The short version
This site has no forms. We collect what you choose to put in an email to us, and — only if you agree — anonymised analytics about which pages get read. Server logs happen automatically and are kept briefly for security.
We do not sell your data. We do not share it with advertisers. We do not build profiles, run retargeting, or load third-party trackers. If you decline analytics, this site stores nothing on your device at all.
Who is responsible
Cynodes LLC is the data controller for this website. Our mailing address is 418 Broadway #12117, Albany, NY 12207, USA. For any privacy question or request, email privacy@cynodes.com.
What we collect, and why
That is the complete list. This site has no form, no login, and no way to collect payment details, government identifiers, health information, or any other special category of data. Please do not send those to us by email either — we will arrange a secure channel when one is needed.
| Data | Why | Lawful basis (GDPR) | Kept for |
|---|---|---|---|
| Email you send us: your address, your name and company if you give them, and whatever you write | To answer you and, if it becomes a commercial conversation, to keep a record of it | Legitimate interest — you wrote to us; and steps toward a contract | Up to 24 months from last contact, then deleted |
| Server logs: IP address, timestamp, page requested, user agent | Keeping the site up and detecting abuse of it | Legitimate interest — security of our own service | 30 days |
| Analytics: pages viewed, approximate region, device type, truncated IP | Understanding which pages are useful so we write better ones | Consent — and only consent. Nothing loads until you say yes | 14 months (Google Analytics default retention) |
What we deliberately do not do
- We do not sell or rent personal information, and never have.
- We do not share it with advertising networks or data brokers.
- We do not use it to train machine-learning models.
- We do not run advertising pixels, social widgets, session recorders, or heatmaps.
- We do not attempt to identify individual visitors from analytics data.
- We do not track you across other websites.
Who else touches it
We keep the list of processors as short as we can, because every additional one is another place your data can go wrong.
- Hostinger — hosting and email. Our mailboxes and server logs live on their infrastructure. Bound by their data processing terms.
- Google Analytics — only if you accepted analytics cookies. IP addresses are truncated before storage, Google Signals and ad personalisation are switched off, and the data is not linked to advertising.
If we later add a CRM or helpdesk, this list will be updated before that system receives any data.
Where your data goes
We are a US company and our hosting is US-based, so data you send us is processed in the United States. For visitors in the UK, EEA, or Switzerland, that is an international transfer; we rely on Standard Contractual Clauses with our processors, and on your explicit action in choosing to contact us.
Your rights
Wherever you live, we will honour the following. We do not require you to prove residency in a particular place to exercise them, because operating two standards of care would be worse than operating one.
- Access — ask what we hold about you, and get a copy.
- Correction — have inaccurate details fixed.
- Deletion — have your data erased. For a contact enquiry this is almost always immediate and unconditional.
- Restriction and objection — tell us to stop a particular use, including any processing based on legitimate interest.
- Portability — receive what you gave us in a machine-readable form.
- Withdraw consent — turn analytics off at any time, from the link in our footer. Withdrawing is as easy as granting.
- Non-discrimination — exercising any of these changes nothing about how we treat you as a client or prospect.
Email privacy@cynodes.com and we will respond within 30 days, usually much sooner. If you are in the EEA or UK you also have the right to complain to your national data protection authority; we would rather you told us first so we can fix it.
California residents
Under the CCPA as amended by the CPRA: in the past 12 months we have collected identifiers (name, email, optional phone) and internet activity information, from you directly and from your use of this site, for the business purposes described above.
We have not sold personal information, and we have not shared it for cross-context behavioural advertising. Because we do not do either, there is no "Do Not Sell or Share My Personal Information" mechanism to offer you — the absence of one here is the honest answer, not an omission. You retain the rights to know, delete, correct, and to be free from discrimination for exercising them.
How we protect it
We are a security company, so it would be a poor look to be careless with this. Concretely: the site is served over HTTPS only, with HSTS. A strict Content Security Policy is enforced. The contact endpoint validates and sanitises every field, rate-limits submissions, checks request origin, and strips anything that could forge a log entry or inject a mail header. Errors never return internal details. The application runs with no database and no file uploads, which removes whole categories of risk rather than mitigating them.
No system is perfect. If you find a weakness in ours, security@cynodes.com — we respond to every report and will not pursue good-faith researchers.
Children
This is a business-to-business site and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has sent us information, email privacy@cynodes.com and we will delete it.
Changes
If we change what we collect or why, we will update this page and change the date at the top. Material changes to how we use data you have already given us will be notified by email where we hold one for you.