Cytranet Privacy Policy
Section 1
Scope and who we are
Telecommunications Firm, LLC, doing business as Cytranet (“Cytranet,” “we,” “us,” or “our”), is a Nevada limited liability company and a licensed telecommunications carrier headquartered in Las Vegas, Nevada. We provide dedicated fiber-optic Internet access, bonded and broadband connectivity, voice and data services, and managed information technology services to business, enterprise, and government customers in Nevada, Arizona, California, and elsewhere in the United States.
This policy applies to the website located at cytranet.com and its subdomains, to our customer account and billing portal, to information you submit through our online forms, and to information we obtain in the course of providing and billing for our services. It applies to prospective customers, current customers, authorized end users on a customer account, vendors, and general visitors.
This policy does not apply to the internal privacy practices of a business or government customer who resells or extends our service to its own users, or to third-party websites and services that you reach through links on our site. Where a signed master service agreement, government contract, task order, or nondisclosure agreement between you and Cytranet imposes stricter confidentiality or data-handling obligations, those instrument terms govern the information covered by them.
Section 2
Information we collect
We collect only what we need to quote, provision, deliver, support, secure, and bill for service, and to meet our obligations as a regulated carrier. We group that information into six categories.
Information you give us directly
- Contact and inquiry information submitted through quote requests, coverage checks, support forms, and email: name, business name, job title, service address, billing address, telephone number, and email address.
- Service order information: requested bandwidth and service type, installation site details, building access and demarcation details, existing carrier and circuit identifiers being ported or replaced, and desired turn-up dates.
- Account credentialing information for the customer portal: username, password (stored only as a salted cryptographic hash), authorized contacts, and account security verification details.
- Billing information: billing contact, purchase order and tax exemption identifiers, remittance details, and payment card or bank account information. Payment card and bank data are collected and processed by our PCI DSS compliant payment processor; Cytranet does not store full payment card numbers on its own systems.
- Business qualification information for credit review, and for government customers, registration identifiers such as UEI, CAGE, and contract or task order numbers.
- Support communications: trouble tickets, correspondence, and — where you are notified in advance — recordings or transcripts of support and sales telephone calls.
Information generated by providing service
- Circuit and service identifiers, IP address assignments, MAC addresses of provisioned equipment, VLAN and routing configuration, and physical port and facility assignments.
- Network performance and utilization telemetry, including throughput, latency, jitter, packet loss, error counts, and outage and restoration records.
- Call detail records for voice services: numbers dialed and received, date, time, duration, and jurisdiction of calls.
- Authentication, session, and equipment status logs generated by network elements.
Cytranet does not inspect, read, log, or sell the content of your Internet traffic, email, messages, or telephone conversations. We do not conduct deep packet inspection for marketing or advertising purposes. We inspect traffic only at the header and flow level, and only for network operation, capacity planning, abuse and attack mitigation, and lawful compliance.
Information collected automatically on our website
- IP address, approximate city- or region-level location derived from that address, browser type and version, operating system, device type, screen dimensions, and language settings.
- Referring URL, pages viewed, time on page, scroll and click interactions, files downloaded, and exit pages.
- Cookie and similar identifiers as described in Section 5.
Information from third parties
- Business credit reporting agencies and public commercial records, used for credit and fraud review on new commercial accounts.
- Underlying carriers, dark fiber providers, colocation operators, and building owners, in connection with facility availability, cross-connects, and circuit provisioning.
- Federal, state, and local procurement systems, including SAM.gov, for government contracting.
- Advertising and analytics partners, which may return aggregated campaign and audience measurement data.
Information from site visits by cameras and physical access controls
Where a technician performs an installation or maintenance visit, we may record the date, time, personnel present, work performed, and photographs of installed equipment and demarcation points for as-built documentation. In secured facilities, our personnel are subject to the badging, escort, and recording practices of the facility operator.
Sensitive information we do not seek
We do not knowingly collect Social Security numbers from consumers, precise geolocation, biometric identifiers, health information, or information about race, religion, sexual orientation, or political affiliation. Please do not include such information in support tickets or form submissions. A sole proprietor applying for commercial credit may be asked for a taxpayer identification number, which we treat as confidential and encrypt at rest.
Section 3
Customer Proprietary Network Information
As a telecommunications carrier, Cytranet is subject to Section 222 of the Communications Act of 1934, as amended, 47 U.S.C. § 222, and to the Federal Communications Commission’s CPNI rules at 47 C.F.R. §§ 64.2001 through 64.2011. This section is our notice to you regarding that information and your rights in it.
