Legal
GDPR
This page explains how CiteTrue works under the GDPR: which role we are in, what we do for you, what we deliberately do not claim, and which obligations stay with you when the manuscript you are checking belongs to someone else.
01Which role we are in depends on whose document it is
CiteTrue sits in one of two roles, and which one decides who carries which obligation.
When you check your own manuscript, you are the data subject as well as the customer. We are the controller of your account data, and the Privacy Policy at /privacy explains what we do with it.
When you check work that belongs to someone else — a student’s thesis, a submitted paper, a colleague’s draft — the author is the data subject, you decide what gets submitted and why, and we act on your instructions. There you are the controller and we are your processor, under the DPA at /dpa.
Most people are in the first case and need nothing from this page. If you are a supervisor, an editor or an institution, you are in the second, and the obligations that come with being a controller are yours.
02What we provide
- A Data Processing Agreement in force for every account without anyone signing anything, incorporating the Standard Contractual Clauses.
- A published list of every sub-processor — including the language-model providers — with what each one handles and where it sits, updated before we add one.
- Encryption in transit and at rest, and documents that are only ever served back to the account that uploaded them, through short-lived signed links.
- Self-service export and deletion, so most data subject requests need no ticket to us.
- Account deletion that you can carry out yourself, immediately, from the dashboard.
- Breach notification without undue delay and within 72 hours of us becoming aware.
03What we do not provide
Stating this plainly saves a round of questions in your review.
- Data residency inside the EEA. All processing happens in the United States; if your assessment requires EU-only processing, tell us before you build on the service rather than after.
- An Article 27 representative in the EU or UK. We are a small operation and do not currently appoint one.
- ISO 27001, SOC 2 or equivalent third-party certification. What we do is described in the DPA’s security section, in enough detail to be checked.
- An automatic maximum retention period. Documents live until you delete them or your account; if you need a fixed ceiling, we will agree one with you in writing.
04Legal bases
For your account and the service you asked for, we rely on performance of a contract. For keeping the service secure and preventing abuse, we rely on legitimate interests. For billing records we rely on legal obligation.
When you submit someone else’s document, the lawful basis for that processing is yours to establish, not ours — usually legitimate interests or a public task, depending on your institution. Academic integrity screening is a well-trodden path here, but it is still your assessment to make and document.
05Where the data goes
Documents, verification results and account data are processed in the United States, by the sub-processors listed in the DPA. Passages of a document are sent to commercial language-model providers to judge whether a cited source supports a claim; those providers are also in the United States and are not permitted to train on what we send.
For data coming from the EEA, the UK or Switzerland this is an international transfer, and we rely on the European Commission’s Standard Contractual Clauses together with the UK Addendum, incorporated into the DPA.
06Handling a data subject request
If you are checking your own work, everything below is self-service. If you are a controller checking other people’s work, this is what you can do without involving us:
| The request | What you do | Need us? |
|---|---|---|
| Access or portability | Open the verification in /dashboard and export the result | No |
| Erasure | Delete the verification — that removes the document behind it — or delete the whole account | No |
| Rectification | The document is yours; correct it and run it again | No |
| Objection or restriction | Stop submitting that author’s work, and delete what you already submitted | No |
| Anything the dashboard cannot do | Write to [email protected] | Yes — within 30 days |
07If you are checking someone else’s work
Three things are worth getting right before you upload a batch of other people’s documents.
- Have a lawful basis, and be able to say what it is. "We screen all submissions for citation integrity" is a policy; write it down where the people affected can see it.
- Tell the authors. A line in your submission guidelines or your academic integrity policy naming the tools you use is usually enough, and it is what a supervisory authority will look for.
- Remember that a flagged reference is a finding, not a verdict. Acting on one without checking the underlying source is the fastest way to turn a data protection question into a fairness complaint.