Privacy Policy
Table of contents
1. Identity of the data controller
2. Scope
3. Data collected
4. Purposes and legal bases
5. Recipients
6. International transfers
7. Retention periods
8. Your rights
9. Security
10. Minors
11. Updates
12. Contact
1. Identity of the data controller
The data controller responsible for the personal data collected through this website is:
Company name: DeepSafe SAS
Legal form: Simplified joint-stock company (SAS) incorporated under French law
Registered address: 60 rue François 1er, 75008 Paris, France
SIREN: 941 975 195
Data protection contact: contact@cynapze.com
DeepSafe SAS operates the website accessible at www.cynapze.com (the "Site") and publishes the Cynapze platform under the same brand.
2. Scope
This Privacy Policy applies exclusively to personal data processed in connection with your use of the Site (www.cynapze.com). It does not govern data processed within the Cynapze platform, which is subject to the terms agreed between DeepSafe SAS and subscribing organizations.This Privacy Policy applies exclusively to personal data processed in connection with your use of the Site (www.cynapze.com). It does not govern data processed within the Cynapze platform, which is subject to the terms agreed between DeepSafe SAS and subscribing organizations.
This policy is issued pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “GDPR”) and the French Act No. 78-17 of 6 January 1978 on data processing, data files and individual liberties (“Loi Informatique et Libertés”), as amended.
3. Data collected
3.1 Data you provide to us
When you interact with the Site, you may provide personal data to us directly, including when you:
Submit a contact, demo or information request form: first name, last name, professional email address, company name, job title, telephone number (optional), and the content of your message
Subscribe to our newsletter or other communications: professional email address and, where provided, first name
Schedule a meeting via our booking tool: first name, last name, professional email address, and your availability
Fields marked as mandatory on each form are those strictly required for processing your request. You are under no legal obligation to provide your personal data; however, failure to provide mandatory fields will prevent us from processing your request.
3.2 Data collected automatically
When you visit the Site, certain technical data is collected automatically by our servers and, subject to your cookie preferences, by the tracking technologies we use. This includes:
IP address and derived approximate geolocation (country and city level)
Browser type, version and language
Device type and operating system
Referring URL and exit pages
Pages visited, time spent on each page, and navigation paths
Date and time of access
Detailed information on the tracking technologies used is set out in our Cookie Policy.
4. Purposes and legal bases
We process your personal data only where we have a lawful basis to do so. The table below sets out each processing purpose and the corresponding legal basis under Article 6 of the GDPR.
Purpose / Data involved / Legal basis (Art. 6 GDPR)
Responding to contact, demo and information requests: Identification and contact data, message content. Legitimate interest (Art. 6(1)(f)) , specifically taking steps prior to entering into a contract
Sending commercial communications (newsletter) : Professional email address, first name. Consent (Art. 6(1)(a))
Scheduling meetings via booking tool : Name, email address, availability. Legitimate interest (Art. 6(1)(f)) , pre-contractual steps
Website analytics and performance measurement : Technical and navigational data. Consent (Art. 6(1)(a)) , collected via cookie preferences
Marketing attribution and retargeting : Technical and behavioural data. Consent (Art. 6(1)(a)) , collected via cookie preferences
Ensuring the security and proper functioning of the Site : Technical connection data, IP address. Legitimate interest (Art. 6(1)(f)) , protection against unauthorized access and abuse
Compliance with legal obligations : As required by applicable law. Legal obligation (Art. 6(1)(c))
Where processing is based on our legitimate interest, we have conducted a balancing test and determined that our interest does not override your fundamental rights and freedoms. You may request information about this balancing test by contacting us at contact@cynapze.com.
We do not carry out automated decision-making or profiling within the meaning of Article 22 of the GDPR.
5. Recipients
We do not sell, rent or trade your personal data to third parties. Your data may be disclosed to the following categories of recipients, solely for the purposes described in Section 4:
Hosting and infrastructure providers, whose infrastructure is located within the European Union
Customer relationship management (CRM) and email communication tools, used to manage and respond to contact requests and commercial communications
Meeting scheduling tools (including Calendly), used to coordinate demo sessions
Web analytics providers, subject to prior consent (see Cookie Policy)
Advertising and marketing platforms, subject to prior consent (see Cookie Policy)
Legal, accounting and professional advisors, where disclosure is necessary for the exercise or defense of legal claims or compliance obligations
Judicial or administrative authorities, where required by applicable law or court order
All third-party processors are bound by data processing agreements in compliance with Article 28 of the GDPR and are authorized to process your data only on our documented instructions, for the specified purposes, and subject to appropriate confidentiality and security obligations.
