Skip to content
Effective January 1, 2026

Privacy Policy

This policy explains what personal information CyberXSolutions Inc collects, why we collect it, how long we keep it, and the rights you have over it. It is written to be read rather than to be defensible, and we have tried to keep the legal formulations to where they are genuinely required.

Who we are

CyberXSolutions Inc ("CyberXSolutions", "we", "us") is the data controller for personal information collected through cyberxsolutions.us. Our registered address is 106 W Fourth Street, PMB #110, Kalkaska, MI 49646, United States.

For any privacy question, request or complaint, contact us at support@cyberxsolutions.us. We aim to respond within five working days and are required to respond substantively within one month.

Information we collect

We collect the minimum needed to answer your enquiry and to understand whether this website is doing its job. We do not buy personal data from brokers, and we do not enrich the records you give us with third-party datasets.

Information we collect
CategoryWhat it includesWhy we collect it
Enquiry informationName, work email, company, role, area of interest, budget range and the message you writeTo answer your enquiry and route it to the right engineer
Recruitment informationThe contents of an application you send us, including any CV or portfolioTo assess your application and communicate with you about it
Technical informationIP address, browser and device type, referring page, pages viewedTo keep the site secure and to understand aggregate usage
Consent recordsYour cookie preferences and the date they were setTo honour your choices and to demonstrate that we did

How we use your information

We do not use the information you send us to train machine learning models, and we do not sell, rent or licence personal information to anyone.

  • To respond to enquiries and provide the services you ask about
  • To assess job applications and communicate about recruitment
  • To maintain the security, availability and integrity of our website and systems
  • To understand aggregate website usage so we can improve the content
  • To meet legal, accounting and regulatory obligations

Our lawful bases

Where the UK GDPR or EU GDPR applies, we rely on the following bases. Where you have consented, you can withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.

  • Legitimate interests — responding to business enquiries, securing our systems and understanding aggregate site usage, balanced against your rights
  • Consent — non-essential cookies and analytics, and any marketing communication you specifically opt into
  • Contract — steps taken at your request before entering into a contract, and performance of a contract once agreed
  • Legal obligation — retention of records required by tax, employment and corporate law

Sharing and processors

We share personal information only with service providers who process it on our behalf under a written data processing agreement, and only to the extent needed to deliver the service. Current categories are set out below; the specific vendors in each category can change, and the current list is available on request.

  • Cloud hosting and content delivery providers
  • Website analytics providers, where you have consented
  • Email delivery and customer relationship management systems
  • Recruitment and applicant tracking systems
  • Professional advisers including accountants, auditors and lawyers

International transfers

We are based in the United States and some of our service providers process data outside your country of residence. Where we transfer personal information out of the UK or European Economic Area, we rely on the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, together with a transfer risk assessment.

For client engagements, we work inside your infrastructure and under your data governance wherever possible, which usually means personal data never leaves the environment you already control.

How long we keep it

At the end of a retention period, information is deleted or irreversibly anonymised. Backups are purged on their own rolling cycle, which may extend actual deletion by up to 35 days.

How long we keep it
CategoryRetention period
Enquiries that do not become engagements24 months from last contact
Client engagement recordsDuration of the engagement plus 7 years for legal and tax purposes
Unsuccessful job applications12 months, unless you ask us to keep them longer
Website server logs90 days
Cookie consent records12 months

Your rights

Depending on where you live, you may have some or all of the following rights. We will not charge you for exercising them and we will not treat you differently for doing so.

  • Access — a copy of the personal information we hold about you
  • Rectification — correction of information that is inaccurate or incomplete
  • Erasure — deletion of information where we no longer have grounds to keep it
  • Restriction — limiting how we use your information while a concern is resolved
  • Portability — a machine-readable copy of information you provided to us
  • Objection — objecting to processing based on our legitimate interests
  • Withdrawal of consent — at any time, for anything we do on the basis of consent
  • Complaint — to your supervisory authority, though we would appreciate the chance to resolve it first

California residents

If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect, to request deletion or correction, to opt out of any sale or sharing of personal information, and to limit the use of sensitive personal information.

We do not sell or share personal information as those terms are defined by the CCPA, and we do not collect sensitive personal information through this website. You may exercise your rights by emailing us; we will verify your identity by confirming details you have previously given us rather than asking for additional documents.

Security

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and notify you without undue delay where the risk is high.

  • Encryption in transit using TLS 1.2 or above, and encryption at rest for stored data
  • Least-privilege access with multi-factor authentication required for all staff
  • Access reviewed quarterly and revoked immediately on role change or departure
  • Logging and monitoring of access to systems holding personal information
  • A documented incident response plan, tested at least annually
  • Supplier due diligence before any processor is engaged

Children

Our website and services are intended for business use and are not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us and we will delete it.

Changes to this policy

We update this policy when our practices change. The effective date at the top of the page always reflects the current version. Where a change materially affects your rights, we will make that clear on this page rather than relying on you to notice.

This document is provided for transparency and is not legal advice. If you need a position on how it applies to your specific circumstances, speak to your own counsel — or write to us and we will put you in touch with ours.