MorphCast Emotion AI for Zoom – Privacy & Cookie Policy

AI Custom Action Eye

Effective June 25, 2024


This Privacy Policy governs the MorphCast Emotion AI for Zoom Plugin, outlining Cynny’s practices for collecting and disclosing Business Users’ Personal Data. It applies exclusively to data collected through the Service, distinct from other Cynny services or the embedded Zoom service. Acceptance of this policy is required for use; changes will be communicated to users.

Personal data collection methods include direct user input and Zoom’s authorization to share profile and video conference data. This data encompasses user identification, meeting details, and, if consent is given, emotional analysis during video conferences.

Cynny uses cookies and local storage for functionality, including authentication and interaction with Zoom’s APIs, ensuring data encryption and security. Cynny also collects website navigation data through browser cookies, with specific policies outlined separately.

Personal data processing aligns with GDPR, aiming to secure and maintain confidentiality. Cynny commits not to sell or trade personal data for marketing without express consent and may share data with TrustPilot for service review purposes, acting as the data controller.

The policy details the purposes and legal bases for data processing, including contractual obligations, legal compliance, and direct marketing activities, with consent as a basis for newsletter subscriptions and feedback collection.

Data retention policies adhere to legal and contractual requirements, ensuring data deletion or anonymization after specified periods or upon account deletion. Third-party disclosures are limited to necessary operations and legal obligations.

Business Users have rights under GDPR to access, rectify, or delete their data, with mechanisms to withdraw consent for newsletters and marketing communications.

Updates to the policy will be communicated, especially for significant changes affecting personal data use. For inquiries or data management requests, contact details for Cynny.

MorphCast® Emotion AI for ZOOM – Privacy & Cookie Policy

Cynny S.p.A. (“Cynny”), enrolled at the Business Registry of Florence, VAT number No. IT06340560488, D-U-N-S® number 434193325, is committed to maintaining the privacy and security of your personal data under the applicable privacy legislation, including the General Data Protection Regulation UE 2016/679 (“GDPR”). The contact details of Cynny are indicated within the “Questions?” section below. 

This Privacy Policy applies to the product MorphCast Emotion AI for Zoom Plugin (the “Service”). This Privacy Policy explains Cynny’s collection and disclosure practices of the Business Users’ Personal Data (as defined below) of the companies or organizations using the Service (“Business Users”) to which the Service is exclusively addressed, as explained by the relevant Terms of Use, and applies solely to the Business Users’ Personal Data that we collect through the Service (and not also through the MorphCast website and/or other tools made available by Cynny not based on MorphCast Emotion AI for Zoom Plugin). For the privacy regulation of other services offered by Cynny, including MorphCast Emotion AI Interactive Media Platform, you may refer to the other policies adopted by Cynny which may apply in this respect, as available in the page at this link: mission. For the privacy regulation of Zoom service embedded in MorphCast Emotion AI for Zoom Plugin you may refer to the policies adopted by Zoom US which may apply in this respect, as available at this link: Zoom Privacy Statement.

Acceptance of Privacy Policy

– By using the Service, you signify your acceptance of the relevant provisions of this Privacy Policy. If you do not agree to the terms of this Privacy Policy, please do not use the Service.  Your continued use of the Service following the posting of changes to these terms will mean that you have accepted those changes.

Categories of Business Users’ Personal Data we collect and how we collect it

As for the modalities through which Cynny can collect the Business Users’ personal data (“Business Users’ Personal Data”), please note that such modalities are determined by your use of the Services. By way of example, you may provide your personal data through sending email in order to voluntarily contact Cynny, and through other interactions with the Services. Cynny processes the Business Users’ Personal Data, according to the terms of this Privacy Policy, as data controller. The specific categories of such Business Users’ Personal Data processed by Cynny consist of the following identifying information:

– You may provide personally identifiable information about yourself when using the Service by expressly authorizing Zoom to provide Cynny with the data related to your profile and your video conferences:

idUser’s Zoom ID Zoom
emailEmail the user used to register for the Zoom service
type‘s account type (eg. Basic, licensed, ect)
timezoneTime zone of the user
pic_urlURL of the profile picture of the user

Zoom, always under your authorization, also makes available data relating to your videoconferences. Of these data, Cynny reads and uses only the following:

idId of the meeting
uuidUnique id of the meeting
agendaDescription of the meeting (maximum 2000 characters)
durationDuration of the meeting
typeType of meeting (e.g. instantaneous, recurring, etc.)
start_timeDate and start time of the meeting
start_urlUrl with which the Zoom account owner starts the meeting
statusStatus of the meeting (e.g. Waiting, Started)
topicTitle of the meeting
join_urlUrl that allows Guests to join the meeting

