This Privacy Policy explains how Cyberin collects, uses, shares, and protects personal information in connection with the Cyberin Platform at cyberin.com. It should be read together with our Terms of Use. We are committed to handling information responsibly and in accordance with applicable data-protection laws, including the EU and UK GDPR where applicable, and the California Consumer Privacy Act as amended by the CPRA where applicable.
1. Who we are
Cyberin is the controller of the personal information described in this Policy. You can reach us regarding privacy at info@cyberin.com.
2. The information we collect
Information you provide
- Registration and account data: name, email address, and professional details such as job title, company name, and company size.
- AI Advisor inputs: the information you enter to receive recommendations, such as industry sector, region, technology environment, and described security needs.
- Contact and inquiry data: information you submit through contact or “list my company” forms, including name, email, company, role, and message content.
- Other submissions: searches, selections, comparisons, saved items, and any other content you choose to provide.
Information collected automatically
- Usage and device data: pages viewed, features used (including AI Advisor sessions), links clicked, referring pages, approximate location from IP address, browser and device type, and timestamps.
- Cookies and similar technologies: used for authentication, security, preferences, analytics, and, where applicable and consented to, measurement.
Information from third parties
We may receive limited information from analytics, security, and infrastructure providers, and from anti-spam services such as the reCAPTCHA service used on our forms.
3. How we use information
We use personal information to provide, operate, secure, and maintain the Platform and your account; generate AI Advisor recommendations and personalise your experience; respond to inquiries; understand how the Platform is used and improve our features, taxonomy, and content; detect and prevent fraud, abuse, and security incidents; send service communications and, where permitted, relevant updates; and comply with legal obligations and enforce our Terms.
4. Commercial use of aggregated and de-identified data
We analyse how the Platform is used — including the categories, vendors, and products users explore, the inputs provided to the AI Advisor, and aggregate demand and interest signals — to operate and improve the Platform and to produce market insights.
We may use and commercialise this information only in aggregated and/or de-identified form — that is, in a form that does not identify you or any individual and that we do not attempt to re-identify. We may produce, publish, license, and sell, from such data, market intelligence, benchmarking, demand and interest trends, and category and vendor-interest analytics (for example, “interest in a category grew this quarter” or “the most-compared products in a domain”). We do not sell information that identifies you as an individual.
Use to improve our systems. We may also use aggregated and de-identified data to develop, improve, and operate the Platform’s ranking systems, classification and taxonomy, comparison logic, and other functionality, including automated systems. We do not use your inputs to train general-purpose AI models offered by third parties.
Re-identification safeguards. Where we aggregate or de-identify data, we apply technical and organisational measures designed to ensure that re-identification of any individual is not reasonably possible, and we do not attempt to re-identify de-identified data except as permitted by law to test those safeguards. Where required by law, we will obtain your consent before processing personal information for these analytics and commercial purposes.
5. Legal bases for processing (GDPR / UK GDPR)
- Contract: to provide the Platform and your account and to deliver features you request, such as the AI Advisor.
- Legitimate interests: to secure and improve the Platform, prevent abuse, and conduct aggregated/de-identified analytics, balanced against your rights.
- Consent: for non-essential cookies, certain marketing, and any processing for which consent is legally required; you may withdraw consent at any time.
- Legal obligation: to comply with applicable laws and respond to lawful requests.
6. How we share information
We do not sell information that identifies you as an individual. We share information only as follows:
- Service providers (processors): hosting, content-delivery, analytics, security, anti-spam, email-delivery, and AI-model providers that process information on our behalf. We enter into data-processing agreements (DPAs) or equivalent terms with such processors, requiring them to protect personal information and process it only on our instructions.
- Aggregated / de-identified insights: with vendors and other third parties, in a form that does not identify you.
- Vendors you choose to contact: if you use a feature to contact or request an introduction to a vendor, the information you submit for that purpose is shared with that vendor.
