Legal

GDPR

Last updated 15 August 20268 sections

This page explains how CiteTrue works under the GDPR: which role we are in, what we do for you, what we deliberately do not claim, and which obligations stay with you when the manuscript you are checking belongs to someone else.

01Which role we are in depends on whose document it is

CiteTrue sits in one of two roles, and which one decides who carries which obligation.

When you check your own manuscript, you are the data subject as well as the customer. We are the controller of your account data, and the Privacy Policy at /privacy explains what we do with it.

When you check work that belongs to someone else — a student’s thesis, a submitted paper, a colleague’s draft — the author is the data subject, you decide what gets submitted and why, and we act on your instructions. There you are the controller and we are your processor, under the DPA at /dpa.

Most people are in the first case and need nothing from this page. If you are a supervisor, an editor or an institution, you are in the second, and the obligations that come with being a controller are yours.

02What we provide

  • A Data Processing Agreement in force for every account without anyone signing anything, incorporating the Standard Contractual Clauses.
  • A published list of every sub-processor — including the language-model providers — with what each one handles and where it sits, updated before we add one.
  • Encryption in transit and at rest, and documents that are only ever served back to the account that uploaded them, through short-lived signed links.
  • Self-service export and deletion, so most data subject requests need no ticket to us.
  • Account deletion that you can carry out yourself, immediately, from the dashboard.
  • Breach notification without undue delay and within 72 hours of us becoming aware.

03What we do not provide

Stating this plainly saves a round of questions in your review.

  • Data residency inside the EEA. All processing happens in the United States; if your assessment requires EU-only processing, tell us before you build on the service rather than after.
  • An Article 27 representative in the EU or UK. We are a small operation and do not currently appoint one.
  • ISO 27001, SOC 2 or equivalent third-party certification. What we do is described in the DPA’s security section, in enough detail to be checked.
  • An automatic maximum retention period. Documents live until you delete them or your account; if you need a fixed ceiling, we will agree one with you in writing.

05Where the data goes

Documents, verification results and account data are processed in the United States, by the sub-processors listed in the DPA. Passages of a document are sent to commercial language-model providers to judge whether a cited source supports a claim; those providers are also in the United States and are not permitted to train on what we send.

For data coming from the EEA, the UK or Switzerland this is an international transfer, and we rely on the European Commission’s Standard Contractual Clauses together with the UK Addendum, incorporated into the DPA.

06Handling a data subject request

If you are checking your own work, everything below is self-service. If you are a controller checking other people’s work, this is what you can do without involving us:

The requestWhat you doNeed us?
Access or portabilityOpen the verification in /dashboard and export the resultNo
ErasureDelete the verification — that removes the document behind it — or delete the whole accountNo
RectificationThe document is yours; correct it and run it againNo
Objection or restrictionStop submitting that author’s work, and delete what you already submittedNo
Anything the dashboard cannot doWrite to [email protected]Yes — within 30 days

07If you are checking someone else’s work

Three things are worth getting right before you upload a batch of other people’s documents.

  • Have a lawful basis, and be able to say what it is. "We screen all submissions for citation integrity" is a policy; write it down where the people affected can see it.
  • Tell the authors. A line in your submission guidelines or your academic integrity policy naming the tools you use is usually enough, and it is what a supervisory authority will look for.
  • Remember that a flagged reference is a finding, not a verdict. Acting on one without checking the underlying source is the fastest way to turn a data protection question into a fairness complaint.

08Supervisory authorities

If you are in the EEA or the UK, you have the right to complain to your local supervisory authority. We would rather hear from you first — write to [email protected] and you will get a real answer — but that right does not depend on talking to us.