Platform
Solutions
Resources
Company
Platform
Solutions
Resources
Company

Privacy Policy

1. Identity of the data controller

The data controller responsible for the personal data collected through this website is:


  • Company name: DeepSafe SAS

  • Legal form: Simplified joint-stock company (SAS) incorporated under French law

  • Registered address: 60 rue François 1er, 75008 Paris, France

  • SIREN: 941 975 195

  • Data protection contact: contact@cynapze.com


DeepSafe SAS operates the website accessible at www.cynapze.com (the "Site") and publishes the Cynapze platform under the same brand.

2. Scope

This Privacy Policy applies exclusively to personal data processed in connection with your use of the Site (www.cynapze.com). It does not govern data processed within the Cynapze platform, which is subject to the terms agreed between DeepSafe SAS and subscribing organizations.This Privacy Policy applies exclusively to personal data processed in connection with your use of the Site (www.cynapze.com). It does not govern data processed within the Cynapze platform, which is subject to the terms agreed between DeepSafe SAS and subscribing organizations.


This policy is issued pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “GDPR”) and the French Act No. 78-17 of 6 January 1978 on data processing, data files and individual liberties (“Loi Informatique et Libertés”), as amended.

3. Data collected

3.1 Data you provide to us


When you interact with the Site, you may provide personal data to us directly, including when you:


  • Submit a contact, demo or information request form: first name, last name, professional email address, company name, job title, telephone number (optional), and the content of your message

  • Subscribe to our newsletter or other communications: professional email address and, where provided, first name

  • Schedule a meeting via our booking tool: first name, last name, professional email address, and your availability

Fields marked as mandatory on each form are those strictly required for processing your request. You are under no legal obligation to provide your personal data; however, failure to provide mandatory fields will prevent us from processing your request.


3.2 Data collected automatically

When you visit the Site, certain technical data is collected automatically by our servers and, subject to your cookie preferences, by the tracking technologies we use. This includes:


  • IP address and derived approximate geolocation (country and city level)

  • Browser type, version and language

  • Device type and operating system

  • Referring URL and exit pages

  • Pages visited, time spent on each page, and navigation paths

  • Date and time of access


Detailed information on the tracking technologies used is set out in our Cookie Policy.

4. Purposes and legal bases

We process your personal data only where we have a lawful basis to do so. The table below sets out each processing purpose and the corresponding legal basis under Article 6 of the GDPR.


Purpose / Data involved / Legal basis (Art. 6 GDPR)

  • Responding to contact, demo and information requests: Identification and contact data, message content. Legitimate interest (Art. 6(1)(f)) , specifically taking steps prior to entering into a contract

  • Sending commercial communications (newsletter) : Professional email address, first name. Consent (Art. 6(1)(a))

  • Scheduling meetings via booking tool : Name, email address, availability. Legitimate interest (Art. 6(1)(f)) , pre-contractual steps

  • Website analytics and performance measurement : Technical and navigational data. Consent (Art. 6(1)(a)) , collected via cookie preferences

  • Marketing attribution and retargeting : Technical and behavioural data. Consent (Art. 6(1)(a)) , collected via cookie preferences

  • Ensuring the security and proper functioning of the Site : Technical connection data, IP address. Legitimate interest (Art. 6(1)(f)) , protection against unauthorized access and abuse

  • Compliance with legal obligations : As required by applicable law. Legal obligation (Art. 6(1)(c))


Where processing is based on our legitimate interest, we have conducted a balancing test and determined that our interest does not override your fundamental rights and freedoms. You may request information about this balancing test by contacting us at contact@cynapze.com.


We do not carry out automated decision-making or profiling within the meaning of Article 22 of the GDPR.

5. Recipients

We do not sell, rent or trade your personal data to third parties. Your data may be disclosed to the following categories of recipients, solely for the purposes described in Section 4:


  • Hosting and infrastructure providers, whose infrastructure is located within the European Union

  • Customer relationship management (CRM) and email communication tools, used to manage and respond to contact requests and commercial communications

  • Meeting scheduling tools (including Calendly), used to coordinate demo sessions

  • Web analytics providers, subject to prior consent (see Cookie Policy)

  • Advertising and marketing platforms, subject to prior consent (see Cookie Policy)

  • Legal, accounting and professional advisors, where disclosure is necessary for the exercise or defense of legal claims or compliance obligations

  • Judicial or administrative authorities, where required by applicable law or court order


All third-party processors are bound by data processing agreements in compliance with Article 28 of the GDPR and are authorized to process your data only on our documented instructions, for the specified purposes, and subject to appropriate confidentiality and security obligations.

