Privacy Policy
How Cyberneza collects, uses, and protects information from visitors and clients.
Last updated: August 14, 2026
Cyberneza ("Cyberneza", "we", "us", or "our") respects your privacy and is committed to protecting it. This Privacy Policy explains how we collect, use, and share information when you visit our website at cyberneza.com, interact with us, or engage our services.
1. Information we collect
We collect the following categories of personal information:
Information you provide directly
- Contact information: name, email address, phone number, company name
- Communications: messages you send via contact forms, email, or scheduling tools
- Professional information: job title, company size, industry, and compliance needs you share with us
Information collected automatically
- Device information: IP address, browser type and version, operating system, device type
- Usage data: pages visited, time spent on pages, referring URLs, click patterns
- Session replay data: where analytics cookies are active (see section 3), Microsoft Clarity records how you interact with pages — mouse movement, scrolling, and clicks — to produce session recordings and heatmaps. Clarity is configured in strict masking mode, so all page text — including anything you type into a form — is masked before the recording is sent, and the content of your entries is not captured.
- Location data: approximate geographic location based on IP address (country/region level only)
2. Legal basis for processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:
- Consent: When you accept analytics cookies via our consent banner, or when you submit a contact form or book a call, you consent to us processing your information for those purposes.
- Legitimate interests: We maintain basic website security and functionality. Our legitimate interests do not override your fundamental rights and freedoms.
- Contract performance: When you engage our services, we process information necessary to fulfill our contractual obligations.
- Legal obligation: We may process data when required to comply with applicable laws.
3. Cookies and tracking technologies
When you first visit our site, a consent banner asks whether you accept or decline non-essential cookies. Your preference is stored in your browser and remembered on future visits. How non-essential cookies behave before you make a choice depends on where you are visiting from:
- EEA, UK, and Switzerland: analytics and advertising cookies are off by default and are set only if you click Accept (opt-in).
- United States and everywhere else: analytics and advertising cookies are on by default, consistent with the opt-out model under U.S. privacy laws. You can turn them off at any time by clicking Decline on the banner or Cookie Settings in the site footer (opt-out).
Essential cookies
Required for basic website functionality. Your cookie consent preference is stored in your browser's local storage so it persists between visits. These cannot be disabled.
Analytics and advertising cookies
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
| _ga | Google Analytics | Distinguishes unique users | 2 years |
| _ga_* | Google Analytics | Maintains session state | 2 years |
| _gcl_au | Google Ads | Stores ad-click information for conversion measurement | 90 days |
| _uetsid | Microsoft Advertising | Session identifier for conversion tracking | 1 day |
| _uetvid | Microsoft Advertising | Visitor identifier for conversion tracking and remarketing | 13 months |
| _clck | Microsoft Clarity | Persists the Clarity user ID for session replay and heatmaps | 1 year |
| _clsk | Microsoft Clarity | Connects page views into a single session recording | 1 day |
Microsoft services may also set third-party cookies on Microsoft's own domains (such as MUID, used to recognize browsers across Microsoft sites, valid up to 13 months). These are governed by the Microsoft Privacy Statement.
First-party campaign attribution (session storage)
If you arrive at our site through a link that carries campaign parameters — utm_source, utm_medium, utm_campaign, utm_term, utm_content, a Microsoft click ID (msclkid), or a Google click ID (gclid) — we store those parameters, the page you landed on, the referring site, the time of your visit, and a random visit identifier (cn_id) in your browser's session storage under the key cn-attrib. This is not a cookie: it is first-party data that records only your first page in the tab session and is deleted automatically by your browser when the tab session ends. It is not shared with advertising networks.
If you decline non-essential cookies (or revoke consent via Cookie Settings), this attribution record is deleted immediately and is not re-created while your choice remains declined.
When you submit a form, the attribution record — together with your answers and your cookie-consent state at that moment — is attached to your submission and stored securely in our systems so that we can respond to your enquiry and understand which ad or link brought you to us. When you open our scheduling links (Calendly), the visit identifier and campaign parameters are included in the scheduling link so that a booking you choose to make can be connected to your enquiry. Scheduling is governed by Calendly's privacy policy.
