Draft

Privacy Policy

Last updated 30 July 2026

This Privacy Policy explains how Cipher Inc. ("Cipher", "we", "us") collects, uses, discloses, and safeguards personal data when you visit our websites, create an account, or use the Cipher platform (together, the "Services").

1. Scope

This policy covers personal data we handle as a controller — primarily data about our customers' administrators and users, website visitors, and prospective customers.

Where our customers upload or generate content within the Services, we handle that content as a processor on the customer's instructions. In that case the customer's own privacy notice governs, and our obligations are set out in the applicable Data Processing Addendum rather than here.

2. Information we collect

2.1 Information you provide

2.2 Information collected automatically

2.3 Information from third parties

We may receive data from identity providers you use to sign in, from our resellers and partners, and from publicly available business sources used for prospecting.

3. How we use information

4. Legal bases for processing

Where the GDPR or equivalent legislation applies, we rely on the following legal bases:

5. Sharing and disclosure

We do not sell personal data. We disclose it only as follows:

A current list of subprocessors is available on request.

6. International transfers

We may process personal data in countries other than the one in which it was collected. Where data is transferred out of the UK, EEA, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses together with any supplementary measures the transfer requires.

7. Retention

We retain personal data for as long as needed to provide the Services and for a reasonable period afterwards to meet legal, accounting, audit, and dispute resolution requirements. Account data is generally deleted or de-identified within a defined period following termination, subject to backups being purged on their ordinary cycle. Customer content is retained and deleted in accordance with the customer agreement.

8. Security

We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, least-privilege administrative access, network segmentation, logging and monitoring, secure development practices, and periodic independent testing. No system can be guaranteed completely secure, and you are responsible for safeguarding your account credentials.

9. Cookies and similar technologies

We use strictly necessary cookies to operate the Services — for example to keep you signed in and to protect against cross-site request forgery. Where we use analytics or preference cookies, we request consent first where the law requires it. You can control cookies through your browser settings, though disabling strictly necessary cookies will prevent parts of the Services from functioning.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal data; to object to or restrict certain processing; to withdraw consent; and to complain to a supervisory authority.

Residents of certain US states may additionally have the right to know what personal data is collected and to opt out of its sale or sharing — noting that we do not sell personal data. We will not discriminate against you for exercising any of these rights.

To exercise a right, contact us using the details in section 13. We may need to verify your identity before acting. If your data is held by us on a customer's behalf, we will refer your request to that customer.

11. Children

The Services are business tools intended for use by organisations. They are not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. Material changes will be notified through the Services or by email before they take effect, and the "last updated" date above will always reflect the current version.

13. Contact

Questions, requests, and complaints can be sent to privacy@cipher-inc.com, or by post to Cipher Inc., Attn: Privacy, at our registered office address.