– You may provide personally identifiable information about you when using the Service, such as: first and last name and Business User’s or organization’s related administrative contact, email address, physical address and other unique identifier, financial processing and payment information, as well as statistical data daily on the use of the Service, aggregated by reference pages in which the Service is implemented such as, by way of example and for this applicable, the license key assigned to each Business User under the Terms of Use of the Service available at the link MorphCast Emotion AI for Zoom – Terms of Use and the Conditions of Use of other MorphCast services, available in the links contained in the page mission, number of times the Service has been requested, initialized, authorized and started, number of errors that may have occurred, number of frames analyzed and usage time spent using the Service by each user.

– Furthermore, if the Business User, Zoom account owner, as organizer of the videoconference/webinar, henceforth also called “Host“, has activated the MorphCast Emotion AI analysis available in the Service and the guest of the videoconference/webinar has expressly agreed to be analyzed, Cynny is appointed responsible of the processing by the Business User, as data controller, of additional categories of personal data (“Guest Personal Data”) exclusively for the purpose of their conservation and related accessibility by the Business User. The specific categories of Guest Personal Data consist of the following information: name entered by the guest prior to participation in the video conference/webinar; with a certain degree of accuracy, the dominant emotions according to the model of Paul Ekman; mood, level of attention and involvement (Russell’s circumflex model of affects based on arousal and valence).

– As regards the Host, Cynny, through the MorphCast For Zoom application, uses cookie and localstorage of the browser for its correct functioning. When you connect with your Zoom account, a cookie is provided to your browser containing:

Mph JWTJSON web token used to authenticate all requests that occur between client and server. Without it, no requests from the client will be processed by the server
Zoom Access TokenToken provided at login via OAuth 2.0 flow, allows the server to interact with the Zoom APIs. This token has a fixed validity time decided by Zoom.
Zoom Refresh TokenToken that allows you to obtain a valid Access Token in case the previous one has expired.

The data indicated above are not accessible from the Host as they are encrypted and decrypted by the server. Encryption takes place using the advanced AES-256 encryption standard with a unique initialization vector (Techtarget: definition of initialization vector). This makes it very difficult for a hacker to decrypt the contents of the cookies.

In addition to this, MorphCast for Zoom saves the timestamp indicating the expiration of the tokens in the Host’s browser local storage, information that is used to decrease Client-Server interactions and therefore speed up the user experience.

In addition to those used by Cynny in the MorphCast for Zoom application, once you enter a video conference/webinar, Zoom also uses cookies to:

·   enable basic functionality

·   analyze trends

·   understand when and how you visit and interact with Zoom websites

·   collect information about your device and settings

·   enable third-party advertising on its websites

Source: Information Cookie Statement powered by

Depending on your jurisdiction, Zoom requires your prior consent for different types of cookies or allows you to refuse them. Zoom cookies are also used for Guests, who instead will not have cookies or data in localstorage by MorphCast for Zoom.

– Finally, Cynny may also collect personal data when users browse the MorphCast website through their browser’s cookies. In that case, please refer to the Website Privacy & Cookie Policy available on the website. 

– Under no circumstances does Cynny collect any special categories of personal data, as defined by Article 9 of the GDPR.

– Under no circumstances does Cynny collect any special categories of personal data, as defined by Article 9 of the GDPR.

Methods of processing Business Users’ Personal Data

Cynny will process Business Users’ Personal Data using manual, paper, computer and electronic instruments, even to store, manage or process such Business Users’ Personal Data, suitable to ensure their security and confidentiality, according to the terms of this Privacy Policy and the applicable privacy legislation, including GDPR.  

Cynny will not sell, rent, license, or trade the Business Users’ Personal Data with third parties for their direct marketing use unless we receive your express consent to do so. 

Furthermore, Cynny may share specific Personal Data, such as the name and email address of Business Users, with TrustPilot solely for the purpose of allowing Trustpilot to send requests to review Cynny’s services. This sharing of information is done with the understanding that Business Users may receive review requests from TrustPilot as part of our effort to enhance our service quality. In this process, Cynny acts as the data controller for the personal data of the Professional Users. This means that we are responsible for the collection, processing, and management of your personal data in relation to the sending of these invitations. Trustpilot, on the other hand, serves as the data processor, managing the personal data of the Professional Users according to our instructions and in compliance with the applicable data protection laws.

Except for this specific purpose, and unless you provide us with permission, Cynny will not share Business Users’ Personal Data, as collected through the use of the Service covered by this Privacy Policy, other than as specified in this Privacy Policy.