First-party engagement measurement (no cookies, no storage)
We measure how our own pages are used with our own software, rather than relying only on Google's and Microsoft's analytics. This measurement is cookieless: it sets no cookie, and it writes nothing to your browser's local or session storage. There is no identifier assigned to you, on your device or anywhere else, and nothing that can be used to recognize you on a later visit or on another site. Because of that it operates without needing your consent under the cookie rules, which govern storing and reading information on your device — and it is why we can measure our pages without tracking you.
What we record for each page you view: the page path (never the query string), the page title, the site you arrived from (the domain only — for example bing.com, never the full address or anything you searched for), whether the page was your entry point, how long the page was open and active, how far down the page you scrolled, your approximate location, your device type, and your browser and operating system family.
About that approximate location. We record the country, the state or region, and the nearest city that our network provider associates with your internet connection — for example "United States, Florida, Orlando". We use it to understand which parts of the country our visitors come from, because we serve clients regionally. Two things are worth being precise about. First, it is derived by our network provider from your connection and given to our server; it is not read from your device, and no cookie or storage is involved, which is why this measurement still operates without consent under the cookie rules. Second, it is approximate and often wrong at the city level — it reflects where your internet provider routes traffic, not where you are. We still do not store your IP address itself (see below).
We also record interactions with our pages: which links and buttons are clicked, and — this is the part we most need in order to fix our own forms — when someone begins filling in a form and does not send it, including how many fields were completed and which field they were on when they stopped. We record the names of our form fields, never anything you type into them. Nothing you enter into a form is recorded unless you choose to submit it.
We do not store your IP address. To group the pages of a single visit together without a cookie, our server combines your IP address and browser identification with a secret value that changes every day, and keeps only the irreversible result. That value cannot be turned back into your IP address, and because the daily secret changes, the value for the same visitor is different tomorrow — so this cannot follow you from one day to the next. The IP address itself is never written to our records.
This data is stored in our own database, is used only by us to improve this website, and is never sold, shared with advertising networks, or used to build a profile of you. It is retained for 13 months and then deleted.
Session recording. As part of this same first-party measurement, we also record a playback of the pages you view here: the page as it was drawn, and what you did on it — where you moved and clicked, how far you scrolled, which form fields you moved between, and any error our own scripts produced. We use it for one purpose, which is to find where our own pages and forms fail people; that is very hard to work out from counts alone. It runs for every visitor on exactly the same basis as the measurement described above — no cookie, nothing written to your browser's local or session storage, no identifier of any kind, and nothing that can recognize you on a later visit or on another site.
What you type is never recorded. Every form field — every text box, every message box, every dropdown — is masked in your browser before anything is sent. The recording carries only the fact that a field of a certain length was filled in, never the characters in it. That masking happens on your device at the moment of capture, so the values are not sent to us and then removed: they never leave your browser at all. Anything you enter into a form — your name, your email address, your message — is outside the recording by construction, whether you typed it or your browser filled it in for you. As with the measurement above, we also do not record the query string of the address you are on, the full address of the site you came from, or your IP address.
Recordings are kept for 30 days and are then deleted automatically. That is deliberately shorter than the 13 months we keep the measurement records described above: a replay is a much richer record than a count, and there is no good reason to keep one for longer than it takes us to act on it.
A one-question prompt, and the only thing here you write yourself. After you have been reading a page for a while, we may show a small box in the bottom-left corner asking what you were hoping to find. Answering is entirely optional and the box closes on a click, on the Escape key, or by being ignored. It never appears on a page where you are filling something in, and never while you have text in a form.
Everything else described on this page is behaviour our scripts observed — pages, counts, timings. Your answer is the one thing we store that you actually wrote, so we keep it separately from the rest and treat it with more care. We do not ask for your name, email or phone number in that box, and we would rather you did not put them there — if you want a reply, please use the contact form instead, which is designed for it. If you close the box without answering, we record only that it was shown and declined, and nothing else. Answers are kept for 13 months, the same as the measurement records above, and are used solely to improve this website.
