← Back to Calculator

Privacy Policy

Last Updated: May 17, 2026

Introduction

This Privacy Policy describes how the Incident Response Cost Calculator ("we", "us", or "our") at ircost.breached.company collects, uses, and shares information about you and explains your privacy rights. This policy applies when you use our website and services. This site is part of the Breached.company network, operated by the CyberAdX Network.

How the Calculator Processes Your Data

All calculator inputs are processed entirely in your browser. The incident type, organization size, industry, compliance selections, and all other form fields you enter are used only to compute cost estimates client-side — they are never transmitted to or stored on our servers. No account is required and no input data is retained after you close your browser tab.

Information We Collect

Information You Provide

We do not collect the specific values you enter into the calculator. Form inputs (incident type, organization details, compliance requirements, etc.) exist solely in your browser session and are discarded when you leave the page.

Automatically Collected Information

When you access our website, we automatically collect certain information through standard web server logs and analytics, including:

  • Log data (IP address, browser type, pages visited, access times, referring URL)
  • Device and browser information
  • Aggregated usage patterns via Google Analytics (see Analytics section below)
  • Cookies set by Google Analytics for session and usage measurement

How We Use Your Information

We use automatically collected information to:

  • Operate and maintain the calculator service
  • Improve and optimize website performance and content
  • Analyze aggregated usage patterns and trends
  • Detect and prevent security incidents and abuse
  • Comply with applicable legal obligations

Analytics and Cookies

We use Google Analytics (GA4) to understand how visitors interact with our site. Google Analytics uses cookies stored on your device to collect anonymous usage data. This information is transmitted to and stored by Google in accordance with their privacy policy.

We do not use Google Analytics to track personally identifiable information. You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on.

A first-visit preference (whether you have seen the welcome modal) is stored in your browser's localStorage. This data never leaves your device.

Information Sharing

We may share information with:

  • Service providers who perform services on our behalf (e.g., hosting, analytics)
  • Professional advisors, such as lawyers and auditors, where required
  • Government authorities when required by applicable law
  • Our affiliated networks (Breached.company and CyberAdX Network)

We do not sell your personal information to third parties.

Data Retention

Server access logs are retained for up to 90 days for security and operational purposes. Google Analytics data is retained in accordance with Google's standard retention settings (14 months by default). localStorage preferences exist only in your browser and can be cleared at any time via your browser settings.

Data Security

We implement appropriate technical and organizational security measures, including HTTPS encryption, HTTP security headers (Content Security Policy, X-Frame-Options, X-Content-Type-Options), and access controls. However, no security system is impenetrable, and we cannot guarantee the absolute security of information transmitted over the internet.

Your Privacy Rights

Depending on your location, you may have rights regarding your personal information under applicable laws including GDPR, CCPA/CPRA, and other state privacy laws. These rights may include:

  • Right to know / access — request information about what personal data we hold
  • Right to correct — request correction of inaccurate information
  • Right to delete — request deletion of your personal information
  • Right to opt out — opt out of certain data sharing practices
  • Right to data portability — receive your data in a portable format
  • Right to non-discrimination — we will not discriminate for exercising your rights

Because we do not collect or store calculator inputs, most data subject requests will relate to analytics data. To exercise your rights, contact us using the information in the "Contact Us" section below.

Children's Privacy

Our service is directed to adults and business professionals. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact us and we will promptly delete it.

International Data Transfers

We are based in the United States. Analytics data collected via Google Analytics may be processed in the United States or other countries. If you are located in the EU/EEA or UK, you acknowledge that such transfers occur and are subject to appropriate safeguards (Google's Standard Contractual Clauses).

Third-Party Links

Our site links to third-party tools including Cyber Insurance Calculator, IR Maturity Assessment, Data Breach Cost Calculator, and others in the Breached.company network. Each linked site has its own privacy policy, and we are not responsible for their practices.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be indicated by updating the "Last Updated" date at the top of this page. We encourage you to review this policy periodically.

Contact Us

If you have any questions about this Privacy Policy or to exercise your privacy rights, please contact us at support.cisomarketplace.com.