Back to home

Privacy

Privacy Policy

Last updated: 2026-07-25

This policy describes how MEDIA SMART, publisher of CyberLex, collects, uses and protects your personal data. It is drawn up in accordance with Law 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data, as amended by Law 25-11 of 24 July 2025, and the regulations of the National Authority for the Protection of Personal Data (ANPDP). The French version is the reference version.

1. Data controller

The data controller is MEDIA SMART, publisher of the CyberLex platform and the Lexy AI module.

Address: Algiers, Algeria (to be confirmed).

Contact: contact@cybrlex.com.

3. Data we collect

We distinguish data you give us voluntarily from data collected automatically.

  • Data you provide: email address, profession, organisation size, working language, research frequency, pain point, wilaya (self-declared, optional).
  • Data collected automatically: IP address (hashed, never stored in clear), browser, operating system, device type, pages viewed, time on page, referrer, UTM parameters, browser language, timezone.

4. Purposes and legal basis

Each processing purpose is mapped to a legal basis (consent or legitimate interest):

Waitlist signup and confirmation email: consent (acceptance of this policy).

Product improvement and news/offers: explicit, optional and revocable consent (separate checkbox).

Anonymous and pseudonymous audience measurement: legitimate interest in understanding platform usage, subject to your choice via the consent banner.

Email open and click tracking: explicit marketing consent, separate from policy acceptance. Recipients who declined this consent receive a byte-identical email with no tracking pixel.

Responding to rights-exercise requests: legitimate interest and legal obligation.

5. Cookies and trackers

CyberLex places analytics and session cookies only after your consent via the consent banner. Strictly necessary cookies (remembering your choice, your waitlist signup) are placed without consent, in accordance with Article 30 of Law 18-07.

The full list of cookies, their purpose, lifetime and type is set out in our dedicated Cookie Policy.

6. Email tracking

When you have explicitly granted marketing consent, our emails may include a transparent pixel and tracked links to measure open and click rates. This data is stored server-side, linked to your user identifier, and retained in accordance with the retention table in section 9.

You can withdraw this tracking at any time: by unticking the marketing consent box in the form, via the unsubscribe link in every email, or by writing to contact@cybrlex.com. Recipients who did not grant this consent receive a byte-identical email with no pixel and no tracked link.

Note: Apple Mail Privacy Protection and Gmail's image proxy pre-fetch images, which may artificially inflate open rates. Our statistics are therefore directional, not exact.

7. Recipients of the data

Your data is accessible to:

MEDIA SMART, as data controller;

Resend, a transactional email provider based in the United States (see section 8);

our hosting provider (Algeria/European Union) for database storage and operation.

No data is sold or transferred to any third party for commercial purposes.

8. International transfers

Sending confirmation emails via Resend involves transferring the recipient's email address to the United States. This transfer is covered by the appropriate safeguards under Article 36 of Law 18-07 and by the processing contract concluded with Resend, acting as a processor.

Other personal data is hosted within our infrastructure (Algeria/European Union) and is not transferred outside that zone.

9. Retention periods

Your data is retained for the following periods, calculated from collection:

  • Page views and analytics events: 14 months, then deleted.
  • Sessions: 14 months, then aggregated to daily counts and deleted.
  • Visitors not linked to a signup: 14 months.
  • Waitlist users (EarlyUser): until platform launch plus 24 months, or until erasure is requested.
  • Consent records and admin audit log: 5 years (proof of compliance).

10. Security measures

We apply the following technical and organisational measures:

TLS encryption of all communications;

password hashing with argon2;

IP address hashing (SHA-256 + server-side pepper) — the raw IP is never persisted;

administration access protected by password, mandatory TOTP 2FA, and restricted to authorised accounts;

least-privilege principle, logging of administrative actions.

11. Your rights

In accordance with Article 38 of Law 18-07, you have the following rights over your personal data:

right of access;

right to rectification;

right to erasure;

right to object;

right to withdraw consent;

right to data portability.

To exercise these rights, write to contact@cybrlex.com specifying the email address concerned. We respond within a maximum of 30 days. You may also lodge a complaint with the ANPDP.

12. Minors

CyberLex is a service for legal professionals and is not directed at persons under 18. We do not knowingly collect data relating to minors.

13. Changes to this policy

This policy may be changed. Each version is identified by a policyVersion string (shown at the top of the page). In the event of a material change, fresh consent will be requested. The last-updated date is shown at the top of this page.

14. Contact

For any question relating to this policy or the processing of your data: contact@cybrlex.com.

15. Disclaimer

CyberLex and Lexy AI provide legal information, not legal advice. The content does not constitute legal advice and is not a substitute for consulting a legal professional.

We use cookies to measure our site's audience (visits, pages viewed) and, with your consent, to improve our product and send you news. You choose freely — rejecting is exactly as easy as accepting.

To learn more, see our Privacy Policy and our Cookie Policy.