Privacy Policy

Effective Date: February 2, 2026

1. Introduction

Cytracom, LLC ("Cytracom," "Company," "we," "us," or "our") provides unified communications, networking, cybersecurity, and compliance solutions, including UCaaS, ControlOne, Unity, Tentacle, and Telivy (collectively, the "Services"). This Global Privacy Policy ("Policy") explains how Cytracom collects, uses, discloses, retains, and protects Personal Information across all Cytracom-owned products, platforms, websites, applications, and services.

This Policy supersedes and replaces all prior privacy policies issued by Cytracom, LLC, Tentacle LLC, and Telivy, Inc.

By accessing or using any Cytracom product, website, application, or service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree to this Policy, please do not access or use our Services.

This Policy applies to Customers, Resellers, Authorized Users, Visitors, and any individual who interacts with the Services, regardless of geographic location.

2. Definitions

       "Personal Information" or "Personal Data" means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with an identified or identifiable natural person or household.

       "Customer Data" means any information that Customers provide or otherwise make available to Cytracom.  “Customer Personal Data” means the subset of Customer Data that is Personal Information submit to Cytracom, generate through their use of the Services, or provide through integrations with third-party systems.

       "Sensitive Personal Information" means categories of Personal Information as defined under applicable privacy laws as requiring heightened protection, including but not limited to unique government issued identifiers such as social security numbers or passports or drivers’ license numbers, financial account information including access/log-in credentials, precise geolocation data, contents of mail, email, or text messaging communications, and information revealing racial or ethnic origin, citizenship or immigration status, religious beliefs, or health information.

       "Processing" means any operation or set of operations performed on Personal Information, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.

       "Subprocessor" means any third party engaged by Cytracom to process Personal Data on our behalf in connection with the Services.

       "Data Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.

       "Data Processor" means a natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Data Controller.

       "Services" means all Cytracom products and platforms, including UCaaS (unified communications as a service), ControlOne, Unity, Tentacle (risk and compliance platform), and Telivy (vulnerability and exposure platform), as well as associated websites, mobile applications, integrations, and plugins.

3. Information We Collect

Cytracom collects only the information reasonably necessary to provide, secure, improve, and support the Services. The categories of information we collect depend on how you interact with our Services.

3.1 Identifiers and Contact Information

       Name (first, last, and/or middle)

       Business email address

       Business phone number

       Account usernames and unique identifiers

       Company or organization name

       Job title and department

3.2 Account and Profile Information

       Business addresses (billing and service locations)

       Contact lists and directories submitted by Customers

       Login credentials (passwords stored in encrypted form)

       Security questions and answers

3.3 Telephony and UCaaS Metadata

Collected strictly to provide UCaaS services:

       Caller and callee phone numbers

       Transcription and summarization outputs (when features are enabled by Customer)

3.4 Device, Network, and Technical Information

       IP address

       Device ID, operating system, browser type and version

       Referrer/exit pages, clickstream data, and usage analytics

       ControlOne telemetry, routing logs, and network diagnostics

       Mobile operating system and device identifiers

       Geolocation data (only if explicitly enabled by user; approximate location may be derived from IP address)

       Mobile contacts and application data (only if explicitly authorized by user)

3.5 Payment and Billing Information

       Billing contact information

       Credit card or bank account data

       Tax identification numbers

       Transaction and payment history

3.6 Inferences

       Inferences drawn from our engagement, including security behavior

 

Note: Payment processing is performed by PCI-DSS compliant third-party processors, including Dwolla and Authorize.net. We do not store card holder data on our systems. For more information, see Dwolla's Privacy Policy.

3.7 Cookies and Tracking Technologies

Cytracom uses cookies, web beacons, pixels, scripts, and similar tracking technologies to:

       Authenticate users and maintain session state

       Remember user preferences and settings

       Analyze website traffic and usage patterns

       Improve site performance and user experience

       Measure the effectiveness of marketing campaigns

 

We categorize cookies as: (a) Essential cookies required for the Services to function; (b) Personalization cookies that remember choices you make (such as your username, language, or the region you are in) and provide enhanced, more personal features; (c) Targeted Advertising cookies used to deliver advertising that is more relevant to you and your interests. May also be used to limit the number of times you see an advertisement and measure the effectiveness of advertising campaigns; and (d) Analytics cookies that help us understand how visitors use our Services.

Do Not Track and Global Privacy Control: We honor Do Not Track (DNT) browser signals and Global Privacy Control (GPC) signals where technically feasible and required by applicable law.

