Privacy Policy and Cookie Notice

Last updated: —

1. Key Terms

TermDefinition
Personal DataAny information that can directly or indirectly identify a natural person (e.g., name, email, IP address, Stripe customer ID).
ProcessingAny operation performed on personal data, including collection, storage, use, transmission, deletion, etc.
ControllerThe entity that determines the purposes and means of data processing. Under this Policy, it is our company (see Chapter 2).
ProcessorAn entity commissioned by the Controller to process data (e.g., Stripe / Cloudflare / Resend; see Chapter 5 and Appendix A).
SubprocessorA further processor commissioned by a Processor (e.g., Stripe's card-issuing bank / Cloudflare's data centers).
Sensitive DataHighly sensitive categories such as health, biometrics, sexual orientation, religion, and criminal records. We do not collect such data.

2. Data Controller Identity

ItemDetails
Company NameDatability Limited (current); to be changed to CyteEditor Limited upon corporate restructuring
Place of RegistrationHong Kong Special Administrative Region
Registered AddressFlat 2401-16, Wing Shing Industrial Building, 26 Ng Fong St, San Po Kong, Hong Kong
Contact Emaillegal@cyteeditor.com (dedicated to data protection matters)
Support Emailsupport@cyteeditor.com
Legal Emaillegal@cyteeditor.com
Data Protection RepresentativeCurrently served by a company director; an independent EU representative will be appointed under GDPR Art. 27 when EU monthly active users exceed 5,000
EU Representative (pending)To be appointed upon reaching the EU customer threshold
UK Representative (pending)To be appointed upon reaching the UK customer threshold

Entity Transition Notice: Pursuant to Article 7 of the EULA (Assignment Right), our company may, upon no less than 90 days' written notice, assign the data controller rights and obligations under this Policy to an Affiliate or Successor Entity (such as CyteEditor Limited). Such assignment shall not alter the purposes, scope, or your rights regarding data processing.


3. Data Types Collected

We collect different types of data in different scenarios. All collection follows the principle of data minimization.

3.1 Account and Billing Data (collected at purchase)

Data ItemSourcePurposeLegal Basis (GDPR Art. 6)
Email addressStripe Checkout formSend License Key, invoices, renewal reminders(b) Contract performance
Billing addressStripe Checkout formIssue compliant invoices (including country / city / postal code)(c) Legal obligation (tax law)
Company name (B2B, optional)Stripe Checkout formInvoice header(b) Contract performance
VAT/GST tax number (B2B, optional)Stripe Checkout formReverse charge record retention(c) Legal obligation
Stripe customer IDStripe APILink subscription / refund / License(b) Contract performance
Last 4 digits of payment method / card brandStripe (display only; we do not store full card numbers)Customer service payment verification(b) Contract performance

We do not directly handle full credit card numbers, CVC codes, passwords, or other PCI data — all payment input is completed on Stripe's hosted page; we receive only desensitized metadata from Stripe.

3.2 License Verification Data (collected when the editor SDK makes a call)

When you (or your end users) trigger a License Key verification in an application loaded with the CyteEditor SDK, the SDK sends a request to api.cyteeditor.com/license/verify, and we record the following at the receiving end:

Data ItemPurposeLegal BasisRetention
License Key (JWT)Verify signature and status(b) Contract performanceNot persisted (log only, 30 days)
Request origin domainAnti-piracy (initial domain binding + subsequent matching)(f) Legitimate interest (preventing unauthorized use)License lifecycle
Request IP addressRate limiting / anomaly detection / audit(f) Legitimate interest (abuse prevention)Aggregated and anonymized after 30 days
User-AgentDebugging / compatibility statistics(f) Legitimate interest30 days
Request timestampAudit / abuse detection(f) Legitimate interest30 days

Key Statement: We do not collect the actual content of the rich text editor in your application (user-entered document text / images / media). This content always remains in your application / on your servers and is never transmitted to our servers.