Opting out. If you would rather not be included even in this anonymous measurement, run the following in your browser's developer console on this site, and we will stop collecting entirely on this browser: localStorage.setItem('cn-telemetry-optout', '1'). This one setting covers session recording and the question prompt as well — with it in place neither is started and their code is never even downloaded. You can also email us at privacy@cyberneza.com and we will explain the steps.
What happens before you choose
We want to be precise about this, because "cookies are blocked" and "nothing is sent" are not the same thing.
If you are in the EEA, UK, or Switzerland: our analytics and advertising tags are not loaded at all until you accept. Nothing is requested from Google or Microsoft, and no data — including your IP address — reaches them, unless and until you choose to accept. We also deliberately omit browser "preconnect" hints for those providers, because those alone would open a connection and disclose your IP address before you had chosen.
If you are in the United States or elsewhere: our Google and Microsoft measurement tags load when the page loads, before you interact with the banner, consistent with the opt-out model described above. If you decline — or if you send the Global Privacy Control signal — they operate in a restricted mode: they do not read or write cookies and do not create a persistent identifier for you, and we delete any such cookies already set. They do still contact Google and Microsoft servers, which necessarily discloses your IP address, the page address you are visiting, and your referring page. If you prefer that no data reach these providers at all, decline non-essential cookies and use a browser content blocker.
Microsoft Clarity (session replay) is never loaded until analytics are permitted for your region or you accept, so no session recording occurs before that point.
Google Analytics: We use Google Analytics 4 to understand website usage patterns. Google may transfer data to servers in the United States. Learn more: Google Privacy Policy | Opt-out Browser Add-on
Managing cookies
You can manage analytics and advertising cookies using the consent banner that appears on your first visit. To change your preference at any time, click the "Cookie Settings" link in the site footer to reopen the banner — reopening it immediately revokes any previously granted consent until you choose again. When you decline or revoke consent, we also delete analytics and advertising cookies previously set by our site from your browser.
Global Privacy Control: We honor the Global Privacy Control (GPC) browser signal. If your browser sends GPC, advertising cookies and ad-related data sharing are disabled automatically for your visit — even if you click Accept on the banner.
How we decide which consent default you see: visitors in the EEA, the United Kingdom, and Switzerland get an opt-in default (nothing loads until you accept); elsewhere the default is opt-out. To apply the right default we look up the country of your IP address at our edge network when you first visit, and store only the resulting two-letter country code — not your IP address — in your browser's local storage. If the lookup fails, we estimate your region from your browser's timezone instead.
Consent records: when you make a choice in the cookie banner — accept, decline, or revoke via Cookie Settings — we keep a record of it so that we can demonstrate what you consented to if you or a regulator asks. The record contains the time, the choice made, the page you were on, your IP address and country, your browser's reported timezone, whether a Global Privacy Control signal was present, and the version of this policy in force at the time. Records are stored with our infrastructure provider (Cloudflare) and are retained for 3 years, after which they are deleted automatically. The IP address recorded with a receipt is deleted after 90 days; the rest of the record is kept for the full 3-year period. A receipt ID is stored in your browser's local storage so you can reference your record in any request to us.
Do Not Track: California law (Cal. Bus. & Prof. Code § 22575(b)(5)) requires us to tell you how we respond to browser "Do Not Track" (DNT) signals. We do not respond to DNT headers, because no common industry standard for interpreting them was ever adopted. We honor the Global Privacy Control signal instead, which is the successor mechanism and is recognized under California regulations. We also do not permit third parties to collect personally identifiable information about your activity across other websites through our site, beyond the advertising cookies described in section 3, which you can turn off at any time.
Most browsers also allow you to:
- View and delete existing cookies
- Block third-party cookies
- Block cookies from specific sites
- Block all cookies
4. How we use information
We use the information we collect to:
- Respond to inquiries and communicate with you about potential or ongoing engagements
- Provide, operate, and improve our services and website
- Understand aggregate usage patterns to improve content, messaging, and user experience
- Send relevant information about our services (only with your consent)
- Maintain the security of our website and services and detect or prevent abuse
- Comply with legal obligations where applicable
Automated decision-making: We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.
