What we collect
We collect the information you choose to send us, such as your name, email address, company, role, message content, meeting details, and any context you provide about a project or inquiry.
Hosting and security systems may also process technical information such as IP address, browser metadata, requested URLs, timestamps, and basic diagnostic logs.
How we use it
- To respond to inquiries and schedule introductory conversations.
- To understand whether Cynsta can help with a project, product, governance, or research need.
- To operate, secure, debug, and improve the public website.
- To keep appropriate business records when a conversation becomes a commercial relationship.
Cookie-free aggregate analytics and third parties
The public website uses Vercel Web Analytics to count aggregate page views and understand landing pages, referrers, and campaign parameters. Vercel describes this service as cookie-free and based on anonymized, daily-reset visitor hashes. Cynsta does not use this data to follow a person across websites or days, and the site does not run advertising or behavioral-tracking pixels.
The language selector uses stable English and Czech URLs and does not set a language cookie. See Vercel's Web Analytics privacy documentation for the provider's current data description.
When you choose to schedule a call, you leave this website and open Cal.com. Cal.com may process scheduling details and set its own cookies under its own policies. External links to GitHub, LinkedIn, and X also operate under their own policies.
Product security
Customer deployments are designed around the sensitivity of the workflow and the environment already in place.
- Run locally, on premises, in a private cloud, or inside a customer-managed cloud account.
- Keep documents, access controls, keys, logs, and reviewer records inside the approved environment.
- Use hosted models only when the workflow permits it, with the payload minimized or masked before transfer.
- Require human approval for consequential releases and preserve the history behind each decision.
Compare the options in our private AI deployment guide.
Shared responsibility
- Every project names who owns identity, patching, backups, monitoring, incidents, and physical security.
- If a hosted provider is selected, its service tier, contract, retention, training, and location settings become part of the design.
- Automated validation and operating records support oversight; important outputs still need the review appropriate to their risk.
Retention and sharing
We keep inquiry and scheduling information only as long as needed for the conversation, security, legal, operational, or business record purposes. We do not sell personal information.
We may share information with service providers that help us host the website, operate email, schedule meetings, manage business records, or protect our systems.
Security
We use HTTPS, access controls, minimal public-site dependencies, and private operational practices to reduce exposure. Public website content is separate from customer project environments and internal case material.
No public website can guarantee perfect security. If you believe you found a vulnerability or accidentally exposed sensitive information, contact us at
hello@cynsta.com.
Your choices
You can ask us to access, correct, or delete personal information you sent through the public website, subject to legal and operational limits. Email
hello@cynsta.com
and we will respond as reasonably as we can.