1. Who is responsible
This notice applies to personal data handled through the cIAo early-access website and planned human-editing service. For privacy questions or rights requests, use the monitored email address in section 15 or the Privacy requests page.
If an organization decides why and how its documents are processed, that organization may be the controller and cIAo may process the document on its instructions. The applicable agreement explains those roles.
2. Data we use
We limit collection to data connected to the purposes described below.
- Category
- Account and contact
- Examples
- Name, email address, country, language, account role, and preferences.
- Source
- You, your organization, or the account service.
- Category
- Orders and documents
- Examples
- Instructions, document files and versions, service level, deadline, status, and delivery details.
- Source
- Customers, assigned editors, and reviewers.
- Category
- Communications and quality
- Examples
- Order messages, support requests, feedback, revisions, and human quality-review records.
- Source
- People taking part in the order or contacting support.
- Category
- Payments and payouts
- Examples
- Transaction references, amount, currency, status, refunds, and payout information. We do not store full payment-card credentials.
- Source
- You, the payment service, and our transaction records.
- Category
- Editors and applicants
- Examples
- Experience, languages, specialties, availability, application material, assignments, and quality history.
- Source
- Applicants, editors, reviewers, and work records.
- Category
- Security and service use
- Examples
- Sign-in and access events, IP address, browser or device information, security alerts, and limited service-performance data.
- Source
- Your device, network requests, and the service.
- Category
- Privacy and legal records
- Examples
- Consent choices, legal-document versions, privacy requests, and evidence required for compliance or legal claims.
- Source
- You, our records, and authorized advisers or authorities where necessary.
3. Required and optional data
Required data makes the requested service possible. Optional processing remains a real choice.
- Activity
- Use an account
- What is needed
- Basic contact, sign-in, and security information.
- Choice and consequence
- Required; without it we cannot create or protect an account.
- Activity
- Order human editing
- What is needed
- Instructions, a document, delivery details, and payment status.
- Choice and consequence
- Required for that order; omit information that is not needed for the edit.
- Activity
- Pay or receive money
- What is needed
- Transaction and verification information required by the payment service or law.
- Choice and consequence
- Required for the relevant payment, refund, or payout.
- Activity
- Optional analytics or marketing
- What is needed
- A consent choice and limited usage or contact information.
- Choice and consequence
- Optional; the core editing service continues if you decline or withdraw.
4. Purposes and legal bases
Each use of personal data must have a defined purpose and legal basis.
- Purpose
- Provide accounts and human editing
- Data involved
- Account, order, document, communication, assignment, and quality data.
- Legal basis
- Contract or steps requested before a contract (GDPR Art. 6(1)(b)).
- Purpose
- Process payments, refunds, and payouts
- Data involved
- Account, order, transaction, and payout data.
- Legal basis
- Contract and legal obligations (Arts. 6(1)(b) and 6(1)(c)).
- Purpose
- Support users and resolve disputes
- Data involved
- Contact, order, communication, and relevant evidence.
- Legal basis
- Contract and legitimate interests in resolving requests and defending claims (Arts. 6(1)(b) and 6(1)(f)).
- Purpose
- Protect the service and prevent abuse
- Data involved
- Sign-in, access, transaction, audit, and security data.
- Legal basis
- Legitimate interests in operating a secure service, and legal duties where applicable (Arts. 6(1)(f) and 6(1)(c)).
- Purpose
- Meet tax, accounting, and other legal duties
- Data involved
- Minimum account, transaction, and compliance records.
- Legal basis
- Legal obligation and legitimate interests in legal claims (Arts. 6(1)(c) and 6(1)(f)).
- Purpose
- Improve reliability and service quality
- Data involved
- Minimized performance information, feedback, errors, and aggregate operational outcomes.
- Legal basis
- Legitimate interests, or consent where the collection method requires it (Arts. 6(1)(f) and 6(1)(a)).
- Purpose
- Optional analytics and marketing
- Data involved
- Consent choice, limited usage events, contact address, and unsubscribe record.
- Legal basis
- Consent, which may be withdrawn for the future (Art. 6(1)(a) and applicable device-access rules).
- Purpose
- Handle privacy requests
- Data involved
- Identity checks, the request, our response, and completion evidence.
- Legal basis
- Legal obligation (Art. 6(1)(c)).
5. Documents containing information about other people
Documents may contain personal or confidential information about people other than the uploader. The uploader must be entitled to provide the material and should remove details that are not needed for the edit.
Do not upload highly sensitive information, information about children, identity or banking numbers, or legally privileged material unless the service has expressly confirmed that the document type is supported and the required safeguards are in place.
