Privacy Policy
This Privacy Policy explains how we handle personal information. The headings below correspond to the eighteen sections of the Policy. Where this document has been translated into a language other than English, the English version remains the authoritative and legally binding text.
Introduction, Scope & Defined Terms
Who We Are
This Privacy Policy describes how Ciosanna LLC, a limited liability company organized in the United States, doing business as Ciosanna Connect ("Ciosanna," "we," "us," or "our"), collects, uses, discloses, retains, secures, and otherwise processes personal information in connection with the Ciosanna platform, the CiosannaConnect.com website, the Ciosanna mobile and web applications, customer support and communications channels, and all related services, features, content, and functionality (collectively, the "Services").
Ciosanna is a veteran-owned business. Our principal mailing address is 714 W 2nd St, Waitsburg, WA 99361. You can reach us regarding this Privacy Policy or any privacy-related question at support@ciosanna.com. We do not currently offer the Services in the European Union and have therefore not designated a representative in the Union under Article 27 of the GDPR; a representative will be designated before any launch of the Services in the European Union.
Who This Policy Applies To
This Privacy Policy applies to all individuals who interact with Ciosanna or whose personal information we process in the course of providing the Services. This includes, without limitation:
- Visitors — anyone who visits, browses, or otherwise accesses the CiosannaConnect.com marketing website, including individuals who request information, subscribe to a newsletter, schedule a demo, contact us through a web form, or interact with our AI sales assistant.
- Customers (also referred to as "Subscribers," "Tenants," "Companies," or "Boss accounts") — businesses that subscribe to the Ciosanna platform, and their authorized representatives, including company owners, property managers, and staff members.
- Residents — individuals who reside in, lease, or are otherwise associated with a property managed using the Ciosanna platform, including applicants, current residents, and former residents, and their household members or co-applicants where applicable.
- Property Owners (also referred to as "Investors") — individuals or entities that own properties managed by a Ciosanna Customer and access the investor portal.
- Vendors — third-party service providers, contractors, or maintenance personnel who access the vendor portal to receive, accept, perform, or document work orders.
- Other Individuals — any other natural person whose personal information may be processed in connection with the Services, including employees, agents, or contacts of Customers, Owners, or Vendors; emergency contacts of Residents; legal representatives; and individuals who otherwise contact us.
This Policy applies regardless of how you interact with the Services — through our websites, mobile applications, APIs, customer support channels, email, postal mail, telephone, or in person.
Defined Terms
- "Personal Information" means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular natural person or household. Where applicable law uses a different term (such as "personal data" under the EU General Data Protection Regulation), that term has the meaning given under such applicable law.
- "Sensitive Personal Information" means the subset of Personal Information subject to heightened protection under applicable law, including government-issued identification numbers, financial account information, precise geolocation, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, health information, biometric information, and the contents of mail, email, and text messages.
- "Processing" means any operation or set of operations performed on Personal Information, including collection, recording, organization, storage, retrieval, use, disclosure, alignment, combination, restriction, erasure, or destruction.
- "Customer Data" means Personal Information relating to a Customer's Residents, Owners, Vendors, or other individuals, which is provided to or generated by the Services by or on behalf of a Customer. When we Process Customer Data on behalf of a Customer, the Customer is typically the "controller" (GDPR) or "business" (CCPA), and Ciosanna acts as the "processor" or "service provider." When we Process Personal Information for our own purposes (for example, Visitor data on our marketing website), Ciosanna acts as the controller or business.
- "Cio" means the artificial-intelligence-powered features integrated into the Services, including the Cio AI Assistant available to authenticated users within the platform and the Cio Sales Agent available to Visitors on the marketing website.
- "Sub-Processor" means a third-party service provider that Processes Personal Information on our behalf in support of the Services.
Relationship Between This Policy and Customer Agreements
Where Ciosanna Processes Customer Data on behalf of a Customer, that Processing is also governed by the agreement between Ciosanna and the Customer, including any Data Processing Addendum. In the event of a conflict between this Privacy Policy and a written agreement with a Customer with respect to that Customer's Customer Data, the written agreement controls.
If you are a Resident, Owner, or Vendor whose information is processed in connection with a Customer's use of the Services, please understand that the Customer (and not Ciosanna) typically determines what information is collected from you, how it is used in connection with the property management relationship, and how long it is retained for the Customer's business purposes. To exercise privacy rights with respect to Customer Data, you should generally contact the Customer first. We will assist Customers in responding to such requests as required by law.
Acceptance and Changes
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the updated Policy on our website, updating the "Last Updated" date at the top of this Policy, and, where required by law or where the change materially affects how we Process your Personal Information, providing additional notice such as an email to your registered email address or a prominent in-product notification. Your continued use of the Services after the effective date of an updated Policy constitutes your acceptance of the updated Policy to the extent permitted by applicable law. Where applicable law requires your affirmative consent to a material change, we will obtain that consent before applying the change.
Language
This Privacy Policy is published in English and is available in eleven additional languages for your convenience. In the event of any conflict or discrepancy between the English version and any translation, the English version shall prevail and is considered the authoritative and legally binding text.
Information We Collect
We collect Personal Information from and about you in three ways: (a) information you provide directly; (b) information we collect automatically when you interact with the Services; and (c) information we receive from third parties. The specific categories depend on how you interact with Ciosanna.
Information We Collect From Visitors
When you visit CiosannaConnect.com or otherwise interact with our marketing channels, we may collect:
- Contact and identifying information you provide voluntarily through forms, including name, business name, email address, telephone number, job title, country, and any other information you include in free-text fields.
- Demo and inquiry information you provide when scheduling a demo, requesting a quote, downloading a resource, or submitting a contact form, including the number of units you manage, property types, preferred contact method, and free-text notes.
- Sales agent conversation data, including the content of your interactions with the Cio Sales Agent, the questions you ask, the responses you receive, your stated preferences, your apparent intent (for example, browsing versus actively shopping), and any information you choose to share during the conversation.
- Newsletter and subscription preferences, including your email address and any topical preferences you indicate.
- Device and browsing information collected automatically, including IP address, approximate geographic location derived from your IP address (city and country level), browser type and version, operating system, device type, screen resolution, referring website, pages viewed, time spent on pages, click events, scroll depth, and language preferences.
- Cookies and similar technologies, as more fully described in our Cookie Policy.
- Consent records, including your responses to cookie consent banners and any Global Privacy Control or similar opt-out signal your browser sends.
Information We Collect From Customers
When you or your organization signs up for, accesses, or uses the Ciosanna platform as a Customer, we may collect:
- Account information, including your name, business email address, telephone number, job title, role within the organization, and login credentials.
- Organization information, including company name, business address, tax identification number where required, number of properties and units managed, property addresses, and other business operational details.
- Billing and payment information, including the name and email of the billing contact, billing address, the last four digits of payment cards, card brand and expiration, ACH bank account information (transmitted to and held by our payment processor; we do not store full payment card numbers or full bank account numbers on our own systems), invoice history, subscription status, and tax information.
- Authentication and security information, including hashed passwords, multi-factor authentication tokens, session identifiers, IP addresses and devices used to log in, login timestamps, and security event logs.
- Communications metadata and content, including emails, in-product messages, support tickets, voice or chat transcripts where applicable, and metadata such as message recipients, timestamps, and read status.
- Platform usage information, including features you access, configuration choices you make, content you upload, properties and units you create, residents you add, leases you record, payments you record, work orders you generate, scoring decisions you review, and audit log entries reflecting actions taken in your account.
- AI interaction data, including your conversations with the Cio AI Assistant, the prompts you submit, the responses you receive, and any feedback you provide on those responses.
Information We Collect From Residents
If you are a Resident at a property managed using the Ciosanna platform, the Customer collects information about you and uploads or generates it in the platform, or asks you to provide it directly. Information processed may include:
- Identifying and contact information, including your full legal name, date of birth, mailing and residential address, telephone numbers, email address, photograph (where required for identification or building access), preferred language, and emergency contact information.
- Government-issued identifiers, including Social Security number or the last four digits thereof, driver's license number or state identification number, and immigration or citizenship documentation where required by applicable law or by the Customer for housing eligibility purposes. These are treated as Sensitive Personal Information and are encrypted at rest using AES-256-GCM encryption with per-tenant key derivation, and are accessible only on a need-to-know basis.
- Application and lease information, including rental history, prior addresses, employment information, income verification documents, references, co-applicants and household members, pets, vehicles, lease terms, security deposits, and any other information you provide on a rental application or in connection with a lease.
- Financial information, including rent payment history, bank account or payment card information used to make payments (transmitted to and held by our payment processor), recurring payment authorizations, ledger balances, late fees, and other charges or credits.
- Communications, including messages exchanged with property management, maintenance vendors, or other authorized parties through the platform; voicemail and call records where the platform records communications; and chat or AI assistant interactions.
- Maintenance and work order information, including descriptions of issues you report, photographs or videos you upload, access permissions you grant, and vendor visit records.
- Scoring and behavioral data, including the data points used by the Cio behavioral scoring system (such as on-time payment history, communication responsiveness, maintenance behavior, and lease compliance events) and the resulting scores. Use of automated decision-making in connection with this scoring is described in Section 10 of this Policy and in our FCRA Disclosure.
- Device, browsing, and access information, including IP address, device identifiers, login timestamps, and physical access events such as building or unit entry where the platform integrates with access control systems.
Information We Collect From Property Owners
If you access the Ciosanna platform as a Property Owner or Investor, we may collect:
- Identifying and contact information, including your name, mailing address, telephone number, email address, and tax identification information where required for owner distributions or tax reporting (for example, a Form 1099).
- Ownership and entity information, including the entity through which you hold property (where applicable), ownership percentages, the properties and units you own, and your role within any ownership entity.
- Financial and distribution information, including bank account information for ACH distributions (held by our payment processor), distribution history, fee schedules, and tax documents.
