Kyber (Pty) Ltd

Privacy Policy

Effective date: January 1, 2026 · Last updated: January 1, 2026

Kyber (Pty) Ltd (registration number K2025930256), a company incorporated in the Republic of South Africa (“Kyber”, “we”, “us”, “our”), operates the website at kyber.cc, including the marketing diagnostic tool at kyber.cc/diagnose, and provides marketing intelligence software and advisory services (together, the “Services”).

This Privacy Policy explains what personal information we collect, why we collect it, who we share it with, and the rights you have over it. It is written to satisfy, in one document, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), the EU and UK General Data Protection Regulation (“GDPR”), and South Africa’s Protection of Personal Information Act 4 of 2013 (“POPIA”). Where those laws use different terms — “personal information,” “personal data” — we use them interchangeably.

For the purposes of the GDPR, Kyber is the data controller of the information described in this Policy. For the purposes of POPIA, Kyber is the responsible party. For the purposes of the CCPA/CPRA, Kyber is the business collecting the information.

1. What this Policy covers — and what it does not

This Policy covers personal information we collect from visitors to our website, users of our diagnostic tool, trial users, subscribers, newsletter readers, and business contacts — people whose relationship is with Kyber directly.

It does not cover data we process on behalf of our clients inside a client engagement or a client’s Kyber intelligence instance (“Client Service Data”). Client Service Data — for example, a client’s customer, revenue, or campaign data connected to a Kyber deployment — is processed under the engagement agreement and data processing terms between Kyber and that client. The client is the controller/responsible party for that data; Kyber acts as a processor/operator on the client’s documented instructions. If your personal information has reached us inside a client’s data, please direct any request to that client; we will support them in responding as their agreement with us requires.

2. Information we collect

We collect the following categories of personal information. We collect no more than the purpose requires, and we have collected these same categories during the 12 months preceding the effective date of this Policy.

Identity and contact information. Name, email address, company name and company URL, job title, and any details you provide when you contact us, book a call, or subscribe to our publications.

Diagnostic and assessment inputs. When you use the diagnostic at kyber.cc/diagnose, the business information you enter (for example stage, spend, channel and headcount figures) together with the email address you provide to receive your results, and the results generated for you.

Account and subscription information. If you register for a trial or paid subscription: login email, password (stored only in hashed form), account settings, plan and subscription status.

Commercial and payment information. Records of the services you have purchased or considered. Payment card details are collected and processed directly by our payment processor, Stripe — Kyber does not receive or store full card numbers; we receive confirmation of payment, the card brand and last four digits, and billing history.

Internet and device activity. IP address, browser type, device identifiers, operating system, pages viewed, referring URLs, time spent, clicks and scroll behaviour, and similar usage data collected through cookies and similar technologies (see Section 4). Coarse location (country/region) may be inferred from your IP address. We do not collect precise geolocation.

Communications. Emails and messages you exchange with us, and engagement data about the emails we send you (delivery, opens, clicks), collected through our email and CRM platforms.

Inferences. Segments or profiles we may draw from the above — for example, that your diagnostic results suggest a particular company stage — used to make our follow-up relevant.

Sensitive personal information. The only sensitive personal information we collect as defined by the CCPA/CPRA is your account login credential (email plus password). We use it solely to authenticate your account — a purpose permitted without a “Right to Limit” option — and for no other purpose. We do not intentionally collect any special-category data under the GDPR or special personal information under POPIA (such as health, religious, biometric, or racial/ethnic data), and we ask that you do not submit any through our forms.

Sources. We collect this information (a) directly from you, when you fill in a form, run the diagnostic, create an account, or correspond with us; (b) automatically, from your device and browser, via cookies and similar technologies; (c) from our service providers, such as payment confirmation from Stripe or analytics from our measurement tools; and (d) occasionally from publicly available business sources (for example your company website or LinkedIn profile) to understand who we are speaking with.

3. How we use personal information

We use personal information for the following business and commercial purposes:

Providing the Services — generating and delivering your diagnostic results; creating and administering accounts; operating trials and subscriptions; processing payments; providing support.

Communicating with you — responding to enquiries; sending your diagnostic results and any follow-up you have agreed to; sending our newsletter and publications where you have subscribed; sending service and transactional messages.

Improving and securing the Services — analytics, debugging, performance measurement, testing site changes, detecting and preventing fraud, abuse and security incidents.

Marketing — understanding which content and channels bring visitors to us; and, if we adopt advertising tools in future, the advertising activities described in Section 5. Every marketing email we send includes a one-click unsubscribe.

Legal compliance — complying with applicable law, tax and accounting obligations, and enforcing our terms.

