This Privacy Policy explains how CYRENIUM LLC, a Texas limited liability company, with its principal business address at 957 E NASA Pkwy, Unit 2187, Houston, TX 77058 ("Cyrenium," "we," "us," or "our"), collects, uses, discloses, stores, and otherwise processes personal information in connection with the Cyrenium website, applications, educator storefronts, course pages, live sessions, messaging tools, payment flows, digital downloads, student dashboards, support tools, and related services (collectively, the "Services").
By accessing or using the Services, you acknowledge the practices described in this Privacy Policy. If you do not agree with this Privacy Policy, do not use the Services.
1. Scope
This Privacy Policy applies to personal information we collect from or about:
- (a) visitors to our websites and landing pages;
- (b) students, prospective students, and purchasers of courses or educational content;
- (c) educators, instructors, presenters, contributors, affiliates, and applicants to become educators;
- (d) users who communicate with us through support, email, messaging, or social media; and
- (e) other individuals whose information we collect in connection with operating, securing, and improving the Services.
This Privacy Policy does not apply to information processed on behalf of third-party service providers where we act solely as a processor or service provider under a separate written agreement, or to third-party websites, applications, or services that are not controlled by Cyrenium.
2. Important Nature of the Services
Cyrenium is an education platform. The Services are not intended to be used for submitting, storing, or transmitting patient records, medical charts, protected health information, screenshots from clinical systems, or other regulated health data. Users are prohibited from uploading such information through the Services.
If you believe any prohibited patient or health information has been uploaded to the Services, contact us immediately at [email protected] and [email protected].
3. Categories of Personal Information We Collect
We may collect the following categories of personal information, depending on how you interact with the Services:
A. Information You Provide Directly
- Name
- Email address
- Telephone number
- Mailing address
- Username and password
- Account profile information
- Professional background and biographical details
- Payment-related information submitted in connection with purchases or payouts
- Tax information where required for educator payouts or legal compliance
- Identity verification information
- Curriculum vitae, resumes, licensing or credential information, and referee details submitted by educators
- Messages, support requests, survey responses, feedback, reviews, comments, and other communications
- Content you upload, submit, post, or transmit through the Services
B. Information Collected Automatically
When you use the Services, we and our service providers may automatically collect:
- IP address
- Device identifiers
- Browser type and version
- Operating system
- Internet service provider
- Referral and exit pages
- Date and time stamps
- Session and clickstream data
- Pages viewed, links clicked, features used, and interaction data
- Crash reports, diagnostics, and performance data
- Approximate geolocation inferred from IP address
- Cookie identifiers and similar tracking data
C. Transaction and Commercial Information
- Course purchases
- Enrollment history
- Payment status
- Refund and chargeback history
- Subscription status, if applicable in the future
- Payout history and transaction logs for educators
D. Verification, Trust, and Safety Information
To maintain platform integrity and safety, we may collect and process:
- Identity documents
- Sanctions or watchlist screening information
- Fraud-risk indicators
- Account security and authentication logs
- Reports, complaints, moderation records, and investigation materials
- Information from references, referees, or verification partners
E. Information from Third Parties
We may receive personal information from:
- Payment processors
- Identity verification providers
- analytics providers
- advertising and attribution partners
- fraud prevention and security vendors
- social media platforms, if you interact with us there
- publicly available sources
- referees or references provided by educators
- business partners and service providers
F. Attendance and Session Information
In connection with live sessions and related Services, we may collect or receive participant names, attendance snapshots, session join and leave times, and related session metadata, including through AI-powered attendance tracking tools or integrated third-party services. We may use this information for purposes such as verifying attendance, resolving disputes, enforcing our Terms and platform policies, and processing refunds. These attendance tracking tools are designed to log participation and presence and do not collect, capture, or use facial geometry, voiceprints, fingerprints, or other biometric identifiers or biometric information to identify individuals. If we ever introduce features that process biometric identifiers, we will provide any notice and obtain any consent required by applicable law before doing so.
