CITAQ

Legal · Privacy Policy

How We Handle Your Data

Last updated: March 2026 · Version 1.0

CITAQ processes B2B product data only. We do not collect, store, or process consumer personal information. This policy describes how we handle operator account data and product catalog information under GDPR, CCPA, and applicable data protection law.

Regulatory Classification

CITAQ is NOT a data processor under GDPR Article 28.

CITAQ operates as a B2B verification infrastructure platform. We process product claims, evidence documents, and operator account data — not consumer personal data. Operators who use CITAQ remain the data controllers for their own customer data. CITAQ does not act as a sub-processor for consumer PII under any operator arrangement.

PartyRole
CITAQData Controller (operator account data)
OperatorData Controller (their customer data)

No consumer PII processed. CITAQ does not track, profile, or store data about the end consumers who visit your store. No consumer cookies. No behavioral tracking. No personal data from third-party customers.

Data We Process

Data CategoryDescriptionLegal Basis
Operator Account DataName, email address, company name, store URL, and billing contact used for account management and authentication.GDPR Art. 6(1)(b) — contract
Product Catalog DataProduct claims, descriptions, SKUs, attributes, and images you submit for verification analysis.GDPR Art. 6(1)(b) — contract
Evidence DocumentsCertifications, laboratory test reports, compliance records, and third-party attestations you upload.GDPR Art. 6(1)(b) — contract
Session and Activity LogsAuthentication tokens, API call logs, and access records required for platform security and immutable audit trail.GDPR Art. 6(1)(f) — legitimate interest
Financial Transaction RecordsCredit wallet activity, payment records, and billing history. Required for regulatory compliance.GDPR Art. 6(1)(c) — legal obligation
Platform TelemetryAggregated, anonymized operational metrics. No individual operator is identifiable.GDPR Art. 6(1)(f) — legitimate interest

Data Retention Schedule

Data TypeRetention PeriodLegal Basis
Access Logs90 days hotGDPR Art. 32 security
API Request Logs30 days hot / 365 days coldSecurity audit
MCP Invocation Logs90 days hot / 2 years coldAudit trail
Operational Telemetry30–90 days (anonymized)GDPR minimization
Financial Transactions7 yearsPCI DSS / IRS
Audit Trail EventsPermanent (immutable)PROHIBITION-001
Evidence Vault Records10+ yearsEU DPP / audit integrity
SHA-256 Hash RecordsPermanent (even after deletion)PROHIBITION-001
Automated BackupsProvider-managedDisaster recovery

Evidence Immutability

Structural constraint — PROHIBITION-001

Evidence documents, audit log events, verification credentials, and cryptographic hash records cannot be permanently deleted. This is a structural constraint of the platform, not a policy decision.

Soft-delete

You may flag evidence as inactive within 30 days of upload. The document is removed from active verification status but retained in the immutable audit vault.

Hard-delete window

A 30-day grace period exists for flagging evidence submitted in error. After 30 days, no erasure is possible without a legal mandate (court order, regulatory requirement).

SHA-256 hashes permanent

Cryptographic hash fingerprints of all evidence documents are retained permanently, even if the underlying document is soft-deleted. This enables audit trail continuity without storing document content.

Legal mandate exception

Full erasure is only possible with a court order or regulatory mandate. CITAQ will comply within 72 hours of receiving a valid legal instrument.

Metrics We Do Not Collect

CITAQ operator dashboards display only: compliance status, evidence expiry dates (absolute), policy violation counts (absolute), and pending review items (absolute). The following metrics are architecturally prohibited from operator-facing surfaces:

  • Verification rates (ratio of verified vs. unverified claims)
  • Request volumes (number of agent queries about your products)
  • Agent type distribution (which AI systems query your catalog)
  • Drift detection rates (how often your claims are flagged)
  • Evidence tier consumption rates (breakdown by tier usage)

This is a constitutional constraint (PROHIBITION-004), not a configurable setting. These metrics cannot be enabled, requested via API, or provided through any channel.

