Legal · Privacy Policy
How We Handle Your Data
Last updated: March 2026 · Version 1.0
CITAQ processes B2B product data only. We do not collect, store, or process consumer personal information. This policy describes how we handle operator account data and product catalog information under GDPR, CCPA, and applicable data protection law.
Regulatory Classification
CITAQ is NOT a data processor under GDPR Article 28.
CITAQ operates as a B2B verification infrastructure platform. We process product claims, evidence documents, and operator account data — not consumer personal data. Operators who use CITAQ remain the data controllers for their own customer data. CITAQ does not act as a sub-processor for consumer PII under any operator arrangement.
| Party | Role |
|---|---|
| CITAQ | Data Controller (operator account data) |
| Operator | Data Controller (their customer data) |
No consumer PII processed. CITAQ does not track, profile, or store data about the end consumers who visit your store. No consumer cookies. No behavioral tracking. No personal data from third-party customers.
Data We Process
| Data Category | Description | Legal Basis |
|---|---|---|
| Operator Account Data | Name, email address, company name, store URL, and billing contact used for account management and authentication. | GDPR Art. 6(1)(b) — contract |
| Product Catalog Data | Product claims, descriptions, SKUs, attributes, and images you submit for verification analysis. | GDPR Art. 6(1)(b) — contract |
| Evidence Documents | Certifications, laboratory test reports, compliance records, and third-party attestations you upload. | GDPR Art. 6(1)(b) — contract |
| Session and Activity Logs | Authentication tokens, API call logs, and access records required for platform security and immutable audit trail. | GDPR Art. 6(1)(f) — legitimate interest |
| Financial Transaction Records | Credit wallet activity, payment records, and billing history. Required for regulatory compliance. | GDPR Art. 6(1)(c) — legal obligation |
| Platform Telemetry | Aggregated, anonymized operational metrics. No individual operator is identifiable. | GDPR Art. 6(1)(f) — legitimate interest |
Data Retention Schedule
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Access Logs | 90 days hot | GDPR Art. 32 security |
| API Request Logs | 30 days hot / 365 days cold | Security audit |
| MCP Invocation Logs | 90 days hot / 2 years cold | Audit trail |
| Operational Telemetry | 30–90 days (anonymized) | GDPR minimization |
| Financial Transactions | 7 years | PCI DSS / IRS |
| Audit Trail Events | Permanent (immutable) | PROHIBITION-001 |
| Evidence Vault Records | 10+ years | EU DPP / audit integrity |
| SHA-256 Hash Records | Permanent (even after deletion) | PROHIBITION-001 |
| Automated Backups | Provider-managed | Disaster recovery |
Evidence Immutability
Structural constraint — PROHIBITION-001
Evidence documents, audit log events, verification credentials, and cryptographic hash records cannot be permanently deleted. This is a structural constraint of the platform, not a policy decision.
Soft-delete
You may flag evidence as inactive within 30 days of upload. The document is removed from active verification status but retained in the immutable audit vault.
Hard-delete window
A 30-day grace period exists for flagging evidence submitted in error. After 30 days, no erasure is possible without a legal mandate (court order, regulatory requirement).
SHA-256 hashes permanent
Cryptographic hash fingerprints of all evidence documents are retained permanently, even if the underlying document is soft-deleted. This enables audit trail continuity without storing document content.
Legal mandate exception
Full erasure is only possible with a court order or regulatory mandate. CITAQ will comply within 72 hours of receiving a valid legal instrument.
Metrics We Do Not Collect
CITAQ operator dashboards display only: compliance status, evidence expiry dates (absolute), policy violation counts (absolute), and pending review items (absolute). The following metrics are architecturally prohibited from operator-facing surfaces:
- Verification rates (ratio of verified vs. unverified claims)
- Request volumes (number of agent queries about your products)
- Agent type distribution (which AI systems query your catalog)
- Drift detection rates (how often your claims are flagged)
- Evidence tier consumption rates (breakdown by tier usage)
This is a constitutional constraint (PROHIBITION-004), not a configurable setting. These metrics cannot be enabled, requested via API, or provided through any channel.
Security Controls
| Control | Standard | Description |
|---|---|---|
| AES-256-GCM | GDPR Art. 32 | Encryption at rest. Sensitive stored credentials, including Shopify OAuth access tokens, are encrypted at rest using AES-256-GCM. |
| TLS 1.2+ | GDPR Art. 32 | Encryption in transit. All network connections are encrypted in transit using TLS 1.2 or higher. |
| SHA-256 | PROHIBITION-001 | Cryptographic hashing. All evidence documents and audit events receive a SHA-256 hash fingerprint retained permanently. |
| 90-day retention | SOC 2 CC6 | Access logging. All data access events logged with timestamp, user ID, and operation type. Immutable append-only store. |
| 72-hour window | GDPR Art. 33 | Breach notification. Affected operators notified within 72 hours of confirmed breach per GDPR Article 33 requirement. |
Compliance targets
SOC 2 Type II (target) · ISO 27001:2022 Annex A · GDPR Article 32 · PCI DSS (financial records)
Data Residency and Transfers
EU operators
EU operator data is stored in an EU database region (Frankfurt). All data is encrypted at rest and in transit, consistent with GDPR Article 44 (data transfer restrictions).
EU database region
US / global operators
US and global operator data is stored in a US database region (N. Virginia). All data is encrypted at rest and in transit. CCPA rights apply to California-based operators.
US database region
Isolation guarantee:Cross-tenant data access is prevented through per-workspace ownership checks enforced on every operator request. No operator can access another operator's catalog, evidence vault, or account data under any conditions.
Sub-Processors
CITAQ uses the following sub-processors. All sub-processors have executed Data Processing Agreements (DPAs) and maintain adequate safeguards under GDPR Article 46.
| Processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Vercel | Hosting, edge compute, content delivery | Global (US / EU edge network) | SCCs + DPA |
| Neon (PostgreSQL) | Database (serverless Postgres) | US / EU (region-selectable) | DPA executed |
| Resend | Transactional email delivery | United States | DPA executed |
| Stripe | Payment and subscription billing | US / global | SCCs + DPA (PCI DSS) |
Your Rights
Access (Art. 15)
Download all account data, product catalog records, and evidence metadata associated with your operator account in JSON or CSV format.
Rectification (Art. 16)
Update product claims, evidence metadata, account information, and contact details at any time via the platform dashboard.
Erasure (Art. 17)
Request account deletion. Evidence attestations, audit trail events, and SHA-256 hashes are excluded from erasure due to immutability constraints (PROHIBITION-001).
Data Portability (Art. 20)
Export your full account data in machine-readable JSON or CSV format. Evidence references export as URIs pointing to your uploaded documents.
Object to Processing (Art. 21)
Object to processing based on legitimate interest. We will evaluate and respond within 30 days.
Lodge a Complaint (Art. 77)
Contact your jurisdiction's data protection authority. EU operators may contact the relevant supervisory authority in their member state.
Rights requests are handled within 30 days (GDPR standard). Submit requests to privacy@citaq.io. Identity verification required before processing.
No Algorithmic Profiling
CITAQ's scoring engine is deterministic and rule-based. We do not train machine-learning models on your data, build behavioral profiles, make predictions about your product performance, or make automated decisions that affect your account status. Verification status changes only when you take an action (uploading evidence, modifying claims) or when submitted evidence reaches its expiry date.
Contact
Privacy requests: privacy@citaq.io
Security incidents: security@citaq.io
72-hour breach notification commitment under GDPR Article 33.