1. Who we are
Moduvia is a product of Cynest, Inc. (“Cynest”, “we”, “us”). This policy explains how we handle personal data for the Moduvia website, related marketing, and Moduvia services—including modules such as Privara, Deployr, Tracepoint, Grid, Guardrail, and Percept.
For GDPR purposes, Cynest, Inc. is typically the controller for website and account administration data. When you run Moduvia as Cynest-managed SaaS, we may also process customer content as a processor under your instructions and a data processing agreement. On air-gapped installs you control the environment; we only process what you send us for support or consulting.
2. What this covers
This policy applies to:
- Visitors to Moduvia marketing sites and pages we host
- People who contact Cynest about Moduvia (sales, support, consulting)
- Administrators and users of Cynest-managed Moduvia SaaS
- Limited personal data we receive when supporting air-gapped or on-prem deployments
Customer content is yours. Logs, models, repositories, telemetry, and surveillance media you put into Moduvia stay under your program’s rules. We don’t mine that content for advertising.
3. What we collect
Website and marketing
- Contact details you submit (name, work email, organization, phone, message)
- Technical data from your browser (IP address, user agent, referring URL, approximate location from IP)
- Cookie and similar identifiers if enabled (see Cookies)
SaaS accounts and operations
- Account profile data (name, email, role, organization)
- Authentication events and admin actions
- Service logs needed to run, secure, and troubleshoot the platform
- Billing and contract contacts when you buy from us
Air-gap / on-prem support
We don’t host your enclave by default. If you open a support case or consulting engagement, we only process the tickets, diagnostics, and artifacts you choose to share.
Sensitive / special-category data
We don’t ask website visitors for special-category data under GDPR. If a deployment processes such data (for example health or biometric content in a customer workload), that processing is governed by your policies and any DPA—not by this marketing site.
4. How we use data
- Respond to inquiries and schedule briefings
- Provide, secure, and improve Moduvia SaaS
- Authenticate users and enforce access controls (including Zero Trust patterns where configured)
- Meet security, audit, and legal obligations
- Send service or contract notices; marketing only where allowed (and you can opt out)
5. GDPR legal bases
Where the GDPR applies, we rely on:
- Contract — to deliver SaaS, support, or consulting you requested
- Legitimate interests — to secure our systems, prevent abuse, and understand how the marketing site is used (balanced against your rights)
- Consent — where required for optional cookies or marketing emails; you can withdraw anytime
- Legal obligation — when law requires retention or disclosure
For processor activity on SaaS customer content, the legal basis is usually yours as controller; we process under your instructions.
6. Sharing
We don’t sell personal data.
We may share data with:
- Infrastructure and security vendors that help us run SaaS (under contract and confidentiality)
- Professional advisors (legal, accounting) under duty of confidence
- Authorities when required by law or valid process
- A successor in a merger or asset transfer, with notice where required
Subprocessors for SaaS are listed in your order form or DPA. Ask your Cynest contact for the current list if you don’t have it.
7. International transfers
Cynest may process data in the United States and other countries where we or our providers operate. For GDPR-restricted transfers we use appropriate safeguards—such as Standard Contractual Clauses—unless another lawful mechanism applies.
8. Retention
We keep personal data only as long as needed for the purpose collected, then delete or anonymize it—unless a longer period is required for contracts, security investigations, or law.
- Marketing inquiries: typically up to 24 months after last meaningful contact, unless you ask us to delete sooner
- SaaS account data: for the subscription term plus a short wind-down window set in your agreement
- Security logs: for a limited operational window aligned to threat detection and audit needs
9. Security
We use administrative, technical, and physical controls appropriate to the risk—including encryption in transit and at rest on supported modes, access control, and monitoring. No method is perfect; if we learn of a breach affecting your personal data, we’ll notify you and regulators as required.
10. Your rights (GDPR and similar laws)
Depending on where you live, you may have the right to:
- Access your personal data
- Correct inaccurate data
- Erase data (in certain cases)
- Restrict or object to processing
- Data portability
- Withdraw consent where we rely on it
- Lodge a complaint with your supervisory authority
To exercise these rights, contact us using the details below. We’ll need to verify who you are first. If we process your data only as a processor for a Moduvia customer, we’ll route the request to that customer when appropriate.
EEA / UK residents: You can also contact your local data protection authority. For the UK, that’s the ICO; in the EU, the authority where you live or work.
11. Cookies and similar tech
The marketing site may use strictly necessary cookies to keep the site working. If we add analytics or preference cookies, we’ll explain them and request consent where the law requires it.
You can control cookies in your browser. Blocking some cookies may break parts of the site.
12. Children
Moduvia is a business platform. We don’t knowingly collect personal data from children under 16. If you think we have, contact us and we’ll delete it.
13. Changes
We may update this policy. The “Effective” date at the top will change when we do. Material updates for SaaS customers may also be called out in product or contract notices.
14. Contact
Privacy questions or GDPR requests:
Cynest, Inc. — Attn: Privacy / Moduvia
Prefer email via your Cynest account team, or use the contact path on
cynest.com.
For SaaS DPA or subprocessors, ask your Cynest commercial contact.