5. How We Use Personal Information
We may use personal information for the following purposes:
- to provide, operate, maintain, and improve the Services;
- to create and manage accounts;
- to process enrollments, orders, payments, refunds, and payouts;
- to verify identity, eligibility, educator onboarding information, and account authority;
- to review CVs, credentials, references, and trust and safety submissions from educators;
- to communicate with users about accounts, purchases, updates, notices, support, and service issues;
- to deliver courses, live sessions, digital content, and user-requested features;
- to personalize user experience and platform functionality;
- to monitor usage, troubleshoot problems, and improve product performance;
- to secure the Services and detect, investigate, prevent, or respond to fraud, abuse, cyber incidents, chargebacks, unauthorized access, or illegal activity;
- to enforce our Terms, policies, and community standards;
- to comply with legal obligations, court orders, lawful requests, tax rules, accounting requirements, and regulatory requirements;
- to establish, exercise, or defend legal claims;
- to send marketing communications, where permitted by law and subject to opt-out rights; and
- for any other purpose disclosed at the time of collection or as otherwise permitted by law.
6. Legal Bases for Processing
Where applicable law requires a legal basis for processing, we rely on one or more of the following:
- performance of a contract or steps taken at your request before entering a contract;
- compliance with legal obligations;
- our legitimate interests, including operating and securing the Services, preventing fraud, improving our platform, onboarding educators, and communicating with users;
- your consent, where required; and
- other lawful bases available under applicable law.
7. How We Disclose Personal Information
We may disclose personal information to the following categories of recipients:
A. Service Providers and Vendors
We may disclose personal information to hosting providers, cloud service providers, payment processors, payout processors, analytics vendors, customer support providers, email and communications vendors, identity verification providers, fraud prevention vendors, sanctions screening providers, security consultants, and other vendors that help us operate the Services.
B. Educators and Students
Where necessary to deliver the Services, we may share limited information between students and educators, such as account name, profile information, enrollment status, communications, and course-related activity.
C. Business Transfers
We may disclose personal information in connection with an actual or proposed merger, acquisition, financing, asset sale, restructuring, bankruptcy, or other corporate transaction.
D. Legal and Safety Disclosures
We may disclose personal information to courts, regulators, law enforcement, government authorities, professional advisors, insurers, or other third parties when we believe disclosure is necessary to:
- comply with law or legal process;
- respond to lawful requests;
- enforce our agreements or policies;
- detect, investigate, or prevent fraud, abuse, cyber threats, or security incidents;
- protect the rights, property, safety, or security of Cyrenium, users, patients, or the public; or
- establish, exercise, or defend legal claims.
E. With Your Direction or Consent
We may disclose personal information where you direct us to do so or where you otherwise consent.
8. User Content and Public Areas
If you post reviews, comments, messages, profile details, course materials, or other content in public or shared areas of the Services, that information may be visible to others and may be copied, collected, or used by third parties. You are solely responsible for the personal information you choose to include in public or shared content.
You must not post patient-identifying information, confidential third-party data, or other information you do not have the right to share.
9. Payment Information
Payments may be processed by third-party payment processors. Cyrenium may receive transaction confirmations, limited payment metadata, billing details, and fraud signals, but we do not necessarily store full payment card numbers on our own systems. Payment processing is subject to the applicable processor’s terms and privacy practices.
10. Educator Verification and References
To support trust and safety, Cyrenium may request and process educator identity documents, resumes or CVs, licensing or credential information, and referee contact details. We may contact referees or other sources to assess educator eligibility, trustworthiness, and platform compliance.
Our review processes are limited and do not guarantee any educator’s qualifications, licensure, certification, professional standing, or suitability.
11. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:
- provide the Services;
- maintain accounts and transaction records;
- process payouts, refunds, disputes, and chargebacks;
- conduct fraud prevention and security monitoring;
- comply with legal, tax, accounting, and regulatory obligations;
- enforce agreements; and
- resolve disputes.
Retention periods may vary depending on the nature of the information, legal requirements, and operational necessity. We may retain information for longer where required or permitted by law, including for backup, archival, fraud prevention, litigation hold, or audit purposes.
12. Data Security
We implement administrative, technical, and organizational safeguards intended to protect personal information. However, no method of transmission over the internet, no application, and no storage system is completely secure. We cannot guarantee absolute security, and cyber threats, unauthorized access, malware, service interruptions, and other incidents may occur despite reasonable safeguards.
You are responsible for protecting your account credentials, using secure devices and networks, and notifying us promptly of any suspected unauthorized access.
