Back to Legal

Privacy Policy

Effective date: August 30, 2026

Last updated: August 30, 2026

Cyrenza, Inc. ("Cyrenza," "we," "us," or "our") respects your privacy. This Privacy Policy explains how Cyrenza collects, uses, discloses, retains, and protects information that identifies or can reasonably be linked to an individual ("Personal Data"). It also explains the choices and rights that may be available to you.

Please read this Privacy Policy in full. If you have questions or wish to exercise a privacy right, contact privacy@cyrenza.com.

1. Scope of this Privacy Policy

This Privacy Policy applies when Cyrenza acts as the organization responsible for deciding why and how Personal Data is processed. It covers Personal Data we receive through:

  • Cyrenza's public website and other public pages that link to this policy;
  • inquiries, introductions, waitlists, demonstrations, surveys, and feedback;
  • business-development and investor communications;
  • events and professional interactions; and
  • other direct communications with Cyrenza.

Cyrenza is building a professional work system for commercial real estate firms. The system is not currently offered for general public use.

This Privacy Policy does not govern documents, evidence, prompts, outputs, Deal information, or other content that a future customer may provide to the Cyrenza system for processing on the customer's behalf ("Customer Data"). A customer agreement and, where applicable, a data processing agreement will govern Customer Data before Cyrenza accepts it in a customer deployment.

If you provide Personal Data to a Cyrenza customer for inclusion in Customer Data, that customer will ordinarily decide why the data is processed. Privacy requests concerning that Customer Data should ordinarily be directed to the customer.

2. Who is responsible for your Personal Data

Cyrenza, Inc. is responsible for the Personal Data covered by this Privacy Policy. Cyrenza, Inc. is incorporated in Delaware, United States.

Depending on the law that applies, Cyrenza may be described as the "controller," "business," or "responsible party" for this processing.

Privacy contact: privacy@cyrenza.com

Registered office for corporate identification:

Cyrenza, Inc.
131 Continental Dr
Suite 305
Newark, DE 19713
United States

3. Personal Data we collect

The Personal Data we collect depends on how you interact with Cyrenza.

3.1 Information you provide directly

We may collect:

  • Contact information, such as your name, work email address, telephone number, and communication preferences.
  • Professional information, such as your employer, job title, business function, industry, professional interests, and the type of organization you represent.
  • Communication information, including the content of messages, inquiries, meeting requests, survey responses, feedback, and other communications you send to us.
  • Interest information, such as your interest in Cyrenza, possible use cases, preferred timing, and requests for updates or demonstrations.
  • Event information, such as registration details and professional interactions if you attend an event involving Cyrenza.

Providing this information is voluntary. If you do not provide information needed to answer a request, we may be unable to respond or provide the requested information.

Do not send confidential Deal materials, transaction documents, government identification numbers, payment-card information, personal financial information, health information, or other sensitive Personal Data through the public website or ordinary email.

3.2 Information collected automatically

When you visit the public website, the systems used to deliver and protect it may automatically receive limited technical information, including:

  • Internet Protocol address;
  • browser and device type;
  • operating system;
  • requested pages, files, and referring page;
  • date and time of access;
  • approximate location derived from an Internet Protocol address;
  • network, diagnostic, and error information; and
  • information used to identify and prevent malicious or automated activity.

This information is generated when a browser communicates with a website and is used primarily to deliver, secure, and troubleshoot the website.

3.3 Information from other sources

We may receive professional contact information from:

  • a colleague or professional contact who introduces you;
  • an organization you represent;
  • event organizers or professional communities;
  • service providers helping us manage business communications; and
  • publicly available professional sources, such as an organization's website or a professional profile you have made public.

We do not intentionally collect Personal Data from data brokers for consumer profiling or targeted advertising.

3.4 Sensitive Personal Data

The public website is not designed to collect sensitive Personal Data. We do not intentionally request information such as government identifiers, precise geolocation, biometric or genetic information, health information, financial credentials, or information about children.

If you provide sensitive Personal Data without being asked, we will process it only as reasonably necessary to protect it, respond appropriately, comply with law, or delete it.

4. How and why we use Personal Data

We may use Personal Data for the following purposes:

Purpose
Deliver, maintain, and secure the public website
Types of Personal Data generally involved
Technical, device, network, and security information
Legal basis where required
Legitimate interests in operating and protecting the website; legal obligations where applicable
Purpose
Respond to inquiries, introductions, and meeting requests
Types of Personal Data generally involved
Contact, professional, and communication information
Legal basis where required
Steps requested before a contract; legitimate interests; consent where required
Purpose
Manage a waitlist or expressions of interest
Types of Personal Data generally involved
Contact, professional, interest, and communication information
Legal basis where required
Consent; legitimate interests in managing product interest
Purpose
Send requested updates and business communications
Types of Personal Data generally involved
Contact, professional, interest, and communication information
Legal basis where required
Consent where required; legitimate interests where permitted
Purpose
Understand interest in Cyrenza and improve public communications
Types of Personal Data generally involved
Contact, professional, interest, communication, and limited technical information
Legal basis where required
Legitimate interests in developing Cyrenza and communicating clearly
Purpose
Prevent fraud, abuse, and security incidents
Types of Personal Data generally involved
Technical, device, network, security, and communication information
Legal basis where required
Legitimate interests; legal obligations
Purpose
Establish, exercise, or defend legal rights
Types of Personal Data generally involved
Any information relevant to the matter
Legal basis where required
Legitimate interests; legal obligations
Purpose
Comply with law and lawful requests
Types of Personal Data generally involved
Any information required by the applicable obligation or request
Legal basis where required
Legal obligations
Purpose
Evaluate or complete a financing, reorganization, acquisition, or other corporate transaction
Types of Personal Data generally involved
Information reasonably relevant to the transaction
Legal basis where required
Legitimate interests; consent or legal obligations where required

Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that occurred before withdrawal or processing supported by another lawful basis.

Where we rely on legitimate interests, we consider whether those interests are overridden by your privacy rights and interests.

5. Automated decision-making

Cyrenza does not use Personal Data covered by this Privacy Policy to make solely automated decisions about you that produce legal or similarly significant effects.

6. How we disclose Personal Data

We may disclose Personal Data to the following categories of recipients, only as reasonably necessary for the purposes described in this policy:

  • Hosting, infrastructure, and security providers that deliver and protect the public website.
  • Business-communication providers that support email, scheduling, contact management, surveys, or requested communications.
  • Professional advisers, including lawyers, accountants, auditors, insurers, and other advisers subject to professional or contractual duties.
  • Corporate transaction parties, including potential investors, purchasers, lenders, and their advisers, subject to appropriate confidentiality and legal protections.
  • Authorities and other persons required by law, including regulators, courts, and law-enforcement bodies where disclosure is required or permitted by applicable law.
  • A person you direct us to contact or disclose information to, or another person where you consent to the disclosure.

We may also disclose information when reasonably necessary to protect the rights, safety, and security of Cyrenza, our personnel, website visitors, or others.

Service providers may process Personal Data only for the services they provide to us or as otherwise permitted by their agreements and applicable law.

7. Sale, sharing, advertising, and profiling

Cyrenza does not sell Personal Data.

Cyrenza does not share Personal Data for cross-context behavioural advertising, use the public website for targeted advertising, or profile individuals for decisions that produce legal or similarly significant effects.

If these practices change, we will update this Privacy Policy and provide any notice, consent mechanism, or opt-out method required by applicable law before the new practice begins.

8. Cookies and similar technologies

Cyrenza does not currently use analytics cookies, advertising cookies, tracking pixels, or similar technologies to follow visitors across unaffiliated websites.

The infrastructure used to deliver and secure the public website may process technical request information or use strictly necessary technologies for security, network routing, or site operation. These technologies are not used for behavioural advertising.

We do not permit third parties to collect Personal Data through the public website about your activities over time and across unaffiliated websites for targeted advertising.

Please read our Cookie Policy for the current technology inventory and your browser choices.

Do Not Track and opt-out preference signals

Some browsers offer "Do Not Track" settings, but there is no uniform standard that determines how websites must respond to them. The website does not separately respond to a Do Not Track signal.

Because Cyrenza does not currently sell Personal Data, share it for cross-context behavioural advertising, or conduct targeted advertising, a browser-based opt-out preference signal does not change the website's current practices. If an applicable law requires recognition of such a signal for a future practice, we will implement the required response before beginning that practice.

9. International processing and transfers

Cyrenza is incorporated in the United States and has operations in South Africa. Personal Data may be processed in the United States, South Africa, and other countries where our service providers or professional advisers operate.

The data-protection laws of those countries may differ from the laws where you live. Where applicable law requires safeguards for an international transfer, we will use a recognized legal mechanism or another lawful basis appropriate to the transfer.

Cyrenza does not claim participation in a data-transfer certification program unless that participation is expressly stated in a subsequently published notice.

10. Data retention

We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy. Retention depends on the nature of the information, our relationship with you, and legal, security, and business requirements.

In general:

  • inquiry and correspondence information is retained while we respond and for a reasonable follow-up period;
  • waitlist and requested-update information is retained while Cyrenza is being developed, while your interest remains current, or until you ask us to remove it;
  • technical, diagnostic, and security information is retained for the period reasonably necessary to operate, protect, and investigate the website;
  • records of privacy requests may be retained to document our response and comply with law; and
  • records needed for legal, tax, accounting, audit, dispute, fraud-prevention, or compliance purposes are retained for the period required or permitted by applicable law.

When Personal Data is no longer required, we delete or anonymize it. If immediate deletion from backup systems is not reasonably possible, we will place the information beyond ordinary use until deletion occurs through the applicable backup cycle, subject to legal obligations.

This section addresses Personal Data covered by this Privacy Policy. Future Customer Data will be subject to the retention and deletion provisions of the applicable customer agreement.

11. Security

Cyrenza uses reasonable administrative, technical, and organizational measures designed to protect Personal Data against unauthorized access, acquisition, loss, misuse, alteration, or disclosure.

