Privacy Policy
Last updated: 23 July 2026
1. Introduction
Cyntari is a cybersecurity research and reports directory operated by:
In this Privacy Policy, “Cyntari,” “we,” “us,” and “our” refer to Bridgerwise s. r. o.
This Privacy Policy explains how we collect, use, retain, disclose, and protect personal data when you visit or use Cyntari, create an account, receive report alerts, submit a report, provide feedback, or otherwise interact with our services.
For questions about this Privacy Policy or the processing of your personal data, contact: director@bridgerwise.com.
Bridgerwise s. r. o. is the data controller responsible for the processing described in this Privacy Policy.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed through:
- The Cyntari website and web application.
- User accounts and profiles.
- Report alerts and platform communications.
- User favourites and report-access history.
- Report submissions.
- Feedback and support communications.
- Security, operational, and technical systems supporting Cyntari.
This Privacy Policy does not apply to third-party websites, report publishers, or external services that you access through links provided by Cyntari.
3. Information we collect
3.1 Information you provide
We may collect information that you provide directly, including:
- Your email address.
- Your password or authentication credentials, in protected or encrypted form where applicable.
- Your account preferences.
- Themes, tags, and other interests selected for report alerts.
- Your preferred alert frequency.
- Reports saved as favourites.
- Report URLs submitted for review.
- Feedback, content issue reports, support messages, and other communications.
- Newsletter and communication preferences.
- Information provided when exercising your privacy rights.
We do not require users to provide unnecessary profile information to create a standard Cyntari account.
3.2 Information generated through your use of Cyntari
When you use Cyntari, we may process:
- Reports whose detail pages you have accessed.
- Reports added to or removed from your favourites.
- Alerts you have created, changed, or deleted.
- The date and time of account-related actions.
- Account status and account recovery information.
- Technical and security logs.
- IP address.
- Browser type.
- Device type.
- Operating system.
- Approximate location derived from an IP address, where necessary for security.
- Error, diagnostic, and performance information.
- Records of acceptance of policies or account settings.
Report-access history is retained while your account remains active, unless you delete it earlier where that functionality is available.
3.3 Information collected from visitors without accounts
People without an account may view limited report pages and summaries.
When an unauthenticated visitor uses Cyntari, we may process limited technical information needed to:
- Deliver the website.
- Maintain security.
- Prevent scraping and abuse.
- Enforce access restrictions.
- Diagnose technical problems.
- Understand aggregate service performance.
3.4 Email information
Cyntari sends report alerts and platform communications through its built-in email functionality.
We do not use tracking pixels to monitor whether you open an email, and we do not track whether you click links inside alert or newsletter emails for analytics or marketing purposes.
Our technical systems may still record information needed to deliver an email, such as:
- The intended recipient.
- Delivery time.
- Delivery success or failure.
- Bounce or suppression status.
- Whether an address has unsubscribed.
4. How we use personal data
We use personal data for the following purposes.
4.1 Providing the Cyntari service
We process personal data to:
- Create and operate user accounts.
- Authenticate users.
- Provide access to account-only content and functionality.
- Save and display favourites.
- Maintain report-access history.
- Create and manage report alerts.
- Process account recovery and deletion requests.
- Respond to user requests.
Our legal basis is generally the performance of our contract with you or taking steps at your request before entering into a contract.
4.2 Sending requested report alerts
When you create an alert, we use your email address and selected preferences to send notifications when relevant reports are added.
You may stop a specific alert by deleting or disabling it in your account.
Our legal basis is the performance of the service you requested.
4.3 Sending platform communications
We may send registered users occasional communications concerning:
- Significant platform updates.
- Changes to available functionality.
- Important changes to the service.
- Security notices.
- Account notices.
- Changes to our legal documents.
- Service availability or maintenance.
- Relevant updates concerning the operation of Cyntari.
Where permitted by law, these communications may be sent to registered users by default on the basis of our legitimate interests in operating, maintaining, and improving Cyntari.
You may unsubscribe from non-essential platform newsletters through your profile or by using the unsubscribe method included in the email.
Communications that are strictly necessary to operate your account or provide a service you requested may continue while your account or the relevant service remains active.
4.4 Marketing communications
Where a communication constitutes marketing or promotional content, we will provide an unsubscribe option and obtain consent where required by applicable law.
Marketing preferences may be managed through your user profile.
Withdrawing consent or unsubscribing does not affect account, security, legal, or other essential service messages.
4.5 Processing report submissions and feedback
We use submitted report URLs, feedback, and support messages to:
- Review possible additions to Cyntari.
- Correct report information.
- Investigate content issues.
- Improve Cyntari.
- Respond to users.
- Detect malicious or abusive submissions.
