Skip to content
CIQRA
All legal documents

Privacy Policy


IN FORCE. See 00-README. GDPR-core, with global sections (CCPA/CPRA §12, US states §13, UK §14). The Turkish (KVKK) supplement is in force and applies on top of this Policy for Türkiye (see 09; owner resolution 7, 2026-08-13). Cookies: see the Cookie Policy.

Legal basis. Every provision below rests on one of three things: a measured fact about the platform (cited to file and line), a rule of law (cited to the instrument and article in the Legal Basis Register), or a commercial choice CIQRA has made where the law leaves it open. Prepared and adopted by CIQRA OÜ.

🔴 Two claims in this Policy were withdrawn on 2026-08-09 as unsupported by the platform: Global Privacy Control honouring (§12) and intra-EEA AI processing (§4). ✅ The GPC half was CLOSED ON 2026-08-19 by building the facility — the signal is now read, the opt-out is persisted per visitor and per store, and it is enforced at the point that decides whether an advertising destination fires (§12, US-03). It is no longer launch-blocking, and §12 states in the same breath what it does not deny. The intra-EEA AI processing claim (§4) remains withdrawn and remains launch-blocking for the market it concerns.

Controller (for CIQRA's own processing): CIQRA OÜ, registry code 16465907, Veskiposti tn 2, Kesklinna linnaosa, Tallinn, Harju maakond, 10138, Estonia. Privacy contact: privacy@ciqra.com · DPO: none appointed — see the Art. 37 assessment in §1.1a.

1.1a Data Protection Officer — determination

CIQRA has not appointed a Data Protection Officer, because Art. 37(1) does not require one on the processing CIQRA carries out today.

🔒 The Art. 37 assessment (2026-08-10). Each limb, and the one that is close.

(a) public authority or body — not engaged. CIQRA OÜ is a private company.

(c) large-scale special-category or criminal-conviction data — not engaged. The platform processes no Art. 9 or Art. 10 data as a core activity; where a Merchant chooses to collect such data in its own storefront, that Merchant is the controller and the question is theirs.

(b) regular and systematic monitoring of data subjects on a large scalethis is the limb that is close, and it fails on ONE factor only. By nature it is engaged: the platform records storefront analytics events carrying pseudonymous identifiers and retains them for 400 days, and it forwards conversion events server-side to advertising platforms. Both are monitoring in the ordinary sense, and neither is ancillary support — server-side tracking is a paid entitlement, i.e. part of what CIQRA sells, which is what makes an activity core rather than incidental. What is missing is scale: as at 2026-08-10 the platform serves a small number of tenants and one live storefront, and "large scale" is assessed on the processing actually carried out, not on the architecture's capacity.

🔴 So this determination is bounded by a factor that changes without anyone deciding it. Nature and purpose already point at Art. 37(1)(b); only volume holds it back, and volume is the one input that moves on its own. Treating "no DPO" as settled would mean the answer silently becomes wrong on an ordinary business day, with no decision recorded anywhere.

③ CIQRA therefore fixes a re-assessment trigger — a commercial choice, not a statutory line, because the GDPR sets no threshold: the Art. 37 assessment is re-run, and this paragraph rewritten, before either (i) a second brand's storefront goes live, or (ii) server-side tracking is enabled for more than one tenant. Whichever comes first. The trigger is deliberately an event a person performs, not a date and not a visitor count: someone has to act for either to happen, and that is the moment the question can actually be put to them.

⚠️ What this paragraph does not claim. It is not a finding that Art. 37 will never apply — the opposite: it records that one limb is engaged on nature and excluded only on scale. And Art. 37(4) permits Member State law to require a DPO in further cases; the Estonian Isikuandmete kaitse seadus could not be retrieved in consolidated form (Legal Basis Register §8, three attempts), so this assessment is made against the Regulation and that limitation is stated rather than hidden.

