Skip to main content

Privacy Notice

Last updated: September 3, 2026


Software Testing Solutions, LLC ("STS," "we," "us" or "our") provides the Cymetryc software platform and related services. This Privacy Notice explains how we collect, use, disclose and protect personal information in connection with:

This Privacy Notice does not apply to information that cannot reasonably be linked to an identifiable individual, including aggregated or deidentified information.


1. Who We Are

Software Testing Solutions, LLC is the organization responsible for the personal information described in this Privacy Notice.

For privacy questions or requests, contact us at dpo@cymetryc.com.


2. Our Role

STS acts as a controller when we determine why and how personal information is processed, including information used to operate the Website, manage business relationships, administer user accounts, protect the security of the Solution, communicate with customers and comply with legal obligations.


STS acts as a processor or service provider when we process Customer Content on behalf of a customer and in accordance with that customer's instructions and our agreement with the customer. In those circumstances, the customer is responsible for its own privacy notices and for responding to requests concerning Customer Content. We will assist the customer with those requests as required by applicable law and our agreement.


3. Personal Information We Collect

Because STS provides the Solution to businesses and organizations, the personal information we collect ordinarily relates to our customers' and prospective customers' employees, contractors and other professional representatives.


Depending on how you interact with us, we may collect the following categories of personal information:


Business contact information

Your name, employer or organization, professional title, business email address, business telephone number and other information you provide when requesting information, scheduling a demonstration, attending an event or communicating with us.


Account and access information

Your name, business email address, organization, username, assigned role, permissions, account status and authentication or single sign-on identifiers used to create, administer and secure access to the Solution.


Solution activity and technical information

Login dates and times, user and administrative actions, approvals, audit records, IP address, browser or device information, diagnostic information, security events, feature usage and other information generated through use of the Solution.


Customer Content

Information submitted to the Solution by or on behalf of a customer, such as test plans, test scripts, issue records, approvals, comments, screenshots, attachments and associated metadata. Customer Content may identify the customer's authorized users or other business personnel.


Communications and support information

Information contained in emails, meeting records, support requests, feedback and other communications with us.


Transaction and business administration information

Customer and vendor contact details, contract information, invoicing records, payment status and related business records.


Website and cookie information

Information about how you interact with the Website, which may include IP address, device and browser information, pages viewed, referring pages and interactions with Website content. For additional information, see our Cookie Policy.


Applicant information

If you apply for employment with STS, the handling of your information is described in our Applicant Privacy Notice.


4. No Patient Data or Protected Health Information

The Solution is not designed or intended to collect, receive, store or process patient-identifiable information or Protected Health Information as defined by the Health Insurance Portability and Accountability Act (HIPAA). Customers and Solution users must not enter or upload such information into the Solution, including in screenshots, test evidence, attachments, issue descriptions, comments or free-text fields.


Testing performed using the Solution must use synthetic, anonymized or appropriately deidentified data. Customers are responsible for ensuring that Customer Content complies with this requirement and with the applicable customer agreement.


STS also does not intentionally collect special-category or sensitive personal information through the Website or Solution. Please do not submit such information to us unless we have specifically requested it for a lawful and necessary purpose.


5. How We Collect Personal Information

We may collect personal information:

  • directly from you;
  • from your employer or the STS customer that authorizes your access to the Solution;
  • automatically when you use the Website or Solution;
  • through identity, authentication and other systems connected to the Solution at the customer's direction;
  • from service providers supporting our business operations; and
  • through professional networking services, industry events or publicly available business sources where permitted by law.

We may use personal information to:

  • respond to inquiries and provide demonstrations or requested information;
  • establish, administer and support customer relationships and user accounts;
  • provide, operate, maintain and troubleshoot the Solution;
  • authenticate users and manage roles and permissions;
  • maintain audit trails and protect the confidentiality, integrity, availability and security of the Website and Solution;
  • investigate suspected misuse, security incidents or violations of our agreements;
  • communicate with customers and users about service, security and administrative matters;
  • analyze Solution performance and usage and improve our products and services;
  • send business-to-business marketing communications where permitted by law;
  • manage contracts, invoices, payments and business records;
  • establish, exercise or defend legal claims;
  • comply with applicable laws, lawful requests and regulatory obligations; and
  • evaluate or complete a financing, merger, acquisition, sale, restructuring or similar corporate transaction.