3.2.1 Client SDK Local Cache (IndexedDB / 24h TTL)

To reduce network round-trips and ensure offline availability, the @cyte-editor/license client SDK writes the following strictly necessary local data in your browser or host application:

Storage LocationData ItemPurposeRetentionTransmitted to Us?
IndexedDB (database cyte-editor-license)Last verification result (payload / status / lastVerifyAt)Offline fast verification at startup, avoiding network requests each time24-hour TTL, automatic expirationNo
IndexedDBMonotonic timestamp (maxObservedTime)Detect system clock rollback attempts, preventing expired License Key reuseSame as License lifecycleNo
IndexedDB (strict mode only)Last successful online verification timestamp (lastOnlineSuccessAt)Supports offlineGraceDays (default 14 days) for offline grace period determinationSame as License lifecycleNo

Boundary with §3.2 Data Collection:

  • The above IndexedDB entries exist only in your browser / your application locally and are never transmitted to our servers;
  • When the SDK is configured with online: false (fully offline mode), we collect zero data;
  • When the SDK is configured with online: 'lazy' or 'strict', it only sends requests to api.cyteeditor.com/license/verify, transmitting only the 5 items listed in the §3.2 table;
  • When IndexedDB is unavailable (browser private mode or disabled), the SDK automatically degrades to sessionStorage, then to in-memory cache, without affecting our data collection scope.

Data Subject Rights: Pursuant to GDPR Art. 15 / Art. 17, you may at any time view or delete the above local data through your browser's developer tools (Application → IndexedDB panel); deletion does not affect the validity of the License Key itself but will trigger re-verification on the next launch.

3.3 Website Visit Data (collected when browsing the homepage)

We use Plausible Analytics (or self-hosted Umami), characterized by:

  • No cookies written;
  • No IP address collection (only briefly used for session identification, immediately hashed and discarded);
  • No cross-site tracking;
  • Only aggregated statistics on page views, source country (coarse-grained), and device type.
Data ItemPersonal Data?PurposeLegal Basis
Page URL (excluding query string)No (aggregated)Traffic analysis(f) Legitimate interest
Referer (source)NoMarketing channel analysis(f) Legitimate interest
Browser typeNoCompatibility optimization(f) Legitimate interest
Country (coarse-grained)NoRegional market analysis(f) Legitimate interest
Screen size (range)NoResponsive design optimization(f) Legitimate interest

We do not use Google Analytics, Facebook Pixel, TikTok Pixel, LinkedIn Insight, Hotjar, Clarity, or other cookie-based tracking tools. If introduced in the future, we will update this Policy and trigger the Cookie banner to re-solicit consent.

3.4 Customer Service and Sales Communication Data

When you communicate with us via email / ticket / form, we collect:

Data ItemPurposeLegal BasisRetention
Your voluntarily provided name, email, contentRespond to your request(b) Contract performance / (f) Legitimate interest5 years (per Hong Kong telecommunications law and statute of limitations)
Email IP / email headersAnti-spam / security audit(f) Legitimate interest90 days

Per GDPR Art. 6(1), the 6 legal bases under which we process personal data:

Processing PurposeLegal BasisData Category (see Chapter 3)
Fulfilling contractual obligation to deliver License Key and invoices(b) Contract performance3.1 Account & Billing
License verification, renewal, revocation(b) Contract performance3.1 + 3.2
Retaining records for tax / AML / business registration laws(c) Legal obligation3.1
Preventing unauthorized use, piracy, abuse; network and information security(f) Legitimate interest3.2
Improving product quality, traffic analysis, market decisions(f) Legitimate interest3.3
Responding to customer service / sales inquiries(b) Contract performance / (f) Legitimate interest3.4
Cookie banner not placing non-essential cookies prior to consent(a) Consent9.1

We do not process data under "(d) vital interests of the data subject" or "(e) public interest tasks."


5. Data Sharing and Processors

We do not sell or rent your personal data. We share data only under the following three circumstances:

5.1 Commissioned Processors (Subprocessors)

To provide our services, we must work with the following subprocessors (see Appendix A for details):

SubprocessorPurposeData CategoryData Residency
Stripe Inc.Payment processing, subscription management, invoice generation3.1 Account & Billing dataUS (GDPR SCC + Stripe DPA)
Cloudflare, Inc.Website hosting, CDN, Worker compute, D1 database, KV cache3.2 + 3.3Global (Cloudflare DPA + SCC)
Resend Inc.Transactional email sendingEmail address + email bodyUS (Resend DPA)
Sentry, Inc.Error monitoring (automatic PII redaction)Error stacks (non-personal data)US (Sentry DPA)
Plausible / UmamiWebsite visit statistics (no cookies / no IP)3.3 aggregated dataEU (Plausible self-hosted) / self-hosted on Cloudflare D1

We have signed or will sign a DPA (Data Processing Agreement) with each Subprocessor, using SCC (Standard Contractual Clauses, 2021/914) as the legal basis for cross-border transfers.

