This policy explains what personal data CITS (Cognitive Integrated Technology Services) collects, why we collect it, how long we keep it and what rights you have over it. We have tried to write it in plain language rather than in the defensive dialect these documents usually use.
Who we are
CITS (Cognitive Integrated Technology Services) is the data controller for personal data collected through this website and through our direct business relationships. Where we process data on behalf of a client, for example inside a platform we built and operate for them, that client is the controller and we act as a processor under a written agreement.
For any privacy question, contact us at the address in the Contact section at the end of this policy. We aim to respond within five working days.
Data we collect
- Contact details you give us (name, email address, telephone number, company and role) when you submit an enquiry, project brief, discovery call request or job application.
- Project information you choose to share, including budget range, timelines and any documents you attach to a brief.
- Recruitment data, including CVs, portfolio links and interview notes, when you apply for a role.
- Technical data such as IP address, browser type, device type, referring page and pages visited, collected through analytics where you have consented.
- Communication records (emails, call notes and meeting summaries) relating to our business relationship.
Why we process it
- To respond to your enquiry and prepare a proposal: necessary for steps taken at your request prior to entering a contract.
- To deliver contracted services, manage the engagement and invoice for it: performance of a contract.
- To assess job applications: steps prior to an employment contract, and our legitimate interest in recruiting.
- To understand how the website is used and improve it: consent, where analytics cookies are accepted.
- To send occasional updates about our work, where you have subscribed: consent, withdrawable at any time.
- To meet accounting, tax and other legal obligations: legal obligation.
Legal bases
Where the UK GDPR, EU GDPR or India's Digital Personal Data Protection Act applies, we rely on one of the following: performance of a contract or pre-contractual steps; your consent; our legitimate interests in operating and promoting a business, balanced against your rights; or compliance with a legal obligation.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before withdrawal.
International transfers
Some of our processors operate outside your country of residence. Where personal data is transferred internationally, we rely on an adequacy decision where one exists, or on standard contractual clauses together with supplementary technical measures such as encryption in transit and at rest.
How long we keep it
- Enquiries that do not become projects: 24 months from last contact.
- Client records and project documentation: the duration of the engagement plus 7 years, to meet contractual and tax obligations.
- Unsuccessful job applications: 12 months, so we can contact you about future roles, unless you ask us to delete them sooner.
- Newsletter subscriptions: until you unsubscribe.
- Analytics data: 14 months in aggregated, non-identifying form.
Your rights
Subject to your jurisdiction, you have the right to access the personal data we hold about you, to have inaccurate data corrected, to request erasure, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent.
To exercise any of these, email us. We will verify your identity before acting on a request. You also have the right to complain to your data protection authority: in the UK the Information Commissioner's Office, in India the Data Protection Board.
Security
We apply encryption in transit and at rest, least-privilege access control, multi-factor authentication on business systems, dependency scanning, and periodic access reviews. No system is perfectly secure, but we design so that a single failure does not become a general one, and we will notify you and the relevant authority without undue delay if a breach affects your data.
Children
Our services are directed at businesses. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We may update this policy as our services or obligations change. The date at the top reflects the most recent revision, and material changes will be highlighted on this page.
Contact
Privacy questions and rights requests: hello@citsglobal.co. Please include enough detail for us to identify the data you are asking about.