Cyryx Labs
Legal · Privacyv2026.07 · Last updated July 23, 2026

Privacy Policy

This Privacy Policy is maintained by Cyryx Labs LLC (“Cyryx Labs”, “we”, “us”). It explains how we collect, use, disclose, and protect information when you visit cyryxlabs.com, contact us, or engage us under a Master Service Agreement. It is designed to align with the EU General Data Protection Regulation (GDPR), UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and comparable U.S. state privacy laws (VCDPA, CPA, CTDPA, UCPA, and successors).

01

Scope & controller

Data controller: Cyryx Labs LLC, a Florida limited liability company. Postal contact available on request via privacy@cyryxlabs.com.

This policy covers the public website and any prospect, client, or vendor personal data we receive in the ordinary course of business. Personal data processed on behalf of a client under an MSA is governed by the applicable MSA / DPA; in those engagements Cyryx Labs acts as a processor and the client remains the controller.

02

Key definitions

  • Personal data — information relating to an identified or identifiable natural person.
  • Processing — any operation performed on personal data (collection, storage, use, disclosure, deletion).
  • Controller / Business — the entity that determines the purposes and means of processing.
  • Processor / Service Provider — an entity that processes personal data on behalf of a controller.
  • Sensitive personal information — categories treated as sensitive under GDPR Art. 9 and CPRA (e.g. government IDs, precise geolocation, health, biometric, or account credentials). We do not solicit these categories through the site.
03

Information we collect

We collect only what you choose to provide and the minimum technical data needed to operate the site securely.

  • Contact form data: name, email, optional company, message body, and consent confirmation.
  • MAAX Studio early-access data: name, work email, telephone, country, consent record, referral source, and campaign attribution parameters you arrive with.
  • Newsletter data: email address and opt-in state, plus timestamped confirmation and unsubscribe records.
  • Technical data: IP address, user agent, request timestamps, referrer, and aggregated performance metrics (Core Web Vitals).
  • Engagement data: if you enter into an MSA, business contact details, invoicing information, and correspondence records.

We do not knowingly collect personal information from children under the age of 16. We do not use facial recognition, biometric identification, or behavioral advertising technologies on this site.

04

How we use information

  • Respond to inquiries and provide the information or service you requested.
  • Manage MAAX Studio early-access requests, assess fit for future access waves, and contact people who expressly joined that list.
  • Deliver newsletters and administrative communications you have opted into.
  • Operate, secure, monitor, and improve the site and our services.
  • Detect, prevent, and investigate fraud, abuse, or security incidents.
  • Comply with legal obligations, respond to lawful requests, and enforce our terms.

We do not use personal data to train third-party generative models, and we do not sell or share personal data for cross-context behavioral advertising.

05

Legal bases (GDPR / UK GDPR)

  • Consent (Art. 6(1)(a)) — newsletter, non-essential communications.
  • Contract (Art. 6(1)(b)) — pre-contractual inquiries and MSA/SOW performance.
  • Legitimate interests (Art. 6(1)(f)) — site security, aggregated analytics, fraud prevention. Balancing test performed and available on request.
  • Legal obligation (Art. 6(1)(c)) — tax, accounting, and regulatory record-keeping.
06

Sharing & subprocessors

We do not sell personal information. We share personal data only with vetted subprocessors under written data-processing terms, and only to the extent required to deliver the service.

  • Hosting, edge compute, and CDN infrastructure.
  • Transactional email delivery.
  • Managed database and authentication backend.
  • Error monitoring and performance analytics (aggregated).

A current subprocessor list is available on request via privacy@cyryxlabs.com. We may disclose personal data when required by law, court order, or to protect the rights, property, or safety of Cyryx Labs, our clients, or the public.

07

Retention & deletion

  • Contact submissions: up to 24 months from last contact.
  • MAAX Studio early-access records: until you withdraw consent or the early-access program ends, plus a minimal suppression record where needed to honor an opt-out.
  • Newsletter records: until you unsubscribe, plus a suppression record retained indefinitely to honor your opt-out.
  • Server logs: up to 90 days, then rotated or aggregated.
  • Engagement records: for the term of the MSA and the period required by tax, accounting, and legal-hold obligations.

You may request earlier deletion; see §09.

08

International transfers

Cyryx Labs is based in the United States and operates globally. Personal data may be processed in countries other than your own. For transfers from the EEA, UK, or Switzerland we rely on Standard Contractual Clauses (Commission Decision (EU) 2021/914), the UK IDTA / UK Addendum, and, where applicable, the EU-U.S. and UK-U.S. Data Privacy Framework. Copies of transfer safeguards are available on request.

09

Your rights (GDPR, CCPA/CPRA, others)

Depending on your jurisdiction, you may have the right to:

  • access the personal data we hold about you;
  • request correction of inaccurate data;
  • request deletion (right to be forgotten);
  • request portability in a structured, machine-readable format;
  • restrict or object to certain processing, including profiling;
  • withdraw consent at any time without affecting prior lawful processing;
  • opt out of the sale or sharing of personal information (see §10);
  • limit the use of sensitive personal information;
  • not be discriminated against for exercising these rights;
  • lodge a complaint with your supervisory authority.

To exercise any of these rights, email privacy@cyryxlabs.com. We respond within the timeframes required by applicable law (typically 30 days under GDPR; 45 days under CCPA/CPRA, extendable once with notice). We may request information reasonably necessary to verify your identity. Authorized agents may submit requests on your behalf with signed authorization.

10

Do not sell or share

Cyryx Labs does not sell personal information and does not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA and comparable state laws. There is no opt-out to submit because the underlying practice does not occur; you may still confirm this in writing via privacy@cyryxlabs.com.

11

Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, and we do not engage in profiling within the meaning of GDPR Art. 22 through the website.

12

Security

We apply administrative, technical, and organizational safeguards proportionate to the risk, including TLS in transit, encryption at rest for managed datastores, role-based access, least-privilege service credentials, audit logging, dependency scanning, and periodic review of subprocessors. No method of transmission or storage is 100% secure; we work to apply current industry best practices and to respond promptly to incidents that materially affect personal data.

13

Cookies & analytics

We use only cookies and similar technologies strictly necessary to operate the site (e.g. security, session, preference) and aggregated, privacy-preserving performance telemetry. We do not use advertising cookies, third-party ad trackers, cross-site tracking pixels, or session replay. Because we do not track across sites, we honor Global Privacy Control (GPC) signals by default.

14

Children

The site is intended for a business audience and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided information, contact privacy@cyryxlabs.com and we will delete it.

15

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be highlighted on this page and the “Last updated” date will be revised. Continued use of the site after changes take effect constitutes acknowledgment of the updated policy.

16

Contact & complaints

Privacy inquiries: privacy@cyryxlabs.com. General inquiries: contact@cyryxlabs.com.

EU/EEA and UK residents may lodge a complaint with their local supervisory authority. California residents may contact the California Privacy Protection Agency. We encourage you to contact us first so we can address your concern directly.

This page is provided for general informational purposes and is not legal advice. Please consult qualified counsel for guidance specific to your situation.