Our legal basis is generally performance of a service requested by you or our legitimate interests in maintaining and improving Cyntari.
Submission of a report does not guarantee that it will be added.
4.6 Security and misuse prevention
We process technical, account, and activity information to:
- Protect user accounts.
- Detect unauthorized access.
- Prevent scraping and mass downloading.
- Enforce rate limits.
- Prevent fraud, malicious submissions, and technical abuse.
- Investigate suspected violations of our Terms.
- Maintain service reliability.
Our legal basis is our legitimate interest in protecting Cyntari, our users, our systems, and third-party content.
4.7 Compliance with legal obligations
We may process or retain personal data where necessary to:
- Comply with applicable law.
- Respond to lawful requests from authorities.
- Establish, exercise, or defend legal claims.
- Maintain records required by law.
- Investigate unlawful activity.
Our legal basis is compliance with a legal obligation or our legitimate interest in protecting our legal rights.
5. Analytics
Cyntari uses Lovable Analytics to understand aggregate service performance and usage.
Lovable Analytics is configured without non-essential cookies or identifiable user tracking. We do not use Google Analytics.
Analytics information is used to understand matters such as:
- General traffic levels.
- Aggregate page usage.
- Technical performance.
- Errors and availability.
- Broad, non-identifiable usage patterns.
We do not use Lovable Analytics to create advertising profiles or follow users across unrelated websites.
If the configuration or nature of our analytics changes, we will update this Privacy Policy and obtain consent where required.
6. Cookies and similar technologies
Cyntari may use strictly necessary cookies, local storage, or similar technologies to:
- Keep users signed in.
- Maintain authentication sessions.
- Store security information.
- Remember essential preferences.
- Protect against unauthorized access.
- Enable account recovery.
- Maintain the operation of the service.
These technologies are necessary for Cyntari to function and are not used for advertising.
Cyntari does not currently use non-essential analytics cookies or identifiable analytics tracking.
Your browser may allow you to block or delete cookies. Blocking strictly necessary technologies may prevent account login or other parts of Cyntari from working correctly.
7. Our service providers
We use service providers to operate Cyntari.
7.1 Supabase
Supabase provides services that may include:
- Database infrastructure.
- User authentication.
- Storage.
- Server-side and backend functionality.
- Security and technical infrastructure.
Supabase processes personal data on our behalf to the extent necessary to provide these services.
7.2 Lovable
Lovable provides services used to build, host, operate, maintain, and analyze Cyntari.
Depending on the service configuration, Lovable may process:
- Technical information.
- Service logs.
- Application data.
- Aggregate analytics information.
- Information required to host or operate the application.
7.3 Other providers
We may also use providers for:
- Domain and hosting infrastructure.
- Email delivery infrastructure.
- Security and error monitoring.
- Backup and recovery.
- Professional legal, accounting, or technical support.
We require service providers to process personal data only for authorized purposes and subject to appropriate contractual and security obligations.
We do not sell personal data to service providers or advertisers.
8. International data transfers
Some service providers or their subprocessors may operate outside Slovakia or the European Economic Area.
Where personal data is transferred outside the European Economic Area, we use a legally recognized transfer mechanism where required, which may include:
- A European Commission adequacy decision.
- European Commission Standard Contractual Clauses.
- Other safeguards permitted under applicable data protection law.
The location and transfer mechanism may depend on the infrastructure region and configuration used by Supabase, Lovable, or their authorized subprocessors.
You may contact us at director@bridgerwise.com for more information about applicable transfer safeguards.
9. Sharing personal data
We may disclose personal data:
- To service providers acting on our behalf.
- To professional advisers subject to confidentiality obligations.
- Where required by law, court order, or lawful government request.
- To investigate fraud, abuse, security incidents, or violations of our Terms.
- To protect the rights, safety, and security of Cyntari, our users, or others.
- In connection with a merger, acquisition, restructuring, financing, or sale of all or part of the business, subject to appropriate safeguards.
We do not sell or rent personal data.
We do not share personal data with report publishers merely because a user views or follows a link to a report.
10. External report websites
Cyntari generally does not host the complete third-party reports listed in its directory.
When you select a report link, you may be directed to:
- A report publisher's website.
- A third-party download page.
- A registration page.
- A form requiring personal or professional information.
- Another external website.
Any information you provide on an external website is collected and controlled by that external organization, not by Cyntari.
Third parties have their own privacy policies, cookie practices, security controls, and terms. We are not responsible for how they collect, use, retain, or disclose your information.
We encourage you to review the external organization's privacy policy before providing personal data.
11. Data retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy.
11.1 Active accounts
While an account remains active, we generally retain:
- Account information.
- Favourites.
- Alert preferences.
- Report-access history.
- Communication preferences.