Legal bases (GDPR) / lawful grounds (POPIA). Where the GDPR or POPIA applies, we rely on: performance of a contract (providing the Services you have requested, including delivering diagnostic results you asked for); consent (non-essential cookies, newsletter subscriptions, and follow-up marketing — withdrawable at any time); legitimate interests (securing and improving the Services, and business-to-business outreach that you would reasonably expect and can opt out of at any time); and legal obligation (records we must keep by law). Under POPIA, these correspond to the grounds in section 11(1), including performance of a contract, consent, compliance with law, and our or your legitimate interests.

We do not use personal information for automated decision-making that produces legal or similarly significant effects about you, and we do not use it to train artificial intelligence models.

4. Cookies, tracking, and your consent

We use cookies and similar technologies in three groups:

Strictly necessary — required for the site to function (for example session integrity, security, and remembering your consent choices). These do not require consent.

Analytics and performance — tools such as Google Analytics 4 and session analytics that tell us how the site is used, in aggregate. Set only with your consent.

Advertising — pixels or tags from advertising platforms (for example Meta, Google Ads, or LinkedIn), which may be introduced in future. Set only with your consent, and treated as “sharing” under the CCPA/CPRA as described in Section 5.

Your choices are collected through the consent banner presented on your first visit, and you can change or withdraw them at any time via the “Cookie Settings” / “Your Privacy Choices” link in the site footer. We also honour the Global Privacy Control (GPC) signal: if your browser sends a GPC signal, we treat it as a valid request to opt out of any sale or sharing of your personal information for that browser.

5. How we disclose personal information — and whether we “sell” or “share” it

Service providers. We disclose personal information to service providers who process it on our behalf, under contracts that restrict their use of it to the services they provide to us. The categories of providers we use are: website hosting and infrastructure (Vercel); payment processing (Stripe); customer relationship management and marketing automation (HubSpot); email marketing (Klaviyo); analytics providers (Google Analytics; Microsoft Clarity); and professional advisers (legal, accounting) where required.

We do not sell personal information for money. We have not sold personal information in the preceding 12 months, and we do not sell or share the personal information of anyone we know to be under 16 years of age.

“Sharing” for advertising. The CCPA/CPRA also treats the disclosure of personal information to advertising platforms for cross-context behavioural advertising as “sharing,” even when no money changes hands. As at the effective date of this Policy we do not deploy advertising pixels. If and when we do, the categories shared would be internet and device activity and identifiers (such as hashed email or advertising identifiers), disclosed to the relevant advertising networks — and you can opt out at any time, before or after that point, in any of three ways: rejecting advertising cookies in the consent banner; using the “Your Privacy Choices — Do Not Sell or Share My Personal Information” link in the footer; or browsing with a GPC-enabled browser. An opt-out applies to the browser and device from which it is made.

Other disclosures. We may disclose personal information: to comply with law or valid legal process; to protect the rights, safety, or property of Kyber, our clients, or others; and in connection with a corporate transaction (merger, acquisition, financing, or sale of assets), in which case this Policy will continue to apply to the transferred information unless you are notified otherwise.

We do not disclose personal information to data brokers, and we do not permit our service providers to sell it.

6. How long we keep personal information

We keep personal information only as long as the purpose requires, then delete or de-identify it. Our criteria: enquiry and diagnostic records are kept while our conversation is live and for up to 24 months after last meaningful contact; account and subscription records are kept for the life of the account and up to 12 months after closure (except where a shorter deletion request applies); billing and tax records are kept for the period required by tax and company law (5–7 years); email marketing data is kept until you unsubscribe, after which we retain only the suppression record needed to honour your opt-out; analytics data is retained per the retention settings of the analytics tool (currently a maximum of 14 months in Google Analytics) or aggregated so it no longer identifies you.

7. Security

We apply technical and organisational measures appropriate to the risk, including encryption of data in transit (TLS), hashed credential storage, access controls on a least-privilege basis, segregated client instances for our intelligence product, and vendor due diligence on every processor listed above. No internet service can guarantee absolute security; if a breach occurs that creates a risk to you, we will notify you and the relevant regulator as applicable law requires (including section 22 of POPIA and Articles 33–34 of the GDPR).

8. International transfers

Kyber is based in South Africa and uses service providers based principally in the United States and the European Union, so your information will be transferred across borders. Wherever we transfer personal information internationally, we do so under lawful transfer mechanisms: for transfers out of the EEA/UK, the European Commission’s Standard Contractual Clauses (and the UK Addendum) or an adequacy decision, including reliance on the EU–US Data Privacy Framework where the receiving provider is certified; for transfers out of South Africa, section 72 of POPIA — the recipient is subject to a law, binding corporate rules, or a binding agreement providing substantially similar protection to POPIA, or the transfer is necessary to perform our contract with you or occurs with your consent.

