Crisis Cloud Trial Privacy Notice

Crisis Cloud Trial Privacy Notice

Version: 2026-08-06
Effective date: 6 August 2026

1. Who we are

Crisis Solutions Ltd provides the Crisis Cloud trial service.

For personal information used to receive, assess, provision and administer trial applications, the controller is:

Crisis Solutions Ltd

Company number: 3981161

Registered office: Ashwell House High Street Longborough GL56 0QE

Privacy email: info@crisis-solutions.com

ICO registration number: Z7986621

This notice applies to applicants, facilitators, participants and other people whose information is used in connection with a Crisis Cloud trial.

2. Information we collect

Registration information

We may collect:

  • organisation name;
  • applicant’s name;
  • business email address;
  • country or region;
  • intended use of the trial;
  • requested organisation name and hostname;
  • acceptance of the Trial Terms and this notice;
  • accepted document URLs and version numbers; and
  • application, verification and provisioning status.

Account and service information

We may collect:

  • WordPress user and site identifiers;
  • username, role and organisation membership;
  • login and account-management activity;
  • facilitator and participant details;
  • service communications and support requests;
  • quota and feature usage;
  • trial start, expiry, suspension and retention dates; and
  • audit records of administrative actions.

Security and technical information

We may process:

  • IP and network information;
  • browser and device information;
  • timestamps;
  • verification and security tokens;
  • rate-limit and anti-abuse results;
  • login and access logs;
  • suspected abuse or security events; and
  • diagnostic information.

Raw security information and secret values are not intended to be exposed through the Client Sites Manager.

Cloudflare Turnstile runs browser checks and generates a token that our server validates with Cloudflare. Cloudflare describes Turnstile as using browser and behavioural signals to distinguish legitimate users from automated activity.

Customer Content

A trial may contain:

  • fictional or real names supplied by the Customer;
  • exercise scenarios and injects;
  • messages, comments and simulated communications;
  • uploaded documents and media;
  • AI prompts and generated output; and
  • information entered by facilitators and participants.

Customers should minimise personal information and use fictional or anonymised exercise information wherever possible.

3. Why we use personal information

PurposeTypical lawful basis
Receiving and assessing a trial requestSteps requested before entering into a contract
Verifying the applicant and creating the trialContract or pre-contractual steps
Creating and administering user accountsContract
Sending verification, access and lifecycle emailsContract
Protecting the service against spam, fraud and unauthorised accessLegitimate interests
Maintaining audit, support and operational recordsContract and legitimate interests
Monitoring capacity, reliability and securityLegitimate interests
Complying with legal, regulatory or court requirementsLegal obligation
Establishing, exercising or defending legal claimsLegitimate interests or legal obligation, as applicable
Optional marketingConsent, where collected separately

The contract basis only applies where processing is necessary to provide the requested service or take the requested pre-contractual steps. Other operational and security uses may require a different lawful basis such as legitimate interests.

Our legitimate interests include:

  • operating and securing Crisis Cloud;
  • preventing abusive or duplicate trial creation;
  • protecting customers and other users;
  • diagnosing faults;
  • managing shared-service capacity;
  • demonstrating what administrative action occurred; and
  • improving service reliability.

We will not add an applicant to general marketing solely because they request a trial. Any marketing choice should be presented separately and be optional.

4. Automated checks

We use automated checks to assess matters including:

  • email validity;
  • duplicate applications;
  • reserved or invalid hostnames;
  • submission speed and volume;
  • bot indicators;
  • rate limits; and
  • whether an application is eligible for automatic UK provisioning.

These checks may prevent immediate automatic provisioning.

An applicant may request human review by contacting:

info@crisis-solutions.com

5. Who receives personal information

We may disclose relevant information to service providers supporting Crisis Cloud, including:

  • Microsoft Azure, for application hosting, database, networking, monitoring and related infrastructure;
  • Brevo, for transactional verification, access and lifecycle email;
  • Cloudflare, for Turnstile bot and abuse protection;
  • Anthropic, where an authorised user invokes an AI-assisted feature;
  • professional advisers, auditors and insurers;
  • contractors supporting the service under confidentiality and data-protection obligations; and
  • courts, regulators, law-enforcement bodies or public authorities where disclosure is required or lawful.

Before publication, confirm that this list matches the signed supplier contracts and actual data flows.

6. Controller and processor roles

Crisis Solutions is the controller for information it uses to:

  • assess trial applications;
  • administer accounts;
  • protect the platform;
  • communicate with applicants;
  • manage billing or conversion discussions; and
  • meet its own legal obligations.

For personal information that the Customer independently chooses to place in an exercise, the Customer will usually determine why that information is used. In that situation, the Customer may be the controller and Crisis Solutions may act as its processor.

The legal role depends on who determines the purpose and means of the particular processing, rather than simply who operates the software.

A separate data-processing agreement may be required before a trial is used with non-fictional or sensitive personal information.

7. International transfers

The UK trial application and database service are intended to be hosted in the United Kingdom.

Some suppliers may nevertheless process support, security, email, AI or diagnostic information outside the United Kingdom.

Where a restricted transfer takes place, we will use an applicable safeguard, which may include:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved contractual clauses; or
  • another legally permitted transfer mechanism.

8. How long we retain information

Complete and approve the periods in this table before publication:

InformationProposed retention
Unverified applicationsOne year
Rejected or duplicate applicationsOne year
Verification tokensUntil used or expired; associated security record for One year
Active trial account and contentFor the duration of the trial
Expired trial site and contentRetention review 30 days after expiry; final archive/deletion period [[DECIDE]]
Security and access logsOne year
Support correspondenceOne year
Terms/privacy acceptance evidenceOne year
Backups after live deletionSix months
Legal or dispute recordsFor as long as reasonably required for the relevant claim or obligation

We may retain information for longer where necessary to investigate abuse, respond to a dispute, comply with law or establish, exercise or defend legal claims.

Where possible, information retained for statistical analysis will be anonymised.

9. Security

We use organisational and technical controls intended to protect personal information, including:

  • role-based access;
  • organisation-site separation;
  • encrypted HTTPS connections;
  • controlled administrative access;
  • environment-based secret storage;
  • rate limiting and bot protection;
  • logging and audit records;
  • backup and recovery controls; and
  • security and deployment review procedures.

No internet service is completely secure. Users must protect their credentials and report suspected unauthorised access promptly.

10. Your rights

Depending on the circumstances, individuals may have the right to:

  • be informed about the use of their information;
  • request access;
  • request correction;
  • request erasure;
  • request restriction;
  • object to processing based on legitimate interests;
  • receive certain information in a portable format;
  • withdraw consent where processing is based on consent; and
  • challenge certain solely automated decisions.

Some rights are subject to legal conditions and exemptions.

Requests should be sent to:

info@crisis-solutions.com

We may need to verify the requester’s identity.

11. Complaints

Please contact us first so we can investigate a concern.

Individuals also have the right to complain to the UK Information Commissioner’s Office.

12. Children

Crisis Cloud trials are intended for professional and organisational use by adults.

Applicants must be at least 18. The service is not directed at children, and Customers must not create accounts for children without prior written agreement and an appropriate legal basis.

13. Changes to this notice

We may publish a new version of this notice where our processing, suppliers, legal obligations or service design changes.

The version accepted during registration will be recorded against the trial request. Material changes affecting existing users will be communicated where appropriate.