🔑 And the defect this replaces was never the missing officer. It was that no assessment existed, so CIQRA could not show which answer it had reached — Art. 5(2) requires the controller to be able to demonstrate compliance, and a decision nobody wrote down demonstrates nothing. Two internal records previously disagreed with each other about the DPO; both are superseded by this paragraph. PA-0356.

Contact point. privacy@ciqra.com handles all data-protection enquiries and is the contact point named under Art. 33(3)(b) for breach notifications. That obligation exists whether or not a DPO is appointed, and is unaffected by this determination. Representatives: CIQRA is established in the EU (Estonia), so no GDPR Art. 27 EU representative is required. If CIQRA targets UK data subjects, a UK GDPR Art. 27 representative will be appointed (EU establishment does not cover the UK).

CIQRA's determination: no UK representative has been appointed. This is correct only while CIQRA does not target UK data subjects. 00-README §3 commits to global availability from launch, and a globally available storefront platform that accepts UK merchants and UK shoppers is difficult to characterise as not targeting the UK. The trigger should be treated as likely met at launch, not deferred to a later UK expansion. In force from: 2026-08-09 · Version: 1.0 · Adopted by: CIQRA OÜ


1. Scope and our two roles

CIQRA operates a multi-tenant e-commerce/CMS platform. Our privacy role depends on whose data it is:

  • CIQRA as CONTROLLER. For personal data we determine the purposes/means of: Merchant account and billing data, our website visitors, prospects/leads, support interactions, platform security and fraud prevention, aggregate/operational analytics, and our own marketing. This Policy governs that processing.
  • CIQRA as PROCESSOR. For personal data in a Merchant's Storefront (that Merchant's Customers, orders, marketing lists, etc.), the Merchant is the controller and CIQRA processes on the Merchant's behalf and instructions under the Data Processing Agreement. For that data, the Merchant's own privacy notice applies to the Customer, and CIQRA acts only as described in the DPA.

If you are a Customer shopping on a Merchant's store, the Merchant is your primary controller; contact that Merchant for its privacy notice and to exercise rights over your order data. This Policy still tells you how CIQRA operates the underlying platform.


2. Personal data we process (as controller)

CategoryExamplesSource
Identity & accountname, business name, role, username, password (hashed)you / your team
Contactemail, phone, address, countryyou
Verification / KYC-KYBbusiness registration, beneficial owners, identity documents (via Stripe), tax IDsyou / Stripe
Billing & transactionsplan, invoices, commission, payout metadata, ledger entries (no raw card numbers — SAQ A)you / Stripe
Usage & devicelog data, IP, device/browser, pages, feature usage, cookies/identifiersautomatic
Support & commstickets, emails, chat, call notesyou
Marketing & preferencesconsent status, subscriptions, campaign interactionsyou
Security & fraudauthentication events, risk/fraud signals, abuse reportsautomatic / third parties
Website visitor & prospectlead data, form submissions, analyticsyou / automatic

We generally do not seek special-category data as controller. We do not knowingly process children's data as controller (see §11).


3. Purposes and legal bases (GDPR Art. 6)

PurposeLegal basis
Provide, operate and maintain the Services; manage your accountContract (Art. 6(1)(b))
Billing, commission, payouts, collectionsContract; Legal obligation (accounting/tax)
KYC/KYB, sanctions/AML screening, fraud prevention, trader traceabilityLegal obligation; Legitimate interests (security, fraud prevention, DSA)
Security, abuse prevention, logging, backupsLegitimate interests; Legal obligation
Support and service communicationsContract; Legitimate interests
Product analytics and improvement (aggregated where possible)Legitimate interests
Direct marketing to Merchants/prospects (double opt-in)Consent and/or Legitimate interests, with opt-out
Cookies/tracking and ad pixels/CAPI (non-essential)Consent (see Cookie Policy)
Legal compliance, disputes, enforcing termsLegal obligation; Legitimate interests

Where we rely on legitimate interests, we balance them against your rights and you may object (§9). Where we rely on consent, you may withdraw it at any time without affecting prior processing.

