Privacy & data handling
We apply data minimization: only what is needed to produce your Cyber Resilience Score and to follow up if you ask us to.
What we collect
Organization profile information (company, country, industry, size bands, technology profile), your fifteen maturity answers, and the business contact details you choose to provide. Campaign parameters are stored with the assessment where present.
What we never collect
Passwords, API keys, firewall configurations, IP address lists, vulnerability exports, detailed network architecture or customer credentials. The assessment measures cybersecurity maturity, not technical configuration.
Consent
Consent is optional for viewing your results and is recorded with a timestamp and the exact text version shown to you. The current text reads: "I agree that DIAMATIX may contact me about this assessment and related cybersecurity services. My details are processed in line with the DIAMATIX privacy policy."
Retention and deletion
Assessment records are retained for as long as they remain commercially relevant, subject to a configurable retention period. You can request deletion of your contact details and associated personal information at any time by emailing sales@diamatix.com; DIAMATIX administrators can permanently remove the record.
Access and export
You may request a copy of the information held about you and the generated report. Internal access is limited to authorized DIAMATIX personnel under role-based access controls.
The DIAMATIX Cyber Resilience Score is an indicative maturity assessment based on information provided by the respondent. It does not constitute a security audit, certification, legal opinion or guarantee that a cybersecurity incident will not occur.
