1. Scope and our role
This Policy applies to the WeCyber website, Workspace, GEO insights, CRM, email, website analysis, APIs, and related support services. WeCyber is a trade name; the service operator is the entity identified in your order form, contract, or invoice.
We generally act as a controller for account registration, subscriptions, service security, support, and website data. For contacts, prospects, inquiries, messages, and other data that customers import, synchronize, or create, we generally act as a processor or service provider under the customer’s instructions. The customer remains responsible for determining the purpose and lawful basis of that processing and for giving required notices.
2. Information we collect
- Account and business details, including names, usernames, work email addresses, companies, regions, roles, account membership, language, verification status, and support records. Passwords are stored only as secure hashes.
- CRM and business data, including companies, contacts, prospects, inquiries, activities, tasks, opportunities, conversion history, notes, tags, webhook events, and customer-uploaded files.
- GEO and website data, including domains, keywords, competitors, prompts, AI-platform responses, citation sources, sentiment, visibility, rankings, Lighthouse reports, and other diagnostics.
- Email data, including sender settings, templates, subjects, recipient lists, delivery status, unsubscribe and bounce records, and, when a mailbox is connected, message headers, bodies, attachment metadata, and synchronization logs.
- Device and usage data, including IP address, browser, device, page actions, login time, cookies, errors, audit logs, job status, and credit balances and usage.
- Information from customer-authorized WordPress sites, mailboxes, marketing and AI providers, APIs, and lawfully accessible business websites, directories, and other public commercial sources.
3. Why and how we use information
- To create and maintain accounts, verify identity, assign permissions, provide support, and perform our contract.
- To synchronize and manage business data, produce GEO, CRM, email, and website insights, and run customer-requested jobs.
- To protect systems, accounts, and email delivery and to prevent fraud, abuse, spam, and unauthorized access.
- To calculate credits, administer plans and limits, manage billing, and maintain audit records.
- To analyze de-identified or aggregated usage and improve performance, reliability, and product experience.
- To comply with law, enforce agreements, resolve disputes, and respond to lawful authority requests. Depending on the context and location, our legal bases may include contract, consent, legal obligation, and legitimate business interests.
4. Customer data and third-party personal data
Customers may process information about their contacts and other third parties through CRM, prospect, inquiry, and email features. Customers must ensure a lawful source, appropriate permission or other valid legal basis, and must meet notice, consent, unsubscribe, deletion, and data-subject request obligations.
If you believe a WeCyber customer uploaded or used your information, contact that customer first. When acting as a processor, we will assist the customer but generally cannot decide how the customer’s business data should be handled.
5. Public data and AI features
- Public availability does not mean unrestricted use. Customers using prospect discovery, website analysis, or integrations must comply with applicable law, robots.txt instructions, source-site terms, intellectual-property rights, and fair-competition rules.
- To provide AI analysis or generation, relevant inputs and necessary context may be sent to the selected AI provider. Do not submit confidential, sensitive, or restricted information that you lack permission to disclose.
- Unless separately disclosed and lawfully authorized, we do not use identifiable Customer Content to train a general-purpose model for other customers. We may use de-identified and aggregated data to evaluate and improve the Service.
6. Sharing, service providers, and international processing
We do not sell personal information as a standalone product. We may provide necessary information to hosting, database, email delivery, mailbox connection, AI, monitoring, security, support, and professional-service providers, and may disclose it for a corporate transaction, legal requirement, or protection of lawful rights.
Some providers may operate outside your country or region. Where required, we use contracts, access controls, data minimization, or other reasonable mechanisms for international processing. Enabling an integration authorizes the transfers necessary to provide that feature.
7. Retention
We retain information only as long as needed to provide the Service, perform contracts, protect security, resolve disputes, and meet legal obligations. Customers may manage or export data during their service term. After termination, data is deleted or de-identified under applicable law, contract terms, and backup cycles, while audit, transaction, security, and compliance records may be retained longer where required.
8. Security
We use administrative and technical safeguards proportionate to risk, including authentication, permission boundaries, account-level data scoping, encryption or hashing, audit logs, backups, and vendor management. No transmission or storage method is completely secure. Contact us promptly if you suspect a security incident affecting you.
9. Your rights and choices
- Subject to applicable law, you may request access, correction, a copy, deletion, or restriction of personal information, withdraw consent, or object to certain processing.
- You may update profile and language settings and use unsubscribe controls in marketing emails. Required transaction, security, and service notices are not affected by marketing opt-out.
- We may verify identity to protect accounts and other people’s data. Some requests may be limited by contract, backups, legal retention duties, or the rights of others.
10. Cookies and similar technologies
We use necessary cookies for login, language, account switching, security tokens, and session state, and may use limited analytics to understand site and product performance. You can manage cookies in your browser, but disabling necessary cookies may prevent login or other features from working.
11. Children, updates, and document priority
The Service is intended for businesses and professional users with legal capacity and is not directed to children. We may update this Policy for legal, technical, or service changes and will revise the date above; material changes will be communicated reasonably. A signed data processing agreement or order form controls if it conflicts with this Policy.
Privacy questions and rights requests
To exercise a privacy right, report a security concern, or ask about data handling, identify yourself, your organization and account, and the nature of your request.
Support@wecyber.net