Crisis Cloud Trial Privacy Notice
Version: 2026-08-06
Effective date: 6 August 2026
1. Who we are
Crisis Solutions Ltd provides the Crisis Cloud trial service.
For personal information used to receive, assess, provision and administer trial applications, the controller is:
Crisis Solutions Ltd
Company number: 3981161
Registered office: Ashwell House High Street Longborough GL56 0QE
Privacy email: info@crisis-solutions.com
ICO registration number: Z7986621
This notice applies to applicants, facilitators, participants and other people whose information is used in connection with a Crisis Cloud trial.
2. Information we collect
Registration information
We may collect:
- organisation name;
- applicant’s name;
- business email address;
- country or region;
- intended use of the trial;
- requested organisation name and hostname;
- acceptance of the Trial Terms and this notice;
- accepted document URLs and version numbers; and
- application, verification and provisioning status.
Account and service information
We may collect:
- WordPress user and site identifiers;
- username, role and organisation membership;
- login and account-management activity;
- facilitator and participant details;
- service communications and support requests;
- quota and feature usage;
- trial start, expiry, suspension and retention dates; and
- audit records of administrative actions.
Security and technical information
We may process:
- IP and network information;
- browser and device information;
- timestamps;
- verification and security tokens;
- rate-limit and anti-abuse results;
- login and access logs;
- suspected abuse or security events; and
- diagnostic information.
Raw security information and secret values are not intended to be exposed through the Client Sites Manager.
Cloudflare Turnstile runs browser checks and generates a token that our server validates with Cloudflare. Cloudflare describes Turnstile as using browser and behavioural signals to distinguish legitimate users from automated activity.
Customer Content
A trial may contain:
- fictional or real names supplied by the Customer;
- exercise scenarios and injects;
- messages, comments and simulated communications;
- uploaded documents and media;
- AI prompts and generated output; and
- information entered by facilitators and participants.
Customers should minimise personal information and use fictional or anonymised exercise information wherever possible.
3. Why we use personal information
| Purpose | Typical lawful basis |
| Receiving and assessing a trial request | Steps requested before entering into a contract |
| Verifying the applicant and creating the trial | Contract or pre-contractual steps |
| Creating and administering user accounts | Contract |
| Sending verification, access and lifecycle emails | Contract |
| Protecting the service against spam, fraud and unauthorised access | Legitimate interests |
| Maintaining audit, support and operational records | Contract and legitimate interests |
| Monitoring capacity, reliability and security | Legitimate interests |
| Complying with legal, regulatory or court requirements | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests or legal obligation, as applicable |
| Optional marketing | Consent, where collected separately |
The contract basis only applies where processing is necessary to provide the requested service or take the requested pre-contractual steps. Other operational and security uses may require a different lawful basis such as legitimate interests.
Our legitimate interests include:
- operating and securing Crisis Cloud;
- preventing abusive or duplicate trial creation;
- protecting customers and other users;
- diagnosing faults;
- managing shared-service capacity;
- demonstrating what administrative action occurred; and
- improving service reliability.
We will not add an applicant to general marketing solely because they request a trial. Any marketing choice should be presented separately and be optional.
4. Automated checks
We use automated checks to assess matters including:
- email validity;
- duplicate applications;
- reserved or invalid hostnames;
- submission speed and volume;
- bot indicators;
- rate limits; and
- whether an application is eligible for automatic UK provisioning.
These checks may prevent immediate automatic provisioning.
An applicant may request human review by contacting:
info@crisis-solutions.com
5. Who receives personal information
We may disclose relevant information to service providers supporting Crisis Cloud, including:
- Microsoft Azure, for application hosting, database, networking, monitoring and related infrastructure;
- Brevo, for transactional verification, access and lifecycle email;
- Cloudflare, for Turnstile bot and abuse protection;
- Anthropic, where an authorised user invokes an AI-assisted feature;
- professional advisers, auditors and insurers;
- contractors supporting the service under confidentiality and data-protection obligations; and
- courts, regulators, law-enforcement bodies or public authorities where disclosure is required or lawful.
Before publication, confirm that this list matches the signed supplier contracts and actual data flows.
6. Controller and processor roles
Crisis Solutions is the controller for information it uses to:
- assess trial applications;
- administer accounts;
- protect the platform;
- communicate with applicants;
- manage billing or conversion discussions; and
- meet its own legal obligations.
For personal information that the Customer independently chooses to place in an exercise, the Customer will usually determine why that information is used. In that situation, the Customer may be the controller and Crisis Solutions may act as its processor.
The legal role depends on who determines the purpose and means of the particular processing, rather than simply who operates the software.
A separate data-processing agreement may be required before a trial is used with non-fictional or sensitive personal information.
7. International transfers
The UK trial application and database service are intended to be hosted in the United Kingdom.
Some suppliers may nevertheless process support, security, email, AI or diagnostic information outside the United Kingdom.
Where a restricted transfer takes place, we will use an applicable safeguard, which may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved contractual clauses; or
- another legally permitted transfer mechanism.
8. How long we retain information
Complete and approve the periods in this table before publication:
| Information | Proposed retention |
| Unverified applications | One year |
| Rejected or duplicate applications | One year |
| Verification tokens | Until used or expired; associated security record for One year |
| Active trial account and content | For the duration of the trial |
| Expired trial site and content | Retention review 30 days after expiry; final archive/deletion period [[DECIDE]] |
| Security and access logs | One year |
| Support correspondence | One year |
| Terms/privacy acceptance evidence | One year |
| Backups after live deletion | Six months |
| Legal or dispute records | For as long as reasonably required for the relevant claim or obligation |
We may retain information for longer where necessary to investigate abuse, respond to a dispute, comply with law or establish, exercise or defend legal claims.
Where possible, information retained for statistical analysis will be anonymised.
9. Security
We use organisational and technical controls intended to protect personal information, including:
- role-based access;
- organisation-site separation;
- encrypted HTTPS connections;
- controlled administrative access;
- environment-based secret storage;
- rate limiting and bot protection;
- logging and audit records;
- backup and recovery controls; and
- security and deployment review procedures.
No internet service is completely secure. Users must protect their credentials and report suspected unauthorised access promptly.
10. Your rights
Depending on the circumstances, individuals may have the right to:
- be informed about the use of their information;
- request access;
- request correction;
- request erasure;
- request restriction;
- object to processing based on legitimate interests;
- receive certain information in a portable format;
- withdraw consent where processing is based on consent; and
- challenge certain solely automated decisions.
Some rights are subject to legal conditions and exemptions.
Requests should be sent to:
info@crisis-solutions.com
We may need to verify the requester’s identity.
11. Complaints
Please contact us first so we can investigate a concern.
Individuals also have the right to complain to the UK Information Commissioner’s Office.
12. Children
Crisis Cloud trials are intended for professional and organisational use by adults.
Applicants must be at least 18. The service is not directed at children, and Customers must not create accounts for children without prior written agreement and an appropriate legal basis.
13. Changes to this notice
We may publish a new version of this notice where our processing, suppliers, legal obligations or service design changes.
The version accepted during registration will be recorded against the trial request. Material changes affecting existing users will be communicated where appropriate.
