This Privacy Policy explains how Cipher Inc. ("Cipher", "we", "us") collects, uses, discloses, and safeguards personal data when you visit our websites, create an account, or use the Cipher platform (together, the "Services").
1. Scope
This policy covers personal data we handle as a controller — primarily data about our customers' administrators and users, website visitors, and prospective customers.
Where our customers upload or generate content within the Services, we handle that content as a processor on the customer's instructions. In that case the customer's own privacy notice governs, and our obligations are set out in the applicable Data Processing Addendum rather than here.
2. Information we collect
2.1 Information you provide
- Account data — name, business email address, employer, job title, and authentication credentials.
- Billing data — billing contact, address, and tax details. Card details are collected and stored by our payment processor, not by us.
- Support data — the contents of support requests and any files or logs you choose to attach.
- Marketing data — details you submit through contact, demo-request, or newsletter forms.
2.2 Information collected automatically
- Usage data — features accessed, actions taken, and timestamps, used to operate and improve the Services.
- Device and connection data — IP address, browser type and version, operating system, and referring pages.
- Log data — application, security, and audit logs generated when you interact with the Services.
- Cookies and similar technologies — see section 9.
2.3 Information from third parties
We may receive data from identity providers you use to sign in, from our resellers and partners, and from publicly available business sources used for prospecting.
3. How we use information
- To provide, maintain, secure, and improve the Services.
- To authenticate users and administer accounts and entitlements.
- To provide support and respond to enquiries.
- To process payments and manage billing.
- To monitor for, investigate, and prevent fraud, abuse, and security incidents.
- To send service and security notices, and — where permitted — relevant marketing communications you may opt out of at any time.
- To produce aggregated or de-identified analytics that do not identify any individual.
- To comply with legal obligations and enforce our agreements.
4. Legal bases for processing
Where the GDPR or equivalent legislation applies, we rely on the following legal bases:
- Contract — to provide the Services you or your employer have contracted for.
- Legitimate interests — to secure and improve the Services, prevent abuse, and conduct business-to-business marketing, balanced against your rights and freedoms.
- Legal obligation — to meet regulatory requirements.
- Consent — where required, for example for certain cookies and marketing. You may withdraw consent at any time.
5. Sharing and disclosure
We do not sell personal data. We disclose it only as follows:
- Service providers and subprocessors — cloud hosting, payment processing, analytics, communications, and support tooling, each bound by contract to process data only on our instructions.
- Within your organisation — account administrators can view usage and audit information for users under their tenancy.
- Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, subject to equivalent protections.
- Legal and safety — where required by law, or to protect the rights, property, or safety of Cipher, our customers, or the public.
A current list of subprocessors is available on request.
6. International transfers
We may process personal data in countries other than the one in which it was collected. Where data is transferred out of the UK, EEA, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses together with any supplementary measures the transfer requires.
7. Retention
We retain personal data for as long as needed to provide the Services and for a reasonable period afterwards to meet legal, accounting, audit, and dispute resolution requirements. Account data is generally deleted or de-identified within a defined period following termination, subject to backups being purged on their ordinary cycle. Customer content is retained and deleted in accordance with the customer agreement.
8. Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, least-privilege administrative access, network segmentation, logging and monitoring, secure development practices, and periodic independent testing. No system can be guaranteed completely secure, and you are responsible for safeguarding your account credentials.
9. Cookies and similar technologies
We use strictly necessary cookies to operate the Services — for example to keep you signed in and to protect against cross-site request forgery. Where we use analytics or preference cookies, we request consent first where the law requires it. You can control cookies through your browser settings, though disabling strictly necessary cookies will prevent parts of the Services from functioning.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal data; to object to or restrict certain processing; to withdraw consent; and to complain to a supervisory authority.
Residents of certain US states may additionally have the right to know what personal data is collected and to opt out of its sale or sharing — noting that we do not sell personal data. We will not discriminate against you for exercising any of these rights.
To exercise a right, contact us using the details in section 13. We may need to verify your identity before acting. If your data is held by us on a customer's behalf, we will refer your request to that customer.
11. Children
The Services are business tools intended for use by organisations. They are not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified through the Services or by email before they take effect, and the "last updated" date above will always reflect the current version.
13. Contact
Questions, requests, and complaints can be sent to privacy@cipher-inc.com, or by post to Cipher Inc., Attn: Privacy, at our registered office address.