What CPNI is
Customer Proprietary Network Information is information that relates to the quantity, technical configuration, type, destination, location, and amount of use of the telecommunications service you purchase from us, and information contained on your bill. In practical terms, this includes the services and features you subscribe to, the bandwidth and circuits you buy, the numbers you call and the numbers that call you, when and how long those calls last, and how much you are charged. Your name, address, and telephone number appearing in published directory listings are not CPNI.
How we use CPNI without asking you
Federal law permits us to use CPNI without additional customer approval to provision, provide, bill, and collect for the services you already buy, to protect our network and other users from fraudulent, abusive, or unlawful use, and to provide inside wiring, installation, maintenance, and repair services. We may also use it to market service offerings within the categories of service to which you already subscribe.
Your right to restrict marketing use
We would like to use your CPNI to inform you about additional products and services outside the category you currently purchase — for example, telling a data-only customer about voice services, or a single-site customer about multi-site or managed IT offerings. You have the right to refuse this use, and refusing costs you nothing. Your decision does not affect your service, your rates, or the quality of support you receive, and it remains in effect until you revoke it.
To opt out, send written notice to the privacy contact in Section 17 stating your company name, account number, and that you are restricting the use of your CPNI for marketing. We will honor a properly submitted request within thirty days of receipt. If we do not hear from you within thirty days of the date this notice is provided to you, we will assume your approval for the uses described in this section.
How we protect and disclose CPNI
- We authenticate callers before disclosing call detail information over the telephone, using a customer-established password or, if a password is unavailable, by calling back to the telephone number of record or mailing the information to the address of record. We do not release call detail based on readily available biographical or account information alone.
- We notify the account of record whenever a password, customer response to a back-up authentication question, online account, or address of record is created or changed.
- We notify law enforcement of any breach of CPNI through the FCC’s central reporting facility, and we notify affected customers, in accordance with 47 C.F.R. § 64.2011 and the notification timing that rule requires.
- We train personnel who have access to CPNI, maintain a disciplinary process for violations, and maintain records of our own marketing campaigns that use CPNI for the period required by rule.
- We file an annual CPNI compliance certificate with the FCC as required by 47 C.F.R. § 64.2009(e).
We do not sell CPNI. We disclose it to third parties only with your approval, to our agents and contractors bound to protect it and use it solely for the purpose we specify, as required to provide the service, or as required by law.
Mobile messaging and SMS. Mobile phone numbers and SMS consent collected by Telecommunications Firm, LLC d/b/a Cytranet are used solely to deliver service-related notifications to the account holder, including technician dispatch, outage and restoration alerts, and account notifications. Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes. No mobile opt-in data is sold, rented, or disclosed to any third party for marketing purposes. Any other section of this Privacy Policy addressing information sharing expressly excludes SMS opt-in and consent data. Message frequency varies and message and data rates may apply. You may opt out at any time by replying STOP, END, CANCEL, or UNSUBSCRIBE to any message, or by contacting support@cytranet.com or 702-846-5000. Full messaging terms are available at https://cytranet.com/sms-policy/.
Section 4
How we use information
| Purpose | What this involves |
|---|---|
| Quoting and provisioning | Confirming serviceability at an address, designing the circuit, coordinating construction and building access, and scheduling turn-up. |
| Service delivery and support | Monitoring circuits, diagnosing faults, dispatching technicians, and resolving trouble tickets. |
| Billing and collections | Invoicing, processing payments, applying taxes and regulatory surcharges, and pursuing past-due balances. |
| Network security | Detecting and mitigating denial-of-service attacks, abuse, spam origination, port scanning, and unauthorized access. |
| Regulatory compliance | Universal Service Fund and regulatory fee reporting, 911 and E911 record accuracy, number porting, CALEA obligations, and records retention. |
| Improving the website | Understanding which pages and coverage areas visitors use, and fixing errors and slow pages. |
| Marketing | Sending service announcements and, subject to your CPNI election and email preferences, offers for other Cytranet services. |
| Contract and proposal work | Preparing responses to solicitations and administering awarded contracts and task orders. |
We do not use automated decision-making that produces legal or similarly significant effects about you without human review, and we do not use personal information to train third-party machine learning models.
Section 7
Law enforcement and legal process
We disclose customer information to law enforcement, regulators, or other parties when we are compelled to do so by valid legal process — a subpoena, court order, search warrant, wiretap order, pen register or trap-and-trace order, National Security Letter, or similar demand — or where disclosure is otherwise required or expressly permitted by law, including the Electronic Communications Privacy Act, the Communications Assistance for Law Enforcement Act, and Section 222 of the Communications Act.
Our practice is to review each demand for facial validity and proper jurisdiction, to produce only the specific records the demand reaches rather than an entire account file, and, where we are legally permitted and no exception applies, to notify the affected customer so that the customer may seek to quash or narrow the demand. Where a demand carries a nondisclosure order, we comply with that order.