- Authentication, communications, AI interaction, and usage information of the same types described in Section 2.2.
Information We Collect From Vendors
If you access the Ciosanna platform as a Vendor, we may collect:
- Identifying and business information, including your name, business name, mailing address, telephone number, email address, license numbers and insurance information where applicable, areas of service, and rate information.
- Work order information, including assignments, schedules, photos and notes you submit in connection with completed work, and ratings or feedback provided by Customers or Residents.
- Payment information, including bank account information for payouts (held by our payment processor) and payment history.
- Authentication, communications, AI interaction, and usage information of the same types described in Section 2.2.
Information We Collect Automatically From All Users
Regardless of your role, when you use the Services we may automatically collect device and connection information (IP address, browser type and version, operating system, device type and identifiers, language settings, time zone, screen resolution, referring URLs); usage and event information (pages viewed, actions taken, timestamps, error logs, performance metrics, security events); approximate location derived from IP address (city/country level only — we do not collect precise geolocation such as GPS coordinates unless you affirmatively grant permission); and cookies and similar technologies as described in our Cookie Policy.
Information We Receive From Third Parties
We may receive Personal Information about you from third parties in connection with the Services, including: payment processors (such as Stripe), which confirm successful or failed transactions, provide partial card details for display, and provide fraud and risk signals; identity verification and background screening providers (where engaged by a Customer in connection with rental applications), which provide identity verification results, credit information, criminal history information, eviction history, and other consumer report information governed by the Fair Credit Reporting Act and applicable state law; communication and notification providers (such as SendGrid for email and any SMS providers); authentication providers (where single-sign-on or social-login integrations are enabled); infrastructure providers (such as Cloudflare), which provide security-related signals including geolocation by IP address, bot-detection scores, and threat intelligence; partners, integrators, and referral sources; and publicly available sources, including business directories, public records, and social media where used to verify business information or in connection with sales prospecting.
California Categories of Personal Information
For purposes of the California Consumer Privacy Act and California Privacy Rights Act, the categories of Personal Information we collect include: identifiers; information described in California Civil Code Section 1798.80(e); characteristics of protected classifications under California or federal law (only as needed for housing eligibility decisions and only as permitted by applicable fair housing laws); commercial information; internet or other electronic network activity information; geolocation data (approximate, not precise); audio, electronic, visual, and similar information; professional or employment-related information; education information; inferences drawn from any of the foregoing; and sensitive personal information (including Social Security numbers, driver's license numbers, account login credentials, account access information, contents of communications, and financial account information).
What We Do Not Collect
We do not knowingly collect Personal Information from individuals under the age of thirteen (or the equivalent minimum age under applicable law in other jurisdictions). We do not collect biometric identifiers (such as fingerprints or facial geometry) unless a Customer specifically enables and discloses such collection in connection with access control features and obtains all required consents from Residents. We do not engage in commercial surveillance unrelated to the Services, and we do not collect Personal Information for the purpose of selling it (see Section 13).
How We Use Information
We Process Personal Information for the purposes described in this section. Where the GDPR, UK GDPR, or similar law applies, we Process Personal Information only when we have a valid legal basis. The applicable legal basis for each purpose is identified below.
To Provide and Operate the Services
We Process Personal Information to register and authenticate users, set up and maintain accounts, enable Customers to manage properties and Residents, enable Residents to make payments and communicate with their property management, enable Owners and Vendors to access the relevant portals, deliver communications, generate reports, and otherwise provide the features and functionality of the Services.
Legal basis: Performance of a contract with you or with the Customer that has provided you access; or, where there is no direct contractual relationship, our legitimate interests in providing functional Services and the Customer's legitimate interests in operating its property management business.
To Process Payments and Distributions
We use payment-related information to process subscription payments from Customers, to facilitate rent payments by Residents, to process distributions to Property Owners, and to process payouts to Vendors, in each case through our payment processor.
Legal basis: Performance of a contract; compliance with our legal obligations, including tax reporting and anti-money-laundering obligations.
To Communicate With You
We Process contact and communications information to send you transactional messages (account confirmations, password resets, payment receipts, work order updates, lease reminders, and other operational notices), to respond to support inquiries, to provide updates about the Services, and, where you have opted in or where applicable law permits, to send you marketing communications. You can opt out of marketing communications at any time by following the unsubscribe instructions in any marketing email or by contacting us at support@ciosanna.com.
Legal basis: Performance of a contract for transactional communications; your consent for marketing communications where required; our legitimate interests in keeping users informed where consent is not required.
To Provide AI-Powered Features
We Process the content of your interactions with Cio (including the Cio Sales Agent on the marketing website and the Cio AI Assistant within the platform) to generate responses, to provide context-aware help, to surface relevant information, and to support sales and customer success workflows. Cio is powered by large language models provided by our AI sub-processor and operates under contractual restrictions that prohibit the use of your conversations to train third-party AI models. We disclose the use of AI in any Cio interaction in compliance with the EU Artificial Intelligence Act and similar laws.
Legal basis: Performance of a contract (for in-platform AI assistance); legitimate interests (for AI-powered sales support, subject to your right to object); your consent where required.
To Operate the Cio Behavioral Scoring System
For Residents and rental applicants where the Customer has enabled scoring features, we Process behavior and payment history information to generate Cio scores intended to assist the Customer in understanding resident tenancy patterns. Use of the score by the Customer is governed by the Customer's own policies, by applicable fair housing law, and by the Fair Credit Reporting Act where the score is used to make eligibility decisions. Section 10 of this Policy and our FCRA Disclosure provide additional detail, including your right to a human review of automated decisions.
Legal basis: Performance of a contract with the Customer; legitimate interests of the Customer in evaluating tenancy risk, balanced against your rights and freedoms; legal compliance with the Fair Credit Reporting Act where applicable.
To Personalize the Services
We use language, locale, and preference information to display the Services in your preferred language, to remember your interface settings, and to surface content relevant to your role.
Legal basis: Performance of a contract; legitimate interests in providing a usable experience.
To Maintain Security and Prevent Fraud
We Process IP addresses, device identifiers, login events, security event logs, bot-detection signals, and similar information to detect and prevent unauthorized access, fraud, abuse, security incidents, and violations of our Terms of Service or applicable law. We use Cloudflare's bot management and threat intelligence services, including the Turnstile CAPTCHA, in connection with these purposes.
Legal basis: Legitimate interests in protecting the security of the Services and our users; compliance with legal obligations.
To Comply With Legal Obligations
We Process Personal Information to comply with our legal obligations, including obligations under tax law, accounting law, anti-money-laundering law, fair housing law, consumer protection law (including the FCRA, CCPA, GDPR, and similar laws), responses to lawful requests from law enforcement, court orders, and regulatory authorities, and the establishment, exercise, or defense of legal claims.
Legal basis: Compliance with a legal obligation; legitimate interests in establishing or defending legal claims; vital interests in rare emergency situations.
To Analyze and Improve the Services
We use usage data, error logs, and aggregated or de-identified data to understand how the Services are used, to diagnose technical problems, to measure feature adoption, to test new features, and to improve the Services. Where feasible, we use aggregated or de-identified data for these purposes. We do not use individual Resident Personal Information to train AI models that are made available to other Customers without explicit authorization.
Legal basis: Legitimate interests in operating and improving the Services.
To Conduct Marketing and Business Development
We Process contact information of business prospects (typically employees of prospective Customer organizations) to conduct outreach, present the Ciosanna platform, schedule demos, and support the sales process. We honor opt-out requests promptly. We do not engage in cross-context behavioral advertising or share Personal Information with third-party advertisers for advertising purposes.
Legal basis: Legitimate interests in sales and business development; your consent where required by law.
To Effect Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, we may Process and disclose Personal Information in connection with such transaction, subject to appropriate confidentiality protections and continued application of this Policy or successor terms substantially similar to this Policy.
Legal basis: Legitimate interests in conducting corporate transactions; compliance with legal obligations.
With Your Consent
We may Process Personal Information for additional purposes with your consent. You can withdraw your consent at any time, although withdrawal will not affect Processing that occurred before withdrawal.
Legal basis: Your consent.
How We Share Information
We share Personal Information only in the limited circumstances described in this section. We do not sell Personal Information for monetary consideration, and we do not share Personal Information for cross-context behavioral advertising.
Sharing Within the Ciosanna Platform
The Ciosanna platform is a multi-portal system that necessarily shares certain information between portals to operate. The following internal sharing occurs in the normal course of the Services:
- Between Customer and its authorized users: Information uploaded or generated by one user of a Customer organization is generally accessible to other authorized users of the same Customer organization, subject to role-based access controls (staff members may have more limited access than managers or company owners).
- From Customer to Resident: Information that the Customer publishes through the platform to a Resident (such as ledger balances, notices, and lease documents) is visible to that Resident in the Resident portal.
- From Resident to Customer: Information that the Resident submits through the platform (such as maintenance requests, communications, and payment information) is visible to authorized users of the Customer organization.
- From Customer to Owner: Information about properties and Residents that the Customer chooses to expose to a Property Owner through the investor portal (such as occupancy, rent roll, financial performance, and Resident scoring summaries) is visible to that Owner. Owners do not have access to all Resident information; access is configured by the Customer subject to applicable law.
- From Customer to Vendor: Information necessary for a Vendor to perform an assigned work order (such as the address, the nature of the issue, access instructions, and Resident contact for scheduling) is shared with the assigned Vendor.
- Between Residents and other Residents: The platform does not share one Resident's Personal Information with other Residents except where the Customer has enabled features that necessarily involve such sharing (for example, community message boards or shared amenity scheduling), and even then only the limited information necessary for the feature.
