journey crosses from tutela-security.com to trial.tutela.cybersift.io, permitted identifiers may be transferred between those domains to maintain attribution and measure a completed registration.
Our consent-management platform records and communicates your choices through Google Consent Mode where applicable. Non-essential storage is not treated as authorised before the required consent has been obtained. You can change or withdraw your choice at any time through the cookie settings available on the website.
For the current list of cookies, providers, purposes and retention periods, please consult the Cookie Policy accessible through the footer and cookie banner.
5. Who receives personal data
We disclose personal data only where necessary and may share it with:
- hosting, cloud-infrastructure, security and content-delivery providers;
- email, SMS, customer-support, CRM and business-operations providers;
- analytics, advertising and consent-management providers, subject to your choices;
- professional advisers, auditors, insurers and group companies where required;
- courts, regulators, law-enforcement bodies or other authorities where disclosure is legally required; and
- a purchaser or successor in connection with a genuine corporate transaction, subject to appropriate confidentiality and data-protection safeguards.
Service providers may process personal data only for the agreed purposes and under appropriate contractual and security obligations.
International transfers
Some providers may process data outside Malta or the European Economic Area. Where required, we use an applicable adequacy decision, the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism, together with supplementary safeguards where appropriate. You may contact the DPO for further information about relevant safeguards.
6. How long we retain data
We retain personal data only for as long as necessary for the purposes described above, including applicable legal, accounting, security and dispute-resolution requirements.
- Enquiries and correspondence: for as long as reasonably necessary to respond and maintain appropriate business records.
- Trial data and configurations: generally for up to 30 days after the trial ends, unless the account is converted, a different period is agreed, deletion is requested where applicable, or retention is legally required.
- Active accounts and service data: for the subscription term and the retention period associated with the applicable plan, followed by deletion or anonymisation subject to legal requirements.
- Security logs: for a proportionate period needed to detect, investigate and prevent incidents.
- Cookie and advertising data: according to the periods shown in the Cookie Policy and your consent choices.
- Legal and transaction records: for the period required by applicable law or needed to establish, exercise or defend claims.
7. Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures may include access controls, logical separation, encryption, monitoring, confidentiality commitments and regular review of security processes.
No internet or storage system can be guaranteed to be completely secure. You are responsible for protecting your account credentials and promptly notifying us of suspected unauthorised access.
8. Data processed through the Tutela service
When a customer uses Tutela to process personal data under its own instructions, the customer is generally the controller and CyberSift acts as processor. The customer is responsible for having a lawful basis, providing required notices and managing data-subject requests relating to that processing.
CyberSift processes such data to provide, secure, maintain and support Tutela, in accordance with the customer’s documented instructions, applicable contractual terms and data-protection law. Further processor obligations may be set out in the applicable agreement or data-processing addendum.
9. Your data-protection rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request erasure of your data;
- request restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive certain data in a portable format;
- withdraw consent at any time, without affecting earlier lawful processing; and
- lodge a complaint with a data-protection authority.
To exercise your rights, email [email protected]. We may need to verify your identity before responding. We normally respond within one month, although the GDPR permits an extension for complex or numerous requests.
10. Children
Tutela is a business service and is not directed to children. We do not knowingly solicit personal data from children through the website or trial-registration process. If you believe that a child has provided personal data to us, please contact the DPO.
11. Contact, complaints and policy changes
Questions about this policy or CyberSift’s processing of personal data should be sent to [email protected].
You also have the right to lodge a complaint with the Office of the Information and Data Protection Commissioner of Malta, or with the supervisory authority in the country where you live or work.
We may update this policy when our services, providers or legal obligations change. Material changes will be communicated through an appropriate notice, and the “Last updated” date above will be revised.