- Legal and safety: where required by law, regulation, or legal process, or to protect the rights, safety, and security of Cyberin, our users, or the public.
- Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
7. AI Advisor processing and AI providers
When you use the AI Advisor, the information you enter is processed to generate a response. Depending on our configuration, this may occur on our own infrastructure and/or through a third-party AI model provider acting as our processor. We do not permit our AI provider to use your inputs to train or improve its general models, and we do not use the content of your AI Advisor inputs to train general-purpose AI models. We may use AI Advisor inputs in aggregated and de-identified form to improve the Cyberin service, including our ranking and classification systems. Please do not enter confidential information or personal information about identifiable individuals into the AI Advisor unless necessary.
8. Cookies and tracking
We use strictly necessary cookies to operate the Platform (for example, to keep you logged in and secure forms), and, subject to your consent where required, analytics and preference cookies. Where consent is legally required (including in the EU/UK), we obtain it through a cookie banner before non-essential cookies are set, offer granular opt-in by category, and allow you to withdraw consent as easily as you gave it. You can also control cookies through your browser. Disabling some cookies may affect functionality.
9. International transfers
Cyberin is based in Israel, which the European Commission recognises as providing an adequate level of data protection. Where information is transferred to or processed by service providers in other countries, we use appropriate safeguards (such as the European Commission’s Standard Contractual Clauses) where required by law.
10. Data retention
We retain personal information only for as long as necessary for the purposes described in this Policy, after which we delete or de-identify it. Aggregated and de-identified information, which does not identify you, may be retained and used indefinitely. Indicative periods are below; actual periods may vary where a longer period is required by law or to resolve disputes.
| Data category | Indicative retention period |
|---|---|
| Account and registration data | For the life of your account, then deleted or de-identified after closure. |
| AI Advisor inputs (identifiable) | A limited period from the session, then deleted or de-identified. |
| Vendor inquiries / contact submissions | Retained to handle follow-up, disputes, and record-keeping. |
| Usage and analytics data (identifiable) | A limited period, then deleted or aggregated/de-identified. |
| Security and audit logs | Retained for security, fraud prevention, and legal compliance. |
| Aggregated / de-identified data | Indefinitely (does not identify you). |
11. Security
We implement reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, or alteration. However, no platform, system, or method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential.
To the maximum extent permitted by law, and despite our reasonable security measures, Cyberin shall not be liable for unauthorised access, data breaches, attacks, intrusions, malware, or service disruptions caused by third parties or by events beyond our reasonable control. If a personal-data breach affecting your information occurs, we will notify the relevant supervisory authority and affected individuals without undue delay, and where the GDPR applies, within 72 hours of becoming aware where feasible, in each case to the extent required by applicable law.
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information; to object to or restrict certain processing; to withdraw consent; and to lodge a complaint with a supervisory authority. Where the CCPA/CPRA applies, you may have rights to know, delete, correct, and opt out of “sale” or “sharing” of personal information, and not to be discriminated against for exercising those rights.
Automated processing and profiling. Where applicable law gives you the right, you may object to processing of your personal information for profiling or other automated analysis. The AI Advisor produces suggestions to assist your own decision-making and does not make decisions producing legal or similarly significant effects about you.
To exercise any right, contact us at info@cyberin.com. We will respond within the timeframes required by applicable law and may need to verify your identity. Cyberin does not sell personal information that identifies you; to the extent any activity is deemed a “sale” or “share” under the CCPA/CPRA, you may opt out by contacting us or using our cookie controls.
13. Children
The Platform is intended for business and professional users and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, please contact us and we will delete it.
14. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new date and, for material changes, take reasonable steps to notify you. Your continued use of the Platform after the changes take effect constitutes acceptance of the updated Policy.
15. Contact
For any question about this Privacy Policy, or to exercise your rights, contact us at info@cyberin.com.
See also our Terms of Use.