Privacy Policy
Effective Date: September 24, 2026 • Version 2.5 (Enterprise Assurance)
At Cursis (operated by Cursis Inc., "we", "our", or "us"), we are committed to safeguarding the privacy, integrity, and confidentiality of your personal and enterprise information. This Privacy Policy delineates how we collect, process, store, and protect information when you access cursis.in and our integrated business workspace applications.
1. Information We Collect
We adhere strictly to the principle of data minimization. We only collect information strictly requisite to providing high-reliability enterprise workspace capabilities:
- Account Identification: Business email address, name, organization identifier, and secure authentication tokens when you register or sign in via email or federated Google OAuth.
- Workspace Operational Data: Team rosters, project tasks, roadmaps, modules, and workflow state created by your authorized team members within your private workspace.
- Telemetry & Security Logs: Cryptographic session tokens, client IP addresses (anonymized for telemetry), user-agent strings, and request payloads exclusively for service availability monitoring, DDoS defense, audit logs, and SOC-2 audit compliance.
2. Zero Third-Party Advertising & Commercialization
Cursis operates with zero third-party tracking or advertising networks. We do not sell your personal information or monetize browsing behaviors. Our cookie utilization is strictly restricted to essential session preservation and tenant isolation.
3. GDPR & International Privacy Rights
Under the General Data Protection Regulation (GDPR), individuals within the European Economic Area (EEA) possess specific statutory rights regarding their personal data:
- Right of Access: You have the right to request comprehensive overviews of your data.
- Right to Rectification: You may update or correct inaccurate personal information.
- Right to Erasure ("Right to be Forgotten"): You may request permanent deletion of your data via our dedicated Data Deletion facility.
- Right to Restriction: You may request temporary suspension of data processing during disputes.
- Right to Data Portability: You have the right to export your workspace data in structured, machine-readable formats (JSON / CSV).
4. Infrastructure Security & Data Isolation
Cursis implements multi-layered defensive security architectures aligned with SOC-2, ISO 27001, and HIPAA best practices:
- Encryption at Rest & Transit: TLS 1.3 enforced for all transport connections; AES-256 with automated key rotation for database storage.
- Tenant Data Isolation: Every workspace operates within an isolated cryptographic namespace, ensuring workspace data cannot bleed across accounts.
- Access Control: Zero-trust role-based access control (RBAC) preventing horizontal privilege escalation across workspaces.
5. Automated Bot & Scraping Policy
Cursis strictly prohibits unauthorized automated harvesting, web scraping, or training of machine learning and large language models (LLMs) on private user or workspace content. We publish explicit machine-readable rules in our robots.txt file blocking unauthorized crawler agents including GPTBot, ChatGPT-User, CCBot, anthropic-ai, and related scrapers.
Questions or Verification Requests
Our data governance and security compliance team reviews requests with SLA commitment within 24 to 48 business hours.