Sub-Processors
We engage carefully selected Sub-Processors to perform services on our behalf. Each Sub-Processor is bound by a written agreement requiring confidentiality, appropriate security measures, and processing of Personal Information only on documented instructions from Ciosanna and consistent with this Policy. The categories of Sub-Processors we use include:
- Cloud infrastructure and database hosting — for storage and processing of Personal Information.
- Payment processing — for processing subscription payments, rent payments, owner distributions, and vendor payouts.
- Email and notification delivery — for transactional and marketing communications.
- Artificial intelligence services — for powering the Cio AI Assistant and Cio Sales Agent.
- Security, content delivery, and bot management — for delivering the Services securely and at scale.
- Identity verification and consumer reporting agencies — where engaged by a Customer in connection with rental applications, subject to the Fair Credit Reporting Act and applicable state law.
- Customer support and helpdesk tooling — where used to manage support tickets.
- Analytics and product telemetry — using first-party, privacy-preserving analytics.
A current list of our material Sub-Processors is available in our Sub-Processors List (referenced in Section 15 of this Policy).
Sharing With Customer's Vendors and Service Providers
A Customer may choose to integrate Ciosanna with third-party services it uses (for example, accounting software, screening services, or insurance providers). When the Customer enables such integrations, Personal Information may be shared with those third parties in accordance with the Customer's instructions and the third party's own privacy policy. We are not responsible for the privacy practices of third-party services that the Customer chooses to integrate.
Sharing With Your Consent
We may share Personal Information with third parties when you direct us to do so or otherwise consent to the sharing.
Sharing for Legal Reasons
We may disclose Personal Information when we believe in good faith that disclosure is required or permitted by law, including: to comply with a subpoena, court order, search warrant, or other legal process; to respond to lawful requests from public authorities, including law enforcement and national security authorities; to enforce our Terms of Service or other agreements; to investigate and prevent fraud, security incidents, or violations of our policies or applicable law; to protect the rights, property, or safety of Ciosanna, our users, or others; and in the context of legal proceedings, including the establishment, exercise, or defense of legal claims.
Where legally permitted, we will notify the affected user before disclosing their Personal Information in response to a legal request, unless we are prohibited from doing so or believe that notification would create a risk of harm.
Sharing in Connection With Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, or sale of company assets, Personal Information may be transferred to the acquiring or successor entity. We will require any such recipient to honor commitments substantially similar to this Policy with respect to your Personal Information.
Aggregated or De-Identified Data
We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you for any lawful purpose, including market research, industry benchmarking, and improving the Services. We maintain reasonable safeguards to prevent re-identification and do not attempt to re-identify de-identified data except as permitted by applicable law.
No Sale of Personal Information; No Cross-Context Behavioral Advertising
We do not sell Personal Information for monetary consideration. We do not share Personal Information for cross-context behavioral advertising. We honor the Global Privacy Control signal as a valid opt-out request for any sharing that could be characterized as a "sale" or "sharing" under California law. Section 13 of this Policy describes your right to opt out of any such activity in further detail.
Cookies and Tracking Technologies
Overview
We and our service providers use cookies and similar tracking technologies (collectively, "Tracking Technologies") to operate, secure, and improve the Services. This Section provides a high-level summary. Our Cookie Policy (available at /legal/cookies) provides a detailed inventory of the specific Tracking Technologies we use, the purposes for which they are used, the categories of information they collect, and their respective retention periods.
What Are Tracking Technologies
Tracking Technologies include: (a) cookies, which are small text files placed on your device by a website you visit; (b) web beacons (also known as pixels or clear GIFs), which are small graphic images embedded in web pages or emails used to measure engagement; (c) local storage and session storage, which are browser-based storage mechanisms used to store preferences and authentication state; (d) software development kits (SDKs) embedded in any mobile or in-product applications; and (e) server-side identifiers used in connection with our infrastructure and security providers.
Categories of Tracking Technologies We Use
We organize Tracking Technologies into the following categories:
- Strictly Necessary — required for the Services to function, including authentication tokens, session identifiers, security cookies, load-balancing cookies, and cookies used to remember your cookie-consent choices. These cannot be disabled through our cookie consent banner because the Services would not function without them.
- Functional — used to remember your preferences and settings, including your language choice, locale, and interface preferences.
- Analytics — used to understand how Visitors and users interact with the Services, including which pages are viewed, which features are used, and how users navigate the Services. We use first-party, privacy-preserving analytics and do not share Visitor-level analytics data with third-party advertising networks.
- Marketing — used in connection with our own marketing communications and on-site personalization. We do not use third-party advertising cookies or share data with third-party advertising networks for cross-context behavioral advertising.
Consent and Choice
We obtain your consent to non-essential Tracking Technologies in accordance with applicable law. Our consent mechanism is geographically aware:
- European Union, European Economic Area, and United Kingdom Visitors: We present a full-screen consent overlay that blocks non-essential Tracking Technologies until you make an affirmative choice. Defaults are set to opt-out, and you must affirmatively accept or customize your selections.
- California, Colorado, Connecticut, Virginia, Utah, and other applicable United States jurisdictions: We present a bottom-of-page consent banner that allows you to opt out of non-essential Tracking Technologies. Where you have a right to opt out of "sale" or "sharing" under applicable state law, the banner makes that option available.
- Other jurisdictions: We apply a conservative bottom-of-page banner default consistent with global best practice.
- Global Privacy Control (GPC): If your browser transmits a Global Privacy Control signal, we automatically apply the most privacy-protective settings (essential cookies only) and treat the signal as a valid opt-out request under applicable law, including the California Privacy Rights Act and the privacy laws of Colorado, Connecticut, Texas, Oregon, Montana, New Hampshire, New Jersey, Delaware, Nebraska, and Minnesota.
You can change your cookie preferences at any time through the cookie settings link in the footer of our website. If you change your preferences, the change applies prospectively; information already collected under your prior preferences will be retained or deleted in accordance with the retention periods described in our Cookie Policy.
Do Not Track
Most modern browsers no longer send a meaningful "Do Not Track" signal. We honor the Global Privacy Control signal as described above. We do not respond to the legacy "Do Not Track" header because no industry-standard interpretation of that signal has been established.
Cookies Set by Third-Party Services
Certain functionality within the Services may rely on third-party services that set their own cookies, including the Cloudflare Turnstile bot-protection challenge, our payment processor's checkout interface, and any embedded customer-support widgets. Cookies set by these third parties are governed by the respective third party's privacy policy. We list these third parties and their cookies in our Cookie Policy.
Data Retention
General Principle
We retain Personal Information only for as long as necessary to fulfill the purposes for which it was collected, to comply with our legal, regulatory, tax, accounting, and reporting obligations, to enforce our agreements, to resolve disputes, and to protect our legal rights, except where a longer retention period is required or permitted by applicable law. When Personal Information is no longer required, we either delete it, anonymize it, or, where deletion is not technically feasible (for example, in immutable backup archives), restrict it from further Processing until deletion is feasible.
Retention of Customer Data
For Customer Data (Personal Information that we Process on behalf of a Customer), our default retention period is the duration of the Customer's subscription to the Services plus a defined post-termination period for orderly wind-down:
- Active subscription: We retain Customer Data for as long as the Customer's account is active.
- Suspended account: If a Customer's account is suspended for non-payment or violation of our Terms of Service, Customer Data is retained in suspended state pending resolution.
- Cancelled account, ninety-day retention window: Upon cancellation of a Customer's subscription, we retain Customer Data for ninety (90) days following the effective date of cancellation. During this period, the Customer may request export of Customer Data or reinstatement of the account.
- After the ninety-day window: Following the ninety-day retention window, Customer Data is purged from active systems. Residual copies may persist in encrypted backups until the backups are rotated out of retention (typically within an additional ninety days), and in audit logs and similar records that are retained as described in Section 6.5 below.
- Deletion at Customer instruction: A Customer may instruct us to delete Customer Data earlier than the default schedule, subject to legal retention requirements and our internal procedures.
- Soft deletion within the platform: Where a Customer marks an account or record as "deleted" through the platform, the underlying data is retained in the Customer's account ledger (for example, for audit and dispute purposes) but removed from default views, unless and until the Customer permanently purges the record or the retention period expires.
Retention of Visitor Data
For Personal Information that we collect from Visitors on the marketing website:
- Sales conversations and lead data (including Cio Sales Agent transcripts, demo requests, and contact form submissions) are retained for up to twenty-four (24) months from the most recent interaction, after which we either delete the data or retain only aggregated, anonymized data for trend analysis.
- Newsletter subscriber data is retained until you unsubscribe, plus a short suppression period (typically thirty days) to ensure your preference is honored across our systems.
- Cookie and analytics data is retained for the periods specified in our Cookie Policy.
- Consent records are retained for the longer of (a) the duration during which the consent is in effect, plus a reasonable period thereafter to demonstrate compliance with applicable law, or (b) any retention period required by law.
Retention of Specific Categories
Certain categories of Personal Information are retained on category-specific schedules:
- Payment records, invoices, and tax documents are retained for at least seven (7) years following the transaction or, where longer, for the period required by applicable tax, accounting, or anti-money-laundering law.
- Sensitive Personal Information (such as Social Security numbers and government identifiers) is retained only for as long as necessary to fulfill the purpose for which it was collected (typically the duration of the lease relationship plus a defined post-tenancy period), and is then deleted or further restricted.
- Background screening and consumer report information is retained in accordance with the Fair Credit Reporting Act and applicable state law, and is not retained beyond the period necessary for the purpose for which the report was obtained.
- Communications data (including emails, messages, and in-platform conversations) is generally retained for the duration of the underlying relationship plus a reasonable period thereafter for dispute resolution and audit, after which it is deleted unless required for legal or regulatory purposes.
- Security and authentication logs are retained for up to twenty-four (24) months for security investigation and audit purposes.
- Cio AI conversation logs are retained as described in Section 3.4 and in our Cookie Policy.
