Last updated: June 18, 2026
cypress-dash is committed to compliance with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Economic Area and United Kingdom. This document outlines our approach to data protection and your rights under GDPR.
For the purposes of GDPR, cypress-dash acts as the data controller for personal information collected through our website and business operations. We determine the purposes and means of processing your personal data.
We process personal data only when we have a lawful basis:
Under GDPR, you have comprehensive rights regarding your personal data:
You have the right to clear information about how we collect and use your personal data, provided through our Privacy Policy and this GDPR page.
You can request confirmation of whether we process your personal data and obtain a copy of that data along with supplementary information about the processing.
If your personal data is inaccurate or incomplete, you have the right to request correction or completion of that information.
Also known as the "right to be forgotten," you can request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purposes for which it was collected.
You have the right to request that we restrict processing of your personal data in specific situations, such as when you contest the accuracy of the data.
You can request to receive your personal data in a structured, commonly used, and machine-readable format and have the right to transmit that data to another controller.
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
You have the right not to be subject to decisions based solely on automated processing that produces legal effects or similarly significant impacts, except in specific circumstances.
We adhere to GDPR data protection principles:
We implement appropriate technical and organizational measures to ensure security appropriate to the risk, including:
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the appropriate supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.
If we transfer personal data outside the European Economic Area, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.
To exercise any of your GDPR rights, contact us at [email protected]. We will respond to requests within one month, though this may be extended by two additional months for complex requests.
You also have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not complied with GDPR requirements.
We may update this GDPR compliance statement periodically. Changes will be posted on this page with an updated revision date.
For questions about GDPR compliance or to exercise your rights, contact us at [email protected].