Legal

Privacy Policy

This policy explains how Cyntecian collects, uses, protects and shares information when you use our website, applications and services. Written in plain language, maintained by Cyntecian.

Effective: 15 July 2026Last updated: 15 July 2026
Privacy by design

Data protection is baked into every feature, from schema to UI. We collect the minimum needed to make Cyntecian work.

Encrypted end-to-end in transit and at rest

All traffic is served over TLS 1.2+. Data at rest is encrypted using industry-standard AES-256.

Your data stays yours

We never sell personal data. We do not train foundation models on your workspace content.

Global rights, honoured

GDPR, UK GDPR, CCPA/CPRA, LGPD and comparable frameworks. Export, correct or delete your data at any time.

1. Overview

Cyntecian is a product of CTC International Marketing Management - FZCO ("CTC International Marketing Management - FZCO", "we", "us", or "our"), an AI operating system for creators, businesses and agencies. We take privacy seriously and are committed to protecting the personal information you share with us.

This Privacy Policy applies to information collected through cyntecian.com, our applications, APIs and related services (the "Services"). By using the Services you agree to the practices described here.

2. Who we are

CTC International Marketing Management - FZCO is the maker of Cyntecian and the controller of personal data processed about visitors to our website and account holders. For content and data you or your organisation upload into a workspace, you are the controller and CTC International Marketing Management - FZCO is the processor, acting on your documented instructions under our Data Processing Agreement.

3. Information we collect

We collect only what is needed to deliver, secure and improve the Services:

  • Account information — name, email, avatar, password hash, organisation and role.
  • Workspace content — files, messages, prompts, briefs, CRM entries and any content you or your team create in Cyntecian.
  • Usage data — pages visited, features used, referrers, device and browser type, IP address, timestamps and diagnostic events.
  • Integrations — tokens and metadata for tools you connect (e.g. email, storage, analytics). We request the narrowest scope needed.
  • Support and communications — messages you send us, survey responses and feedback.
  • Billing — company name, billing address and tax details. Card details are handled by our PCI-DSS certified payment processor; we never see or store full card numbers.

We do not knowingly collect special-category data (health, biometrics, political views, etc.). Please do not upload such data unless a specific feature requires it and the appropriate legal basis is in place.

4. How we use information

  • Provide, operate and maintain the Services.
  • Authenticate accounts and prevent fraud, abuse and security incidents.
  • Deliver AI features you invoke, using the models and providers described in section 13.
  • Bill you for paid plans and manage taxes and receipts.
  • Respond to support requests and communicate about the Services.
  • Improve product performance, reliability and design (using aggregated or de-identified data).
  • Comply with law and enforce our agreements.

6. Sharing and subprocessors

We do not sell or rent personal information. We share data only with vetted subprocessors who help us run the Services under written data-processing terms. Categories include:

  • Cloud hosting and databases (e.g. our hosting and backend providers).
  • Authentication and identity management.
  • AI model providers used to fulfil requests you initiate (see section 13).
  • Analytics and product-telemetry providers configured with privacy-first defaults.
  • Email delivery for transactional and account emails.
  • Payment processing for paid plans.
  • Customer support tooling.

We may disclose information when legally required, to protect the rights, property or safety of Cyntecian, our users or others, or in connection with a merger, acquisition or sale of assets — in which case we will notify affected users.

7. International data transfers

Cyntecian operates globally. Where personal data is transferred outside the EEA, UK or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with additional technical and organisational measures such as encryption in transit and at rest.

8. Data retention

We keep personal data only as long as necessary for the purposes described in this policy. Typical retention windows:

  • Account data — for the life of your account, plus up to 90 days after deletion for backups.
  • Workspace content — until you delete it or your organisation cancels; then removed from live systems within 30 days and from backups within 90 days.
  • Billing records — retained for the period required by tax and accounting laws (typically 7–10 years).
  • Security and access logs — up to 12 months.

9. Security

We follow industry best practices to protect your information, including:

  • TLS 1.2+ for data in transit and AES-256 for data at rest.
  • Row-level security so each workspace only sees its own data.
  • Least-privilege access controls and multi-factor authentication for staff.
  • Continuous vulnerability scanning, dependency auditing and code review.
  • Isolated environments for development, staging and production.
  • Incident-response procedures with prompt notification of affected users where required by law.

No system is perfectly secure. If you believe your account or our systems have been compromised, please contact us immediately at info@ctc-marketing.com.

10. Your privacy rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your personal data ('right to be forgotten').
  • Restrict or object to certain processing.
  • Port your data in a structured, machine-readable format.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with your local data-protection authority.

Most of these rights can be exercised directly from your account settings. For anything else, email info@ctc-marketing.com and we will respond within 30 days.

11. California residents (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, to request deletion, to correct inaccurate information and to opt out of "sharing" for cross-context behavioural advertising. Cyntecian does not sell personal information and does not share it for cross-context behavioural advertising. To exercise any right, contact info@ctc-marketing.com. We will not discriminate against you for exercising your rights.

12. Cookies and tracking

We use cookies and similar technologies for three purposes:

  • Strictly necessary — authentication, session integrity and security. Always on.
  • Preferences — to remember your workspace and UI choices.
  • Analytics — privacy-friendly, aggregate usage analytics. Loaded only after consent where required.

You can manage cookies in your browser settings. Disabling strictly necessary cookies will prevent core Services from working. For full details, see our Cookie Policy.

13. AI processing

When you use AI features, the prompts and content you submit are sent to model providers to generate a response. We select providers with strong privacy commitments and configure them so that:

  • Your prompts and outputs are not used to train foundation models.
  • Data is processed only to return the response you requested.
  • Provider-side retention is limited to short abuse-monitoring windows or zero-retention where available.

A current list of AI subprocessors is available on request via info@ctc-marketing.com.

14. Children's privacy

Cyntecian is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

15. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes we will notify you by email or through the Services at least 30 days before they take effect. The "Last updated" date at the top always reflects the most recent revision.

16. Contact us

Questions, requests or complaints about this policy or your personal data:

info@ctc-marketing.com
Data Protection Officer

CTC International Marketing Management - FZCO — Attn: Privacy Team, maker of Cyntecian. Reach us any time; we respond within 30 days.

This page is maintained by Cyntecian and describes our current practices. It is not a certification or independent audit. For our commercial terms, see the Terms of Service.