Privacy & cookie policy
Last updated: [insert date] · Version 1
This policy explains how Cynthian Digital Innovations (“CDI”, “we”) processes personal data collected through this website, under Regulation (EU) 2016/679 (GDPR) and the applicable national ePrivacy rules. Company identification is in the legal notice.
1. Controller and contact
Cynthian Digital Innovations
Registered office: [insert registered address]
Tax identification number: [insert NIPC/VAT number]
Privacy contact: info@cynthiandigital.com
Data protection officer: [insert DPO name and contact, or state that no DPO is required]
2. What we process, why, and on what basis
2.1 Contact and demo forms
Fields you fill in: name, email, and — on the demo form — job title, company, industry, company size, phone number and country; plus the message you write.
- Purpose: answering your enquiry and, where relevant, preparing a demonstration.
- Legal basis: steps taken at your request before entering a contract (Art. 6(1)(b) GDPR); for enquiries that are not pre-contractual, our legitimate interest in responding to business contacts (Art. 6(1)(f)).
- Recipients: our commercial team and our email provider. [insert CRM, if one is used]
- Retention: [insert period, e.g. 24 months] from the last contact, unless a contract is signed — in which case the contractual and legal retention periods apply.
- Obligation to provide: none. Name, email and (on the contact form) a message are required only because without them we cannot reply.
2.2 Anti-spam
Our forms use a hidden field and a minimum fill time, and — once configured — Google reCAPTCHA v3. reCAPTCHA processes your IP address, browser data and interaction signals to produce a risk score.
- Legal basis: legitimate interest in preventing abuse of our forms (Art. 6(1)(f) GDPR).
- Recipient: Google Ireland Ltd. and Google LLC.
- Transfers: see section 5.
2.3 Server logs
Our hosting provider records the IP address, user agent, requested URL and timestamp of each request. We additionally store a one-way hash of the IP address to rate-limit form submissions.
- Legal basis: legitimate interest in security, availability and abuse prevention (Art. 6(1)(f) GDPR).
- Retention: [insert log retention, typically 14–90 days].
3. Cookies and browser storage
This site sets no cookies at all until you choose. What we do use
is localStorage for two strictly necessary preferences, plus the
tags you consent to.
| Name | Type | Purpose | Duration | Basis |
|---|---|---|---|---|
cdi-theme | localStorage | Remembers your light/dark choice. | Until you clear it | Strictly necessary |
cdi-consent | localStorage | Records your cookie choice, its date and the policy version. | Until you clear it | Strictly necessary (legal proof of consent) |
_ga, _ga_* | Cookie (Google Analytics 4) | Anonymous usage statistics. Only if you accept analytics. | Up to 24 months | Consent |
| Marketing tags | Cookie | Campaign measurement. Only if you accept marketing. | Up to 24 months | Consent |
_GRECAPTCHA | Cookie (Google) | Set by reCAPTCHA when a form is submitted, to distinguish humans from bots. | Up to 6 months | Legitimate interest (security) |
Analytics and marketing are blocked by default: Google Consent Mode v2 is initialised in “denied” state and no tag is loaded before you accept. You can change or withdraw your choice at any time via cookie settings, or by clearing your browser storage for this site. Withdrawing consent does not affect processing carried out before the withdrawal.
4. What we do not do
- We do not sell or rent personal data.
- We do not use automated decision-making or profiling with legal effects (Art. 22 GDPR).
- We do not load Google Fonts: the fonts are served from our own servers, so visiting this site sends no request to Google for typography.
- We do not embed third-party trackers beyond those listed in section 3.
5. Processors and international transfers
- Hosting: [insert provider, legal entity and country]
- Email delivery: [insert SMTP provider]
- Google reCAPTCHA / Analytics: Google Ireland Ltd. (EU) and Google LLC (US).
Where a processor is outside the EEA, the transfer relies on an adequacy decision (for the United States, the EU–US Data Privacy Framework, where the recipient is certified) or on the European Commission’s standard contractual clauses together with supplementary measures. [confirm the mechanism for each provider]
6. Security
The site is served over HTTPS with HSTS, a strict Content Security Policy, and modern security headers. Form submissions are validated and rate-limited on the server. Access to submitted data is limited to staff who need it for their work.
7. Your rights
You have the right to access, rectify, erase and restrict the processing of your personal data, to object to processing based on legitimate interest, and to data portability. Where processing relies on consent, you may withdraw it at any time.
To exercise a right, write to info@cynthiandigital.com. We reply within one month; that period may be extended by two further months for complex requests, and we will tell you if that happens.
You also have the right to lodge a complaint with a supervisory authority — in Portugal, the Comissão Nacional de Proteção de Dados (CNPD) — or with the authority of your habitual residence.
8. Personal data breaches
If a breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it, and we notify you directly where the risk is high.
9. Children
This site is aimed at businesses. We do not knowingly collect personal data from children. If you believe a child has sent us data, write to us and we will delete it.
10. Changes
We may update this policy. The current version is always published here, with the revision date and version number at the top. Material changes affecting consent will re-open the consent banner.