Audit Logs and Backups
We maintain audit logs reflecting actions taken within the Services for security, compliance, and dispute-resolution purposes. Audit logs are retained for periods consistent with applicable law and our internal governance requirements, generally not less than the retention period of the underlying records to which the log entries relate.
Backups of our production systems are maintained for disaster recovery and business continuity purposes. Personal Information that has been deleted from active systems may persist in encrypted backups until those backups are rotated out of retention. We do not restore deleted Personal Information from backups except as necessary for disaster recovery.
Legal Holds
If we receive notice of pending or anticipated litigation, government investigation, regulatory inquiry, or other matter that triggers a legal hold, we will preserve relevant Personal Information notwithstanding the retention periods above, until the hold is released.
Deletion in Response to Verified Requests
Where you have a right under applicable law to request deletion of your Personal Information, we will honor a verified deletion request in accordance with Section 9 of this Policy. Certain exceptions apply, including where retention is necessary to complete a transaction, detect security incidents, comply with a legal obligation, exercise free speech, comply with the California Electronic Communications Privacy Act, engage in research in the public interest, or exercise or defend legal claims.
Data Security
Our Security Program
We maintain an information security program designed to protect Personal Information against unauthorized access, accidental loss, alteration, disclosure, and destruction. Our program is informed by recognized industry standards and includes administrative, technical, and physical safeguards appropriate to the nature of the Personal Information we Process and the risks associated with such Processing. The principal components of our security program are described below. No security program is perfect, and we cannot guarantee the absolute security of Personal Information; the safeguards described in this Section are designed to reduce risk to a level appropriate for the Services, but you should also take appropriate steps to protect your own Personal Information, including using strong, unique passwords and enabling multi-factor authentication where available.
Encryption
- Encryption in transit: All connections to the Services are encrypted using Transport Layer Security (TLS) version 1.3 or, where TLS 1.3 is not available on a connecting client, TLS 1.2 with modern cipher suites. We maintain a "Full (Strict) SSL" configuration with our content delivery and security provider to ensure end-to-end encryption between client, edge, and origin.
- Encryption at rest: Personal Information stored in our production database is encrypted at rest. Sensitive Personal Information (including government identifiers such as Social Security numbers, dates of birth, and financial account information) is subject to an additional layer of application-level encryption using the Advanced Encryption Standard in Galois/Counter Mode with 256-bit keys ("AES-256-GCM"), with cryptographic keys derived per-tenant using the HMAC-based Key Derivation Function (HKDF). Searchable fields are protected using keyed hash representations (HMAC) so that authorized lookups can be performed without exposing plaintext.
- Backups and disaster recovery copies are encrypted using comparable mechanisms.
Access Controls
- Role-based access control (RBAC): Access to Personal Information within the Services is governed by role-based access controls. Customer organizations are configured as multi-tenant accounts with row-level security enforced at the database layer, so that one Customer's data is not accessible to another Customer.
- Need-to-know access for Ciosanna personnel: Access to Personal Information by Ciosanna personnel is limited to those individuals who require such access to perform their duties. All such access is logged.
- Authentication: Access to Customer-facing accounts is protected by password authentication, with support for multi-factor authentication. Administrative access to internal systems requires multi-factor authentication.
- Session management: Sessions expire automatically after a period of inactivity. Suspicious authentication events trigger additional verification or session termination.
Infrastructure Security
- Web application firewall (WAF): Inbound traffic to the Services is filtered through a web application firewall that detects and blocks common attack patterns including SQL injection, cross-site scripting, and known malicious traffic.
- Distributed denial-of-service (DDoS) protection: Our infrastructure is protected by an enterprise-grade DDoS mitigation service.
- Bot management: We deploy Cloudflare Bot Fight Mode and similar automated bot-detection mechanisms to identify and block malicious automated traffic.
- Bot challenges on forms: Public-facing forms, including sign-in forms, signup forms, and the visitor DSAR submission form, are protected by Cloudflare Turnstile, a privacy-preserving CAPTCHA alternative that does not require user interaction in most cases and does not rely on tracking cookies.
- Network segmentation and least privilege: Production systems are segmented from development and staging systems, and inter-service communications are restricted to the minimum required for the Services to function.
Software Development and Vulnerability Management
We employ secure software development practices including code review, dependency monitoring, automated security testing, and prompt patching of known vulnerabilities in third-party libraries and underlying infrastructure. We monitor security advisories from our software vendors and apply critical patches in accordance with the severity of the disclosed vulnerability.
Personnel Security
Ciosanna personnel with access to Personal Information are subject to confidentiality obligations, are trained in privacy and security practices, and are required to comply with our information security policies. Access is provisioned on a need-to-know basis and revoked upon role change or separation.
Sub-Processor Security
We contractually require our Sub-Processors to maintain security measures appropriate to the Personal Information they Process on our behalf. We periodically review the security posture of material Sub-Processors and, where applicable, review their independent security audit reports (such as SOC 2 reports).
Incident Response and Breach Notification
We maintain an incident response plan designed to identify, contain, investigate, and remediate security incidents. In the event of a personal data breach as defined under applicable law:
- We will notify the relevant supervisory authority (such as an EU Data Protection Authority) without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, in accordance with Article 33 of the GDPR.
- We will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, or where otherwise required by applicable law (including state breach-notification laws in the United States).
- Where we Process Personal Information on behalf of a Customer, we will notify the Customer without undue delay so the Customer can fulfill its own notification obligations.
The form, timing, and content of breach notifications will be tailored to the requirements of applicable law and the facts of the specific incident.
Your Responsibilities
You play an important role in protecting your own Personal Information. We encourage you to: use strong, unique passwords and enable multi-factor authentication where available; never share your account credentials with others; sign out of the Services when using shared or public devices; keep your devices, operating systems, and browsers up to date with the latest security patches; be cautious about phishing emails or messages that appear to be from Ciosanna and verify the sender before clicking links or providing credentials; and promptly notify us at support@ciosanna.com if you suspect any unauthorized access to your account.
International Data Transfers
Where We Process Personal Information
Ciosanna is headquartered in the United States, and our production infrastructure is operated primarily within the United States. When you use the Services, your Personal Information may be transferred to, stored in, and Processed in the United States and in any other country where we or our Sub-Processors maintain facilities. The data protection and privacy laws of the United States and other countries to which Personal Information may be transferred may not provide the same level of protection as the laws of the jurisdiction in which you reside.
Transfers From the European Economic Area, the United Kingdom, and Switzerland
When we transfer Personal Information from the European Economic Area ("EEA"), the United Kingdom, or Switzerland to the United States or to another country that has not been recognized as providing an adequate level of data protection, we rely on one or more of the following lawful transfer mechanisms:
- Standard Contractual Clauses (SCCs): We execute the European Commission's Standard Contractual Clauses (Module 2 for controller-to-processor transfers, or other applicable Module, as set out in Commission Implementing Decision (EU) 2021/914) with our Sub-Processors located outside the EEA. The SCCs impose binding obligations on the data importer regarding the protection of Personal Information.
- United Kingdom International Data Transfer Addendum to the SCCs (or the UK International Data Transfer Agreement), as issued by the UK Information Commissioner's Office, for transfers subject to the UK GDPR.
- Swiss Data Protection Authority recognized mechanisms for transfers subject to the Swiss Federal Act on Data Protection.
- EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Framework: Where we or our Sub-Processors are certified under the applicable Data Privacy Framework administered by the U.S. Department of Commerce, we may rely on such certification as a lawful transfer mechanism. We are currently evaluating self-certification under the Data Privacy Framework; until certification is in place and noted in this Policy, we rely on the SCCs and other mechanisms described above.
- Other lawful transfer mechanisms authorized by applicable law, including binding corporate rules where applicable, derogations for specific situations under Article 49 of the GDPR (such as where the transfer is necessary for the performance of a contract or with your explicit consent), and any other mechanism formally approved by the relevant supervisory authority.
Supplementary Measures
In addition to the contractual safeguards described above, we apply supplementary technical and organizational measures designed to protect transferred Personal Information, including the encryption controls described in Section 7, contractual restrictions on Sub-Processor access, transparency reporting where permitted by law in response to government access requests, and policies governing how we respond to law enforcement requests for Personal Information.
Transfers From Other Jurisdictions
For transfers of Personal Information from other jurisdictions with cross-border transfer restrictions (including but not limited to Canada, Brazil, Japan, South Korea, Australia, India, and others), we comply with applicable cross-border transfer requirements through one or more of: applicable data transfer agreements; the data subject's consent where required; performance of a contract; or other mechanisms permitted under the relevant law.
Your Right to Information About Transfers
You have the right to receive information about the safeguards we apply to transfers of your Personal Information outside your jurisdiction. To request a copy of the applicable safeguards (such as the relevant SCCs, with confidential commercial terms redacted), contact us at support@ciosanna.com.
Data Localization
We do not currently offer data localization options that would restrict the storage or Processing of Personal Information to a specific country or region. If you require data localization for regulatory or contractual reasons, please contact your Ciosanna account representative; localization may be available on an enterprise basis subject to additional terms.
Your Privacy Rights
Depending on where you live and the nature of your relationship with Ciosanna, you may have legal rights with respect to your Personal Information. This Section describes those rights and explains how to exercise them. Where Ciosanna acts as a "processor" or "service provider" on behalf of a Customer, you should generally direct your rights requests to the Customer first; we will assist Customers in responding to such requests as required by law. Where Ciosanna acts as a "controller" or "business" (for example, with respect to Visitor information on the marketing website or our own internal business contacts), you may exercise your rights directly with us.
Rights Under the European Union and United Kingdom General Data Protection Regulation
If you are located in the European Economic Area, the United Kingdom, or Switzerland, or if the EU GDPR, UK GDPR, or Swiss Federal Act on Data Protection otherwise applies to the Processing of your Personal Information, you have the following rights:
- Right of access (Article 15). You have the right to obtain confirmation as to whether we Process Personal Information concerning you and, where we do, to receive a copy of that Personal Information together with information about the Processing.