- Account settings.
- Relevant security records.
11.2 Account deletion and recovery
When you request account deletion through your profile:
- Your account is deactivated.
- The account and its associated data become inaccessible.
- A 90-day recovery period begins.
- During that period, you may restore the account yourself.
- If you restore the account, access to the account and its retained information is reactivated.
- If you do not restore the account within 90 days, the account is scheduled for permanent deletion from active systems.
After permanent deletion from active systems, residual copies may remain in encrypted or protected backups for up to an additional 90 days.
Backup copies are not restored for ordinary business use and are deleted according to the applicable backup cycle.
We may retain limited information for longer where required to:
- Comply with law.
- Prevent fraud or repeated abuse.
- Maintain an unsubscribe or suppression record.
- Resolve disputes.
- Enforce our agreements.
- Establish, exercise, or defend legal claims.
11.3 Alerts
Alert preferences are retained while the relevant alert or account remains active.
Deleting an alert stops future notifications associated with that alert, subject to messages already being processed.
11.4 Submissions and feedback
Report submissions, feedback, and related correspondence may be retained for as long as needed to review the matter, maintain an editorial record, prevent abuse, and resolve disputes.
11.5 Technical and security logs
Technical and security logs are retained for a limited period appropriate to their purpose, unless longer retention is necessary to investigate an incident or comply with law.
12. Account deletion
You may request account deletion directly through your Cyntari profile.
During the 90-day recovery period:
- Your account is inactive.
- You cannot use account functionality.
- Your account data is not displayed to you through the service.
- Alerts and non-essential communications are stopped.
- You may restore the account yourself.
You may contact director@bridgerwise.com if you experience a problem with account deletion or recovery.
13. Your rights
Subject to applicable conditions and exceptions, you may have the right to:
- Receive information about how your personal data is processed.
- Access personal data we hold about you.
- Correct inaccurate or incomplete personal data.
- Request deletion of personal data.
- Restrict processing.
- Object to processing based on legitimate interests.
- Receive eligible personal data in a portable format.
- Withdraw consent at any time where processing is based on consent.
- Object to direct marketing.
- Lodge a complaint with a data protection authority.
- Obtain information about international transfer safeguards.
- Avoid decisions based solely on automated processing where those decisions produce legal or similarly significant effects.
Cyntari does not currently use solely automated decision-making to make decisions about users that produce legal or similarly significant effects.
To exercise your rights, contact: director@bridgerwise.com.
We may need to verify your identity before acting on a request.
We normally respond within the period required by applicable law. Some rights may be limited where an exception applies, including where retention is required by law or necessary to protect legal rights.
14. Supervisory authority
You have the right to lodge a complaint with the supervisory authority in your country of residence, place of work, or the place of the alleged infringement.
Our lead supervisory authority is expected to be:
You may also contact us first at director@bridgerwise.com so that we have an opportunity to address your concern.
15. Users aged 16 and over
Cyntari is intended for people aged 16 or older.
People under 16 may not create a Cyntari account.
We do not knowingly collect personal data from a person under 16 through an account. If you believe that a person under 16 has created an account or provided personal data, contact director@bridgerwise.com.
We may delete an account where we reasonably believe that the user does not meet the minimum age requirement.
16. Security
We use reasonable technical and organizational measures designed to protect personal data against:
- Unauthorized access.
- Loss.
- Misuse.
- Alteration.
- Destruction.
- Disclosure.
These measures may include:
- Access controls.
- Authentication protections.
- Encryption in transit.
- Managed infrastructure.
- Logging and monitoring.
- Rate limiting.
- Backup and recovery controls.
- Restricted administrative access.
No website, database, or electronic transmission can be guaranteed to be completely secure. You are responsible for protecting your password, authentication links, and access to your email account.
17. AI-assisted content
Some Cyntari report summaries, classifications, questions, metadata, or editorial content may be created with assistance from artificial intelligence or other automated tools.
Cyntari uses a mixed human and AI-assisted process, and content is approved by the Cyntari team before publication.
AI-assisted content may nevertheless contain errors, omissions, or imperfect interpretations. Users should consult the original report and publisher for authoritative information.
AI-assisted content is not used to make legal or similarly significant automated decisions about Cyntari users.
18. Changes to this Privacy Policy
We may update this Privacy Policy to reflect:
- Changes to Cyntari.
- Changes to our service providers.
- Changes to our processing activities.
- Changes to applicable law.
- Security or operational developments.
The updated policy will be published with a revised “Last updated” date.
Where a change materially affects your rights or how we process personal data, we may provide additional notice through Cyntari or by email.
19. Contact
For questions, concerns, complaints, or requests concerning privacy or personal data, contact:
Email: director@bridgerwise.com
