Privacy Policy

Last Updated: 06 Sep, 2026

This Privacy Policy explains how Royal Cyber Inc. and its affiliates (“Royal Cyber,” “we,” “us,” “our”) collect, use, disclose, and protect personal data when you visit customersax.com or use the CustomerSAX platform and related services (the “Service”).

CustomerSAX is a product of Royal Cyber Inc. We are committed to complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and other regional privacy regulations.

‍

1. Scope and Our Role

This policy applies to customersax.com, the CustomerSAX application, and any associated support, trial, and demo environments.

‍

Our role depends on the data:

  • As a data controller, we determine why and how data is processed when you browse our website, submit a form, register for a demo or webinar, subscribe to communications, or create and administer a CustomerSAX account.
  • As a data processor, we handle personal data that our business customers upload to, or generate within, the CustomerSAX platform. In those cases the customer is the controller, processing is governed by our customer agreement and Data Processing Addendum (DPA), and we act only on documented instructions. If you are an end user or employee of one of our customers, direct your privacy requests to that organization; see Section 5.

2. Personal Data We Collect

‍

Directly provided data

Name, business email, job title, company, and phone number — used for account creation, contact and demo requests, and event registration.

‍

Account and authentication data

Username, hashed credentials, SSO identifiers, role and permission settings, and MFA status — used to provision access, authenticate users, and secure accounts.

‍

Service usage data

Feature usage, session activity, configuration changes, and audit logs — used to deliver the Service, provide support, monitor security, and improve the product.

‍

Automatically collected data

IP address, browser type, device and operating system, referring URL, pages viewed, and timestamps — used for site performance, security, and analytics.

‍

Cookie-based data

Described in our Cookie Policy — used for analytics, personalization, advertising, and CRM integration.

‍

Marketing and CRM data

Form submissions, campaign source, ad clicks, referrals, and content downloads — used for lead generation, campaign attribution, and communications.

‍

Billing and contract data

Billing contact, purchase order and invoice details, and subscription tier — used for contract administration, invoicing, and tax and accounting obligations.

‍

Support data

Ticket contents, correspondence, and any diagnostic information you share — used to resolve support requests.

Full details on cookies, pixels, and similar technologies are in our Cookie Policy.

‍

3. Legal Basis for Processing

‍

Where GDPR or similar law applies, we process personal data on one or more of these bases:

  • Your consent, for example for marketing communications and non-essential cookies
  • Performance of a contract with you or your organization
  • Compliance with legal obligations
  • Our legitimate interests, including securing the Service, preventing fraud and abuse, improving our products, and conducting business-to-business marketing — balanced against your rights and interests

‍

4. How We Use Personal Data

‍

  • Provide, operate, maintain, and secure the CustomerSAX platform
  • Create and administer accounts, authenticate users, and manage permissions
  • Respond to inquiries, demo requests, and support tickets
  • Register and manage participation in webinars, trials, and events
  • Send service notices, product updates, and — where you have consented or we are otherwise permitted — marketing communications
  • Analyze aggregate usage to improve performance, reliability, and functionality
  • Integrate marketing data with our CRM and marketing systems, such as Microsoft Dynamics 365
  • Deliver and measure advertising on platforms such as LinkedIn and Meta
  • Detect, investigate, and prevent security incidents, fraud, and misuse
  • Process billing and meet legal, tax, and regulatory obligations

‍

5. Customer Data Processed Within the Platform

‍

When a customer uses CustomerSAX, personal data belonging to that customer’s own customers, employees, or end users may be processed in the platform — for example, contact records, conversation transcripts, case notes, or attachments.

For this data:

  • The customer is the controller and decides what data enters the platform, how long it is kept, and who may access it.
  • Royal Cyber is the processor and acts only on the customer’s documented instructions, under our customer agreement and DPA.
  • We do not use this data for our own marketing, and we do not sell or share it.
  • If you are an individual whose data is held in a customer’s CustomerSAX workspace and you want to access, correct, or delete it, please contact that organization directly. If you contact us instead, we will refer your request to the relevant customer and support them in responding.

‍

6. AI and Automated Processing

‍

CustomerSAX uses artificial intelligence and machine learning to [summarize interactions, suggest responses, classify and route requests, and generate insights — adjust to your actual feature set].