- Right to rectification (Article 16). You have the right to have inaccurate Personal Information concerning you corrected and, taking into account the purposes of Processing, to have incomplete Personal Information completed.
- Right to erasure ("right to be forgotten") (Article 17). You have the right to have Personal Information concerning you erased without undue delay in certain circumstances, including where the Personal Information is no longer necessary for the purposes for which it was collected, where you withdraw consent on which the Processing is based, where you object to the Processing and there are no overriding legitimate grounds, or where the Personal Information has been unlawfully Processed.
- Right to restriction of Processing (Article 18). You have the right to obtain restriction of Processing in certain circumstances, including where you contest the accuracy of the Personal Information, where Processing is unlawful but you oppose erasure, or where you have objected to Processing pending verification of overriding legitimate grounds.
- Right to data portability (Article 20). Where Processing is based on consent or on a contract and is carried out by automated means, you have the right to receive the Personal Information you provided to us in a structured, commonly used, and machine-readable format and to transmit that Personal Information to another controller without hindrance.
- Right to object (Article 21). You have the right to object, on grounds relating to your particular situation, to Processing of Personal Information that is based on our legitimate interests or on a task carried out in the public interest. You have the unconditional right to object at any time to Processing of your Personal Information for direct marketing purposes.
- Right not to be subject to a decision based solely on automated Processing (Article 22). You have the right not to be subject to a decision based solely on automated Processing, including profiling, that produces legal effects concerning you or similarly significantly affects you, subject to limited exceptions. Section 10 of this Policy describes our practices with respect to automated decision-making.
- Right to withdraw consent. Where Processing is based on your consent, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of Processing based on your consent before the withdrawal.
- Right to lodge a complaint with a supervisory authority. You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. A list of EU supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. In the United Kingdom, you may contact the Information Commissioner's Office at https://ico.org.uk. In Switzerland, you may contact the Federal Data Protection and Information Commissioner at https://www.edoeb.admin.ch.
We encourage you to contact us at support@ciosanna.com before lodging a complaint so that we have an opportunity to address your concerns directly.
Rights Under the California Consumer Privacy Act and California Privacy Rights Act
If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA"):
- Right to know. You have the right to request that we disclose the categories of Personal Information we have collected about you, the categories of sources from which the Personal Information was collected, the business or commercial purpose for collecting (and, if applicable, selling or sharing) the Personal Information, the categories of third parties with whom we shared the Personal Information, and the specific pieces of Personal Information we have collected about you.
- Right to delete. You have the right to request deletion of Personal Information we have collected from you, subject to the exceptions enumerated in the CCPA (including completing transactions, detecting security incidents, complying with legal obligations, and others).
- Right to correct. You have the right to request that we correct inaccurate Personal Information that we maintain about you.
- Right to opt out of sale or sharing. You have the right to opt out of the "sale" or "sharing" of your Personal Information as those terms are defined under the CCPA. As stated in Section 4.8, we do not sell Personal Information for monetary consideration and do not share Personal Information for cross-context behavioral advertising. We honor the Global Privacy Control signal as a valid opt-out request.
- Right to limit use and disclosure of Sensitive Personal Information. You have the right to direct us to use or disclose Sensitive Personal Information only for the purposes enumerated in the CCPA (such as performing the Services you requested or complying with legal obligations). Section 12 of this Policy describes our practices with respect to Sensitive Personal Information.
- Right to data portability. Where your right to know request specifies, you have the right to receive your Personal Information in a portable and, to the extent technically feasible, readily usable format.
- Right to non-discrimination. You have the right not to receive discriminatory treatment for exercising any of your CCPA rights, including by way of denied service, different prices or rates, or different levels of quality.
To exercise your CCPA rights, see Section 9.6 below. You may also designate an authorized agent to make a request on your behalf, subject to verification requirements.
Shine the Light. California Civil Code Section 1798.83 (the "Shine the Light" law) permits California residents to request certain information regarding our disclosure of Personal Information to third parties for those third parties' direct marketing purposes. We do not disclose Personal Information to third parties for their direct marketing purposes.
Rights Under Other United States State Privacy Laws
If you are a resident of a U.S. state with a comprehensive consumer privacy law (currently including, without limitation, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, New Hampshire, New Jersey, Tennessee, Delaware, Indiana, Iowa, Minnesota, Maryland, Nebraska, Rhode Island, and Kentucky, and any other state with a comprehensive privacy law now or hereafter in effect), you may have rights similar to those described above, which may include:
- The right to access or know what Personal Information we Process about you.
- The right to correct inaccurate Personal Information.
- The right to delete Personal Information.
- The right to obtain a portable copy of Personal Information.
- The right to opt out of the sale of Personal Information, targeted advertising, and profiling in furtherance of decisions that produce legal or similarly significant effects.
- The right to appeal a denial of a rights request.
- In certain states, the right to obtain a list of categories of third parties to whom we have disclosed Personal Information.
The specific scope of each right varies by state. To exercise rights under your state's law, see Section 9.6 below. We honor the Global Privacy Control signal as a valid opt-out request under each state law that recognizes universal opt-out mechanisms. Where the applicable state law provides for an appeal process, you may appeal our decision on your rights request by responding to our determination email or by contacting us at support@ciosanna.com with the subject line "Privacy Rights Appeal."
Rights Under Other International Laws
- Brazil (Lei Geral de Proteção de Dados — LGPD): If you are located in Brazil, you have rights under the LGPD substantially similar to those described in Section 9.1, including rights of access, rectification, anonymization, blocking, deletion, portability, information about sharing, and the right to revoke consent. You may also lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD).
- Canada (Personal Information Protection and Electronic Documents Act — PIPEDA and provincial laws): If you are located in Canada, you have rights to access, correct, and withdraw consent with respect to your Personal Information under PIPEDA and applicable provincial privacy laws (including Quebec's Law 25). You may lodge a complaint with the Office of the Privacy Commissioner of Canada or with the relevant provincial commissioner.
- Australia (Privacy Act 1988): If you are located in Australia, you have rights under the Australian Privacy Principles, including rights of access, correction, and complaint. You may lodge a complaint with the Office of the Australian Information Commissioner.
- Japan (Act on the Protection of Personal Information — APPI), South Korea (Personal Information Protection Act — PIPA), and other jurisdictions: Where you are located in a jurisdiction with comprehensive privacy law that grants you data subject rights, we will honor those rights to the extent applicable to our Processing of your Personal Information.
Authorized Agents
Where applicable law permits, you may designate an authorized agent to submit a privacy rights request on your behalf. We may require: (a) proof that you have given the agent signed permission to act on your behalf; (b) verification of your own identity in accordance with Section 9.6; and (c) confirmation directly from you that you authorized the request. We may deny requests from agents who do not satisfy these requirements.
How to Exercise Your Rights
You may exercise your rights through any of the following methods:
- **Submit a request through our online form at /legal/privacy-request** on CiosannaConnect.com. This form is the preferred method for visitors and individuals who do not have a Ciosanna account, and is available to all individuals regardless of relationship with Ciosanna.
- Email us at support@ciosanna.com with the subject line "Privacy Rights Request" and a description of your request.
- Through your account settings, where you have a Ciosanna account, you may directly access, update, and in many cases delete certain categories of Personal Information using the in-product privacy controls available to your account type.
To process your request, we may need to verify your identity. The verification process depends on the type of request, the sensitivity of the Personal Information involved, and the risk of harm from unauthorized disclosure. We may ask you to provide information that matches information already in our records, to confirm ownership of an email address by clicking a verification link, or to provide additional documentation in higher-risk cases. We will not request more information than is reasonably necessary to verify your identity and will delete any verification information used solely for this purpose after the verification is complete.
Response timelines. We will respond to verifiable rights requests within the timeframes required by applicable law, generally:
- Forty-five (45) days for requests under the CCPA and most other U.S. state privacy laws, with a permitted extension of up to forty-five additional days where reasonably necessary and where we have notified you of the extension.
- Thirty (30) days for requests under the EU GDPR, UK GDPR, and Swiss law, with a permitted extension of up to two additional months for complex or numerous requests.
- Other timeframes as required by the applicable law of your jurisdiction.
Exceptions and denials. We may decline to honor a rights request in whole or in part where permitted or required by law, including where the request: cannot be verified; would violate the rights of another individual; relates to Personal Information that we are required to retain by law; or falls within a specific statutory exception (such as those enumerated in CCPA Section 1798.105(d) for deletion requests). Where we decline a request in whole or in part, we will explain the reason for the denial and inform you of your right to appeal where applicable.
Cost. We do not charge a fee for honoring rights requests, except where permitted by law for manifestly unfounded, excessive, or repetitive requests, in which case we may charge a reasonable fee or refuse to act on the request.
Sensitive Combinations and Special Categories
Certain Sensitive Personal Information (including racial or ethnic origin, religious beliefs, sexual orientation, health information, and biometric information) is subject to additional restrictions under applicable law, including the GDPR (special categories of Personal Data under Article 9). We do not Process special categories of Personal Data except: (a) with your explicit consent; (b) where Processing is necessary for the establishment, exercise, or defense of legal claims; (c) where Processing is required by law (such as for fair housing compliance, on a strictly need-to-know basis); or (d) on another lawful basis enumerated in Article 9 of the GDPR or analogous provisions of other applicable law.
Automated Decision-Making and the Cio Scoring System
What This Section Covers
This Section provides additional transparency about our use of automated processing and profiling, including how the Cio behavioral scoring system works, how it may be used in decisions about you, and the rights you have with respect to such decisions. This Section supplements, and should be read together with, Section 9 of this Policy and our FCRA Disclosure (available at /legal/fcra), which provides additional detail relevant to scoring information used as a consumer report under the federal Fair Credit Reporting Act.