We may also disclose information without legal process where we believe in good faith that an emergency involving danger of death or serious physical injury requires disclosure without delay, and where necessary to protect our rights, property, network, or personnel, or to investigate suspected fraud or violations of our Acceptable Use Policy.
Section 8
Nevada rights and opt-out of sale
Nevada Revised Statutes Chapter 603A, as amended by Senate Bill 220 (2019) and Senate Bill 260 (2021), gives Nevada consumers the right to direct an operator of an Internet website or online service not to make any sale of certain covered information collected about them. Covered information includes name, physical address, email address, telephone number, Social Security number, an identifier that allows a specific person to be contacted, and any other information collected and maintained in combination with an identifier in a form that makes it personally identifiable.
Under NRS 603A.320, a “sale” means the exchange of covered information for monetary consideration by the operator to a person for that person to license or sell the information to additional persons. Cytranet does not engage in such sales, and we have no present intention of doing so. We nonetheless honor verified opt-out requests and maintain a record of them, so that our position does not change without your knowledge.
To submit a request, email the privacy contact in Section 17 with the subject line “Nevada Opt-Out of Sale,” and include your name, the email address and physical address associated with your interaction with us, and a statement that you are directing Cytranet not to sell your covered information. We will verify your request and respond within sixty days as required by NRS 603A.345, and may extend that period by thirty days where reasonably necessary, in which case we will notify you of the extension.
Nevada law also requires operators to state whether a third party may collect covered information about a consumer’s online activities over time and across different websites. Our analytics and advertising partners described in Section 5 may do so. You may limit this by declining analytics and advertising cookies.
Cytranet is a Nevada company serving customers in several states. If you reside in a state that grants broader privacy rights than Nevada does, tell us in your request which state’s law you are invoking. As a matter of practice, we extend access, correction, and deletion handling to all United States customers on the same terms, subject to the records we are required by federal and state telecommunications law to retain.
Section 9
Your choices and access rights
- Access and correction. You may request a copy of the personal information we hold about you and ask us to correct anything inaccurate. Account administrators can review and correct most contact, billing, and technical details directly in the customer portal.
- Deletion. You may request deletion of information that we are not required to retain. We will explain what we cannot delete and why — carrier records, call detail, tax records, and contract files are commonly subject to mandatory retention.
- Marketing email. Every marketing message includes an unsubscribe link, and we honor unsubscribe requests within ten business days as required by the CAN-SPAM Act. Transactional and operational messages — outage notices, maintenance windows, invoices, service disconnection warnings, and legally required notices — continue regardless of your marketing preferences, because you need them to use the service.
- Text messages. Where you have consented to receive outage or dispatch notifications by text, reply STOP to any message to end them.
- CPNI restriction. See Section 3.
- Directory listing. For voice service, you may request that your listing be unpublished or non-listed.
We verify requests before acting on them. For an account holder, we verify through the account of record and established authentication. For a website visitor with no account, we may ask for information sufficient to match your request to our records, and we will use that information only for verification. We do not charge a fee for a first request in any twelve-month period, and we do not deny service, charge different prices, or provide a different level of service because you exercised a privacy right.
An authorized agent may submit a request on your behalf with written authorization signed by you, and we may still contact you directly to confirm.
Section 10
Security safeguards
NRS 603A.210 requires businesses that maintain records containing personal information of Nevada residents to implement and maintain reasonable security measures. NRS 603A.215 requires encryption of personal information transmitted electronically outside our secure system and of data storage devices moved beyond our logical or physical controls. Our program is designed to meet those obligations, and we align our internal controls with the NIST Cybersecurity Framework.
- Transport Layer Security on all website, portal, and API traffic, and encryption at rest for stored credentials, financial identifiers, and customer databases.
- Role-based access control, least-privilege provisioning, and multi-factor authentication for administrative and network management access.
- Network segmentation between corporate systems, provisioning and management planes, and customer-facing systems.
- Centralized logging, monitoring, and alerting, with periodic review of privileged access.
- Background screening and confidentiality obligations for personnel with access to customer records, and CPNI-specific training with a documented disciplinary process.
- Vendor due diligence and contractual data-protection terms before a service provider receives customer information.
- Vulnerability management, patching, and periodic third-party assessment; secure destruction of media and paper records at end of life.
No system is perfectly secure. We do not guarantee that unauthorized access will never occur, and you are responsible for safeguarding your portal credentials and for promptly telling us if you believe an account has been compromised. Suspected vulnerabilities in our systems may be reported to the security contact in Section 17.
