Legal
Legal

Privacy, Terms & Disclaimers

CCF 2026 legal documentation. Last updated May 2026.

Privacy Policy

Last Updated: May 2026

Controller

dōlogiic Inc. ("dōlogiic", "CCF", "we", "us") is the data controller for personal data collected through the CCF platform at ccf2026.com. For privacy inquiries, contact privacy@dologiic.com.

Information We Collect

We collect information you provide directly, including: full name, work email address, phone number (optional), company name, job title, industry, company size, country, and assessment responses. We also collect usage data such as page views, session duration, browser type, and IP address through analytics tools.

Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Consent — For marketing communications, assessment delivery, and resource downloads. You may withdraw consent at any time.
  • Legitimate Interest — To improve the platform, prevent fraud, and ensure security.
  • Contract — To deliver services you have subscribed to or requested.

How We Use Your Information

  • Deliver requested services, assessments, and resources
  • Send CCF publications, insights, event invitations, and relevant communications
  • Improve the platform experience and content relevance
  • Respond to inquiries and support requests
  • Comply with legal obligations

We do not sell personal data to third parties.

Data Sharing

We may share personal data with trusted service providers who assist us in operating the platform (e.g., hosting, email delivery, analytics). All processors are bound by data processing agreements requiring appropriate security and confidentiality. We do not transfer data to third-party advertisers.

International Transfers

If your data is transferred outside your jurisdiction (e.g., outside the EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) where required.

Data Retention

We retain personal data for as long as necessary to provide the requested services or as required by law. Lead and inquiry data is retained for up to 3 years unless deletion is requested sooner. You may request deletion at any time.

Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access — Request a copy of the personal data we hold about you
  • Rectification — Request correction of inaccurate data
  • Erasure — Request deletion of your personal data ("right to be forgotten")
  • Restriction — Request that we limit processing of your data
  • Portability — Receive your data in a structured, machine-readable format
  • Objection — Object to processing based on legitimate interests
  • Withdraw Consent — Withdraw previously given consent at any time without affecting prior lawful processing

To exercise any right, contact privacy@dologiic.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

CCPA Notice (California Residents)

California residents have rights under the California Consumer Privacy Act (CCPA) including the right to know, delete, and opt-out of sale of personal information. We do not sell personal information. To exercise CCPA rights, contact privacy@dologiic.com.

Cookie Policy

Last Updated: May 2026

The CCF platform uses cookies and similar tracking technologies. You can manage cookie preferences via the consent banner on first visit.

Types of Cookies We Use

  • Essential Cookies — Required for the platform to function (authentication, session management). Cannot be disabled.
  • Analytics Cookies — Help us understand how visitors use the platform. Collected in aggregate. Only set with your consent.
  • Preference Cookies — Remember your settings and preferences (e.g., cookie consent status).

We do not use advertising or third-party tracking cookies.

Managing Cookies

You can withdraw analytics consent at any time by clearing your browser's local storage or cookies. Essential cookies cannot be disabled as they are required for the site to function.

Terms of Use

Last Updated: May 2026

Acceptance of Terms

By accessing or using the CCF platform, you agree to these Terms of Use. If you do not agree, please discontinue use immediately.

Permitted Use

CCF content, templates, and resources are licensed for internal organizational use and professional practice. Commercial redistribution, resale, or delivery to third parties requires a Partner License agreement with dōlogiic Inc.

Intellectual Property

All CCF content, methodology, frameworks, templates, scorecards, and materials are the intellectual property of dōlogiic Inc. The Clinical Cybersecurity Framework and CCF are trademarks of dōlogiic Inc. Unauthorized reproduction or commercial use is prohibited.

Subscriber Terms

Subscription access is granted to the individual named subscriber. Team or enterprise access requires an Enterprise subscription. Sharing login credentials is strictly prohibited and may result in account termination.

Limitation of Liability

To the maximum extent permitted by applicable law, dōlogiic Inc. shall not be liable for any indirect, incidental, or consequential damages arising from use of the CCF platform or reliance on CCF content.

Governing Law

These Terms are governed by the laws of the State of Delaware, USA, without regard to conflict of law principles.

Assessment & Content Disclaimer

Last Updated: May 2026

  • CCF resources are provided for educational, advisory, and strategic planning purposes only.
  • CCF does not replace legal, regulatory, compliance, or technical professional advice.
  • Assessment results are preliminary and indicative only. Results are not validated unless obtained through a formal CCF engagement conducted by a licensed CCF assessor or the dōlogiic advisory team.
  • Certification and academic partnerships are subject to future formal agreements and approvals.
  • The Cyber Wellness Score and Maturity Level produced by self-service tools are estimates based on self-reported responses and are not audited or independently verified.
  • CCF maturity levels and scores should not be used as representations of regulatory compliance status.

For validated assessments, formal maturity certifications, or regulatory-aligned evaluations, please engage the dōlogiic advisory team through the Advisory Services page.

Security

Last Updated: May 2026

dōlogiic takes the security of your personal data seriously. We implement the following controls:

  • Encryption in Transit — All data is transmitted over TLS 1.2 or higher (HTTPS).
  • Encryption at Rest — Personal data and assessment records are stored using industry-standard encryption.
  • Access Controls — Platform access is role-based. Administrative functions are restricted to authorized personnel only.
  • Authentication — User authentication is managed by the platform provider with secure session management.
  • Minimal Data Collection — We collect only the data necessary to deliver requested services.
  • Breach Notification — In the event of a data breach affecting your personal data, we will notify you as required by applicable law.

To report a security concern or vulnerability, contact security@dologiic.com.