6. International transfers
The Site is hosted on infrastructure located within the European Economic Area (EEA). Some of the third-party tools we use (including analytics and marketing platforms) may transfer personal data to countries outside the EEA, in particular to the United States.
Where such transfers occur, we ensure that they are subject to appropriate safeguards in accordance with Chapter V of the GDPR, including:
Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Article 46(2)(c) of the GDPR
An adequacy decision by the European Commission pursuant to Article 45 of the GDPR, where applicable
You may obtain information about the specific safeguards applicable to any given transfer by contacting us at contact@cynapze.com.
7. Retention periods
We retain personal data only for as long as necessary for the purpose for which it was collected, and in compliance with applicable legal obligations. The following retention periods apply:
Category of data / Retention period
Contact, demo and information requests : 3 years from the date of your last interaction with us
Newsletter and commercial communications : Until you withdraw consent or unsubscribe; thereafter, suppression list retained for 3 years to avoid re-contact
Meeting scheduling data : 3 years from the date of the scheduled meeting
Website analytics data : As configured per tool (maximum 13 months for standard analytics cookies)
Technical connection logs : 12 months from the date of connection, in accordance with French legal obligations (Article L. 34-1 of the Code des postes et des communications électroniques)
Cookie consent records : 6 years (limitation period under French civil law)
At the end of the applicable retention period, personal data is either deleted or anonymized.
8. Your rights
Pursuant to Articles 15 to 22 of the GDPR and the French Loi Informatique et Libertés, you have the following rights with respect to your personal data:
Right of access (Art. 15 GDPR): the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of the data and information about how it is processed
Right to rectification (Art. 16 GDPR): the right to request correction of inaccurate or incomplete personal data
Right to erasure (Art. 17 GDPR): the right to request deletion of your personal data where certain conditions are met, including where the data is no longer necessary for the purposes for which it was collected
Right to restriction of processing (Art. 18 GDPR): the right to request that we temporarily limit the processing of your personal data in certain circumstances
Right to data portability (Art. 20 GDPR): the right to receive personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller, where processing is based on consent or a contract and is carried out by automated means
Right to object (Art. 21 GDPR): the right to object at any time to processing based on our legitimate interest, or to processing for direct marketing purposes
Right to withdraw consent (Art. 7(3) GDPR): the right to withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal
Right to define post-mortem instructions: pursuant to Article 85 of the French Loi Informatique et Libertés, you have the right to define instructions regarding the fate of your personal data after your death
To exercise any of the above rights, please send a written request to contact@cynapze.com. Where required by applicable law, we may ask you to provide proof of identity before processing your request. We will respond within one month of receiving your request. In cases of complexity or high volume, this period may be extended by a further two months, in which case we will inform you accordingly.
If you consider that the processing of your personal data constitutes a breach of applicable data protection law, you have the right to lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL), the French supervisory authority, at the following address:
CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
Website: www.cnil.fr
You may also lodge a complaint with any other competent supervisory authority in the European Union where you are habitually resident or where the alleged infringement occurred.
9. Security
DeepSafe SAS implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. These measures include, without limitation:
Encryption of data in transit using TLS (Transport Layer Security)
Access control measures limiting access to personal data to authorized personnel on a need-to-know basis
Regular review of security practices and procedures
Use of subprocessors subject to equivalent security obligations
In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify you in accordance with Article 34 of the GDPR, without undue delay.
10. Minors
The Site and the Cynapze platform are intended exclusively for professional use. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have inadvertently collected personal data from a minor, we will take steps to delete that data as soon as reasonably practicable. If you have reason to believe that a minor has provided us with personal data, please contact us at contact@cynapze.com.
11. Updates
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or operational requirements. The effective date and last updated date at the top of this document will be revised accordingly.
We encourage you to review this policy periodically. Where changes are material, we will take reasonable steps to bring them to your attention, including where appropriate by placing a notice on the Site.
12. Contact
For any questions, requests or concerns relating to this Privacy Policy or the processing of your personal data, please contact us:
By email: contact@cynapze.com
By post: DeepSafe SAS, Data Protection, 60 rue François 1er, 75008 Paris, France