13. International Data Transfers
Cyrenium and its service providers may process and store personal information in the United States and other jurisdictions that may not provide the same level of data protection as your home jurisdiction. By using the Services, you understand that your information may be transferred to and processed in countries outside your place of residence, subject to applicable legal safeguards where required.
14. Your Rights and Choices
Depending on where you live, you may have rights regarding your personal information, subject to legal exceptions and verification of your identity. These may include the right to:
- access personal information we hold about you;
- request correction of inaccurate information;
- request deletion of personal information;
- request portability of certain information;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent; and
- appeal certain decisions or request review of denied rights requests.
You may also opt out of marketing emails by using the unsubscribe link in those messages. We may still send transactional or service-related communications.
To exercise privacy rights, contact us at [email protected]. We may need to verify your identity before processing your request.
15. U.S. State Privacy Disclosures
Residents of certain U.S. states may have additional privacy rights under applicable law, including rights to know, access, correct, delete, or opt out of certain processing activities. Cyrenium does not sell personal information for money. If our practices change in a way that triggers additional notice or opt-out obligations under applicable law, we will update this Privacy Policy and provide any required disclosures.
If you are a resident of a state with applicable privacy rights, you may submit a request using the contact details listed below. You will not be discriminated against for exercising applicable privacy rights, except as permitted by law.
16. Children’s Privacy
The Services are not directed to children under 18, and Cyrenium does not knowingly collect personal information directly from children under 18 through the Services. If we learn that we have collected personal information from a child under 18 without appropriate authorization, we will take steps to delete it as required by law.
If minors are permitted to access certain educational content under applicable law, any such use must comply with our Terms and any required consent or supervision requirements.
17. Third-Party Services and Links
The Services may contain links to third-party websites, tools, integrations, content, or services. We are not responsible for the privacy, security, or data handling practices of third parties. Your use of third-party services is governed by their own terms and privacy policies.
18. Google User Data and Limited Use
The Services offer sign-in with Google and integrate with Google Calendar and Google Meet to schedule and deliver live sessions. When you sign in with Google or connect your Google account, we request your permission to access certain information from your Google Account through Google APIs.
Google information we access. With your consent, we access: (a) basic profile information and your email address (Google scopes openid, userinfo.email, and userinfo.profile) to create and authenticate your account; and (b) your Google Calendar events (Google scope calendar.events) to create, update, and remove calendar entries and associated Google Meet links for live sessions you host or attend, and to add those sessions to your calendar. We request calendar.events (event-level access) rather than full calendar access to limit our access to only what is necessary to provide these features.
How we use Google information. We use Google user data solely to provide and improve these features — authenticating your account, generating Google Meet links, and creating or updating the calendar events for the specific live sessions you host or enroll in. We do not use Google user data for advertising, and we do not sell it.
Limited Use. Cyrenium's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In accordance with that policy, we (i) only use the Google user data to provide or improve the user-facing features described above; (ii) do not transfer or sell the data except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with your prior consent; (iii) do not use the data for serving advertisements; and (iv) do not allow humans to read the data unless we first obtain your consent, it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and anonymized.
Refresh tokens and storage. To keep your calendar in sync without asking you to sign in repeatedly, we securely store the OAuth access and refresh tokens Google issues for your account. These tokens are stored in encrypted form and used only to make the Google API calls described above.
Revoking access. You may revoke Cyrenium's access to your Google Account at any time at https://myaccount.google.com/permissions. Revoking access may prevent us from creating or updating your Google Calendar events and Google Meet links for live sessions. You may also contact us at [email protected] to request deletion of the Google tokens we hold for your account.
19. Do Not Track
Some browsers offer a “Do Not Track” setting. Because there is not a universally accepted standard for responding to these signals, the Services may not respond to all Do Not Track signals unless required by law.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the Services, legal requirements, or our data practices. When we make changes, we will update the “Last Updated” date and, where required by law, provide additional notice or obtain consent.
Your continued use of the Services after an updated Privacy Policy becomes effective means you acknowledge the updated policy, to the extent permitted by law.
21. Contact Us
If you have questions about this Privacy Policy or would like to exercise privacy rights, contact:
- Cyrenium
- CYRENIUM LLC
- 957 E NASA Pkwy, Unit 2187, Houston, TX 77058
- Email: [email protected]
- Legal Notices: [email protected]
- Support: [email protected]