CIQRA's determination: the legitimate-interests balancing referred to here has not been documented as a completed LIA for each processing purpose that relies on it. Art. 5(2) accountability requires the assessment to exist, not merely the conclusion. Consent withdrawal itself is mechanised for cookies/tracking (see Cookie Policy §3.2).


4. AI features and how your data is handled

4.1 CIQRA offers AI-assisted features (e.g. AI product-description/SEO generation, semantic search and recommendations, image generation/editing, and an AI chatbot), delivered via third-party AI/LLM providers accessed through an AI gateway.

4.2 Data-minimisation and safeguards. We are contractually and technically committed to:

  • sending AI providers only the input needed for the requested feature, and avoiding sending personal data / PII to models except where strictly necessary and disclosed;
  • no-training and minimised retention — under providers' business/commercial terms, customer inputs/outputs are not used to train their models, and retention is minimised (e.g. short-term abuse-monitoring only, or zero-data-retention where configured);
  • content moderation / safety filtering on inputs and outputs; and
  • transparency — where you interact with an AI system (e.g. chatbot) or where content is AI-generated/synthetic, this is disclosed/marked as required by the EU AI Act (Reg. (EU) 2024/1689) Art. 50.

4.3 You remain responsible for reviewing AI outputs before publishing. When CIQRA acts as processor on Merchant data, these AI safeguards are mirrored in the DPA.

🔴 CIQRA's determination: the AI section of this Policy must be read with two corrections made on 2026-08-09. (i) The providers actually in use are Anthropic, OpenAI, Voyage AI and fal.ai — all four in the US — and Voyage and fal.ai were absent from every prior version of the Subprocessor List. (ii) There is no self-hosted AI gateway: requests go directly to the provider APIs, so AI processing is a third-country transfer, not intra-EEA. Zero-retention/no-training is published vendor policy, not a verified executed term. Full detail and evidence: AI Terms §§1–2.


5. Advertising pixels, analytics and server-side tracking

5.1 CIQRA and Merchants may use analytics and advertising integrations — e.g. Google Analytics 4 / Google Tag Manager, Meta (Facebook) Pixel & Conversions API (CAPI), TikTok, and similar — including server-side tracking and conversion APIs.

5.2 These are non-essential and consent-based. Advertising/analytics cookies and equivalent tracking (including server-side event forwarding that shares personal data such as hashed email, IP, or event data with ad platforms) run only after the user gives consent via the cookie/consent banner. Server-side tracking does not bypass the consent requirement: if consent is refused or withdrawn, such sharing does not occur. See the Cookie Policy.

Measured 2026-08-09 (lane/L @ 81807dc44): consent gating for both browser and server-side tracking is implemented — three consent categories (ConsentCategory.cs:55-57), Google Consent Mode v2 signals with a denied default (wwwroot/theme/storefront.js:2305-2319), and a declared RequiredConsent on each server-side destination adapter so an event is not dispatched without it (Ciqra.Modules.Marketing/Adapters/Ga4MeasurementProtocolAdapter.cs:23, GoogleAdsEnhancedConversionsAdapter.cs:37). This claim is accurate.

5.3 On a Merchant's Storefront, the Merchant configures and is the controller for its own marketing pixels/CAPI; CIQRA provides the tooling and consent gating.


6. Who we share data with (recipients & subprocessors)

We share personal data with service providers acting for us, and with partners, only as needed:

