Privacy
Privacy Policy
Last updated: 2026-07-25
This policy describes how MEDIA SMART, publisher of CyberLex, collects, uses and protects your personal data. It is drawn up in accordance with Law 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data, as amended by Law 25-11 of 24 July 2025, and the regulations of the National Authority for the Protection of Personal Data (ANPDP). The French version is the reference version.
1. Data controller
The data controller is MEDIA SMART, publisher of the CyberLex platform and the Lexy AI module.
Address: Algiers, Algeria (to be confirmed).
Contact: contact@cybrlex.com.
2. Legal framework
The processing of your personal data is governed by:
Law 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data, as amended by Law 25-11 of 24 July 2025;
the normative acts of the National Authority for the Protection of Personal Data (ANPDP).
The processing has been the subject of a prior declaration to the ANPDP, in accordance with Article 12 of Law 18-07.
3. Data we collect
We distinguish data you give us voluntarily from data collected automatically.
- Data you provide: email address, profession, organisation size, working language, research frequency, pain point, wilaya (self-declared, optional).
- Data collected automatically: IP address (hashed, never stored in clear), browser, operating system, device type, pages viewed, time on page, referrer, UTM parameters, browser language, timezone.
4. Purposes and legal basis
Each processing purpose is mapped to a legal basis (consent or legitimate interest):
Waitlist signup and confirmation email: consent (acceptance of this policy).
Product improvement and news/offers: explicit, optional and revocable consent (separate checkbox).
Anonymous and pseudonymous audience measurement: legitimate interest in understanding platform usage, subject to your choice via the consent banner.
Email open and click tracking: explicit marketing consent, separate from policy acceptance. Recipients who declined this consent receive a byte-identical email with no tracking pixel.
Responding to rights-exercise requests: legitimate interest and legal obligation.
6. Email tracking
When you have explicitly granted marketing consent, our emails may include a transparent pixel and tracked links to measure open and click rates. This data is stored server-side, linked to your user identifier, and retained in accordance with the retention table in section 9.
You can withdraw this tracking at any time: by unticking the marketing consent box in the form, via the unsubscribe link in every email, or by writing to contact@cybrlex.com. Recipients who did not grant this consent receive a byte-identical email with no pixel and no tracked link.
Note: Apple Mail Privacy Protection and Gmail's image proxy pre-fetch images, which may artificially inflate open rates. Our statistics are therefore directional, not exact.
7. Recipients of the data
Your data is accessible to:
MEDIA SMART, as data controller;
Resend, a transactional email provider based in the United States (see section 8);
our hosting provider (Algeria/European Union) for database storage and operation.
No data is sold or transferred to any third party for commercial purposes.
8. International transfers
Sending confirmation emails via Resend involves transferring the recipient's email address to the United States. This transfer is covered by the appropriate safeguards under Article 36 of Law 18-07 and by the processing contract concluded with Resend, acting as a processor.
Other personal data is hosted within our infrastructure (Algeria/European Union) and is not transferred outside that zone.
9. Retention periods
Your data is retained for the following periods, calculated from collection:
- Page views and analytics events: 14 months, then deleted.
- Sessions: 14 months, then aggregated to daily counts and deleted.
- Visitors not linked to a signup: 14 months.
- Waitlist users (EarlyUser): until platform launch plus 24 months, or until erasure is requested.
- Consent records and admin audit log: 5 years (proof of compliance).
10. Security measures
We apply the following technical and organisational measures:
TLS encryption of all communications;
password hashing with argon2;
IP address hashing (SHA-256 + server-side pepper) — the raw IP is never persisted;
administration access protected by password, mandatory TOTP 2FA, and restricted to authorised accounts;
least-privilege principle, logging of administrative actions.
11. Your rights
In accordance with Article 38 of Law 18-07, you have the following rights over your personal data:
right of access;
right to rectification;
right to erasure;
right to object;
right to withdraw consent;
right to data portability.
To exercise these rights, write to contact@cybrlex.com specifying the email address concerned. We respond within a maximum of 30 days. You may also lodge a complaint with the ANPDP.
12. Minors
CyberLex is a service for legal professionals and is not directed at persons under 18. We do not knowingly collect data relating to minors.
13. Changes to this policy
This policy may be changed. Each version is identified by a policyVersion string (shown at the top of the page). In the event of a material change, fresh consent will be requested. The last-updated date is shown at the top of this page.
14. Contact
For any question relating to this policy or the processing of your data: contact@cybrlex.com.
15. Disclaimer
CyberLex and Lexy AI provide legal information, not legal advice. The content does not constitute legal advice and is not a substitute for consulting a legal professional.
