← Back to Adversary X
Canary Zero Ltd

Privacy Policy

Last updated: September 2026

This Privacy Policy explains how Canary Zero Ltd ("Canary Zero", "we", "us" or "our") collects, uses, shares and protects personal data when you use Adversary X, our AI-driven cyber incident, crisis and operational-resilience tabletop exercise platform, our website at adversary-x.com, and any related services (together, the "Services").

We have written this policy to be read by the people who use Adversary X and by the security, procurement and data protection teams of the organisations that buy it. If anything is unclear, contact us at support@adversary-x.com.

Summary of key points

Who is responsible for your data? Canary Zero Ltd, a company registered in England and Wales, is the data controller for personal data collected through our website, for account and billing records, and for our own security logs. Adversary X is sold to organisations, not consumers: the content your organisation enters into exercises is processed on that organisation's behalf, with Canary Zero acting as its processor (see section 2).

What do we collect? Account details (name, email, organisation, job title, industry, region), billing details, the decisions and free-text responses you enter during exercises, the names and roles of exercise attendees you record, and technical data such as IP address, sign-in history and usage logs (see section 3).

Do we process sensitive (special category) data? No, and the Services are not designed to receive it. Please do not enter special category data or real incident details containing it into an exercise.

Is your data used to train AI models? No. Exercise content is sent to our AI provider, Anthropic, to generate scenarios and debriefs. Under our commercial terms with Anthropic, your inputs and outputs are not used to train their models (see section 5).

Who do we share it with? Only the service providers we need to run Adversary X (identity, hosting, database, email, AI, DNS/security, analytics and our demo-request CRM), each listed in section 6, plus authorities where the law requires.

Where is it stored? Our application and production database are hosted in the United Kingdom. Some providers process data in the United States under recognised UK transfer safeguards (see section 7).

What are your rights? Access, correction, deletion, restriction, portability and objection, plus the right to complain to the Information Commissioner's Office (ICO). Export and deletion are self-service in Settings → Security (see section 11).

1. Who we are

Canary Zero Ltd is registered in England and Wales under company number 14664394, with its registered office at 71–75 Shelton Street, London WC2H 9JQ, United Kingdom. We are registered with the Information Commissioner's Office as a data controller and have paid the data protection fee; our registration number will be published here once issued. We do not have a statutory Data Protection Officer; privacy enquiries are handled by our founding team and can be sent to support@adversary-x.com.

2. Our role: controller or processor

Adversary X is sold to businesses and other organisations on Basic, Pro and Enterprise tiers. Our role depends on the data concerned.

Regardless of tier, Canary Zero is always the controller for account credentials and authentication, billing records, our own security and audit logs, aggregated benchmarking statistics, and our communications with you.

3. What personal data we collect

Information you give us

Information collected automatically

Information about other people

Adversary X lets you record the names and roles of colleagues who attended an exercise, and lets custom scenarios describe your organisation's environment. You are responsible for ensuring you are entitled to share that information with us — for example, that attendees know their name will appear on the exercise report. Only enter what is needed to run the exercise. Do not enter special category data, real customer data, or credentials.

Information from third parties

Our identity provider, Clerk, gives us the name and email address associated with the sign-in method you choose. Our demo-request form is provided by our CRM platform, GoHighLevel, which may pass us attribution data about how you reached the form. We do not buy personal data from data brokers or enrich your profile from other sources.

4. Why we process your data and our legal bases

UK GDPR requires us to have a lawful basis for each purpose. The table below sets them out.

PurposeData usedLawful basis
Creating and securing your account, signing you in, and managing sessionsAccount data, sign-in and security dataPerformance of a contract (our Terms of Service)
Running tabletop exercises: generating scenarios, reacting to your decisions, and producing debriefs and PDF reportsExercise content, attendee records, profile data (industry, region, organisation name)Performance of a contract
Agreeing and administering your subscription: order forms, invoicing, payment reconciliation and renewalsBilling and contract dataPerformance of a contract; legal obligation (tax and accounting records)
Sending service emails such as exercise reminders you have scheduled and important account noticesEmail address, schedule and notification settingsPerformance of a contract
Sending product news and marketing emailsEmail address, marketing consent recordConsent — you can withdraw it at any time in Settings → Notifications
Producing anonymised, aggregated industry benchmarks (only ever shown where at least five organisations are in the cohort)Industry, region, exercise scoresLegitimate interests (improving the value of the Services to all customers)
Keeping the Services secure: detecting abuse, investigating incidents, maintaining an audit trail, protecting against botsSign-in and security data, audit trail, usage dataLegitimate interests (security of our Services and customers); legal obligation
Understanding how the website and product are used, fixing bugs and improving featuresUsage and diagnostic data; analytics cookies where you have consentedLegitimate interests; consent for non-essential cookies
Measuring our advertising and attributing demo requestsAdvertising cookies and pixelsConsent
Responding to demo requests and enquiriesDemo request data, correspondenceLegitimate interests (responding to a request you made); steps prior to entering a contract
Complying with law, responding to lawful requests from authorities, and establishing or defending legal claimsAny of the above as relevantLegal obligation; legitimate interests

Where we rely on legitimate interests we have considered the impact on you and concluded the processing is proportionate. You can ask us for details of that assessment.

5. How we use artificial intelligence

Adversary X uses large language models to generate exercise scenarios, react to your decisions in real time, and write debriefs. These models are provided by Anthropic Ireland, Limited through its commercial API.

6. Who we share your data with

We do not sell personal data. We share it only with the providers below, each of which processes data under a written contract that restricts its use to providing the service to us.

