1. Overview
Cyntecian is a product of CTC International Marketing Management - FZCO ("CTC International Marketing Management - FZCO", "we", "us", or "our"), an AI operating system for creators, businesses and agencies. We take privacy seriously and are committed to protecting the personal information you share with us.
This Privacy Policy applies to information collected through cyntecian.com, our applications, APIs and related services (the "Services"). By using the Services you agree to the practices described here.
2. Who we are
CTC International Marketing Management - FZCO is the maker of Cyntecian and the controller of personal data processed about visitors to our website and account holders. For content and data you or your organisation upload into a workspace, you are the controller and CTC International Marketing Management - FZCO is the processor, acting on your documented instructions under our Data Processing Agreement.
3. Information we collect
We collect only what is needed to deliver, secure and improve the Services:
- Account information — name, email, avatar, password hash, organisation and role.
- Workspace content — files, messages, prompts, briefs, CRM entries and any content you or your team create in Cyntecian.
- Usage data — pages visited, features used, referrers, device and browser type, IP address, timestamps and diagnostic events.
- Integrations — tokens and metadata for tools you connect (e.g. email, storage, analytics). We request the narrowest scope needed.
- Support and communications — messages you send us, survey responses and feedback.
- Billing — company name, billing address and tax details. Card details are handled by our PCI-DSS certified payment processor; we never see or store full card numbers.
We do not knowingly collect special-category data (health, biometrics, political views, etc.). Please do not upload such data unless a specific feature requires it and the appropriate legal basis is in place.
4. How we use information
- Provide, operate and maintain the Services.
- Authenticate accounts and prevent fraud, abuse and security incidents.
- Deliver AI features you invoke, using the models and providers described in section 13.
- Bill you for paid plans and manage taxes and receipts.
- Respond to support requests and communicate about the Services.
- Improve product performance, reliability and design (using aggregated or de-identified data).
- Comply with law and enforce our agreements.
5. Legal bases for processing (GDPR)
Where GDPR or UK GDPR applies we rely on the following legal bases:
- Contract — to provide the Services you or your organisation subscribed to.
- Legitimate interests — to secure the Services, prevent abuse, and improve product quality, balanced against your rights.
- Consent — for non-essential cookies, marketing emails and optional integrations. You can withdraw consent at any time.
- Legal obligation — to comply with tax, accounting and law-enforcement obligations.
7. International data transfers
Cyntecian operates globally. Where personal data is transferred outside the EEA, UK or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with additional technical and organisational measures such as encryption in transit and at rest.
8. Data retention
We keep personal data only as long as necessary for the purposes described in this policy. Typical retention windows:
- Account data — for the life of your account, plus up to 90 days after deletion for backups.
- Workspace content — until you delete it or your organisation cancels; then removed from live systems within 30 days and from backups within 90 days.
- Billing records — retained for the period required by tax and accounting laws (typically 7–10 years).
- Security and access logs — up to 12 months.
9. Security
We follow industry best practices to protect your information, including:
- TLS 1.2+ for data in transit and AES-256 for data at rest.
- Row-level security so each workspace only sees its own data.
- Least-privilege access controls and multi-factor authentication for staff.
- Continuous vulnerability scanning, dependency auditing and code review.
- Isolated environments for development, staging and production.
- Incident-response procedures with prompt notification of affected users where required by law.
No system is perfectly secure. If you believe your account or our systems have been compromised, please contact us immediately at info@ctc-marketing.com.
10. Your privacy rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your personal data ('right to be forgotten').
- Restrict or object to certain processing.
- Port your data in a structured, machine-readable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data-protection authority.
Most of these rights can be exercised directly from your account settings. For anything else, email info@ctc-marketing.com and we will respond within 30 days.
11. California residents (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request deletion, to correct inaccurate information and to opt out of "sharing" for cross-context behavioural advertising. Cyntecian does not sell personal information and does not share it for cross-context behavioural advertising. To exercise any right, contact info@ctc-marketing.com. We will not discriminate against you for exercising your rights.
13. AI processing
When you use AI features, the prompts and content you submit are sent to model providers to generate a response. We select providers with strong privacy commitments and configure them so that:
- Your prompts and outputs are not used to train foundation models.
- Data is processed only to return the response you requested.
- Provider-side retention is limited to short abuse-monitoring windows or zero-retention where available.
A current list of AI subprocessors is available on request via info@ctc-marketing.com.
14. Children's privacy
Cyntecian is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
15. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes we will notify you by email or through the Services at least 30 days before they take effect. The "Last updated" date at the top always reflects the most recent revision.
16. Contact us
Questions, requests or complaints about this policy or your personal data:
CTC International Marketing Management - FZCO — Attn: Privacy Team, maker of Cyntecian. Reach us any time; we respond within 30 days.
This page is maintained by Cyntecian and describes our current practices. It is not a certification or independent audit. For our commercial terms, see the Terms of Service.