  • Payments: Stripe (incl. Stripe Connect) — payment processing, KYC/KYB, fraud, payouts (Stripe is an independent controller/processor for payment data).
  • Cloud hosting / infrastructure: Microsoft Azure — Germany West Central (Frankfurt) primary + Germany North DR (compute, database, media storage, secrets/keys). All core data stays in the EU.
  • CDN / security / DNS: Cloudflare (edge; EU data-localization for EU traffic).
  • Email / transactional messaging: Azure Communication Services (primary); Amazon SES (EU region, fallback).
  • Error monitoring / observability: Sentry (EU region); Grafana Cloud (EU) via OpenTelemetry.
  • Search: Typesense (self-hosted on Azure, EU — internal component).
  • AI / LLM: AI gateway (LiteLLM, self-hosted) + model providers (OpenAI, Anthropic) under zero-retention / no-training terms.
  • Advertising / analytics platforms: Google, Meta, TikTok, etc. — consent-based (§5).
  • Marketplace channels (future feature; if enabled): where a Merchant connects a sales channel (e.g. Amazon, Etsy), order/customer data is shared with that channel operator as needed for listing/fulfilment, subject to that operator's terms and transfer safeguards.

CIQRA's determination: this is described as a future feature. No marketplace-channel integration was found in this reconciliation, so no such transfer occurs today. It is retained as forward-looking drafting per 00-README, but a channel connection would be a new category of third-country disclosure requiring its own transfer assessment before launch of the feature — not covered by the existing SCC analysis.

  • Professional advisers, auditors, authorities — where legally required or to establish/defend legal claims.
  • Corporate transactions — in a merger, acquisition or reorganisation, subject to confidentiality.

The authoritative, current Subprocessor List (with entities, locations and roles) is maintained separately and incorporated into the DPA. We do not sell personal data (and, for California, honor opt-out of "sharing" — see §13).


7. International data transfers

7.1 Personal data is stored and processed in the EU/EEA — core hosting is Microsoft Azure in Germany (West Central primary, North DR); there is no transfer of core personal data outside the EU/EEA for hosting, compute, database, storage or secrets.

7.2 Where a recipient/subprocessor is outside the EEA (or a Merchant enables a non-EEA integration/channel), we use an appropriate Art. 46 safeguard — principally the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), together with any required supplementary measures and, where available, reliance on an EU adequacy decision. A copy of the relevant safeguards is available on request at privacy@ciqra.com.

🔴 CIQRA's determination: the set of non-EEA recipients is larger than earlier internal versions disclosed. As at 2026-08-09 it includes: Stripe (US flows), all four AI providers (Anthropic, OpenAI, Voyage AI, fal.ai — US), Cloudflare (US parent), hCaptcha (US), the consent-based ad platforms, and Turkish SMS providers (Netgsm, İletimerkezi — a third country with no adequacy decision for these transfers). CIQRA has not verified that an executed Art. 46 mechanism is on file for the AI providers or the SMS providers, and the Transfer Impact Assessment referred to in DPA §11.2 was not located. See Subprocessor List §§4 and 5.


8. How long we keep data

We keep personal data only as long as needed for the purposes above or as required by law. Summary (full matrix in the Data Retention policy):

  • Order / invoice / tax / accounting records — 7 years (Estonian Accounting Act).
  • Merchant account data — for the account's life and 90 days after closure (then deleted/anonymised), subject to legal holds.
  • Payment/chargeback records — 13 months+ (dispute windows).
  • Support tickets & logs — 12–24 months.
  • Marketing consent & preferences — until consent withdrawal / objection.
  • Backups — 30 days rolling (measured default, BackupSchedule.cs:27; the schedule is operator-configurable between 1 and 365 days).

9. Your rights (GDPR)

Subject to conditions and exemptions, you have the right to: access; rectification; erasure ("right to be forgotten"); restriction; data portability; object (incl. to legitimate-interest processing and to direct marketing at any time); and rights relating to automated decision-making (we do not make solely-automated decisions producing legal/similarly significant effects about you without a lawful basis and safeguards). Where processing is based on consent, you may withdraw it at any time.

To exercise rights (where CIQRA is controller): email privacy@ciqra.com. We respond within one month (extendable by two months for complexity), free of charge unless manifestly unfounded/excessive. Where CIQRA is processor (Storefront Customer data), please contact the relevant Merchant (the controller); we will assist that Merchant as required by the DPA.