ProviderPurposeData processedLocation of processing
Clerk, Inc.Identity and authentication, sessions, two-factor authenticationAccount data, sign-in and security dataUnited States
Supabase Pte. Ltd.Production database and backupsAll account, exercise, subscription and audit dataUnited Kingdom (AWS London, eu-west-2)
Vercel, Inc.Application hosting, serverless functions, edge network and server logsAll data in transit through the application; request logs including IP addressUnited Kingdom (London) for application functions; global edge network for static content and routing
Anthropic Ireland, LimitedAI scenario generation and debriefsExercise content and scenario context (section 5)United States
Plus Five Five, Inc. (Resend)Transactional email delivery (reminders, account notices)Email address, name, email contentUnited States
Cloudflare, Inc.DNS, network proxy, domain registration and Turnstile bot protectionIP address and request metadataGlobal network (UK/EU points of presence; US company)
Google (Google Ireland Ltd / Google LLC)Google Tag Manager, Google Analytics 4 and Google Ads conversion measurement — only where you have consented to analytics/advertising cookiesCookie identifiers, pages visited, device and approximate location dataIreland / United States
GoHighLevel (HighLevel, Inc.)Demo-request form and CRM; the form embeds a Meta (Facebook) pixel for attribution where you have consentedDemo request data, attribution dataUnited States
Meta Platforms Ireland LtdAdvertising attribution pixel within the demo-request form, where consentedCookie identifiers and form interaction eventsIreland / United States

We may also disclose personal data where required by law, court order or a regulator; to our professional advisers under confidentiality; and, if Canary Zero is involved in a merger, acquisition or sale of assets, to the counterparties and their advisers, in which case this policy will continue to apply to your data.

We will update this table when we add or change a provider. Enterprise customers under our Data Processing Agreement will be notified in advance of any new sub-processor.

7. International transfers

Canary Zero is based in the United Kingdom and our application and production database are hosted in the United Kingdom. Several of the providers in section 6 are US companies or process data in the United States. Where personal data leaves the UK we rely on one of the following safeguards recognised under UK GDPR:

You can request a copy of the relevant safeguard for any provider by contacting us.

8. Cookies and similar technologies

We use two kinds of cookies and similar technologies:

You can change or withdraw your choice at any time through the cookie controls on our website or by clearing cookies in your browser. Refusing analytics and advertising cookies does not affect your ability to use Adversary X.

9. How long we keep your data

DataRetention
Account, profile, preferences and exercise contentFor as long as your account is open. When you delete your account in Settings → Security, this data is deleted from our production systems immediately. Where an account is closed by an organisation administrator or through our identity provider rather than in-app, the account is marked deleted immediately and remaining records are removed in line with the Terms of Service and any Data Processing Agreement.
Order forms, invoices and payment history6 years from the end of the financial year in which the transaction took place, to meet UK tax and accounting obligations.
Account audit trail (security-relevant actions)12 months on a rolling basis, then automatically deleted.
Sign-in history and sessionsRetained by our identity provider (Clerk) while the account is open and for up to 90 days after the account is deleted, in line with its data processing terms.
Server and request logsRetained by our hosting and network providers for a short operational period, typically no longer than 30 days. Transactional email delivery logs are retained by our email provider (Resend) for up to 90 days.
Database backupsDeleted data may persist in encrypted backups for up to 30 days before those backups are cycled out.
Demo requests and sales correspondenceUp to 24 months after our last contact with you, unless you become a customer.
Marketing consent recordsFor as long as we rely on your consent, and for a period afterwards to evidence that consent was given or withdrawn.
Anonymised benchmark statisticsIndefinitely; they do not identify you or your organisation.

When a customer organisation's agreement ends, its Customer Content and generated reports — including, for an MSP, every client tenant under its account — are permanently deleted 30 days after the termination or expiry date, as set out in our Terms of Service. The organisation may request an export during those 30 days.

10. How we protect your data

Adversary X is built and operated by security practitioners. Measures currently in place include:

No system is perfectly secure. If we become aware of a personal data breach affecting you we will notify the ICO where required within 72 hours and inform you, or the organisation that is your controller, without undue delay.

11. Your rights

Under UK GDPR (and, if you are in the EEA or Switzerland, the equivalent local law) you have the right to:

Self-service. Signed-in users can export a copy of their data and permanently delete their account from Settings → Security, manage marketing consent in Settings → Notifications, and update profile details in Settings → Profile.

Everything else. Email support@adversary-x.com. We will respond within one month, extendable by two further months for complex requests, and we may ask you to verify your identity first. If you use Adversary X through an Enterprise or MSP customer, we may redirect your request to that organisation as the controller.

Complaints. You can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or by calling 0303 123 1113. We would appreciate the chance to resolve your concern first. If you are in the EEA or Switzerland you may also complain to your local supervisory authority.

12. Marketing communications

We only send marketing email if you have opted in, and every message includes an unsubscribe link. You can also switch marketing off in Settings → Notifications. Service messages that are necessary to run your account — such as exercise reminders you have scheduled, invoice and renewal notices and security alerts — are not marketing and will continue while your account is open; reminders can be turned off in Settings → Preferences.

13. Children

Adversary X is a business service intended for use by adults in a professional capacity. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.

14. Do-Not-Track and Global Privacy Control

Our cookie banner is the mechanism for controlling non-essential cookies. We do not currently respond to browser Do-Not-Track or Global Privacy Control signals; if a legal requirement to honour them arises we will update the Services and this policy.

15. Changes to this policy

We will update this policy when our processing changes — for example when we add a sub-processor. The "Last updated" date at the top shows the current version. For material changes we will notify account holders by email or by an in-app notice before the change takes effect. Earlier versions are available on request.

16. Contact us

Email: support@adversary-x.com

Post: Canary Zero Ltd, 71–75 Shelton Street, London WC2H 9JQ, United Kingdom

Adversary X is a product of Canary Zero Ltd, company number 14664394, registered in England and Wales.