Purposes and legal basis of the processing of Business Users’ Personal Data 

We may use the Business Users’ Personal Data you provide to us, in compliance with the applicable privacy legislation, when you use the Service, in the following ways: 

  1. for the execution of pre-contractual and contractual obligations with the Business Users, including, without limitation, to allow us to provide you with a better service answering your requests and to quickly process your transactions. In this case, the legal basis for the processing of the Business Users’ Personal Data is the execution of an agreement of which you are part or, as applicable, the execution of pre-contractual measures adopted upon your request; 
  2. to comply with the obligations provided for by the laws, the regulations and, in general, by the law applicable from time to time, to fulfill fiscal and accounting obligations or other obligations deriving from an order of the Authority that are related, directly and/or indirectly, to the Service. In this case, the legal basis for the processing of the Business Users’ Personal Data is the fulfillment of a legal obligation of the data controller; 
  3. to exercise Cynny’s rights, including, but not limited to, the right to defend itself in Court and to carry out sale, assignment, merger or other transfer of all or a portion of Cynny’s business. In these cases, the legal basis for the processing of the Business Users’ Personal Data is the data controller’s legitimate interest.
  4. to send communications of promotional nature via email concerning the Service already purchased by the Business User and/or services similar to the same offered by Cynny (“Soft Spam Communications“); also in this case, the legal basis for the processing of the Business Users’ Personal Data is the data controller’s legitimate interest;
  5. to carry out direct marketing activities by sending newsletters. In this case the legal basis for the processing of the Business Users’ Personal Data is the consent that will be provided by the Business Users once they subscribe to the newsletter through the relevant consent form.
  6. To carry out activities to collect feedback through the Trustpilot platform, from its Professional Users in order to improve the services offered in the legitimate interest of Cynny. The user has the right to object to this processing at any time by contacting us directly or by following the instructions provided in each review invitation email. 

The provision and processing of the Business Users’ Personal Data for the purposes under points a), b), and c) above is necessary for the provision of the Service and does not require your consent. Any refusal to provide the requested Business Users’ Personal Data or their inaccuracy could make it impossible for you to use the Service. 

It is acknowledged that the Business User may revoke his/her consent to receive the newsletter and/or communicate its intention to interrupt the delivery of Soft Spam Communications by sending an email to Cynny or by using the link found in each newsletter email or Soft Spam Communication, as indicated in the following section “Rights of the Business Users”. 

Data retention. The Business Users’ Personal Data that are collected for the purposes identified under the above-mentioned section “Purposes and legal basis of the processing of Business Users’ Personal Data” may be stored, in accordance with the proportionality principle, for the fulfillment of contractual and legal obligations, including those of a social security and/or tax nature, for a period not exceeding (i) the data retention period provided for by the regulations in force for each category of data, and (ii) the limitation period provided for by law in order to enforce or defend a legal claim against you or against third parties, provided that the Business Users’ Personal Data collected for the sending of newsletter for the purposes identified under letter e) above will be stored for a maximum period of 24 months unless Business Users withdraw their consent previously.

At the end of the above-mentioned data retention periods, the Business Users’ Personal Data will be deleted or made anonymous. 

The Business Users’ Personal Data of Business Users that delete their personal account, where applicable, will be no longer stored, unless such storage is specifically required by a legislative provision. 

Disclosures to Third Parties Assisting In Our Operations. Cynny may share the Business Users’ Personal Data under proper data processing agreements with other companies that work with, or on behalf of Cynny, to provide products and services, such as a cloud hosting service, a document storage company or payment processing services.  These companies shall have access only to the Business Users’ Personal Data that are necessary to carry out their duties and, in any case, shall process the Business Users’ Personal Data in accordance with this Privacy Policy , the relevant data processing agreement and the applicable privacy legislation. However, these companies do not have any independent right to share this information. 

Disclosures Under Special Circumstances.  As already indicated under the section above “Purposes and legal basis of the processing of Business Users’ Personal Data”, letter c), we may provide the Business Users’ Personal Data to respond to subpoenas, court orders, legal process or governmental regulations, or to establish or exercise our legal rights or defend against legal claims. We believe it is necessary to share information in order to investigate, prevent or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any Business User or any other person, or as otherwise required by law.


The Service may contain links to third-party websites that may offer information of interest. This Privacy Policy does not apply to those websites. Therefore, Cynny recommends you to review those websites’ privacy policies individually.


Cynny understands that storing data in a secure manner is essential. Cynny stores the Business Users’ Personal Data and other data using industry standard physical, technical and administrative safeguards to secure data against foreseeable risks, such as unauthorized use, access, disclosure, destruction or modification.  Please note, however, that while Cynny has endeavored to create secure and reliable Service for Business Users, the confidentiality of any communication or material transmitted to or from the Service or via e-mail cannot be guaranteed in case of breaches attributable to third parties or in any case outside of Cynny’s control.