Description of the Cio Behavioral Scoring System
The Cio behavioral scoring system is a feature of the Ciosanna platform that, where enabled by a Customer, generates a numeric score and supporting indicators intended to summarize a Resident's behavioral patterns over the course of a tenancy. The score is calculated based on information processed by the platform during the ordinary course of the Customer's property management activities, including:
- Payment history, including on-time payments, late payments, returned payments, partial payments, and the use of auto-pay features.
- Communication patterns, including responsiveness to messages from property management, the volume and nature of communications, and the use of in-platform messaging features.
- Maintenance behavior, including the volume and nature of work order submissions, cooperation with vendor scheduling, and resolution outcomes.
- Lease compliance events, including lease renewals, notices issued by property management, documented violations, and similar events.
The score is recalculated periodically based on the most recent data, and historical contributing events are reflected in the score weight in accordance with the scoring system's specification.
How the Score May Be Used
The Cio score is presented to authorized Customer personnel within the platform. Use of the score is at the Customer's discretion, subject to the following constraints:
- Customer policies and applicable law: A Customer's use of the score is governed by the Customer's own policies, by applicable federal and state law (including fair housing law), and by the Customer's agreement with Ciosanna.
- Fair Credit Reporting Act: Where the Customer uses the score as a "consumer report" within the meaning of the Fair Credit Reporting Act (for example, to make an eligibility determination for housing), the Customer is obligated to comply with the FCRA, including obtaining required consents and providing adverse action notices where applicable. Our FCRA Disclosure provides further information.
- Fair Housing Act and state fair housing laws: Decisions based on the score must comply with the Fair Housing Act and applicable state and local fair housing laws, including the prohibition on discrimination based on protected characteristics.
- Cio does not make final decisions: The Cio scoring system does not, by itself, make rental, eviction, lease renewal, or other adverse housing decisions. Such decisions remain with the Customer.
Your Rights With Respect to Automated Decision-Making
Where you are subject to a decision that produces legal effects concerning you or similarly significantly affects you (such as a rental eligibility decision) and the decision is made on the basis of automated Processing (including profiling), you have the following rights:
- Right to obtain human review. You have the right to request that a qualified human individual review the decision. The Customer (acting as the entity making the decision) is responsible for providing this review. We will support the Customer in providing the necessary information.
- Right to express your point of view. You have the right to provide additional information or context that you believe is relevant to the decision.
- Right to contest the decision. You have the right to contest the decision and request that it be reconsidered.
- Right to meaningful information about the logic involved. You have the right to receive meaningful information about the logic of the automated Processing, as well as the significance and the envisaged consequences of the Processing for you. This Section, our FCRA Disclosure, and the Cio scoring specification (available upon request) provide this information.
To exercise these rights with respect to a decision affecting your housing relationship, you should first contact the Customer that manages your property, because the Customer (and not Ciosanna) is making the decision. Where Customer support is not available, you may contact us at support@ciosanna.com and we will assist in directing your request appropriately.
Cio AI Assistant and Cio Sales Agent (Generative AI Features)
Cio also includes generative artificial intelligence features (the Cio AI Assistant available within the platform, and the Cio Sales Agent available on the marketing website). These features do not make decisions affecting your rights; they generate text responses to your questions and prompts. We disclose the use of generative AI clearly in any Cio interaction, in compliance with applicable law (including the EU Artificial Intelligence Act, Article 50, regarding transparency obligations for AI systems intended to interact with natural persons). Outputs from Cio generative AI features are not guaranteed to be accurate and should not be relied upon as legal, financial, tax, or other professional advice.
No Use of Personal Information to Train Third-Party AI Models
We contractually require our AI Sub-Processor to refrain from using your Personal Information (including the contents of your Cio interactions) to train AI models that are made available to third parties. Your interactions with Cio may be used by us, on an aggregated or de-identified basis, to evaluate and improve the Cio features themselves, subject to the safeguards described in Section 3.9.
Children's Privacy
Services Not Directed to Children
The Services are not directed to children, and we do not knowingly collect Personal Information directly from children. For purposes of this Section, "children" means:
- Individuals under the age of thirteen (13) under the United States Children's Online Privacy Protection Act ("COPPA").
- Individuals under the age of sixteen (16) under the EU GDPR, except where an EU Member State has set a lower age (down to thirteen).
- Individuals under the age of eighteen (18) for purposes of certain California protections relating to minors (including the California Online Privacy Protection Act provisions concerning minors' use of online services).
- Individuals deemed minors under any other applicable law.
If a Child Has Provided Personal Information
If you believe that we have inadvertently collected Personal Information from a child without appropriate parental consent, please contact us at support@ciosanna.com. We will investigate and, where appropriate, promptly delete the Personal Information, terminate any account associated with the Personal Information, and take other steps required by applicable law.
Residents Under the Age of Eighteen in Family Housing
We recognize that minors may live in housing managed using the Ciosanna platform (for example, as members of a Resident's household). In such cases:
- We rely on the Customer to comply with applicable law regarding the collection and use of Personal Information about minor household members.
- We do not provide Resident-portal accounts to individuals under the age of eighteen. Where a Customer requires a Resident-portal account, that account must be established in the name of an adult Resident or guardian.
- We collect only the minimum information about minor household members that is necessary for housing administration (such as name and relationship), and we do not collect Sensitive Personal Information about minor household members unless required by law for fair housing compliance and obtained from a parent or guardian.
Compliance With State Minor-Protection Laws
We monitor evolving U.S. state laws concerning the protection of minors online (including, without limitation, the Florida Online Protections for Minors Act, the New York SAFE for Kids Act, the California Age-Appropriate Design Code Act, and similar laws now or hereafter in effect) and adjust our practices to comply with applicable requirements. Because the Services are not directed to minors, many of these requirements may not apply by their terms; however, where any requirement does apply to the Services, we will comply.
Educational and Family Services
The Services are not designed for, marketed to, or offered as an educational service for children. We do not knowingly collect Personal Information from children for educational purposes or otherwise, and we do not engage in advertising directed to children.
Sensitive Personal Information
Categories of Sensitive Personal Information We Process
In the course of providing the Services, we may Process the following categories of Sensitive Personal Information:
- Government-issued identifiers, including Social Security numbers (and the last four digits thereof), driver's license numbers, state identification numbers, and immigration or citizenship documentation, in connection with rental applications and identity verification for Resident accounts.
- Financial account information, including bank account numbers and routing numbers (used by our payment processor for ACH transactions) and partial payment card details, used to process payments, distributions, and payouts.
- Account credentials, including passwords (which are stored as hashes, not plaintext) and multi-factor authentication tokens.
- Precise communication contents, including the contents of messages, calls, voicemails, and AI assistant conversations.
- Citizenship, immigration status, or national origin information, only where required by applicable law for housing eligibility or fair housing compliance purposes.
- Information about racial or ethnic origin, religion, sexual orientation, gender identity, disability, or familial status, only to the extent that a Customer collects such information for the purpose of complying with applicable fair housing laws (including the Fair Housing Act and equivalent state laws) and only on a strictly need-to-know basis.
- Health information, only to the extent that you voluntarily provide such information (for example, in connection with a reasonable accommodation request under the Fair Housing Act or the Americans with Disabilities Act, or in the context of an emergency contact's medical information), and only for the purpose for which it was provided.
- Biometric information, only if and to the extent that a Customer enables, discloses, and obtains required consents for an optional access control feature that uses biometric identifiers.
We do not Process Sensitive Personal Information for the purpose of inferring characteristics about you, for cross-context behavioral advertising, or for any purpose other than those described in this Policy.
Purposes for Processing Sensitive Personal Information
We Process Sensitive Personal Information only for the following purposes, which are limited to those purposes enumerated under applicable law (including the CCPA's list of permitted purposes in Section 1798.121):
- Performing the Services reasonably expected by an average consumer who requests them.
- Helping to ensure security and integrity to the extent that the use is reasonably necessary and proportionate.
- Detecting and resisting malicious, deceptive, fraudulent, or illegal actions, and prosecuting those responsible.
- Performing services on behalf of a Customer (including maintaining or servicing accounts; processing or fulfilling orders and transactions; verifying information; processing payments; providing financing; providing analytic services; providing storage; and providing similar services on behalf of the Customer).
- Verifying or maintaining the quality or safety of a service or device, and improving, upgrading, or enhancing the service or device.
- Complying with applicable law and legal process.
Special Protections We Apply
Sensitive Personal Information is subject to the following additional protections:
- Application-level encryption. Sensitive Personal Information stored in our database is protected by an additional layer of application-level encryption (AES-256-GCM with per-tenant key derivation via HKDF), beyond the encryption applied to ordinary Personal Information at rest.
- Searchable hash representations. Where Sensitive Personal Information must be searchable (for example, to enable lookups by the last four digits of a Social Security number for fraud prevention), we use keyed hash representations (HMAC) so that authorized lookups can be performed without exposing plaintext.
- Restricted access. Access to Sensitive Personal Information by Ciosanna personnel is strictly limited and logged. Customer-side access is governed by role-based access controls configured by the Customer in accordance with applicable law and the Customer's own policies.
- Limited retention. Sensitive Personal Information is retained only for as long as necessary for the purpose for which it was collected and is then deleted or further restricted, as described in Section 6.4.
- No use for advertising. We do not use Sensitive Personal Information for advertising or marketing purposes.
Your Right to Limit Use of Sensitive Personal Information
Where applicable law (including the CCPA) provides a right to limit the use or disclosure of Sensitive Personal Information to purposes other than those enumerated in the law, you may exercise that right by submitting a request through the methods described in Section 9.6. Because we use Sensitive Personal Information only for the limited purposes described in Section 12.2 (which fall within the statutory exceptions), exercising this right will not typically restrict our current Processing of your Sensitive Personal Information. We will, however, confirm the scope of our use upon request and apply any further restrictions you request to the extent consistent with applicable law and the provision of the Services.