Security Controls

ControlStandardDescription
AES-256-GCMGDPR Art. 32Encryption at rest. Sensitive stored credentials, including Shopify OAuth access tokens, are encrypted at rest using AES-256-GCM.
TLS 1.2+GDPR Art. 32Encryption in transit. All network connections are encrypted in transit using TLS 1.2 or higher.
SHA-256PROHIBITION-001Cryptographic hashing. All evidence documents and audit events receive a SHA-256 hash fingerprint retained permanently.
90-day retentionSOC 2 CC6Access logging. All data access events logged with timestamp, user ID, and operation type. Immutable append-only store.
72-hour windowGDPR Art. 33Breach notification. Affected operators notified within 72 hours of confirmed breach per GDPR Article 33 requirement.

Compliance targets

SOC 2 Type II (target) · ISO 27001:2022 Annex A · GDPR Article 32 · PCI DSS (financial records)

Data Residency and Transfers

EU operators

EU operator data is stored in an EU database region (Frankfurt). All data is encrypted at rest and in transit, consistent with GDPR Article 44 (data transfer restrictions).

EU database region

US / global operators

US and global operator data is stored in a US database region (N. Virginia). All data is encrypted at rest and in transit. CCPA rights apply to California-based operators.

US database region

Isolation guarantee:Cross-tenant data access is prevented through per-workspace ownership checks enforced on every operator request. No operator can access another operator's catalog, evidence vault, or account data under any conditions.

Sub-Processors

CITAQ uses the following sub-processors. All sub-processors have executed Data Processing Agreements (DPAs) and maintain adequate safeguards under GDPR Article 46.

ProcessorPurposeLocationSafeguards
VercelHosting, edge compute, content deliveryGlobal (US / EU edge network)SCCs + DPA
Neon (PostgreSQL)Database (serverless Postgres)US / EU (region-selectable)DPA executed
ResendTransactional email deliveryUnited StatesDPA executed
StripePayment and subscription billingUS / globalSCCs + DPA (PCI DSS)

Your Rights

Access (Art. 15)

Download all account data, product catalog records, and evidence metadata associated with your operator account in JSON or CSV format.

Rectification (Art. 16)

Update product claims, evidence metadata, account information, and contact details at any time via the platform dashboard.

Erasure (Art. 17)

Request account deletion. Evidence attestations, audit trail events, and SHA-256 hashes are excluded from erasure due to immutability constraints (PROHIBITION-001).

Data Portability (Art. 20)

Export your full account data in machine-readable JSON or CSV format. Evidence references export as URIs pointing to your uploaded documents.

Object to Processing (Art. 21)

Object to processing based on legitimate interest. We will evaluate and respond within 30 days.

Lodge a Complaint (Art. 77)

Contact your jurisdiction's data protection authority. EU operators may contact the relevant supervisory authority in their member state.

Rights requests are handled within 30 days (GDPR standard). Submit requests to privacy@citaq.io. Identity verification required before processing.

No Algorithmic Profiling

CITAQ's scoring engine is deterministic and rule-based. We do not train machine-learning models on your data, build behavioral profiles, make predictions about your product performance, or make automated decisions that affect your account status. Verification status changes only when you take an action (uploading evidence, modifying claims) or when submitted evidence reaches its expiry date.

Cookie Policy

This section covers cookies set on citaq.iofor visitors and signed-in operators — it does not relate to the end consumers of your store, whom CITAQ never tracks. Essential cookies are always on because the service can't run without them. Analytics and marketing cookies load only after you opt in, and you can change or withdraw that choice at any time from the cookie preferences panel.

CategoryPurposeProviderRetention
EssentialSign-in, session security, CSRF protectionCITAQ (first-party)Session – 30 days
EssentialStores your cookie-consent choiceCITAQ (citaq_consent_v1)180 days
EssentialRemembers returning visitors to warm the dashboardCITAQ (citaq_known)180 days
AnalyticsAnonymous, cookieless usage & performance measurementVercel Analytics / Speed InsightsNo cookies set
AnalyticsAggregate site usage (IP-anonymized, Consent Mode v2)Google Analytics 4Up to 14 months
MarketingMeasures ad effectiveness; off by defaultMeta (Facebook) PixelUp to 90 days

Legal basis.Essential cookies rely on legitimate interest / contract (GDPR Art. 6(1)(b),(f)). Analytics and marketing cookies rely on your consent (GDPR Art. 6(1)(a); ePrivacy / PECR). Signed-in operators can also manage this from Settings → Privacy & Data. We never sell your data.

Contact

Privacy requests: privacy@citaq.io

Security incidents: security@citaq.io

72-hour breach notification commitment under GDPR Article 33.