How Cypher Capital Technology LLC collects, uses, stores and shares personal data in connection with Strata.
This Privacy Policy explains how Cypher Capital Technology LLC (“CCT”, “we”, “us” or “our”) collects, uses, stores, shares and otherwise processes personal data in connection with Strata, an artificial-intelligence workplace assistant (the “Service”). CCT is the data controller responsible for the personal data processed through the Service.
Strata is currently provided to authorised personnel of Cypher Capital, Storm Group and their affiliated entities (the “Group”). Users access the Service using an organisational account and may connect the Service to third-party tools they are authorised to use. By accessing the Service and connecting these tools, you acknowledge the practices described in this Policy.
We process personal data in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”). Where users or data subjects are located in the European Economic Area, the United Kingdom, Switzerland or the United States, the additional regional rights and disclosures in Section 12 also apply. We also comply with the requirements of the platforms we integrate with, including the Google API Services User Data Policy (Section 7).
Controller: Cypher Capital Technology LLC
Privacy contact: legal@cyphercapital.com
We collect and process the following categories of personal data:
We do not intentionally collect special categories of personal data through the Service. Please do not submit such data unless it is necessary and lawful to do so.
We use personal data to provide the Service's features (meeting intelligence and search, tracking of action items and decisions, calendar and meeting preparation, drafting and sending communications at your direction, CRM and deal tracking, reporting, and creating or updating documents and records); to personalise the Service to you (including through the memory feature); to operate, secure, maintain and improve the Service; and to comply with our legal and regulatory obligations.
Legal bases. Under Article 4 of the PDPL we rely on your consent and on the processing being necessary for the arrangement under which the Service is provided. For data subjects to whom the GDPR or UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|
| Providing and operating the Service to you and your organisation | Performance of a contract; legitimate interests |
| Personalisation, security, maintenance and improvement | Legitimate interests (running and securing the Service) |
| Connecting Google and third-party tools and processing their data | Consent (granted via OAuth and the connection settings) |
| Legal, regulatory and compliance obligations | Compliance with a legal obligation |
Automated writes and actions — for example, creating or updating records, or sending messages — require your explicit approval before they are executed.
We share personal data with the service providers and sub-processors that host and operate the Service and provide its integrated functionality. Our current sub-processors are:
| Recipient | Purpose | Primary location |
|---|---|---|
| Cloud hosting and infrastructure provider | Hosting and infrastructure | United States |
| Google LLC (incl. Gemini) | Workspace integration; meeting transcription and notes | United States |
| Anthropic (Claude) | Language processing that generates the Service's responses | United States |
| Twenty | CRM / deal data integration | United States |
| Notion Labs | Workspace pages integration | United States |
| Telegram; Slack | Messaging integration (where connected) | United Arab Emirates (Telegram); United States (Slack) |
An up-to-date list of sub-processors is maintained at cypher.strata.mosaicsolutions.ai/subprocessors, and is also available on request from legal@cyphercapital.com. We also share personal data with other authorised users within your organisation (subject to the visibility settings available to you); with professional advisers, regulators and authorities where required or permitted by law; and with a successor entity in connection with a merger, acquisition or sale of assets. We do not sell personal data, and we do not share personal data for cross-context behavioural advertising.
Strata's access to, and use, storage and sharing of, information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
Restricted-scope Google data, such as Gmail data, is used solely to deliver the Service's features to you and is handled in accordance with these commitments.
The Service relies on third-party artificial-intelligence providers to deliver its features, including Google (Gemini) for meeting transcription and note generation and Anthropic (Claude) for the language processing that generates the Service's responses. When you submit a query, or the Service prepares an output, relevant content is transmitted to these providers solely to generate the response or feature you have requested.
We do not use your content — including your Google user data and your meeting content — to develop, train or improve generalised or non-personalised artificial-intelligence or machine-learning models, we do not train our own models on your content (including on de-identified content), and we contractually prohibit our artificial-intelligence providers from using your content to train or improve their own models.
Automated writes and actions require your explicit approval before they are executed.
The Service and certain of our sub-processors operate outside the UAE, including in the United States. Where we transfer personal data outside the UAE, we do so in accordance with the PDPL, relying on your consent and/or the other bases permitted under the PDPL, with contractual and organisational safeguards.
Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards, principally the European Commission's Standard Contractual Clauses (together with the UK International Data Transfer Addendum and the Swiss addendum, as applicable), supported by additional measures where required.
We retain personal data only for as long as necessary for the purposes described in this Policy or as required by law. Indicative retention periods:
| Category | Retention |
|---|---|
| Account and profile data | For the duration of your authorisation, then deleted within 30 days of account closure |
| Google Workspace data | Only while your Google account is connected; access ceases and cached data is purged on revocation |
| Meeting transcripts, notes and action items | No longer than 24 months, unless you delete them sooner |
| Usage and technical logs | Up to 12 months |
| Memory data | Until you clear it, or when your account is closed |
You may disconnect integrations or revoke the Service's access to your Google account at any time through your Google Account settings or the Service's connection settings; on revocation, the Service will cease further access to the relevant data.
We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration and loss, including access controls, encryption of data in transit and at rest, and approval gating of automated actions. We maintain procedures to address personal-data breaches and will notify affected parties and regulators where required by law. No system can be guaranteed to be completely secure.
Subject to the PDPL, you have the right to: be informed about and access your personal data (Article 13); receive it in a structured, machine-readable format (Article 14); request correction or erasure (Article 15); request restriction of, or that we stop, processing (Articles 16 and 17), including objecting to direct marketing; object to decisions based solely on automated processing that produce legal consequences (Article 18); and withdraw consent at any time.
To exercise these rights, contact us at legal@cyphercapital.com. You may also lodge a complaint with the UAE Data Office.
If you are in the EEA, the UK or Switzerland, you have the rights to access; rectification; erasure; restriction of processing; data portability; to object to processing based on our legitimate interests and to direct marketing; and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Where we rely on consent, you may withdraw it at any time without affecting prior processing. We aim to respond within one month. You also have the right to lodge a complaint with your local supervisory authority. The legal bases for our processing are set out in Section 4 and our transfer safeguards in Section 9.
We do not “sell” your personal information, and we do not “share” it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act (as amended) and comparable state laws. The categories of personal information we process are described in Section 3 (identifiers, professional or employment-related information, commercial information, internet or electronic activity, and inferences). Subject to applicable law, you have the rights to know/access, delete, and correct your personal information; to opt out of sale, sharing and targeted advertising; to non-discrimination for exercising your rights; and to appeal a decision. You may use an authorised agent. To exercise these rights, contact us at legal@cyphercapital.com.
The Service is intended for use by authorised business users and is not directed to children.
We may update this Policy from time to time. If we change the way we use Google user data, we will notify affected users and obtain their consent to the updated Policy before using Google user data in the new way.
This Policy, and any matter arising out of or in connection with it, is governed by the laws of the United Arab Emirates as applied in the Emirate of Dubai. The regional provisions in Section 12 grant additional statutory rights to data subjects in the relevant jurisdictions and do not change the governing law of this Policy.