Fair Housing and Anti-Discrimination
Where Sensitive Personal Information may be relevant to a housing decision (for example, disability information in connection with a reasonable accommodation request, or familial status), we and our Customers are required by law to use such information only in compliance with the Fair Housing Act and analogous state and local laws. The Cio behavioral scoring system does not use protected-class information as an input to scoring. If you believe that information about you has been used in a manner inconsistent with fair housing law, you may file a complaint with the U.S. Department of Housing and Urban Development at https://www.hud.gov/fairhousing or with the relevant state or local fair housing agency.
No Sale of Personal Information; No Sharing for Cross-Context Behavioral Advertising; Your Right to Opt Out
Our Practices
We do not sell your Personal Information in exchange for monetary or other valuable consideration, as the term "sell" is defined under the California Consumer Privacy Act and analogous laws of other U.S. states.
We do not share your Personal Information for "cross-context behavioral advertising," as that term is defined under the California Privacy Rights Act and analogous laws. We do not participate in third-party advertising networks, we do not use third-party advertising cookies or pixels, and we do not provide your Personal Information to third parties for them to advertise their own products or services to you on other websites or services.
We do not engage in "profiling in furtherance of decisions that produce legal or similarly significant effects" within the meaning of state privacy laws, except for the Cio behavioral scoring system, which is described in detail in Section 10 of this Policy. Where the scoring system results in such effects, we provide the rights described in Section 10.4.
Global Privacy Control
We recognize and honor the Global Privacy Control (GPC) signal as a valid opt-out request for any activity that could be characterized as a "sale" or "sharing" under applicable law, and (where the applicable state law treats GPC as a universal opt-out mechanism) as a valid opt-out of targeted advertising and certain profiling.
When your browser transmits a GPC signal to our website, we automatically:
- Treat your visit as an opt-out of any sale or sharing of Personal Information, even though we do not sell or share Personal Information in the ordinary course of business.
- Apply essential-cookies-only settings to non-essential Tracking Technologies, including suppressing any analytics, marketing, or functional Tracking Technologies that are not strictly necessary.
- Record the GPC signal and associate it with your session, so that subsequent activity is treated consistently with the opt-out.
The states whose laws expressly recognize universal opt-out mechanisms such as GPC include, as of the effective date of this Policy, California, Colorado, Connecticut, Texas, Oregon, Montana, New Hampshire, New Jersey, Delaware, Nebraska, and Minnesota, and any other state that has subsequently adopted equivalent recognition.
How to Submit an Opt-Out Request Manually
In addition to GPC, you may submit an opt-out request through any of the following methods:
- Click the "Cookie Settings" link in the footer of our website to adjust your cookie preferences at any time. Setting all non-essential categories to "off" has the same effect as a GPC signal.
- **Submit a request through the privacy request form at /legal/privacy-request** and select "opt out of sale or sharing" as the request type.
- Email us at support@ciosanna.com with the subject line "Opt-Out Request."
Notice at Collection
This Privacy Policy, together with the contextual notices we provide at the point of collection (such as the cookie consent banner, the labels on our forms, and the disclosures included in any AI-generated content), constitutes our "notice at collection" as required by the CCPA and analogous laws of other U.S. states. The notice at collection sets out the categories of Personal Information we collect, the purposes for collection, whether the information is sold or shared (it is not, except as described above), and the categories of Sensitive Personal Information collected.
Right to Limit Use and Disclosure of Sensitive Personal Information
As described in Section 12.4, you have the right under certain state privacy laws to limit the use and disclosure of Sensitive Personal Information to specific enumerated purposes. Because we use Sensitive Personal Information only for those purposes, exercising this right will not materially restrict our current Processing, but we honor the right by confirming the scope of our use upon request.
Non-Discrimination
We will not discriminate against you for exercising any of your rights under applicable privacy law, including by denying Services, charging different prices or rates, providing a different level or quality of Services, or suggesting that you will receive a different price or quality of Services as a result of exercising your rights, except as expressly permitted by applicable law (such as where the difference is reasonably related to the value provided to us by your data).
Marketing Communications and Opt-Out
Categories of Communications
We send two principal categories of communications:
- Transactional and operational communications include account confirmations, password resets, login verification codes, billing statements, payment receipts, payment failure notices, security alerts, lease and rent reminders, work order updates, owner distribution notices, vendor work order assignments, system maintenance notices, legal notices (including notices of changes to this Privacy Policy or the Terms of Service), and other communications necessary to provide the Services or required by law. You generally cannot opt out of transactional and operational communications while you maintain an active account or relationship with us, because these communications are necessary for our performance of the contract or for compliance with legal obligations.
- Marketing communications include newsletters, product announcements, promotional offers, event invitations, customer success outreach, sales outreach, and similar communications intended to inform you about Ciosanna products, features, and offers. You may opt out of marketing communications at any time, regardless of any other relationship you have with us.
Legal Bases and Consent
- In the United States: We send marketing emails to existing customers under the established business relationship exemption permitted under the federal CAN-SPAM Act, and to opt-in subscribers who have affirmatively requested to receive marketing communications. Every marketing email includes a clear "unsubscribe" link and our valid physical postal address as required by CAN-SPAM.
- In the European Economic Area, the United Kingdom, and Switzerland: We send marketing communications only where we have a lawful basis, which is typically your prior, freely given, specific, informed, and unambiguous consent. We rely on the "soft opt-in" exception (where applicable under national implementations of the ePrivacy Directive) only for marketing of our own similar products to existing customers, and only where you were given a clear opportunity to opt out at the time of collection and in every subsequent communication.
- In Canada: We comply with Canada's Anti-Spam Legislation (CASL) by sending commercial electronic messages only with your express or implied consent and including the required identification, contact, and unsubscribe information in every commercial message.
- In other jurisdictions: We send marketing communications in accordance with the applicable law of your jurisdiction.
SMS, Voice, and Other Channels
Where you have provided a mobile telephone number and consented to receive text messages, we may send transactional and (where you have separately opted in) marketing messages by SMS. Message and data rates may apply. We comply with the Telephone Consumer Protection Act (TCPA) and analogous laws governing automated telephone communications. You may opt out of SMS marketing at any time by replying STOP to any marketing SMS or by contacting support@ciosanna.com. Standard transactional messages (such as login verification codes and payment confirmations) may continue to be sent unless you remove your phone number from your account.
We do not place outbound marketing telephone calls using automated dialing technology except where expressly permitted by applicable law. We do not call telephone numbers on the National Do Not Call Registry except where an exemption applies.
In-Product Notifications
Within the Ciosanna platform, we may display in-product notifications (such as banners, dialogs, and toast messages). These notifications may include operational announcements, feature releases, and, occasionally, promotional content. You may not be able to globally suppress all in-product notifications, but we will use reasonable efforts to label promotional in-product notifications clearly and to provide dismissal controls.
How to Opt Out of Marketing Communications
You may opt out of marketing communications by any of the following methods:
- Click the "unsubscribe" link in the footer of any marketing email you receive from us.
- Update your communication preferences in your account settings, where you have a Ciosanna account.
- Reply STOP to any marketing SMS you receive from us.
- Email us at support@ciosanna.com with the subject line "Opt-Out of Marketing."
We will honor opt-out requests as soon as reasonably practicable, and in any event within the timeframes required by applicable law (typically ten business days under the CAN-SPAM Act).
Effect of Opting Out
Opting out of marketing communications does not affect transactional or operational communications and does not affect your account or any other relationship with us. You can resubscribe at any time by updating your communication preferences in your account settings or by contacting us.
Sub-Processors
Approach to Sub-Processors
We engage Sub-Processors to perform discrete functions necessary to operate the Services. Each Sub-Processor is bound by a written agreement that requires, at a minimum: (a) Processing of Personal Information only on our documented instructions; (b) confidentiality with respect to Personal Information; (c) implementation of appropriate technical and organizational security measures; (d) restrictions on engaging further sub-processors without our approval; (e) cooperation with us in responding to data subject requests and supervisory authority inquiries; (f) assistance with personal data breach notification; (g) deletion or return of Personal Information at the end of the engagement; and (h) submission to audits or inspections to verify compliance.
Current Material Sub-Processors
The principal Sub-Processors we currently engage to support the Services are listed below. This list is subject to change. We update this list when we engage a new material Sub-Processor or remove an existing one.
- Supabase, Inc. — Database hosting, authentication, file storage, and row-level security for Personal Information processed within the Ciosanna platform. Country of processing: United States.
- Stripe, Inc. — Payment processing for Customer subscription payments, Resident rent payments, Property Owner distributions, and Vendor payouts. Stripe operates as an independent controller with respect to certain payment-related information that it processes for its own compliance and fraud-prevention purposes. Country of processing: United States.
- Twilio Inc. (SendGrid) — Transactional and marketing email delivery, including email engagement and delivery analytics. Country of processing: United States.
- Cloudflare, Inc. — Content delivery network, web application firewall, distributed denial-of-service protection, bot management (including Bot Fight Mode and the Turnstile CAPTCHA), and geolocation by IP address. Country of processing: United States and global edge network.
- Anthropic, PBC — Large language model services that power the Cio AI Assistant within the platform and the Cio Sales Agent on the marketing website. Anthropic is contractually restricted from using your conversations to train its AI models. Country of processing: United States.
- Replit, Inc. — Cloud development and application hosting infrastructure for the Ciosanna platform and CiosannaConnect.com sales site. Country of processing: United States.
We may also engage additional Sub-Processors on a transitional or limited basis (for example, professional services firms acting as confidential advisors, identity verification providers engaged by a Customer, or analytics providers used on a privacy-preserving basis), in each case subject to the contractual safeguards described in Section 15.1.