A Cookie Management Platform (CMP) is available on our websites to allow you to manage your cookie preferences.  Please note that you may not opt-out of Essential cookies as they are necessary for the proper functioning of the Services.

3.8 Information from Other Sources

We may receive Personal Information from:

       Resellers and channel partners

       Identity providers and single sign-on (SSO) services

       Integration partners (CRM, messaging, productivity, and telephony platforms)

       Analytics and cloud service providers

       Public databases and commercially available sources

 

3.9 Personal Information Collected in the Past Twelve Months

We have collected the following categories of Personal Information in the past twelve (12) months:

·         Identifiers

·         Account and Profile Information

·         Device and Technical Information

·         Payment and Billing Information

·         Browsing History

·         Device History

·         Geolocation

·         Audio Recordings

·         Inference like security behavior

4. How We Use Personal Information

Cytracom uses Personal Information for the purposes: listed below.  For EEA/UK/Switzerland users, the legal basis(es) for processing is also identified.

Purpose

Legal Basis

Deliver, operate, maintain, and support the Services

 

Consent, Contract Performance, Legitimate Interests

Authenticate users and manage account access

Contract Performance, Legitimate Interests

Enable UCaaS calling, routing, messaging, and collaboration features

 

Contract Performance, Legitimate Interests

Detect, prevent, investigate, and mitigate security threats, fraud, and abuse

 

Contract Performance, Legitimate Interests

Monitor platform performance, reliability, and availability

 

Legitimate Interests

Improve product functionality, features, and user experience

 

Legitimate Interests

Provide customer support and respond to inquiries

 

Contract Performance, Legitimate Interests

Process billing, payments, and financial transactions

 

Contract Performance

Comply with legal and regulatory obligations

 

Legal Obligation, Legitimate Interests

Enable Customer-approved third-party integrations

 

Consent, Contract Performance

Conduct research and analytics to improve our Services

 

Legitimate Interests

Send marketing communications about products and services

 

Consent

Enforcing or defending our legal rights and interests

 

Legal Obligation, Legitimate Interests

Send service-related communications, updates, security alerts

Contract Performance

 

 

Important: Cytracom does not use Customer Data to train general-purpose artificial intelligence or machine learning models. See Section 6 (AI Usage and Governance) for details on how AI is used within our Services.

5. AI Usage and Governance

Cytracom incorporates artificial intelligence (AI) technologies to enhance certain features of our Services:

5.1 AI Features by Service

       ControlOne: Report and threat summarization

       UCaaS: Real-time transcription, call summarization, and noise reduction

       Telivy: Vulnerability scoring, risk classification, and prioritization

       Tentacle: Compliance framework mapping, evidence analysis, and document categorization

5.2 AI Governance Commitments

Cytracom is committed to responsible AI use. We do NOT:

       Train foundation models or general-purpose AI systems using Customer Data

       Sell, license, or provide Customer Data to AI vendors for their model training purposes

       Use AI for fully automated decision-making that produces legal or similarly significant effects without human oversight

       Use AI features to discriminate based on protected characteristics

For detailed information about our AI practices, please refer to our separate Responsible AI Disclosure document available the Trust Center linked below.

6. How We Share Information

Cytracom does not sell Personal Information. We do not share Personal Information for cross-context behavioral advertising purposes.

6.1 Subprocessors and Service Providers

We engage trusted third parties to help us operate and deliver the Services, including:

       Cloud hosting and infrastructure providers

       Telecommunications carriers and network providers

       AI compute and processing providers

       Customer support and ticketing systems

       CRM and sales platforms

       Analytics and logging platforms

       Payment processors (Autorize.net, Dwolla)

All Subprocessors are contractually bound to process Personal Data only as instructed and to maintain appropriate security measures. A current list of Subprocessors is maintained the Trust Center linked below.

6.2 Customer-Enabled Integrations

Cytracom exchanges limited data with third-party applications only when Customers explicitly enable integrations (e.g., CRM systems, productivity suites, other telephony platforms). Data shared through integrations is governed by both this Policy and the third party's privacy policy.

6.3 Resellers and Channel Partners

We may share Customer account information and usage data with our authorized Resellers who introduced you to our Services, solely for the purpose of supporting your account and the Reseller relationship.