7. Legal Bases for EEA and UK Personal Data

Where the EU General Data Protection Regulation (EU GDPR) or UK GDPR applies and STS acts as a controller, we rely on one or more of the following legal bases:

PurposeLegal basis
Responding to inquiries and arranging requested demonstrationsOur legitimate interests in developing business relationships and, where applicable, taking steps requested before entering into a contract
Providing and administering the Solution, customer relationships and supportPerformance of a contract where the individual is a party and our legitimate interests in providing services to our organizational customers
Authentication, audit logging, security, misuse prevention and incident responseOur legitimate interests in protecting our customers, users, systems and business and compliance with legal obligations where applicable
Product performance analysis and improvementOur legitimate interests in understanding and improving the performance, reliability and usability of our products and services
Service and administrative communicationsPerformance of a contract where applicable and our legitimate interests in managing customer relationships and operating the Solution
Business-to-business marketingOur legitimate interests in promoting relevant services and consent where required by applicable electronic-marketing laws
Contract, invoicing, accounting and business recordsPerformance of a contract, compliance with legal obligations and our legitimate interests in administering our business
Legal claims, regulatory matters and corporate transactionsCompliance with legal obligations and our legitimate interests in protecting and managing our business
Non-essential cookies and similar technologiesConsent or another applicable exception permitted by law


Where STS processes personal information solely on behalf of a customer, the customer determines the applicable legal basis.


8. How We Disclose Personal Information

We may disclose personal information to the following categories of recipients when reasonably necessary for the purposes described above:

  • Your organization: Customer administrators and other authorized personnel may access information associated with their organization's users and use of the Solution.

  • Service providers: Providers supporting cloud infrastructure, hosting, authentication, security, communications, customer support, analytics, accounting and other business operations. These providers are permitted to process personal information only for the services they provide to us and are subject to appropriate contractual obligations.

  • Professional advisers: Lawyers, auditors, insurers, accountants and other advisers who are subject to professional or contractual confidentiality obligations.

  • Government and legal recipients: Courts, regulators, law-enforcement bodies or other parties when disclosure is required by law or reasonably necessary to protect rights, safety or security.

  • Corporate transaction recipients: Prospective or actual purchasers, investors, lenders and their advisers in connection with a financing, merger, acquisition, restructuring or sale of all or part of our business, subject to appropriate confidentiality protections.

  • EU and UK representatives: Our appointed representatives when needed to address privacy inquiries, requests or regulatory obligations.


We do not sell personal information for monetary consideration. We do not disclose Customer Content for targeted advertising. Website analytics or advertising providers may receive Website device or activity information as described in our Cookie Policy and subject to the choices and consent mechanisms required by applicable law.


9. International Transfers


STS is established in the United States, and personal information may be processed in the United States and other countries in which we or our service providers operate. Those countries may have data-protection laws that differ from the laws where you are located.


When required for transfers of personal data from the European Economic Area, the United Kingdom or another jurisdiction with transfer restrictions, we use an approved legal mechanism appropriate to the transfer. Depending on the circumstances, this may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, an applicable adequacy decision or another legally recognized mechanism. We also apply supplementary contractual, technical and organizational safeguards where appropriate.


For additional information about the safeguards applicable to a transfer, contact dpo@cymetryc.com.


10. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Notice. In determining the appropriate period, we consider:

  • the duration of the customer or business relationship;
  • the customer's instructions and the retention and deletion provisions of the applicable agreement;
  • the nature, amount and sensitivity of the information;
  • security, audit, backup and business-continuity requirements;
  • applicable limitation periods; and
  • legal, accounting and regulatory requirements.

11. Security

We maintain administrative, technical and organizational safeguards designed to protect personal information against unauthorized access, use, alteration, disclosure or destruction. These safeguards include measures appropriate to the nature of the information and the risks associated with its processing, such as encryption in transit and at rest, access controls, authentication, logging, monitoring and security-management procedures.


No system or transmission method can be guaranteed to be completely secure. If you believe that your account or information may have been compromised, contact us promptly at dpo@cymetryc.com.