Section 11
Retention and disposal
We keep information for as long as needed for the purpose it was collected, and then for any additional period required by law, contract, or the defense of legal claims.
| Record type | Retention |
|---|---|
| Website inquiry and quote forms not converted to an order | 24 months from last contact |
| Customer account and service records | Term of service plus 7 years |
| Billing, tax, and payment records | 7 years |
| Call detail records for billed toll service | Not less than 18 months, per 47 C.F.R. § 42.6 |
| Network and security logs | 12 months, longer where subject to an active investigation or legal hold |
| CPNI marketing campaign records | 1 year, per 47 C.F.R. § 64.2009(c) |
| Government contract files | As required by the contract and applicable FAR records clauses |
| Analytics and advertising identifiers | Per the partner’s retention settings, not to exceed 26 months |
When a retention period ends, we destroy records in accordance with NRS 603A.200 by shredding, erasing, or otherwise modifying them so the personal information is unreadable and cannot practicably be reconstructed. A litigation hold or lawful preservation request suspends destruction for the affected records until the hold is released.
Section 12
Breach notification
If we determine that unencrypted personal information has been acquired by an unauthorized person, we will notify affected individuals in the most expedient time possible and without unreasonable delay, consistent with the needs of law enforcement and any measures necessary to determine the scope of the breach and restore the integrity of the system, as required by NRS 603A.220. Where a breach affects more than 1,000 Nevada residents at one time, we will also notify the major consumer reporting agencies as that statute requires. Where the breach involves CPNI, we will follow the separate federal process in 47 C.F.R. § 64.2011, including notification to the United States Secret Service and the Federal Bureau of Investigation through the FCC’s central reporting facility. Where a breach affects a government customer, we will follow the incident reporting timelines in the applicable contract.
Section 13
Children’s privacy
Cytranet sells to businesses, enterprises, and government agencies. Our website and services are not directed to children under the age of thirteen, and we do not knowingly collect personal information from them, consistent with the Children’s Online Privacy Protection Act. If we learn that we have collected such information, we will delete it promptly. A parent or guardian who believes a child has provided information to us should contact the privacy contact in Section 17.
Where a school, library, or institutional customer provides our connectivity to minors, that customer is responsible for its own filtering, acceptable use, and consent obligations, including any obligations under the Children’s Internet Protection Act.
Section 14
Government and enterprise customers
Where Cytranet performs under a federal, state, or local government contract, the handling of information generated under that contract is governed by the contract, the applicable Federal Acquisition Regulation and agency supplement clauses, and any system security plan or authorization to operate that applies. This includes safeguarding of Controlled Unclassified Information and covered defense information where those clauses are incorporated. In the event of a conflict between this policy and such a contractual requirement, the contractual requirement controls for the information it covers.
Enterprise customers who require a data processing addendum, a business associate agreement, a security questionnaire response, or a subprocessor list may request one from the privacy contact in Section 17.
Section 15
Third-party sites and equipment
Our website links to third-party resources, and our service may be delivered alongside equipment or software licensed from third parties, including routers, firewalls, session border controllers, and hosted voice platforms. Those parties handle information under their own privacy policies, which we do not control. Review those policies before providing information to them. Where we provide managed equipment, we access it only for provisioning, monitoring, support, and security purposes described in this policy.
Our services are intended for use in the United States. If you access our website from outside the United States, understand that your information will be transferred to, stored in, and processed in the United States, where privacy laws may differ from those in your jurisdiction.
Section 16
Changes to this policy
We may revise this policy to reflect changes in our services, technology, or legal obligations. When we do, we will update the effective and revision dates at the top of this page and post the revised policy here. If a change materially reduces the protection of information we already hold about you, we will provide advance notice by email to the account of record, by a notice on your invoice, or by a prominent notice on this website, at least thirty days before the change takes effect. Continued use of our website or services after the effective date constitutes acceptance of the revised policy. Prior versions are available on request.
Section 17
How to contact us
Direct privacy questions, CPNI restriction requests, Nevada opt-out requests, access, correction, and deletion requests, and security reports to:
Privacy OfficerTelecommunications Firm, LLC d/b/a Cytranet
Las Vegas, Nevada
Privacy and data requests: privacy@cytranet.com
Security reports: security@cytranet.com
Web: www.cytranet.com
Please put the nature of your request in the subject line so we can route it correctly. We acknowledge requests within ten business days and substantively respond within the timeframes stated in Sections 3, 8, and 9.
If you are not satisfied with our response, you may contact the Nevada Office of the Attorney General, Bureau of Consumer Protection, or, for matters concerning telecommunications service and CPNI, the Federal Communications Commission Consumer and Governmental Affairs Bureau or the Public Utilities Commission of Nevada.
© 2026 Telecommunications Firm, LLC d/b/a Cytranet. All rights reserved. This policy is effective September 8, 2026 and supersedes all prior privacy notices published by Cytranet.