  • Model training. We do not use customer data to train, fine-tune, or improve foundation models for the benefit of other customers or third parties, unless a customer has expressly agreed in writing.
  • Third-party model providers. Where the Service relies on third-party AI providers, data sent for inference is governed by agreements that restrict use to providing the service and prohibit training on that data. Our current AI subprocessors are listed at [subprocessor page URL].
  • Human oversight. AI outputs are intended to assist rather than replace human judgment. We do not use the Service to make decisions that produce legal or similarly significant effects about individuals without human involvement. Where such processing occurs under a customer’s configuration, that customer is responsible for meeting the applicable requirements.
  • Accuracy. AI-generated output may be incomplete or incorrect and should be reviewed before being relied upon.

‍

7. Cookies and Tracking Technologies

We use cookies, pixels, and local storage to understand site usage, personalize content, and measure marketing performance. These include tools such as Google Analytics 4, Meta Pixel, LinkedIn Insight Tag, and CRM-linked trackers.

Product analytics tools used inside the authenticated application are limited to operating and improving the Service and are described in our Cookie Policy.

You can manage your preferences through our cookie banner or your browser settings.

‍

8. Data Sharing, Subprocessors, and International Transfers

‍

We may share personal data with:

  • Royal Cyber global affiliates and subsidiaries
  • Cloud hosting and infrastructure providers [specify]
  • AI and model-inference providers [specify]
  • CRM, marketing, analytics, and support platforms
  • Payment and billing processors
  • Professional advisors, auditors, and legal or regulatory authorities where required
  • An acquirer or successor in the event of a merger, acquisition, or asset sale

‍

A current list of subprocessors used to deliver the Service is maintained at [subprocessor page URL]. Customers may subscribe to notifications of changes as described in the DPA.

We do not sell personal data, and we do not share it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.

Personal data may be transferred to and processed in the United States and other countries where we or our providers operate. For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary technical and organizational safeguards.

Service data is hosted in [region(s)]. Customers with data residency requirements should contact us at [email] to discuss available options.

‍

9. Security

‍

We apply industry-standard technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, and loss. These include encryption in transit and at rest, role-based access control, network segmentation, logging and monitoring, vulnerability management, employee security training, and periodic audits and penetration testing.

[If you hold SOC 2, ISO 27001, or similar certifications, name them here.]

No method of transmission or storage is completely secure. If a breach affecting your personal data occurs, we will notify affected parties and regulators as required by applicable law.

‍

10. Data Retention

‍

We retain personal data only as long as necessary for the purposes described in this policy, or as required by law.

  • Website and marketing data: retained for [X] months after last engagement, or until you unsubscribe or object
  • Account data: retained for the duration of the subscription and [X] days afterward
  • Customer data in the platform: retained according to the customer’s configuration and contract, and deleted or returned within [X] days of termination, as set out in the DPA
  • Billing and transaction records: retained as required by tax and accounting law
  • Security and audit logs: retained for [X] months

‍

11. Your Rights

‍

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your data
  • Withdraw consent at any time, without affecting prior processing
  • Object to direct marketing or to processing based on legitimate interests
  • Restrict processing in certain circumstances
  • Request portability of data you provided to us
  • Opt out of the sale or sharing of personal data, and limit the use of sensitive personal information (California)
  • Be free from discrimination for exercising these rights
  • Lodge a complaint with your local supervisory authority

To exercise any of these rights, email [privacy@customersax.com] or dpo@royalcyber.com. We will verify your identity before acting and respond within the timeframe required by applicable law. You may use an authorized agent where the law permits.

‍

12. Children’s Privacy

‍

CustomerSAX is a business product and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

‍

13. Changes to This Policy

‍

We may update this Privacy Policy from time to time. Material changes will be posted here with a revised “Last Updated” date and, where required, communicated directly. Continued use of the Service after an update constitutes acceptance of the revised policy.

‍

14. Contact Us

‍

Royal Cyber Inc.
55 Shuman Blvd, Suite #275
Naperville, IL 60563, USA
Phone: +1.630.355.6292

General inquiries: [info@customersax.com]
Privacy requests: [privacy@customersax.com]
Data Protection Officer: dpo@royalcyber.com

[EU/UK representative under GDPR Article 27, if you have EEA or UK users.]

All disputes arising from this policy are subject to the jurisdiction of the courts of Illinois, USA.

‍

Unlock your AI Sales Super Powers