6. International transfers

The Site is hosted on infrastructure located within the European Economic Area (EEA). Some of the third-party tools we use (including analytics and marketing platforms) may transfer personal data to countries outside the EEA, in particular to the United States.


Where such transfers occur, we ensure that they are subject to appropriate safeguards in accordance with Chapter V of the GDPR, including:


  • Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Article 46(2)(c) of the GDPR

  • An adequacy decision by the European Commission pursuant to Article 45 of the GDPR, where applicable


You may obtain information about the specific safeguards applicable to any given transfer by contacting us at contact@cynapze.com.

7. Retention periods

We retain personal data only for as long as necessary for the purpose for which it was collected, and in compliance with applicable legal obligations. The following retention periods apply:


Category of data / Retention period

  • Contact, demo and information requests : 3 years from the date of your last interaction with us

  • Newsletter and commercial communications : Until you withdraw consent or unsubscribe; thereafter, suppression list retained for 3 years to avoid re-contact

  • Meeting scheduling data : 3 years from the date of the scheduled meeting

  • Website analytics data : As configured per tool (maximum 13 months for standard analytics cookies)

  • Technical connection logs : 12 months from the date of connection, in accordance with French legal obligations (Article L. 34-1 of the Code des postes et des communications électroniques)

  • Cookie consent records : 6 years (limitation period under French civil law)


At the end of the applicable retention period, personal data is either deleted or anonymized.

8. Your rights

Pursuant to Articles 15 to 22 of the GDPR and the French Loi Informatique et Libertés, you have the following rights with respect to your personal data:


  • Right of access (Art. 15 GDPR): the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of the data and information about how it is processed

  • Right to rectification (Art. 16 GDPR): the right to request correction of inaccurate or incomplete personal data

  • Right to erasure (Art. 17 GDPR): the right to request deletion of your personal data where certain conditions are met, including where the data is no longer necessary for the purposes for which it was collected

  • Right to restriction of processing (Art. 18 GDPR): the right to request that we temporarily limit the processing of your personal data in certain circumstances

  • Right to data portability (Art. 20 GDPR): the right to receive personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller, where processing is based on consent or a contract and is carried out by automated means

  • Right to object (Art. 21 GDPR): the right to object at any time to processing based on our legitimate interest, or to processing for direct marketing purposes

  • Right to withdraw consent (Art. 7(3) GDPR): the right to withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal

  • Right to define post-mortem instructions: pursuant to Article 85 of the French Loi Informatique et Libertés, you have the right to define instructions regarding the fate of your personal data after your death


To exercise any of the above rights, please send a written request to contact@cynapze.com. Where required by applicable law, we may ask you to provide proof of identity before processing your request. We will respond within one month of receiving your request. In cases of complexity or high volume, this period may be extended by a further two months, in which case we will inform you accordingly.


If you consider that the processing of your personal data constitutes a breach of applicable data protection law, you have the right to lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL), the French supervisory authority, at the following address:


  • CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07

  • Website: www.cnil.fr

You may also lodge a complaint with any other competent supervisory authority in the European Union where you are habitually resident or where the alleged infringement occurred.

9. Security

DeepSafe SAS implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. These measures include, without limitation:


  • Encryption of data in transit using TLS (Transport Layer Security)

  • Access control measures limiting access to personal data to authorized personnel on a need-to-know basis

  • Regular review of security practices and procedures

  • Use of subprocessors subject to equivalent security obligations


In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify you in accordance with Article 34 of the GDPR, without undue delay.

10. Minors

The Site and the Cynapze platform are intended exclusively for professional use. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have inadvertently collected personal data from a minor, we will take steps to delete that data as soon as reasonably practicable. If you have reason to believe that a minor has provided us with personal data, please contact us at contact@cynapze.com.

11. Updates

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or operational requirements. The effective date and last updated date at the top of this document will be revised accordingly.


We encourage you to review this policy periodically. Where changes are material, we will take reasonable steps to bring them to your attention, including where appropriate by placing a notice on the Site.

12. Contact

For any questions, requests or concerns relating to this Privacy Policy or the processing of your personal data, please contact us:


  • By email: contact@cynapze.com

  • By post: DeepSafe SAS, Data Protection, 60 rue François 1er, 75008 Paris, France

Vendor intelligence

for the threats that matter

With Cynapze, companies monitor their vendor ecosystem continuously,
meet regulatory requirements with confidence, and scale without losing visibility.

Copyright ©2026 Cynpaze. All rights reserved.

Vendor intelligence

for the threats that matter

Copyright ©2026 Cynpaze. All rights reserved.