Important Notices to European Business Users 

The provided Business Users’ Personal Data are stored within the European Union. However, considering that the Service is available worldwide, as a result of technical services provided by third parties, the Business Users’ Personal Data may be transferred also to third countries outside the European Union subject to the verification of the existence of appropriate measures to ensure that the above-mentioned Personal Data is adequately protected in the country of destination, such as the existence of an adequacy decision of the European Commission, the adoption of standard contractual clauses for the protection of personal data pursuant to Article 46, paragraph 2, letters c) and d) of GDPR, or the adoption of the binding corporate rules pursuant to Article 47 of GDPR. 

Rights of the Business Users

For EU regulation 2016/679: Articles 15, 16, 17, 18, 19, 20, 21, 22,

1. The data subject has the right to obtain confirmation as to whether or not personal data concerning him or her exist, regardless of their being already recorded, and disclosure of such data in intelligible form, and the right to lodge a complaint with the supervisory authority.

2. The data subject has the right to be informed of:

  1. the source of the personal data;
  2. the purposes and methods of processing;
  3. the logic applied if the data are processed by electronic devices;
  4. the identification data concerning the Data Controller, the Data Processors and the representative designated as per article 5, comma 2;
  5. the entities or categories of entity to whom or which the personal data may be disclosed and who or which may get to know said data as designated representative in the State’s territory, as data processors or as persons in charge of the processing.

3. The data subject is entitled to obtain:

  1. the updating, rectification or, where interested therein, integration of the data;
  2. the erasure, anonymisation or blocking of data that have been unlawfully processed, including data whose retention is not necessary for the purposes for which they were collected or subsequently processed;
  3. certification to the effect that the operations as per letters a) and b) have been notified, as also related to their contents, to the entities to whom or which the data were disclosed or disseminated, unless this requirement proves impossible or involves a manifestly disproportionate effort compared to the right that is to be protected;
  4. the portability of the data.

4. The data subject has the right to object, in whole or in part:

  1. on legitimate grounds, to the processing of personal data concerning him/her, even though they are relevant to the purpose of the collection;
  2. to the processing of personal data concerning him/her, where it is carried out for the purpose of sending advertising materials or direct selling or else for the performance of market or commercial communication surveys.

At any time, you may ask Cynny to verify and obtain access to the Business Users’ Personal Data that Cynny has collected in order to integrate, update, rectify, cancel or request the limitation of the processing of such data, or object to the processing (including the nature of the same in case of automated processing). You also have the right to receive the above-mentioned Personal Data in a readable and commonly used format, and have the right to transmit those data to another controller without any obstacle from Cynny. Business Users may also oppose the processing of Business Users’ Personal Data for the sending of newsletters as well as to refuse to continue receiving Soft Spam Communications. 

You can send your request via email to

If you prefer, you can also mail your request to the following postal address: Cynny S.p.a., Via Delle Mantellate n. 8, 50129 Firenze (Italy). 

With particular regard to newsletter emails or Soft Spam Communications, Business Users may object to receiving such communications also by clicking on the link contained in each newsletter email or Soft Spam Communication they have received. 

Pursuant to Article 13 of the GDPR, if you believe that the processing of the Business Users’ Personal Data infringes the legislation on the protection of personal data, you will also have the right to lodge a complaint with the competent Authority for the protection of personal data or, alternatively, appeal to the competent judicial authority.

Policy Updates

This Privacy Policy may be revised from time to time as we add new features and services, as laws change, and as industry privacy and security best practices evolve.  We display an effective date on the policy in the upper right corner of this Privacy Policy so that it will be easier for you to know when there has been a change. If we make any change to this Privacy Policy regarding use or disclosure of the Business Users’ Personal Data, we will provide advance notice through email reporting any changes to allow you to exercise your rights under the applicable privacy legislation. Small changes or changes that do not significantly affect individual privacy interests may be made at any time and without prior notice.


If you have any questions about this Privacy Policy or about Cynny’s handling of your Business Users’ Personal Data, please contact or mail your request to the following postal address: Cynny S.p.a., Via Delle Mantellate n. 8, 50129 Firenze (Italy). 

You can use the contact details above also if you need to obtain a copy of the list of third parties to whom the Business Users’ Personal Data may be disclosed, pursuant to the terms of this Privacy Policy; this list is constantly updated and, together with a copy of the appropriate or suitable guarantees, is available at Cynny’s head office.