Notice of New Sub-Processors and Right to Object
Where required by an applicable Data Processing Addendum with a Customer, we will provide the Customer with advance notice of any new material Sub-Processor and a reasonable opportunity to object. If a Customer objects to a new Sub-Processor on reasonable data protection grounds, we will work in good faith with the Customer to find a mutually acceptable resolution, which may include providing additional safeguards or, where no resolution can be reached, allowing the Customer to terminate the affected portion of the Services.
Where to Find the Current List
A current, dated version of the material Sub-Processors list is available on request by contacting support@ciosanna.com. We will provide the list together with the country of processing for each Sub-Processor and the categories of Personal Information that each Sub-Processor Processes.
Artificial Intelligence Features and Generated Content
Disclosure of AI Interactions
In accordance with Article 50 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) and analogous transparency obligations in other jurisdictions, we disclose clearly and conspicuously whenever you are interacting with an AI system rather than a human. The Cio Sales Agent on CiosannaConnect.com and the Cio AI Assistant within the Ciosanna platform are AI systems powered by large language models provided by our AI Sub-Processor (Anthropic, PBC). Each Cio interaction is labeled as an AI interaction at the start of the conversation, and reasonable steps are taken to remind you of the AI nature of the interaction if the conversation extends over a significant period.
Labeling of AI-Generated Content
Where Cio generates content that could reasonably be mistaken for content created by a human (including responses to your questions, generated summaries, or generated text), the content is presented in a clearly labeled AI interface and is not represented as human-authored. We do not generate AI-synthesized media (such as deepfake images, audio, or video). If we begin to generate AI-synthesized media in the future, we will mark it as artificially generated or manipulated in accordance with applicable law.
Limitations of AI-Generated Content
AI-generated content is provided for informational and conversational purposes only. It may be inaccurate, incomplete, or out of date. It does not constitute legal, financial, tax, real estate, medical, or other professional advice. You should not rely on AI-generated content for any decision that has significant consequences without independent verification. Where AI-generated content provides an answer that conflicts with this Privacy Policy, the Terms of Service, or other authoritative documentation, the authoritative documentation controls.
No Profiling Based on AI Conversations
We do not use the content of your conversations with Cio to build a profile of you for advertising, to make eligibility decisions about you, or to share characteristics about you with third parties for marketing purposes. We may use aggregated or de-identified information about conversation patterns to improve the Cio features themselves, as described in Section 3.9.
Your Right to Interact With a Human
You have the right at any time to discontinue an AI interaction and instead interact with a human (in the case of the Cio Sales Agent, by emailing support@ciosanna.com or by scheduling a demo with a member of our team; in the case of the Cio AI Assistant within the platform, by contacting your Customer organization's designated administrators, or, where the Customer makes a human support channel available, by contacting that channel).
Classification Under the EU AI Act
We have evaluated the Cio features against the categories established under the EU AI Act and have determined that, in their current configuration, they do not constitute "high-risk AI systems" within the meaning of Annex III of the Act. We will reassess this classification as the Cio features evolve and as guidance from EU authorities develops. If we determine that any Cio feature falls within a high-risk category, we will comply with the additional requirements applicable to high-risk AI systems, including risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, and cybersecurity requirements.
No Decisions Based Solely on AI
As described in Section 10, Cio does not by itself make decisions that produce legal effects or similarly significantly affect you. The Cio behavioral scoring system is a decision-support tool whose outputs are reviewed and acted upon by humans (typically authorized Customer personnel). The Cio AI Assistant and Cio Sales Agent generate text responses to user prompts and do not autonomously act on your account or take consequential actions on your behalf.
Changes to This Privacy Policy
Reasons for Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, our Sub-Processors, applicable law, or the interpretation of applicable law. We may also update this Policy to clarify language or correct errors.
Categories of Changes
We classify changes to this Privacy Policy into two categories:
- Non-material changes are changes that do not materially affect your rights or how we Process your Personal Information. Examples include clarifications, corrections of typographical errors, changes to the names of Sub-Processors that do not involve any change in the function performed, and minor formatting changes.
- Material changes are changes that materially affect your rights or how we Process your Personal Information. Examples include the addition of new categories of Personal Information collected, new purposes of Processing, new categories of Sub-Processors or recipients, changes to how we honor opt-out signals, changes that reduce your privacy rights, and changes to our breach notification commitments.
Notice of Changes
When we make changes to this Privacy Policy, we will:
- Post the updated Privacy Policy on the CiosannaConnect.com website.
- Update the "Last Updated" date at the top of the Policy.
- For material changes, provide additional notice through one or more of the following channels, as appropriate: (a) email to your registered email address; (b) a prominent in-product notification within the Ciosanna platform the next time you log in; (c) a banner on the website; or (d) any other means reasonably designed to inform you of the change.
- Where applicable law requires advance notice of a material change, we will provide such notice in advance of the effective date.
- Where applicable law requires your affirmative consent to a material change before it applies to your Personal Information, we will obtain that consent before applying the change.
Effective Date and Continued Use
Each updated Privacy Policy is effective as of the "Effective Date" stated at the top of the updated Policy, unless an earlier or later effective date is specified for a particular provision. Your continued use of the Services after the Effective Date of an updated Privacy Policy constitutes your acceptance of the updated Policy, to the extent permitted by applicable law and subject to any consent requirement described in Section 17.3.
Prior Versions
You may request a copy of any prior version of this Privacy Policy by contacting us at support@ciosanna.com. We retain prior versions in accordance with our document retention policies.
Contact, Complaint, and Supervisory Authority Information
How to Contact Us
For any question, request, concern, or complaint regarding this Privacy Policy, our privacy practices, or the Processing of your Personal Information, please contact us by any of the following methods:
- Email: support@ciosanna.com
- Postal mail: Ciosanna LLC, 714 W 2nd St, Waitsburg, WA 99361, United States
- Online form: Submit a request through our privacy request form at https://ciosannaconnect.com/legal/privacy-request
When contacting us, please include enough information to enable us to identify you and to understand the nature of your inquiry or request, while being mindful not to include unnecessary Sensitive Personal Information in your initial communication.
Designated Privacy Contact
Inquiries directed to support@ciosanna.com with a subject line indicating a privacy matter (such as "Privacy Request," "Privacy Rights Request," "DSAR," or "Privacy Complaint") will be routed to the personnel responsible for handling privacy matters at Ciosanna.
EU Representative
Ciosanna does not currently offer the Services in the European Union and has therefore not designated a representative in the Union in accordance with Article 27 of the GDPR. A representative will be designated in accordance with Article 27 before any launch of the Services in the European Union, and this Privacy Policy will be updated at that time. Until an EU representative is formally designated, EU residents may contact us directly using the methods described in Section 18.1. The designation of an EU representative does not affect our or our representatives' responsibilities or liabilities under the GDPR.
UK Representative
Where we are required to appoint a representative in the United Kingdom under Article 27 of the UK GDPR, the designated UK representative will be identified in this Section. Until a UK representative is formally designated, UK residents may contact us directly using the methods described in Section 18.1.
Right to Lodge a Complaint With a Supervisory Authority
If you believe that our Processing of your Personal Information violates applicable law, you have the right to lodge a complaint with a supervisory authority, in particular in the country or state of your habitual residence, place of work, or place of the alleged violation. Below is non-exhaustive information for major supervisory authorities relevant to our users:
- European Union: A list of national supervisory authorities is maintained by the European Data Protection Board at https://edpb.europa.eu/about-edpb/about-edpb/members_en. You may lodge a complaint with the supervisory authority of your EU Member State of habitual residence, place of work, or place of the alleged infringement.
- United Kingdom: Information Commissioner's Office (ICO), https://ico.org.uk, telephone +44 0303 123 1113.
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC), https://www.edoeb.admin.ch.
- California, United States: California Privacy Protection Agency (https://cppa.ca.gov) and California Attorney General (https://oag.ca.gov/privacy).
- Other United States states: Inquiries concerning state privacy laws may be directed to the relevant state Attorney General. Contact information for each state Attorney General is available at https://www.naag.org/find-my-ag/.
- Canada: Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca) and, for residents of Quebec, the Commission d'accès à l'information du Québec (https://www.cai.gouv.qc.ca).
- Brazil: Autoridade Nacional de Proteção de Dados (ANPD), https://www.gov.br/anpd.
- Australia: Office of the Australian Information Commissioner (OAIC), https://www.oaic.gov.au.
We encourage you to contact us at support@ciosanna.com before lodging a complaint, so that we have an opportunity to address your concerns directly.
Fair Housing Complaints
If your complaint concerns a Customer's use of the Services in a manner you believe violates the Fair Housing Act or analogous state or local fair housing law, you may file a complaint with the U.S. Department of Housing and Urban Development at https://www.hud.gov/fairhousing, or with the relevant state or local fair housing agency. We will cooperate with fair housing investigations and proceedings as required by law.
Fair Credit Reporting Act Complaints
If your complaint concerns the use of consumer report information (including the Cio behavioral scoring system to the extent it is used as a consumer report) in a manner you believe violates the Fair Credit Reporting Act, you may file a complaint with the federal Consumer Financial Protection Bureau at https://www.consumerfinance.gov, with the Federal Trade Commission at https://www.ftc.gov, or with the relevant state regulatory authority. Our FCRA Disclosure (available at /legal/fcra) provides additional information.
Accessibility
If you require this Privacy Policy in an alternative accessible format, or if you require accommodation in exercising your privacy rights, please contact us at support@ciosanna.com and we will provide a reasonable accommodation.
End of Privacy Policy.
The information provided on this page is for general informational purposes only and does not constitute legal advice. For advice regarding your specific situation, please consult a qualified attorney licensed in your jurisdiction.
Questions about this document? Contact us at support@ciosanna.com