5. How we share information
We do not sell, rent, or trade your personal information for money. We do use advertising cookies from Google and Microsoft for conversion tracking and remarketing (see section 3). Because those cookies let advertising partners recognize your browser across other sites, this may qualify as "sharing" for cross-context behavioral advertising under the California Privacy Rights Act. You can opt out at any time by clicking Decline on the cookie banner, Cookie Settings in the footer, or the Do Not Sell or Share My Info link in the footer — any of these turns advertising cookies off. Beyond those advertising cookies, we may share information in the following limited situations:
- Service providers: Third parties who help us operate our website, analytics, or communications, bound by contractual confidentiality obligations and data processing agreements.
- Professional advisors: Legal, accounting, or other professional advisors when reasonably necessary.
- Legal requirements: When required to comply with applicable laws, regulations, court orders, or legal processes.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with notice provided to affected users.
Third-party services we use
- Google Analytics: Website analytics — Privacy Policy
- Google Ads: Advertising conversion tracking and remarketing. Advertising cookies follow your consent choice and region as described in section 3, and are disabled by the Global Privacy Control signal — Privacy Policy
- Microsoft Advertising: Advertising conversion tracking and remarketing (Universal Event Tracking). Advertising cookies follow your consent choice and region as described in section 3, and are disabled by the Global Privacy Control signal — Privacy Policy
- Microsoft Clarity: Session replay and heatmap analytics. Configured in strict masking mode, so all page text and form inputs are masked — Privacy Policy
- Calendly: Appointment scheduling — Privacy Policy
- Cloudflare: Form security (Turnstile) and form processing. Form submissions, including the contact details you provide, are processed by a Cloudflare Worker and retained in short-term operational logs for reliability monitoring — Privacy Policy
- Supabase: Database hosting (Supabase, Inc.). Form submissions, including the contact details you provide, are stored in a database hosted by Supabase in the United States — Privacy Policy
- Resend: Transactional email delivery for form submissions — Privacy Policy
- Render: Website hosting — Privacy Policy
- Better Business Bureau: our pages display a BBB accreditation seal that is loaded from a BBB content delivery network. Loading that image discloses your IP address and the referring page to BBB and its CDN provider; it sets no cookies — Privacy Policy
Client and engagement data
This policy covers information collected from website visitors and prospective clients. Information we handle inside a consulting engagement — such as your policies, evidence, system documentation, or personnel data processed during readiness work — is governed by the engagement agreement (master services agreement and, where applicable, a data processing agreement) between Cyberneza and the client, not by this policy. In those engagements we act as a service provider or processor, handling client data for the purposes and on the instructions set out in that agreement. Clients should refer to their executed agreement for the controlling terms.
6. Data retention
We retain personal information for specific periods based on the type of data and purpose:
- Contact form submissions: 3 years from last interaction, or until you request deletion
- Email correspondence: 3 years from last interaction
- Client engagement records: 7 years after engagement ends (for legal and accounting purposes)
- Analytics data: up to 14 months (Google Analytics 4 user-level data retention; aggregated reports may persist longer)
- Session replay data: individual Microsoft Clarity session recordings are retained for approximately 30 days; aggregated heatmap data for up to 13 months
- First-party engagement measurement: 13 months, then deleted. These records contain no cookie, no device identifier and no IP address (see "First-party engagement measurement" above)
- First-party session recordings: 30 days, then deleted automatically — shorter than the measurement records above, on purpose. They contain no cookie, no device identifier, no IP address, and nothing you typed into a form (see "Session recording" above)
- Answers to the one-question prompt: 13 months, then deleted. This is the only record here containing text you wrote yourself; we never ask for contact details in it (see "A one-question prompt" above)
- Form processing logs: operational logs from our Cloudflare form worker (submission type and sender address) are retained for 3 days
- Hosting and network logs: our website is statically hosted; access logs are maintained by our hosting and network providers (Render, Cloudflare) under their own published retention policies, and we do not separately retain server logs
When information is no longer needed, we securely delete or anonymize it.
7. Information security
As a security-focused company, we implement appropriate technical and organizational measures to protect personal information.
However, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, but we commit to notifying affected individuals and relevant authorities of any breach as required by applicable law.