Security is an ongoing process. No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

Do not send sensitive or confidential information through ordinary email. If Cyrenza introduces a secure submission channel, we will identify it separately.

12. Your privacy rights

Depending on where you live and subject to applicable exceptions, you may have the right to:

  • ask whether we process your Personal Data;
  • request access to or a copy of your Personal Data;
  • request correction of inaccurate or incomplete Personal Data;
  • request deletion of Personal Data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive certain Personal Data in a portable format;
  • withdraw consent where processing is based on consent;
  • opt out of marketing communications;
  • appeal a decision we make about a privacy request; and
  • complain to an applicable privacy or data-protection authority.

To exercise a right, email privacy@cyrenza.com and describe your request. We may ask for information reasonably necessary to verify your identity, locate the relevant information, and prevent unauthorized disclosure. We will not require you to create a new account solely to submit a request.

An authorized agent may submit a request where permitted by law. We may ask for evidence of the agent's authority and may verify your identity directly.

Applicable rights are not absolute. We may decline or limit a request where permitted or required by law, including when information must be retained to protect rights, comply with law, prevent fraud, or preserve another person's privacy. If we deny a request, we will provide the explanation and appeal information required by applicable law.

You will not be discriminated against for exercising an applicable privacy right.

13. Jurisdiction-specific information

13.1 European Economic Area, United Kingdom, and Switzerland

If European or United Kingdom data-protection law applies to our processing, the legal bases described in Section 4 apply as relevant. You may have rights of access, correction, erasure, restriction, objection, portability, and withdrawal of consent.

You may also lodge a complaint with the data-protection authority where you live, work, or believe a violation occurred. Contact details for authorities in the European Economic Area are available through the European Commission, and the United Kingdom authority is the Information Commissioner's Office.

Cyrenza has not appointed a data protection officer or European representative merely by publishing this policy. If applicable law requires such an appointment, the relevant contact information will be added here.

13.2 United States

For purposes of United States state privacy laws, the categories of Personal Data Cyrenza may have collected during the preceding 12 months are:

  • identifiers, such as name, email address, Internet Protocol address, and similar contact information;
  • professional or employment-related information;
  • Internet or other electronic-network activity information;
  • correspondence and other information you provide; and
  • approximate location derived from an Internet Protocol address.

We collect these categories from the sources described in Section 3, use them for the purposes described in Section 4, and disclose them to the categories of recipients described in Section 6.

Cyrenza has not sold Personal Data or shared Personal Data for cross-context behavioural advertising during the preceding 12 months. Cyrenza does not have actual knowledge that it sells or shares the Personal Data of anyone under 18.

Depending on your state and whether the applicable law covers Cyrenza's processing, you may have rights to know, access, correct, delete, or obtain a portable copy of Personal Data, and to opt out of certain sale, targeted advertising, sharing, or profiling practices. Cyrenza does not currently conduct those opt-out processing activities.

To appeal a denied request, reply to our decision or email privacy@cyrenza.com with the subject "Privacy Request Appeal."

13.3 South Africa

Where the Protection of Personal Information Act, 2013 ("POPIA") applies, Cyrenza acts as the responsible party for Personal Data covered by this Privacy Policy. Cyrenza processes that information for the purposes and on the grounds described in this policy, subject to POPIA's conditions for lawful processing.

Subject to applicable law, you may request access to Personal Data, ask for correction or deletion, object to certain processing, withdraw consent, or complain about how Personal Data is processed.

Requests should first be sent to privacy@cyrenza.com. You may also lodge a complaint with the Information Regulator (South Africa) through its official complaints process.

14. Marketing communications

You may ask us to stop sending promotional communications at any time by using the unsubscribe method in the communication or contacting privacy@cyrenza.com.

If you opt out of marketing, we may still send non-promotional communications needed to respond to you, administer an existing relationship, provide legal notices, or protect security.

15. Children

The public website is intended for business and professional audiences. It is not directed to anyone under 18, and we do not knowingly collect Personal Data from anyone under 18.

If you believe that a person under 18 has provided Personal Data to Cyrenza, contact privacy@cyrenza.com so that we can investigate and, where appropriate, delete it.

16. Third-party websites

The public website may contain links to websites operated by third parties. Cyrenza does not control those websites or their privacy practices. Review the third party's privacy and cookie notices before providing information to it.

17. Changes to this Privacy Policy

We may update this Privacy Policy as Cyrenza, the website, and applicable law develop. We will post the updated policy and revise the "Last updated" date.

If a change materially affects how we use Personal Data already collected, we will provide additional notice or seek consent where required by law.

When a previous version exists, Cyrenza will make it available through the Legal Center or on request.

18. Contact us

For privacy questions, requests, appeals, or complaints, contact:

privacy@cyrenza.com

Registered office for corporate identification:

Cyrenza, Inc.
131 Continental Dr
Suite 305
Newark, DE 19713
United States

A defined assignment. A measured engagement.

Each engagement covers agreed evidence, outputs, professional review, acceptance criteria, and measurement.

A defined professional assignment