CyberTwin
Legal · Effective January 2026

Privacy Policy

This policy describes how CyberTwin (“we”, “us”) handles personal data when you use our web app, marketing site, or API. We treat this document as a contract — if any line is unclear, write to privacy@cybertwin.io and we will clarify in writing.

What we collect

  • Account data: name, email, organization, role.
  • Environment data: the structured profile you submit through the intake wizard, document uploads, and the structured output our engine produces.
  • Integration data: CyberTwin is upload-based today. Should we later offer read-only API integrations, we would pull only the minimum-scope data described on our Trust & security page.
  • Operational data: sign-in events, audit-log entries, billing events from our payment processor (Polar).
  • Marketing-site data: conversion events on the marketing site (which call-to-action was used) sent to our own server with no identity attached; PostHog product analytics (EU Cloud) on marketing pages — page views and interaction events, kept under a first-party analytics cookie and browser storage; and the LinkedIn Insight Tag on marketing pages for advertising attribution — a third-party cookie. Both tags are described under Cookies below. The signed-in app loads neither: no advertising or analytics tags inside the product.

Why we collect it

  • To deliver the recommendation engine you are paying for (legitimate interest, contractual necessity).
  • To bill you (contractual necessity).
  • To meet our security and audit obligations (legal obligation).
  • To send transactional email related to your account (contractual necessity).
  • To send marketing email only if you opt in (consent).

How we protect it

Data is encrypted at rest by the cloud provider and in transit via TLS 1.2 or higher. Any integration credential we hold (CyberTwin is upload-based today; read-only integrations are not live) is encrypted at rest with a server-side key (AES-256-GCM). Region-pinned data residency is available on Enterprise — contact us to scope it for your organisation.

Who we share it with

Only our subprocessors, listed on our Trust & security page. We notify customers in writing before adding a subprocessor.

How long we keep it

  • Active account data: while your account is active.
  • Environment data: while your account is active; after cancellation, the account is read-only for 90 days so you can export, data is retained a further 90 days for re-activation, then deleted — 180 days total. (See the cancellation terms for the full timeline.)
  • Audit logs: 12 months.
  • Billing records: 7 years (tax retention requirements).

Your rights

If you are in the EU/UK, GCC, California, or any jurisdiction whose privacy law gives you specific rights, you can request access, correction, deletion, or portability. Email privacy@cybertwin.io; we respond within 30 days.

Cookies

Strictly necessary cookies for authentication and session in the app. On marketing pages, and only there, we load two tags. PostHog (EU Cloud) product analytics sets a first-party analytics cookie and uses browser storage to recognise a returning browser across marketing pages and to count page views and interactions. The LinkedIn Insight Tag sets a LinkedIn cookie used to measure whether a LinkedIn ad led to a visit or a signup; LinkedIn's opt-out is at linkedin.com/psettings/guest-controls/retargeting-opt-out, and browsers that block third-party cookies block it entirely. Neither tag loads inside the signed-in app, which sets session cookies only. We set no other analytics or advertising cookies.

Children

Not directed at children under 16. We do not knowingly collect data from them.

Changes

We update this policy when our practices change. Material changes are emailed to org Owners with at least 14 days notice. Old versions are linked here.

Contact

Privacy team: privacy@cybertwin.io
Security disclosure: security@cybertwin.io