- Home
- Legal
- Privacy Policy
Privacy Policy
This Privacy Policy is maintained by Cyryx Labs LLC (“Cyryx Labs”, “we”, “us”). It explains how we collect, use, disclose, and protect information when you visit cyryxlabs.com, contact us, or engage us under a Master Service Agreement. It explains the website data flows implemented for project fit reviews, MAAX Studio early-access requests, newsletters, contact channels, operational telemetry, and the authenticated workspace. Specific legal rights depend on where you live.
Scope & controller
Data controller: Cyryx Labs LLC, a Florida limited liability company. Postal contact available on request via privacy@cyryxlabs.com.
This policy covers the public website and any prospect, client, or vendor personal data we receive in the ordinary course of business. Personal data processed on behalf of a client under an MSA is governed by the applicable MSA / DPA; in those engagements Cyryx Labs acts as a processor and the client remains the controller.
Key definitions
- Personal data — information relating to an identified or identifiable natural person.
- Processing — any operation performed on personal data (collection, storage, use, disclosure, deletion).
- Controller / Business — the entity that determines the purposes and means of processing.
- Processor / Service Provider — an entity that processes personal data on behalf of a controller.
- Sensitive personal information — categories treated as sensitive under GDPR Art. 9 and CPRA (e.g. government IDs, precise geolocation, health, biometric, or account credentials). We do not solicit these categories through the site.
Information we collect
The website collects information through the following implemented flows:
- Project fit-review data: name, work email, company, project type, problem, desired outcome, why-now context, consent record, and any optional role, company website, stage, investment range, timeline, systems, involvement, or notes you provide. Allowlisted source and intent values may accompany the submission.
- MAAX Studio early-access data: name, work email, company, role, intended use case, operating constraint, country, consent record, and optional telephone. We also receive the landing path, a referrer reduced to origin and path, and allowlisted UTM campaign parameters.
- Newsletter data: email address and opt-in state, plus timestamped confirmation and unsubscribe records.
- Form-protection data: shortened hashes derived from the request IP address and user agent. The IP hash uses a daily rotating salt so it is not designed as a persistent identifier.
- Call-to-action telemetry: the page path, clicked destination, copy variant, referrer reduced to origin and path, and user agent associated with a recorded click. Browser queries and fragments are removed before this operational event is sent.
- Performance telemetry: the browser can send Core Web Vitals to a website endpoint. The current endpoint consumes and discards that payload; it does not persist it.
- Engagement data: if you enter into an MSA, business contact details, invoicing information, and correspondence records.
We do not knowingly collect personal information from children under the age of 16. We do not use facial recognition, biometric identification, or behavioral advertising technologies on this site.
How we use information
- Assess a commercial fit-review request and respond about a possible engagement.
- Manage MAAX Studio early-access requests, assess fit for future access waves, and contact people who expressly joined that list.
- Deliver newsletters and administrative communications you have opted into.
- Understand navigation and campaign attribution, operate the website, and improve its public journeys.
- Detect, prevent, and investigate fraud, abuse, or security incidents.
- Comply with legal obligations, respond to lawful requests, and enforce our terms.
We do not use personal data to train third-party generative models, and we do not sell or share personal data for cross-context behavioral advertising.
Legal bases (GDPR / UK GDPR)
- Consent (Art. 6(1)(a)) — newsletter, non-essential communications.
- Contract (Art. 6(1)(b)) — pre-contractual inquiries and MSA/SOW performance.
- Legitimate interests (Art. 6(1)(f)) — site security, limited operational telemetry, and fraud prevention, where those interests are not overridden by applicable rights.
- Legal obligation (Art. 6(1)(c)) — tax, accounting, and regulatory record-keeping.
Sharing & subprocessors
We do not sell personal information. Website data may be processed by the managed providers configured to host the application, store records and authentication data, or deliver transactional email when that pipeline is configured. The exact provider set can change with the deployed environment.
- Configured application hosting and delivery infrastructure.
- Managed database and authentication services.
- Transactional email delivery, when configured.
A current subprocessor list is available on request via privacy@cyryxlabs.com. We may disclose personal data when required by law, court order, or to protect the rights, property, or safety of Cyryx Labs, our clients, or the public.
Retention & deletion
Records are retained while needed for the purpose described above, to honor a withdrawal or suppression request, or to meet applicable contractual, tax, accounting, dispute, and legal-hold obligations. A single code-enforced global deletion schedule is not currently implemented for every website record type.
You may request deletion or withdraw consent through privacy@cyryxlabs.com. We may retain a minimal suppression record where needed to prevent a communication you declined or to meet a legal obligation.
International transfers
Cyryx Labs is based in the United States. Managed providers may process website data in countries other than your own. Contact privacy@cyryxlabs.com for information about the current provider configuration and transfer safeguards applicable to a specific flow.
Your rights (GDPR, CCPA/CPRA, others)
Depending on your jurisdiction, you may have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion (right to be forgotten);
- request portability in a structured, machine-readable format;
- restrict or object to certain processing, including profiling;
- withdraw consent at any time without affecting prior lawful processing;
- opt out of the sale or sharing of personal information (see §10);
- limit the use of sensitive personal information;
- not be discriminated against for exercising these rights;
- lodge a complaint with your supervisory authority.
To exercise any of these rights, email privacy@cyryxlabs.com. We respond within the timeframes required by applicable law. We may request information reasonably necessary to verify your identity. Authorized agents may submit requests on your behalf with signed authorization.
Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, and we do not engage in profiling within the meaning of GDPR Art. 22 through the website.
Security
Implemented website safeguards include server-side secrets, narrow database procedures for public form writes, row-level access controls that do not grant anonymous direct table writes, role-gated administrative views, and shortened hashes for form-protection metadata. No transmission or storage method is completely secure, and these safeguards do not guarantee that an incident cannot occur.
Cookies & analytics
The public fit-review and MAAX forms do not require an analytics cookie. The authenticated workspace uses session data required for sign-in. The site records limited call-to-action events containing public path, query-free destination, origin-and-path referrer, copy variant, and user agent. The current Web Vitals endpoint consumes and discards performance payloads. We have not identified advertising cookies or third-party advertising trackers in the implemented website code.
Consent checkboxes for the fit-review, early-access, and newsletter flows are unchecked, required for submission where displayed, versioned, and stored with the applicable record. You can withdraw that consent independently by emailing privacy@cyryxlabs.com.
Children
The site is intended for a business audience and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided information, contact privacy@cyryxlabs.com and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be highlighted on this page and the “Last updated” date will be revised. Continued use of the site after changes take effect constitutes acknowledgment of the updated policy.
Contact & complaints
Privacy inquiries: privacy@cyryxlabs.com. General inquiries: contact@cyryxlabs.com.
EU/EEA and UK residents may lodge a complaint with their local supervisory authority. California residents may contact the California Privacy Protection Agency. We encourage you to contact us first so we can address your concern directly.
This page is provided for general informational purposes and is not legal advice. Please consult qualified counsel for guidance specific to your situation.