6.4 Legal and Security Disclosures

We may disclose Personal Information to law enforcement and other first responders, regulatory agencies, the judiciary, or parties involved in legal proceedings with us when we believe in good faith that disclosure is necessary to:

       Comply with applicable law, regulation, legal process, or governmental request

       Enforce our agreements, including Terms of Service

       Protect the rights, property, or safety of Cytracom, our users, or others

       Detect, prevent, or address fraud, security, or technical issues

       Respond to an emergency involving danger of death or serious physical injury

6.5 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, Personal Information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our website of any change in ownership or uses of your Personal Information, as well as any choices you may have.

 

6.6 Entities We Have Disclosed Personal Information to in the Past Twelve Months

 

In the past twelve (12) months, we have disclosed the Personal Information we have collected to the following categories of entities:

 

·         Subprocessors and Service Providers

·         Third Parties Providing Customer-Enabled Integrations

·         Resellers and Channel Partners

 

7. Customer Responsibilities

Customers who use our Services are responsible for:

       Ensuring they have a lawful basis (such as consent or contractual necessity) for any Personal Data they upload or process through the Services

       Managing user authentication, roles, permissions, and access controls

       Configuring security and privacy settings appropriately for their use case

       Securing user credentials, devices, and endpoints

       Approving, configuring, and managing third-party integrations

       Complying with applicable laws regarding their collection and use of Personal Data

       Providing required notices to, and obtaining necessary consents from, their end users

8. SMS Texting Privacy (10DLC Compliance)

8.1 Explicit Non-Sharing of Information

We do not share mobile opt-in information with any third parties for marketing or sales purposes.

8.2 SMS Opt-Out Instructions

If you no longer wish to receive text messages from us, you can opt out at any time by replying with the word 'STOP' or 'UNSUBSCRIBE' – which you agree are the only reasonable phrases to withdraw your consent – to the number from which you received the message. Upon receiving your request, we will remove you from our messaging list, and you will no longer receive further text communications from us.

9. Data Retention

We retain Personal Information only as long as reasonably necessary for:

       The duration of your Customer relationship with us

       Providing the Services you have requested

       Security monitoring, incident response, and audit requirements

       Compliance with legal, regulatory, tax, accounting, or reporting obligations

       Establishing, exercising, or defending legal claims

Customer Data is deleted upon verified Customer request, subject to any legal retention requirements. Backup copies may be retained for a limited period in accordance with our backup retention schedule.

10. Data Security

Cytracom maintains a comprehensive information security program that includes:

       Encryption of data in transit (TLS 1.2+) and at rest (AES-256)

       Multi-factor authentication (MFA) for administrative access

       Role-based access control (RBAC) and least privilege principles

       Network segmentation and firewall protections

       Continuous monitoring, intrusion detection, and security logging

       Vulnerability management and penetration testing

       Secure software development lifecycle (SDLC) practices

       Employee security awareness training

       Incident response and business continuity planning

 

Certifications: Cytracom maintains SOC 2 Type II, PCI DSS, and HIPAA Type 1 compliance. Current attestation reports and certifications are available through our Trust Center (link below).

11. International Data Transfers

Cytracom is headquartered in the United States. The majority of our data processing occurs within the United States. For Tentacle services, certain processing may also occur within the European Union region.

11.1 Transfers from the EEA, UK, and Switzerland

When we transfer Personal Data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we rely on appropriate safeguards, including: (a) Standard Contractual Clauses (SCCs) approved by the European Commission; (b) the UK International Data Transfer Agreement or Addendum, as applicable; and (c) supplementary measures where required. You may request a copy of these safeguards by contacting us at privacy[at]cytracom.com.

By using our Services, you acknowledge and consent to the transfer, processing, and storage of your Personal Data in the United States and other countries where our Subprocessors operate, subject to the safeguards described above.

12. Your Privacy Rights

12.1 Rights for All Users

Regardless of your location, you may opt-out of marketing communications at any time.  You may unsubscribe from emails by following the instructions in the email or reply to a text message with the word “stop” or “unsubscribe.”  

Depending on your location, the laws of different jurisdictions may provide different privacy rights.

12.2 California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

       Right to Know: Request disclosure of the categories and specific pieces of Personal Information we have collected, the sources, purposes of collection, and categories of third parties with whom we share it.

       Right to Delete: Request deletion of your Personal Information, subject to certain exceptions.

       Right to Correct: Request correction of inaccurate Personal Information.

       Right to Limit Use of Sensitive Personal Information: Direct us to limit the use and disclosure of Sensitive Personal Information to purposes necessary to perform the Services.

       Right to Opt-Out of Sale/Sharing: Cytracom does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising.

       Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

 

California Shine the Light: Under California Civil Code Section 1798.83, California residents may request information about the disclosure of Personal Information to third parties for direct marketing purposes. Cytracom does not disclose Personal Information to third parties for their direct marketing purposes.

12.3 European / United Kingdom / Swiss Privacy Rights

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) or the Swiss Federal Act on Data Protection equivalent legislation:

       Right of Access: Obtain confirmation of whether we process your Personal Data and access to that data.

       Right to Rectification: Request correction of inaccurate or incomplete Personal Data.

       Right to Erasure: Request deletion of your Personal Data in certain circumstances ("right to be forgotten").

       Right to Restriction: Request restriction of processing of your Personal Data in certain circumstances.

       Right to Data Portability: Receive your Personal Data in a structured, commonly used, machine-readable format and transmit it to another controller.

       Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.

       Rights Related to Automated Decision-Making: Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects, with certain exceptions.

       Right to Withdraw Consent: Where processing is based on consent, withdraw that consent at any time.

       Right to Lodge a Complaint: Lodge a complaint with your local supervisory authority if you believe your rights have been violated.

12.4 How to Exercise Your Rights

To exercise any of the rights described above, please submit a request either (a) by email to privacy[at]cytracom.com and specify the right you wish to exercise in the subject line (e.g. ”CA Right to Data Portability”); or (b) by webform by following the webform URL linked to this policy or (c) by calling us at (888)232-9530. We may need to verify your identity before processing your request, including by matching your information to Personal Information we may hold about you. If you are making a request on behalf of another person, we may require proof of authorization. 

We will respond to verified requests within the timeframes required by applicable law (generally 30-45 days). If we need additional time to respond to your request, we may extend the time by another 30-45 days, depending on the applicable law. We will inform you of the reason prior to the expiration of the initial time frame. 

Please note that the rights may be conditional, and we may not be able to fulfil every request. If we determine that we are unable to fulfil your request, we will inform you of the reason for our decision and provide a way for you to appeal the decision.

13. Children's Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect Personal Information from children and have no actual knowledge of having collected any Personal Information from anyone under the age of 16. If we learn that we have collected Personal Information from a child without proper parental consent, we will take steps to delete that information as soon as possible. If you believe we have collected information from a child, please contact us at privacy[at]cytracom.com.

14. Links to Third-Party Websites and Services

Our Services may contain links to third-party websites, applications, or services. We do not control the operations of these third-party websites and services, and this Privacy Policy does not apply to those them. We are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party website you access and third-party service you use to understand how they may be collecting, using, and sharing your Personal Information.

15. Do Not Track Policy (CalOPPA)

Do Not Track ("DNT") is a privacy preference that users can set in certain web browsers. We honor DNT signals and Global Privacy Control (GPC) signals where required by applicable law. Some third-party websites that link to our Services may track your browsing activity. If you visit such websites, you may set your browser preferences to inform those websites that you do not wish to be tracked.

16. Changes to This Privacy Policy

Cytracom may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. We will post the updated Policy on our website with a revised "Effective Date." For material changes, we will provide notice through the Services interface, by email, or by other means as required by applicable law. We encourage you to periodically review this Policy. The changes are effective when posted.  Your continued use of the Services after the effective date of any changes constitutes your acceptance of the revised Policy.

17. Contact Information

If you have questions, concerns, or complaints about this Privacy Policy or our privacy practices, please contact us:

Cytracom, LLC

7300 State Highway 121 Access Rd, Suite 800

McKinney, TX 75070

United States

Email: privacy[at]cytracom.com

Trust Center: https://trust.cytracom.com

18. EU/EEA & UK GDPR Representatives (Article 27)

 

If you are located in the EU or UK and have questions or concerns regarding your personal data, you may contact our appointed GDPR representative:

 

EU Representative:

Euverify Ltd (Ireland)

Unit 3D North Point House

North Point Business Park

New Mallow Road, Cork

T23 AT2P, Ireland

Email: gdpr@euverify.com

 

UK Representative:

Euverify Ltd (UK)

3rd Floor

86-90 Paul Street

London, EC2A 4NE

United Kingdom

Email: gdpr@euverify.com

 

To submit a Data Subject Access Request (DSAR), data deletion request, or any other GDPR-related inquiry, please use our secure portal. This link allows you to verify our appointed representative and submit GDPR requests directly. Requests submitted through this portal are logged and tracked to ensure timely response and compliance.