Legal / Privacy Policy

Privacy and Data Retention Policy

Version 1.0

This privacy and data retention policy (this “Policy”) describes how the CyberIllumination™ service (the “Service”) provided by Continuous Compliance, LLC, a Maryland limited liability company (the “Company”), uses data collected from you when you visit cyberillumination.us (the “Site”). All references to “you” (and related possessive use) within this Policy shall mean you, any of your agents, and any third party on whose behalf you use the Site and/or the Service.

1. What information is collected?

The Service provides supply chain illumination for prime contractors and subcontractors in the U.S. Defense Industrial Base. For the Service to be implemented, the Company collects non-anonymized, detailed, secure information about you and your organization. Your IP address may be collected as well.

The Company employs third parties to administer some of the Site’s functions. These third parties may collect your personal information. The manner in which third parties use, store, and disclose your information is not governed by this Policy but by the policies of such third parties. The Company shall have no liability or responsibility for the privacy practices or other actions of any third parties that administer any of the Site’s functions.

Type of information collectedHow the information is usedDeleted when Data Retention Period ends?
Website contact informationSupportNo
Organizational contact informationIllumination usageYes
Organizational company profile information (including CAGE code and UEI)Illumination usageYes
Compliance and illumination status responsesIllumination usageDetail deleted; aggregated responses retained anonymously
Sharing grants and access-control settingsIllumination usageYes
Access logs (who viewed your data, and when)Audit trailYes
Attachment uploadsIllumination usageYes
Generated reports and rollupsIllumination usageYes
Usage tracking dataSupportYes

2. How is the data used?

At your sole discretion, your non-anonymized, detailed, secure data will be shared with other users of the Site and/or the Service — for example, prime contractors above you in a supply chain, or the Department of War where you have authorized such access. You control who sees your data and for how long, and every view of your data is written to an access log.

Your data may also be anonymized and subsequently aggregated for peer analysis and industrial-base rollups, as described in our Terms of Use.

3. How does the Site protect stored data?

The Company shall use commercially reasonable efforts to maintain appropriate administrative, physical, and technical safeguards for the protection of the security, confidentiality, and integrity of your data. The Service is FedRAMP High Authorized (Class D) and is hosted in AWS GovCloud. See our Security page for details.

4. How long does the Site store data?

Your data will be stored while your subscription to the Service (your “Subscription”) remains active and for a period of six (6) months after your Subscription becomes inactive (the “Data Retention Period”). Should your Subscription be cancelled by you or terminated by the Company, any non-anonymized, detailed, secure data associated with your account will be deleted by the Company at the end of the Data Retention Period; however, the anonymized data collected from you will be retained in storage by the Company for the purposes of industry and peer analysis. See the Data Retention Policy for details.

5. Can users of the Site shorten the Data Retention Period?

Yes. At any time after your Subscription has become inactive, you may request that the Data Retention Period be shortened by contacting the Company via email or mail (see Section 12 below). Upon receipt of your request, the Company may at its sole discretion delete any non-anonymized, detailed, secure data associated with your account. Any such request shall be subject to a balancing of your interest in the data against the interests of the Company and other users of the Service in the same data being retained.

6. Once the Company deletes data, can it still be retrieved?

The Company reserves the right to permanently delete your non-anonymized, detailed, secure data at the termination of the Data Retention Period with no option for recovery.

7. Does the Site use cookies?

Yes, the Site uses cookies in a variety of ways to improve your experience on the Site, and more specifically for app sessions. Cookies also allow the Company to monitor and evaluate how you use the Site. You may control your cookies as described on our Cookies page, or change your browser settings to not accept cookies; however, doing so may prevent some features of the Site from functioning properly.

8. What rights do users of the Site have regarding the protection of their data?

You have the right to request “Data Erasure.” This right provides that you may request that the Company erase your personal data and cease further dissemination of your data, as outlined in Article 17 of the General Data Protection Regulation (“GDPR”). Any request by you for Data Erasure is subject to a balancing of your interest in the data against the interests of the Company and other users of the Site and/or the Service in the data remaining available.

9. Does this Policy apply to websites accessed by links that appear on the Site?

No, this Policy applies only to the Site. A user who accesses a third-party website via a hyperlink that appears on the Site should review the privacy policy and/or data retention policy of that third-party website.

10. Will user data be used for marketing purposes?

The Company will occasionally send marketing communications to you regarding additional services offered by the Company. The Company will not release your data to third parties to be used for marketing communications.

11. Is the Site compliant with the requirements of the Children’s Online Privacy Protection Act (COPPA)?

Yes. The Company will not intentionally collect any information from anyone under thirteen (13) years of age. The Site and the Service are directed at people who are at least thirteen (13) years of age or older.

12. How do I contact the Company regarding this Policy?

Questions, concerns, and requests regarding this Policy may be emailed to privacy@cyberillumination.us, or sent by mail to:

Continuous Compliance, LLC
915 South Ann Street
Baltimore, Maryland 21231

13. How can a violation of this Policy be reported?

If you feel that your rights under this Policy have been violated and that the Company has been unresponsive to your concerns, you may contact the Federal Trade Commission through its “FTC Complaint Assistant” website.

14. Demo, training, support, and other call recordings and transcripts

When utilizing recording technology for calls and meetings, recordings and transcripts may be created for the following purposes:

  • Internal use: to assist in internal documentation and team alignment.
  • AI-generated recaps: for creating automated recaps to improve accessibility and meeting efficiency.
  • Direct sharing with attendees: recordings and transcripts may be shared only with those who attended the call.

Restrictions on use: these recordings and transcripts will not be used for marketing purposes and will not be shared with third parties without prior consent.

Rights of attendees: at any time during a call, attendees may request that the recording be stopped, and may request that any existing recording or transcript of the call be destroyed.

Version History

Version 1.0 – 2026.08 – Initial version.