Complaints. You may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, https://www.aki.ee) or your local supervisory authority.

CIQRA's determination: CIQRA identifies Andmekaitse Inspektsioon as its lead supervisory authority on the basis of its Estonian main establishment. No Art. 56 one-stop-shop analysis has been performed, and because CIQRA processes data of individuals across the EU, other authorities may be concerned authorities. Your right to complain to your own local authority is unaffected either way.


10. Security

We implement appropriate technical and organisational measures, including tenant isolation with PostgreSQL row-level security and per-tenant scoping, encryption in transit (and at rest where applicable), access controls and least privilege, secrets management, logging/monitoring, backups, and a documented incident-response and breach-notification process (see doc 07). No system is perfectly secure; we cannot guarantee absolute security. Card data is handled on a PCI DSS SAQ A basis (raw PAN never touches CIQRA).

Measured 2026-08-09 (lane/L @ 81807dc44): the security measures described here are implemented, not aspirational. Row-level security is applied across the schema — 35 migration files carry ROW LEVEL SECURITY statements (e.g. Platform.Persistence/Migrations/20260706210040_AddRowLevelSecurity.cs, plus per-module catalog/payment/AI variants). Key management runs through Azure Key Vault (Ciqra.Api/Program.cs:94builder.AddCiqraKeyVault) with envelope encryption: a Key Vault KEK (Ciqra.Api/Secrets/AzureKeyVaultKek.cs) wrapping per-tenant data keys (Platform.Persistence/Cryptography/TenantCryptographyService.cs, TenantDataKeyConfiguration.cs). This is the best-evidenced section of the Policy.


11. Children

The Services (as sold by CIQRA to Merchants) are not directed to children, and CIQRA does not knowingly collect children's data as controller. On Storefronts, the digital-consent age is applied per market (GDPR 16; Estonia 13; some jurisdictions 13–15); a Merchant offering services to children must have a lawful basis and, where required, parental consent.

CIQRA's determination: the per-market digital-consent age (GDPR default 16; Estonia 13 under IKS §8) is stated as policy. This reconciliation did not locate a mechanism that varies the consent age by market or enforces an age gate at storefront signup. Age assurance is in practice the Merchant's responsibility under the AUP, and this Policy should not imply CIQRA enforces it.


12. California privacy rights (CCPA/CPRA)

This section applies to California residents and supplements the above. Under the CCPA (as amended by the CPRA):

  • Our roles. For personal information CIQRA processes on a Merchant's behalf, CIQRA is a "service provider" under a written contract; for CIQRA's own account/billing data, CIQRA is a "business."
  • Your rights: to know/access, delete, correct, opt out of the sale or "sharing" (cross-context behavioral advertising) of personal information, limit the use of sensitive personal information (SPI), and non-discrimination for exercising rights.
  • "Do Not Sell or Share" & Global Privacy Control. We do not sell personal information for money. Where advertising cookies/pixels (e.g. GA4, Meta) constitute "sharing" for cross-context behavioral advertising, you may opt out via our "Do Not Sell or Share My Personal Information" control. ✅ CIQRA reads the Global Privacy Control browser signal and treats it as a valid Do-Not-Sell/Share request. A request carrying Sec-GPC: 1 records an opt-out for that visitor on that store, and the opt-out is remembered so it applies to later visits; it is honoured on every store on the platform, whether or not that merchant has switched a cookie banner on, because a merchant's banner setting is a choice about whether to ask and cannot waive a right you exercised without being asked. ⚠️ What it denies, and what it does not. It withholds the consent categories the store declares to be a sale or share — the advertising and cross-context categories — and an advertising destination is then not contacted for you. It does not switch off the store's own first-party measurement of how many people used the site, which identifies nobody and is neither a sale nor a share; if you want that stopped as well, decline the analytics category in the cookie banner, which is a separate control. ①