9. Your California privacy rights (CCPA/CPRA)

This section applies to California residents. It supplements the rest of this Policy.

A note on applicability: the CCPA/CPRA formally binds businesses meeting statutory thresholds (such as USD 25 million in annual revenue or data on 100,000+ California residents). Kyber extends the rights below to California residents as a matter of policy regardless of whether we currently meet those thresholds.

Categories collected. In the preceding 12 months we have collected the categories described in Section 2, which map to the statutory categories as follows: Identifiers (name, email, IP address); Customer records (contact and billing information); Commercial information (services purchased or considered); Internet or other electronic network activity (usage and device data); Coarse geolocation (IP-derived, non-precise); Professional or employment-related information (company, role); Inferences (segments drawn from your diagnostic and engagement); and Sensitive personal information (account login credentials, used only for authentication). Sources, purposes, and recipients for each are as described in Sections 2, 3 and 5; retention criteria are in Section 6.

Sale and sharing. We do not sell personal information. We do not currently share personal information for cross-context behavioural advertising; if we adopt advertising pixels, the categories shared would be identifiers and internet activity, and the opt-out mechanisms in Section 5 — including the “Your Privacy Choices — Do Not Sell or Share My Personal Information” footer link and GPC signals — apply.

Your rights. Subject to verification and legal exceptions, you have the right to: know/access the personal information we hold about you, including the categories, sources, purposes, and recipients; delete personal information we collected from you; correct inaccurate personal information; opt out of any sale or sharing of personal information; limit the use of sensitive personal information (not applicable in practice, because we use login credentials only for the exempt purpose of authentication); and non-discrimination — we will never deny you services, charge different prices, or provide a different level of service because you exercised a privacy right.

How to exercise them. Email privacy@kyber.cc with the subject line “Privacy Request,” or use the contact form at kyber.cc. As a business operating exclusively online with a direct relationship with the consumers whose information we collect, we designate email as our primary request method. We will confirm receipt within 10 business days and respond within 45 calendar days, extendable once by a further 45 days with notice. To verify your identity we will match the information you provide against what we hold — typically by confirming control of the email address on file; we will never ask for more information than verification requires. You may use an authorised agent to submit a request on your behalf; we will ask for your signed permission and may still verify your identity directly. Opt-out requests (sale/share) are honoured without verification.

Shine the Light. California Civil Code §1798.83 permits California residents to request information about disclosures of personal information to third parties for those parties’ direct marketing purposes. We do not make such disclosures.

10. Your European Economic Area, UK, and Swiss rights (GDPR)

If you are in the EEA, the United Kingdom, or Switzerland, you have the right to: access your personal data and receive a copy; rectify inaccurate data; erase data (“right to be forgotten”); restrict processing; data portability (receive data you provided in a structured, machine-readable format); object to processing based on legitimate interests, including direct marketing, at any time; and withdraw consent at any time where processing is based on consent, without affecting prior processing.

To exercise any of these, email privacy@kyber.cc. We will respond within one month, extendable by two further months for complex requests, with notice. We do not require a fee unless a request is manifestly unfounded or excessive. You also have the right to lodge a complaint with your local supervisory authority — a list is available at edpb.europa.eu — though we would welcome the chance to resolve your concern directly first.

11. Your South African rights (POPIA)

Kyber (Pty) Ltd is the responsible party under POPIA. Our Information Officer can be reached at privacy@kyber.cc.

Under POPIA you have the right to: be notified that your personal information is being collected (this Policy, and our consent banner, serve that purpose); access the personal information we hold about you, as also provided for by the Promotion of Access to Information Act 2 of 2000 (PAIA); request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, or unlawfully obtained; object to processing based on legitimate interests, and to direct marketing; not be subject to a decision based solely on automated processing that has legal or similarly significant effects; and complain to the Information Regulator:

The Information Regulator (South Africa) — JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 — complaints.IR@inforegulator.org.za inforegulator.org.za.

Where we send direct marketing by electronic communication to prospects in South Africa, we do so within section 69 of POPIA — either with your consent (which we request once) or to existing customers for similar services, always with a working opt-out.

12. Children

Our Services are business tools directed at working professionals. They are not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact privacy@kyber.cc and we will delete it.

13. Changes to this Policy

When we change this Policy, we will update the “Last updated” date above, and for material changes we will give notice on the website or by email before the change takes effect. Archived versions are available on request.

14. Contact us

Kyber (Pty) Ltd (Registration number K2025930256)
17 Dock Road, V&A Waterfront, Cape Town, 8001
Email: privacy@kyber.cc

For any privacy question, request, or complaint under any of the laws above, privacy@kyber.cc is the fastest route and reaches our Information Officer directly.