8. Your privacy rights
Depending on your location, you may have the following rights regarding your personal information:
All users
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Opt-out: Opt out of marketing communications at any time
EEA, UK, and Swiss residents (GDPR)
In addition to the above, you have the right to:
- Portability: Receive your data in a structured, commonly used, machine-readable format
- Restriction: Request restriction of processing in certain circumstances
- Object: Object to processing based on legitimate interests
- Withdraw consent: Withdraw consent at any time where processing is based on consent
- Lodge a complaint: File a complaint with your local data protection authority
Cyberneza is a U.S. business with no establishment in the EEA or UK. We do not advertise into, or direct our services at, the EEA or the UK, so we do not believe the GDPR or UK GDPR applies to our processing of its own force, and we have not appointed a representative under Article 27 of either regulation. To the extent those regulations do not apply, we honor the rights above voluntarily as a matter of good practice. If that changes — if we begin marketing to or serving customers in the UK or the EEA — we will appoint a representative where required and update this policy before doing so.
Complaints: if you are in the United Kingdom you may complain to the Information Commissioner's Office (ICO). If you are in the EEA you may complain to your national supervisory authority, listed by the European Data Protection Board. In Switzerland, the authority is the Federal Data Protection and Information Commissioner (FDPIC). We would rather hear from you first at info@cyberneza.com, but you are not required to contact us before complaining.
California residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know: Request disclosure of the categories and specific pieces of personal information we have collected
- Right to delete: Request deletion of your personal information, subject to certain exceptions
- Right to correct: Request correction of inaccurate personal information
- Right to opt-out of sale/sharing: We do not sell personal information for money. Our use of Google and Microsoft advertising cookies may qualify as "sharing" for cross-context behavioral advertising — you can opt out at any time via Decline on the cookie banner, the Cookie Settings or Do Not Sell or Share My Info links in the footer, the Global Privacy Control browser signal (which we honor automatically), or by contacting us at the address below
- Right to limit use of sensitive personal information: We do not use or disclose sensitive personal information for purposes other than those permitted by the CPRA
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights
Categories of information collected in the past 12 months: Identifiers (name, email, IP address), internet activity information (browsing history on our site), and professional information (job title, company).
Notice at collection: the categories above, the purposes we use them for (section 4), how long we keep them (section 6), and the fact that we sell no personal information but may "share" it for cross-context behavioral advertising through the cookies in section 3, together make up our notice at collection. A short version of this notice also appears on every form on this site, at the point you submit your details.
To exercise your rights: Contact us at info@cyberneza.com. We will verify your identity before processing your request. You may use an authorized agent to submit a request on your behalf; we will ask the agent for proof of your written authorization and may ask you to confirm it directly.
Sensitive personal information and minors: we do not collect sensitive personal information as defined by the CPRA, and we do not sell or share the personal information of consumers we know to be under 16.
9. International data transfers
Cyberneza is based in the United States. If you access our website or services from outside the U.S., your information will be transferred to and processed in the United States.
For transfers from the EEA, UK, or Switzerland to the United States, we rely on the transfer safeguards maintained by our service providers:
- Data Privacy Framework: Google, Microsoft, and Cloudflare are certified under the EU-U.S. Data Privacy Framework (including the UK Extension and the Swiss-U.S. DPF)
- Standard Contractual Clauses (SCCs): our other service providers (including Calendly, Resend, and Render) incorporate EU-approved SCCs in their published data processing agreements
You may request more information about these safeguards by contacting us.
10. Third-party websites and services
Our site contains links to third-party websites and services, including Calendly for scheduling and various compliance framework resources. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies:
11. Children's privacy
Our website and services are not directed to children under 16 (or under 13 in the United States), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us immediately so we can delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Revise the "Last updated" date at the top of this page
- Provide notice on our website for significant changes
- Where required by law, obtain your consent to material changes
We encourage you to review this page periodically to stay informed about our practices.
Use of this website is separately governed by our Terms of Service.
13. How to contact us
If you have questions about this Privacy Policy, want to exercise your privacy rights, or have concerns about how we handle personal information, contact us at:
Cyberneza
626 North Alafaya Trail
Orlando, Florida 32828
United States
Email: info@cyberneza.com
Privacy inquiries response time: We aim to respond to all privacy-related inquiries within 5 business days.
