Privacy Policy
This Policy explains how Cypho handles personal information across our website, Threat Intelligence Platform, and related services.
Effective date: September 18, 2026
This Privacy Policy describes how Cypho (“Cypho,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information when you visit cypho.io, communicate with us, request a demo, or use the Cypho Threat Intelligence Platform and related services (collectively, the “Services”).
1. Scope and Our Role
This Policy applies to website visitors, prospects, customers, authorized platform users, and people whose information we receive in business communications.
Cypho generally acts as a controller for website, account, sales, support, and service-usage information. When Cypho processes information submitted or configured by a customer to provide the Services, Cypho generally acts on that customer’s instructions. The applicable agreement, including any data processing agreement, governs that processing.
The Services analyze cyber-threat information from varied sources. That content may incidentally contain personal information. Section 3 explains how threat intelligence is handled.
2. Information We Collect
Depending on how you interact with Cypho, we may collect:
- Account and contact information: name, business email address, phone number, job title, organization, username, authentication data, and account preferences.
- Commercial information: subscription plan, order, billing contact, transaction details, and records of products or services requested. If payment information is collected, it may be processed by a payment provider under that provider’s privacy terms.
- Customer Data: domains, IP addresses, keywords, brands, email domains, executive names, digital assets, indicators, cases, notes, uploaded files, and data from integrations that you configure.
- Service and device data: IP address, device and browser type, operating system, timestamps, pages and features used, searches, clicks, referring URLs, log data, approximate location derived from IP address, and diagnostic or security events.
- Communications: demo requests, support tickets, feedback, survey responses, and correspondence with Cypho.
- Cookie and analytics data: identifiers and interaction data collected through cookies and similar technologies, as described in Section 7.
3. Threat Intelligence Data
To provide cyber-threat intelligence, the Services collect and analyze information from public websites and records, technical infrastructure, licensed data providers, security researchers, community feeds, customer-authorized integrations, and surface, deep, and dark-web sources. This data may include identifiers such as usernames, email addresses, aliases, domain-registration information, IP addresses, online posts, exposed credentials, or other information connected to security incidents and malicious activity.
Cypho processes this information to detect and contextualize cyber threats, credential exposure, data leaks, impersonation, malicious infrastructure, vulnerabilities, threat actors, and campaigns; notify affected customers; protect systems and users; and support lawful defensive security research. We seek to limit processing to information relevant to those purposes and apply access controls appropriate to the sensitivity of the source and data.
4. Sources of Information
We collect information:
- directly from you and your organization;
- automatically when you use the website or platform;
- from customer-configured services and integrations;
- from service providers, partners, event organizers, and business contact sources; and
- from the threat-intelligence sources described in Section 3.
5. How We Use Information
Cypho may use personal information to:
- provide, operate, maintain, and support the Services;
- configure monitoring, produce alerts and reports, correlate indicators, and deliver threat intelligence;
- authenticate users, administer accounts, process orders, and communicate about subscriptions;
- respond to questions, demo requests, feedback, and support needs;
- secure the Services, prevent abuse and fraud, investigate incidents, and enforce our agreements;
- analyze performance and usage, troubleshoot, and improve or develop features;
- send product, service, event, or marketing communications, subject to your choices and applicable law; and
- comply with law, protect rights and safety, and establish, exercise, or defend legal claims.
We may aggregate or de-identify information so that it no longer reasonably identifies an individual and use it for analytics, security research, benchmarking, and service improvement. We do not attempt to re-identify de-identified information except to test our de-identification measures.
6. Legal Bases for Processing
Where applicable law requires a legal basis, Cypho relies on one or more of the following: performance of a contract; compliance with legal obligations; consent; and legitimate interests, including providing and securing the Services, detecting cyber threats, improving our products, communicating with customers, and operating our business. We consider the potential impact on individuals when relying on legitimate interests.
7. Cookies and Analytics
Cypho uses cookies and similar technologies that are necessary for website functionality and security and may use analytics technologies, including Google Analytics, to understand website traffic and interactions. These technologies may collect online identifiers, device information, and usage data.
You can control cookies through your browser settings and any cookie controls we make available. Blocking some cookies may affect website or platform functionality. You can also use Google’s available browser opt-out tools for Google Analytics.
8. How We Disclose Information
We may disclose personal information to:
- Service providers that support hosting, security, analytics, communications, support, billing, and other business operations under contractual safeguards;
- Your organization and authorized users to administer accounts and provide shared platform functionality;
- Integration providers when you enable or direct an integration;
- Professional advisers such as auditors, insurers, legal counsel, and financial advisers;
- Authorities or other parties when reasonably necessary to comply with law, respond to lawful process, protect rights or safety, investigate misuse, or enforce our agreements; and
- Transaction participants in connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality measures.
Cypho does not sell personal information for money. Some privacy laws define “sale” or “sharing” broadly to include certain analytics or advertising activities. Where those laws apply, we honor the choices and rights they require.
9. International Data Transfers
Cypho, its service providers, and threat-data sources may process information in countries other than the country where you live. Privacy laws in those locations may differ. Where required, we use appropriate transfer mechanisms and safeguards for international transfers.
10. Retention
We retain personal information for as long as reasonably needed to provide the Services, fulfill the purposes described in this Policy, comply with legal and contractual obligations, resolve disputes, and protect the Services. Retention periods depend on the type and sensitivity of the information, customer settings and agreements, source restrictions, security needs, and legal requirements. We delete or de-identify information when it is no longer needed, unless retention is required or permitted by law.
11. Security
Cypho uses administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You are responsible for protecting your credentials and promptly reporting suspected account misuse.
12. Your Rights and Choices
Depending on where you live and subject to legal exceptions, you may have rights to request access to, correction of, deletion of, portability of, or restriction of personal information; object to certain processing; withdraw consent; opt out of marketing; or appeal a decision about a request. You may also have the right to complain to your local data protection authority.
To exercise a right, email [email protected]. We may need to verify your identity and authority before completing the request. If Cypho processes the information solely for a customer, we may direct your request to that customer. Authorized agents may submit requests where permitted by law. Cypho will not discriminate against you for exercising applicable privacy rights.
You can unsubscribe from marketing emails using the link in the message. We may still send non-promotional service messages.
13. Children’s Privacy
The Services are intended for organizations and adults and are not directed to children under 18. We do not knowingly collect personal information directly from children through account registration. If you believe a child has provided personal information to us, contact us so we can review and take appropriate action.
14. Third-Party Services
The Services may link to or integrate with third-party websites and services. Their privacy practices are governed by their own policies, and Cypho is not responsible for those practices.
15. Changes to This Policy
We may update this Policy as our Services, laws, or practices change. We will post the revised Policy and update the effective date. If a change materially affects how we use personal information, we will provide additional notice when required.
16. Contact Us
For privacy questions or requests, contact Cypho at [email protected]. Use of the Services is also subject to our Terms of Service.
Experience Next Generation Threat Intelligence
Minimize complexity and maintain a secure posture with real-time monitoring and actionable insights