🔒 CIQRA's determination of 2026-08-19 · review horizon 3 months (review by 2026-11-18). The facility is built and measured, not asserted. The signal is read in one place (Ciqra.Platform.Http/GpcSignal.cs, implementing the W3C Global Privacy Control specification's rule that only the exact value 1 counts and that any other value is processed as though the header were absent); the opt-out is persisted through the same recording path a banner click takes, so there are not two records of what a visitor allowed; what it denies lives in exactly one function (GpcDenialPolicy), whose answer is a per-category sale-or-share declaration a merchant can see and change; and it is enforced where the platform already decides whether a destination fires (CommerceEventDispatcher), not in a second place invented for it. Each store answers for itself at its own origin, and a machine-readable statement of this posture is served at /.well-known/gpc.json. Deleting the reader fails the build (tools/legal-gate/legalgate.py, check GPCREADER), so this paragraph cannot outlive the code beneath it. The horizon is three months rather than six because the legal backing retrieved for it is narrow — one state's instrument — and is recorded as such in the US market obligations register §2.5 rather than overstated here.

  • Sensitive PI. We do not use SPI for purposes requiring a "Limit" link beyond permitted business purposes; a "Limit the Use of My Sensitive Personal Information" control is provided where applicable.
  • Notice at collection & retention. Categories of PI/SPI collected, purposes, whether sold/shared, and retention criteria are described in §§2, 3, 8.
  • Automated decision-making (ADMT). Where CIQRA uses automated decision-making/AI within the CCPA ADMT rules (effective 2026), we provide the required pre-use notice and opt-out/appeal rights.

CIQRA's determination: CIQRA has not assessed whether any of its automated processing falls within the CCPA ADMT rules, and no pre-use notice or opt-out/appeal flow was found. Two candidates exist and should be assessed rather than assumed out of scope: the rules-based fraud scorer that can cause a purchase to be refused (Ciqra.Api/Fraud/FraudScorer.cs:54 notes "a false positive here is a real customer refused a real purchase"), and AI-assisted features. Whether these are significant decisions under the rules is exactly the question that has not been answered.

  • How to exercise / authorized agents. Email privacy@ciqra.com; you may use an authorized agent. We verify requests and do not discriminate. We respond within CCPA timelines.

13. Other US state privacy rights

If you reside in a US state with a comprehensive privacy law (e.g. Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others), you generally have rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. ✅ CIQRA reads the Global Privacy Control signal and treats it as an opt-out of sale and sharing, on the terms set out at §12 — including what it does not reach. ⚠️ Stated plainly rather than left to the word "recognised": GPC is the one opt-out preference signal CIQRA reads. Where a state's rules recognise a different signal, CIQRA has not measured whether it is handled, and this paragraph does not claim it is. To exercise these rights, contact privacy@ciqra.com; an appeal mechanism is available where the law requires one.

CIQRA's determination: US state-law rights are described generically. CIQRA has not mapped which state laws it is in scope for (thresholds differ by revenue, volume and "sale/share" activity), and no state-specific request flow or appeal process exists beyond the general DSAR mechanism (see §9 and Retention A.0, which records that the DSAR access/erasure mechanism is implemented). ✅ Amended 2026-08-19: recognised-signal handling is no longer among the gaps — GPC is read and enforced (§12). The scope map and the state-specific flows are still absent, so the US sections remain the least substantiated part of this Policy; they are simply no longer the only part with nothing behind them.

13.1 🔒 What CIQRA does give every US data subject, and the limit that statement leaves — stated rather than covered by the word "global"

③ Determination of 2026-08-18 · review horizon 6 months (review by 2027-02-18). CIQRA extends the rights in §9 — access, rectification, erasure, restriction, portability and objection — to every US data subject, and conditions none of them on a finding that a particular state law reaches CIQRA. The mechanism already exists and is measured: Retention A.0 records the DSAR access and erasure path as implemented. Withholding a right pending a scope map would buy nothing and risk a representation, so the scope map is not what the offer depends on.

