Privacy
Last updated: 2026-07-16
- Controller
- Cyberalert, UAB (trading as CBRX) — private limited liability company (uždaroji akcinė bendrovė) governed by the Lithuanian Civil Code and Law on Companies, Director: Kazimieras Sadauskas (per Articles of Association signed 14 November 2025)
- Registered office
- Smolensko 10B, Vilnius, Lithuania
- Company code (juridinio asmens kodas)
- 306426102
- VAT code (PVM mokėtojo kodas)
- LT100017416214
- Founded
- 2023-09-18
- Data protection contact
- privacy@cbrx.ai
This notice explains what personal data CBRX collects, how we use it, what our lawful basis is, and what rights you have. We aim to keep this concise and direct, in the same register we use in our outbound communications. If anything is unclear, write to privacy@cbrx.ai.
1. Who we are
CBRX is the trading name of Cyberalert, UAB — an AI adoption agency for mid-market service businesses across the Baltics, Nordics, and EU. We provide three productised services (Scan / Sprint / Managed AI) that help mid-market firms reduce senior-time-tax via AI-driven workflow automation.
When we process your personal data, Cyberalert, UAB is the data controller under the EU General Data Protection Regulation 2016/679 (the "GDPR").
2. What personal data we process
We process personal data in four contexts.
2.1 Marketing and outbound outreach
When we identify your firm as a potential CBRX customer (within our ICP — mid-market professional services in LT/DK/SE/NO/FI/DE), we may contact you on LinkedIn. The personal data we hold for outreach purposes is:
- Identity: name, professional title, employer
- Contact: professional email, professional phone (where publicly available), LinkedIn profile URL
- Firm context: company name, sector, size band (FTE), country of registration
- Engagement signals: whether you've clicked a link we sent, whether you've replied, profile-visit frequency on LinkedIn
We do not process your private email, your home address, your bank details, your government identifiers, your health data, or any special-category data under Article 9 of the GDPR.
2.2 Reply triage calibration (the LI reply rules dataset)
When you reply to a CBRX LinkedIn message, we record a pseudonymised summary of the exchange to calibrate our internal reply triage rules. The pseudonymised dataset holds:
- A SHA-1 hash (first 8 characters) of `firstname.lastname@company` — pseudonymous identifier
- A sector + size descriptor (e.g., "DK audit, 40 FTE")
- The sentiment of your reply (positive / neutral / not interested / asking-about-AI)
- The response option we chose (warm-acknowledge / brand-seed / discovery question / book a call)
- An anonymised one-line rationale for the choice
This dataset is pseudonymous, not anonymous, under Article 4(5) and recital 26 of the GDPR — re-identification is technically possible via our CRM index. We treat it as personal data subject to GDPR.
We hold this dataset for 24 months from collection, after which it is deleted. If you become a CBRX customer (sign a Sprint), your row is deleted at conversion.
2.3 Customer engagement (when you become a CBRX customer)
If you sign a Scan, Sprint, or Managed AI engagement, separate processing applies under Article 28 GDPR (data processor capacity). The contractual data processing addendum (DPA) we sign with you governs that processing. This privacy notice is not the operative document for customer-engagement processing — your engagement letter / DPA is.
2.4 Website visitors (analytics and advertising measurement)
When you visit cbrx.ai, we measure how the site is used and — if you consent — how our advertising performs.
Always, without cookies and without consent: we use Plausible Analytics, a cookieless analytics tool. It records the page you viewed, the referring site, your approximate country, your device type, and which on-site actions occurred (for example: opening an FAQ item, interacting with the admin-tax calculator, clicking through to our booking page). Plausible sets no cookies, stores no identifier on your device, and builds no profile of you. We cannot identify you from this data.
Only with your consent (the "Analytics & advertising" category in our cookie banner):
- Google Analytics 4 — with anonymised IP. Sets cookies on your device and records the same on-site actions, plus a randomly-generated identifier that lets us recognise a returning session and measure whether an advertising click led to a booking. We share conversion measurements with Google Ads, which is linked to this property.
- LinkedIn Insight Tag — LinkedIn's advertising pixel. Sets cookies on your device, tells LinkedIn that a visit or conversion occurred on cbrx.ai, and lets LinkedIn attribute it to a LinkedIn ad you saw or clicked (30-day click / 7-day view window). LinkedIn may use this to include you in a retargeting audience, and reports aggregate conversion counts back to us. We never see, and never receive, your identity from LinkedIn.
- Campaign parameters — where you reached us from an advertising link, we store that link's campaign parameters (`utm_source`, `utm_medium`, `utm_campaign`, `utm_content`, `utm_term`) for the duration of your browsing session, so that if you go on to book a call we know which campaign the booking came from. This is stored only in your browser and is erased when you close the tab.
If you decline: Google Analytics writes no cookies, the LinkedIn Insight Tag is not loaded at all, and campaign parameters are not stored. Plausible continues, cookielessly. You can change your choice at any time from the "Cookie settings" link in our footer — withdrawing is as easy as granting.