6. Optional specialist processing
A specialist feature that would send document text to another provider is not part of ordinary human editing unless it is expressly offered and selected. Before any such use, we will show a short notice naming the recipient and explaining the text sent, purpose, legal basis, retention, location, and available choice.
A specialist or automated signal is treated as advisory. It does not by itself prove authorship or decide rejection, suspension, payment, or payout.
7. Who receives data
Access is limited to the following specific categories and only for the stated function.
- Recipient category
- Assigned editors and reviewers
- Purpose
- Perform the requested edit and human quality review.
- Data involved
- The document and minimum order context needed for the assignment.
- Recipient category
- Account, hosting, and secure-storage providers
- Purpose
- Operate sign-in, the website, private storage, and core service records.
- Data involved
- Account, document, order, security, and technical data as needed for those functions.
- Recipient category
- Payment and payout providers
- Purpose
- Collect payments, issue refunds, prevent payment fraud, and transfer editor earnings.
- Data involved
- Contact, order reference, transaction, verification, and payout data.
- Recipient category
- Email and customer-support providers
- Purpose
- Send account or order messages and receive support requests.
- Data involved
- Email address and the minimum message or service-status information needed.
- Recipient category
- Security, analytics, or specialist providers
- Purpose
- Protect files or the service, measure optional product use, or provide a feature you specifically request.
- Data involved
- Only the data described at the point of use and limited to that purpose.
- Recipient category
- Professional advisers and public authorities
- Purpose
- Meet legal duties, respond to valid requests, audit, insure, or establish and defend claims.
- Data involved
- Only the records necessary for the matter.
8. International transfers
Some provider categories may process data outside the European Economic Area. Where required, we rely on an adequacy decision, approved contractual clauses with appropriate safeguards, or another lawful transfer mechanism.
You may ask for information about the transfer mechanism and a copy of relevant safeguards, subject to necessary protection of confidential and security information.
10. Retention
We do not keep every type of data for the same period.
- Data
- Completed-order files
- Retention approach
- Deleted after the order-specific retention deadline shown in the account. A revision, dispute, legal duty, security issue, or valid hold may require limited longer retention.
- Data
- Abandoned or unpaid files
- Retention approach
- Deleted after the short operational period configured for an abandoned order, unless a payment, fraud, security, dispute, or legal hold requires limited retention.
- Data
- Account, support, and security records
- Retention approach
- Kept while needed for the account or request and then only as long as necessary for security, legal duties, or claims; otherwise deleted or anonymized.
- Data
- Payment, tax, and legal records
- Retention approach
- Kept for the statutory period that applies to the record. This does not extend the retention of document files.
- Data
- Optional analytics and marketing
- Retention approach
- Kept only for the stated purpose and deleted or anonymized after withdrawal or when no longer needed, subject to limited proof of the choice.
- Data
- Provider copies and backups
- Retention approach
- Provider copies follow the enabled service’s deletion or expiry process. Backups expire on a rolling schedule; if deleted data is restored, it is queued for deletion again unless a valid hold applies.
11. Security
We use organizational and technical measures designed to limit access, protect accounts and files, and detect misuse. Access is restricted by role and assignment, and people handling documents are subject to confidentiality obligations.
No online service can promise perfect security. If an incident affects personal data, we assess it and make any notifications required by law.
12. Automated processing and human review
Rules and calculations may help with prices, assignments, payment status, access control, security, and service operations. We do not make solely automated decisions that have legal or similarly significant effects on you under this notice.
A material decision about quality, integrity, access, or payout requires human review and can be challenged through support.
13. Your rights
Depending on the circumstances, you may request access, correction, erasure, restriction, or portability. You may object to processing based on legitimate interests and to direct marketing at any time. You may withdraw consent for the future without affecting earlier lawful processing.
We normally respond within one month. Rights can be limited by applicable law or the rights of others, and we may verify identity proportionately. Do not send passwords, full payment details, an identity-document image, or a confidential draft in your first message.
14. Children and sensitive data
The service is intended for adults aged 18 or older unless a separately approved organization flow provides the required authority and safeguards.
We do not ordinarily request special-category or criminal-offence data. A document may still contain it, so only include sensitive information when it is necessary and you are entitled to provide it.
15. Changes, contact, and complaints
We show the version and publication date of this notice. Material changes will be communicated when required, and a new purpose will not be applied retroactively where another legal basis or choice is needed.
Use the email address below or the Privacy requests page to contact us. You may also complain to a data-protection authority in your habitual residence, place of work, or the place of the alleged infringement.
Contact
Email customersupport@ciaowrite.com. Do not include a password, full payment data, an identity document, or a confidential draft in your first message.