⚠️ The limit, written down because "global" would otherwise cover it. That determination is not a claim that CIQRA complies with any named state law. The comprehensive state statutes carry obligations that are not a rights list. Of the four this Policy named on 2026-08-18, one has since been built and three have not.Recognised opt-out preference signal handling — provided since 2026-08-19 (§12: GPC read, opt-out persisted, enforced at the dispatch point, guarded by a build check). ⛔ Still absent: a state-specific appeal mechanism, a notice at collection in the form some states prescribe, and profiling / targeted-advertising opt-outs operated separately from the cookie-consent categories. ⚠️ The count is written as three-of-four rather than quietly deleting the closed item, because a limit that shrinks without saying so reads as a limit that was never there. Which of those CIQRA actually owes turns on a scope question it has not answered, and the answer turns on a measurement of revenue and volume by state that cannot currently be produced from the platform's own data — the establishment fact it stores is a two-character country code.

Where the whole of this is written up, with what would settle each question and who owns it: US market obligations register §1.2 and §2.2. That record is evidence about CIQRA rather than a term binding a Merchant, which is why it is not part of this set.

14. UK privacy rights (UK GDPR)

For UK data subjects, processing is governed by the UK GDPR + Data Protection Act 2018. Your rights mirror §9. The supervisory authority is the Information Commissioner's Office (ICO, https://ico.org.uk**)**. For restricted transfers out of the UK, we use the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs. If CIQRA offers services to UK data subjects without a UK establishment, it will appoint a UK Art. 27 representative.

CIQRA's determination: the UK section states the applicable regime correctly but depends on the unresolved Art. 27 UK representative question above. The Data (Use and Access) Act 2025 (DUAA) is referenced in the document set; CIQRA has not assessed which of its changes affect this Policy.


15. Changes and contact

We may update this Policy; material changes will be notified (email or in-dashboard) before taking effect, and the "last updated" date will change. Questions or requests: privacy@ciqra.com or CIQRA OÜ at the postal address above.


Provision register (this document)

ProvisionBasisWhere
DPO to be named(B) Art. 37 assessment never performed; programme records conflict on whether a DPO exists§header
UK Art. 27 rep(B) trigger likely met at launch given global availability, not deferred§header
legitimate interests(B) no documented LIA§6
🔴 (A) measured 4 US providers, no gateway, 2 previously undisclosed§4
consent-based tracking(A) measured — claim accurate§5.2
marketplace channels(B) feature does not exist; needs own assessment when built§6
Art. 46🔴 (A) recipient set larger than disclosed; TIA not located§7.2
complaints / lead SA(B) no Art. 56 analysis§9
security measures(A) measured RLS ×35 migrations, Key Vault, envelope encryption — best-evidenced section§10
children / consent age(B) no age-gate mechanism found§11
Do-Not-Sell / GPC(A) measured PRESENT (2026-08-19) — signal read, opt-out persisted per visitor and per store, enforced at the dispatch point; /.well-known/gpc.json per tenant. No longer launch-blocking. Guarded by GPCREADER: deleting the reader fails the build. ⚠️ History kept deliberately: measured absent 2026-08-09, withdrawn in the banner/determination/this row the same day, and left standing in the §12 bullet and §13 until 2026-08-18 because the guards were spelled honoured and the claims were spelled honor. Built by 02-09-PLAN.md§12
(B) scope never assessed; fraud scorer + AI are live candidates§12
US state laws(B) no in-scope mapping, no state-specific flows — §13.1 (2026-08-18) states what is given and the four things it did not reach; one of the four, opt-out preference signal handling, was built on 2026-08-19 and the other three are still open, review horizon 6 months§13
UK / DUAA(B) depends on Art. 27; DUAA impact unassessed§14

Composition: 3 measured facts · 10 declared positions · 2 withdrawn claims.

End of Privacy Policy . See also: Cookie Policy · DPA + subprocessors · Subprocessor List · Data Retention & Breach · AI Terms.