What withdrawing does, precisely. It stops these tools loading on any further page, and erases what they stored on cbrx.ai — including your campaign parameters. It cannot reach cookies that Google or LinkedIn set on *their own* domains: those are held by them, under their own privacy policies, and we have no technical ability to delete them from here. To remove those, use your Google account settings, your LinkedIn account settings (LinkedIn: Settings → Data privacy → Advertising data), or your browser's cookie controls. We would rather tell you this than imply a clean sweep we cannot deliver.
If you book a call with us: the Calendly booking form carries the campaign parameters above into our CRM, attached to the booking you chose to make. That data is then processed under §2.1 / §2.3 as applicable. We do not process anything you did not enter into the booking form yourself. Calendly's booking widget is embedded from calendly.com and sets its own cookies under Calendly's own privacy notice; it presents its own cookie choices inside the booking window.
We do not use website analytics to build a profile of you as an individual, and we do not combine it with the outreach data in §2.1 to target you personally.
3. Lawful basis
| Processing context | Lawful basis (GDPR Article 6) |
|---|---|
| Marketing and outbound outreach (§2.1) | Article 6(1)(f) — legitimate interest. Our legitimate interest is to identify and engage potential CBRX customers within our ICP. We balance this against your privacy interests using the safeguards in §5 below. You have the right to object to this processing at any time (§6). |
| Reply triage calibration (§2.2) | Article 6(1)(f) — legitimate interest. Our legitimate interest is to calibrate our outbound communications process to make them more relevant to recipients. The Article 6(1)(f) balancing test for this dataset is documented internally; we will share a redacted version on request to privacy@cbrx.ai. |
| Customer engagement (§2.3) | Article 6(1)(b) — performance of a contract (your CBRX engagement letter), or your DPA-governed processing terms. |
| Website analytics and advertising measurement (§2.4) | Article 6(1)(a) — consent, for Google Analytics 4, the LinkedIn Insight Tag, and the storage of campaign parameters. Consent is collected via our cookie banner and can be withdrawn at any time from the "Cookie settings" link in our footer; withdrawal is as easy as granting. Storing and accessing this data on your device additionally relies on your consent under Article 5(3) of the ePrivacy Directive (2002/58/EC) as implemented in Lithuanian law. Cookieless Plausible analytics is processed under Article 6(1)(f) — legitimate interest in understanding aggregate site usage; it sets no identifiers and cannot identify you. |
4. Recipients of your personal data
For §2.1 and §2.2, your personal data is processed by:
- Cyberalert, UAB (controller) — KS + AM only have access to the reply triage calibration dataset. Other CBRX team members (currently zero) and contractors (currently zero) do not have access.
- HubSpot, Inc. (CRM processor) — under Article 28 DPA. EU-residency configured where the option is available.
- Google LLC (Google Workspace processor — email, docs, drive) — under Article 28 DPA. Cyberalert, UAB is on Google Workspace's EU-residency setting where applicable.
- LinkedIn Corporation (Microsoft) — when we contact you on LinkedIn, LinkedIn processes the message metadata. We use LinkedIn's standard professional features; we do not transfer your data to LinkedIn beyond the use of their platform for the message. (For LinkedIn's separate role as our advertising measurement provider on cbrx.ai, see §2.4 and the recipients listed below.)
- Lusha Systems, Inc. (data provider) — for ICP enrichment. Lusha holds professional contact data on a separate lawful basis declared in their own privacy notice.
For §2.4 (website visitors), your personal data is processed by:
- Google Ireland Limited / Google LLC (Google Analytics 4 and Google Ads) — under Google's data processing terms incorporating Article 28 GDPR obligations. IP anonymisation is enabled. Google acts as our processor for analytics; for Google Ads conversion measurement Google acts as an independent controller for its own purposes, as described in Google's own privacy policy.
- LinkedIn Ireland Unlimited Company (LinkedIn Insight Tag / LinkedIn Marketing Solutions) — LinkedIn is a joint controller with us for the collection and transmission of Insight Tag data, under LinkedIn's Ads Agreement and its Joint Controller Addendum. LinkedIn processes it further as an independent controller for its own purposes under its own privacy policy. We receive only aggregate conversion counts and never your identity.
- Plausible Insights OÜ (Estonia, EU-hosted) — cookieless aggregate analytics processor under Article 28 DPA. EU data residency by default.
- Calendly LLC — when you book a call, Calendly processes the details you enter plus the campaign parameters described in §2.4, and passes them to our CRM.
For §2.3 (customer engagement), additional processors apply per your engagement letter / DPA.
5. International transfers
CBRX operates an EU-first data architecture. Google Workspace EU-residency is configured (confirmed 2026-05-08). HubSpot CRM is configured to EU data residency where the option is available. In normal operation, your personal data does not leave the EU/EEA.