12. Your Privacy Rights

Depending on your location and applicable law, you may have the right to:

  • request confirmation that we process your personal information and obtain access to it;
  • request correction of inaccurate or incomplete information;
  • request deletion of personal information;
  • request restriction of certain processing;
  • object to certain processing, including direct marketing;
  • receive certain information in a portable format;
  • withdraw consent at any time where processing is based on consent; and
  • lodge a complaint with an applicable data-protection authority.

To exercise a right concerning information for which STS acts as a controller, contact dpo@cymetryc.com or use the secure portal identified below. We may request information reasonably necessary to verify your identity and authority. We will respond within the period required by applicable law.


If your request concerns Customer Content or your use of the Solution through your employer or another STS customer, please contact that organization first. We will assist the customer in responding to the request as required by applicable law and our agreement.


13. Marketing Choices

You may unsubscribe from marketing emails by using the unsubscribe link in the message or by contacting dpo@cymetryc.com. We may retain limited information necessary to record and honor your opt-out.


Even if you opt out of marketing, we may continue to send service, security, account and other non-promotional communications relating to an existing customer relationship or your use of the Solution.


14. Cookies and Similar Technologies

We use cookies and similar technologies to operate and secure the Website, understand Website performance and, where enabled, measure or support business-to-business marketing. Non-essential technologies are used only with consent or under another applicable legal exception.


For information about the technologies we use, their providers, purposes, duration and available choices, see our Cookie Policy.


15. Children's Privacy

The Website and Solution are intended for business and professional use and are not directed to children. We do not knowingly collect personal information from children through the Website or Solution. If you believe a child has provided personal information to us, contact dpo@cymetryc.com so that we can investigate and take appropriate action.


16. Links to Other Websites

The Website or Solution may contain links to websites or services operated by third parties. Their privacy practices are governed by their own notices, and we encourage you to review those notices before providing personal information.


17. Data Protection Complaints

You have the right to raise a complaint with us if you have concerns about how we collect, use, disclose, retain or otherwise process your personal information.

You can submit a complaint by emailing DataProtectionComplaints@sts-healthcare.com. You may also raise a data protection complaint through any of our usual contact channels.


Please provide as much information as you reasonably can about your concern, including:

  • your name and preferred contact details;

  • a description of what happened;

  • any relevant dates, correspondence or reference numbers; and

  • what you would like us to do to resolve the matter.


Please do not send unnecessary sensitive or confidential information by email.


We will acknowledge receipt of your complaint within 30 calendar days. We will take appropriate steps to investigate and respond without undue delay, keep you informed of material progress where appropriate and provide you with the outcome of our investigation.


We may need to ask you for additional information, proof of identity or evidence that you are authorized to act for another person. We will request only the information reasonably necessary to handle the complaint.


You also have the right to lodge a complaint with an appropriate data protection supervisory authority. You do not have to complete our internal complaints process before contacting a supervisory authority.

  • United Kingdom: the Information Commissioner's Office (www.ico.org.uk).

  • European Economic Area: the supervisory authority in the country of your habitual residence, place of work or where the alleged infringement occurred.

Depending on the circumstances, you may also have the right to seek a judicial remedy.


18. EU/EEA & UK GDPR Representatives (Article 27)

If you are located in the EU or UK, and have questions or concerns regarding your personal data, you may contact our GDPR representative:


EU Representative:

Euverify Ltd (Ireland)

Unit 3D North Point House

North Point Business Park

New Mallow Road, Cork

T23 AT2P, Ireland

Email: gdpr@euverify.com


UK Representative:

Euverify Ltd (UK)

3rd Floor, 86-90 Paul Street

London, EC2A 4NE

United Kingdom

Email: gdpr@euverify.com


To submit a Data Subject Access Request (DSAR), data deletion request, or any other GDPR-related inquiry, please use our secure portal.

This link allows you to verify our appointed representative and submit GDPR requests directly. Requests submitted through this portal are logged and tracked to ensure timely response and compliance.


19. Changes to This Privacy Notice

We may update this Privacy Notice periodically to reflect changes in our practices, services or legal obligations. We will post the revised notice on the Website and update the date shown above. If a change materially affects how we use personal information, we will provide additional notice where required by law.


20. Contact Us

For questions, concerns or requests concerning this Privacy Notice or our handling of personal information, contact:

Software Testing Solutions, LLC
Email: dpo@cymetryc.com