One exception is not incidental. If you consent to the analytics and advertising category (§2.4), that measurement necessarily involves recipients established in the United States — Google, LinkedIn, and Calendly. This transfer is inherent to those services, not accidental. If you decline the category, no such transfer takes place: the LinkedIn Insight Tag is never loaded and Google Analytics writes no cookies.
Where personal data is transferred outside the EEA — whether inherently, as above, or incidentally (e.g., a Google support engineer accessing data from a non-EU location for incident resolution; HubSpot processing operations where EU-residency is not yet available for a specific feature) — we rely on:
- Standard Contractual Clauses (Article 46 GDPR) — the European Commission's SCCs adopted in Implementing Decision 2021/914, applied via Google's, HubSpot's, LinkedIn's, and Calendly's standard data processing terms
- Adequacy decisions (Article 45 GDPR) — including the European Commission's adequacy decision of 10 July 2023 for the EU–U.S. Data Privacy Framework, where the receiving organisation is certified under that framework at the time of transfer
We re-evaluate transfer basis when our processors update their data location guidance.
6. Your rights
Under GDPR Articles 15-21, you have the following rights regarding your personal data:
- Article 15 — right of access: request a copy of the personal data we hold about you
- Article 16 — right to rectification: correct inaccurate data
- Article 17 — right to erasure: request deletion ("right to be forgotten")
- Article 18 — right to restriction: restrict processing in certain circumstances
- Article 20 — right to data portability: receive your data in a machine-readable format (where Article 6(1)(b) consent applies)
- Article 21 — right to object: object to processing under Article 6(1)(f) legitimate interest. We will cease processing within 5 working days unless we demonstrate compelling overriding grounds.
- Article 22 — automated decision-making: we do not make automated decisions that significantly affect you. Every CBRX outbound communication is reviewed and sent by a human (KS or AM). Our internal rule engine produces *recommendations*, not decisions.
To exercise any of these rights, write to privacy@cbrx.ai. We will respond within 30 days per Article 12(3).
If you are not satisfied with our response, you have the right to lodge a complaint with the supervisory authority in your EU/EEA member state. For Lithuania, the supervisory authority is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija — VDAI), L. Sapiegos g. 17, Vilnius, vdai@ada.lt. For other countries, see the European Data Protection Board's list of national authorities at edpb.europa.eu.
7. Retention
| Data type | Retention period |
|---|---|
| Marketing outbound contact data (§2.1) | 24 months from last interaction. Earlier deletion on your Article 17 erasure request or Article 21 objection. |
| Reply triage dataset (§2.2) | 24 months from collection. Earlier deletion on conversion to CBRX customer (auto-deletion), Article 17 request, or Article 21 objection. |
| Customer engagement data (§2.3) | Per your engagement letter / DPA. |
| Website analytics — Google Analytics 4 (§2.4) | 14 months from your last visit, per the user-and-event data retention setting on our GA4 property; the period resets on new activity. Cookieless Plausible data is aggregate only and is not tied to you. |
| Website analytics — LinkedIn Insight Tag (§2.4) | Per LinkedIn's published retention: direct identifiers are removed within 7 days, and the remaining pseudonymised website-visit data is deleted at 180 days. Retargeting-audience membership expires on a rolling basis according to the engagement window set on the audience (between 30 and 180 days). Conversion attribution windows are configured at 30-day click / 7-day view. |
| Campaign parameters (§2.4) | Your browser session only — erased when you close the tab, and immediately if you withdraw consent. Never stored on our servers. |
8. AI use disclosure (per AI Act Article 50)
CBRX uses AI to draft outbound communications on the cold-channel outreach sequence (Lusha-sourced contacts within our ICP who have not previously interacted with CBRX). KS reviews and edits every AI-drafted message before send. Warm-channel outreach (referrals, prior conversations, ex-colleagues, second-degree connections) is hand-written by KS without AI drafting.
When we send you a LinkedIn message:
- First-touch cold message: AI-assisted drafting + KS review before send. The disclosure language is included verbatim in the message.
- Warm-channel message: hand-written by KS.
- Reply to your reply: depends on the path; we are transparent on request.
If you ask whether AI was used in any specific message we sent you, we will answer directly and verbatim. We will not deflect, hedge, or claim full human authorship where AI was involved.
This notice is itself written by KS with AI assistance (drafting + structure) and reviewed by external counsel before publication.
9. Changes to this notice
We will update this notice when our processing materially changes (new data categories, new processors, new lawful bases, new retention periods). Material updates are dated in the "Last updated" line at the top. Where the change affects your rights, we will inform you via the next outbound communication or via a separate notice email.
The current version is 1.0 (2026-05-12). Previous versions, when they exist, will be archived at cbrx.ai/privacy/archive.
10. Contact
For any data protection question, write to privacy@cbrx.ai. We aim to respond within 5 working days for non-rights questions and within 30 days for Article 15-21 rights requests.