Only under the following circumstances may we disclose personal data without your prior consent:

  • A lawful written request from a court, regulatory authority, or tax authority with jurisdiction;
  • Fulfilling criminal, anti-money laundering, or anti-terrorism financing legal obligations;
  • Protecting our legitimate rights, property, or personal safety (e.g., cooperating with DDoS attack investigations or IP infringement litigation).

We will notify you in advance to the extent permitted by law.

5.3 Business Transfer

Pursuant to Article 7 of the EULA (Assignment Right), our company may transfer the business along with your personal data to an Affiliate or Successor Entity upon 90 days' written notice. The transferee shall be equally bound by this Policy.


6. Cross-Border Data Transfer

As our infrastructure is globally distributed (Stripe US, Cloudflare global, Resend US), your personal data may be transferred to the EU, US, or other jurisdictions. We take the following measures to ensure legality:

Cross-Border PathLegal Basis
HK → EU(1) No Adequacy Decision between HK and EU; (2) SCC executed with each Subprocessor (2021/914 Module 4: processor-to-processor)
HK → USSCC + each party's DPF (Data Privacy Framework) participation with Stripe / Resend / Cloudflare / Sentry
HK → OtherCase-by-case assessment + SCC fallback
EU resident data → HKSCC Module 1 (controller-to-controller) + supplementary measures where necessary

If you reside in the EU/UK and wish to obtain copies of the SCCs we have executed with our Subprocessors (with sensitive commercial terms redacted), please email legal@cyteeditor.com.


7. Data Retention Periods

Data CategoryRetentionBasis
Stripe account and billing records7 years (from transaction date)Hong Kong tax law / dispute resolution
License JWT + database license recordsLicense lifecycle + 5 years after revocationAnti-piracy audit + customer dispute resolution
License verify call logs (IP / UA / timestamp)Aggregated and anonymized after 30 days; original records deletedLegitimate interest + minimization
Customer service email communications5 yearsStatute of limitations and dispute resolution
Website visit statistics (aggregated)Permanent (no longer personal data)Legitimate interest
Cookie consent records13 months (re-consent cycle)GDPR / ePrivacy practice
Error monitoring stacks (Sentry)90 daysLegitimate interest

Upon expiration, we will securely delete or irreversibly anonymize the corresponding data. Data in backup media will be deleted within the next backup rotation cycle (maximum 14 days).


8. Your Rights

The following table summarizes the data subject rights we recognize across different jurisdictions:

RightGDPR (EU/UK)PDPO (HK)CCPA (CA)PIPL (CN)
Right to be informed✅ Art.13/14✅ DPP1✅ §1798.100✅ Art.17
Right of access✅ Art.15✅ DPP6✅ §1798.110✅ Art.45
Right to rectification✅ Art.16✅ DPP6✅ §1798.106✅ Art.46
Right to erasure / forgotten✅ Art.17⚠️ Limited✅ §1798.105✅ Art.47
Right to restriction✅ Art.18✅ Art.44
Right to data portability✅ Art.20✅ Art.45
Right to object✅ Art.21❌ (Opt-out for sale)✅ Art.44
Right against automated decisions✅ Art.22⚠️ Limited✅ Art.24
Right to withdraw consent✅ Art.7✅ Art.15
Right against discrimination (post-exercise)✅ Art.21✅ §1798.125✅ Art.50

8.1 How to Exercise Your Rights

Send an email to legal@cyteeditor.com and provide:

  1. Your identity verification (order email + Stripe customer ID or last 8 digits of License Key);
  2. The specific right you wish to exercise and the scope of data involved;
  3. Your preferred response method (email / postal address).

We commit to:

  • Completing processing within 30 calendar days (GDPR Art. 12 standard);
  • If an extension of up to 60 days is needed, we will inform you of the reason within the first 30 days;
  • First exercise is free; from the second exercise of the same right in the same calendar year, a reasonable cost fee of USD 30 may be charged (only if the request is deemed "manifestly unfounded or excessive").

8.2 Right to Complain

If you are not satisfied with our response, you have the right to file a complaint directly with your local supervisory authority:

JurisdictionSupervisory AuthorityContact
Hong KongOffice of the Privacy Commissioner for Personal Data (PCPD)https://www.pcpd.org.hk
EU Member StatesEach member state's DPAhttps://edpb.europa.eu/about-edpb/board/members_en
UKInformation Commissioner's Office (ICO)https://ico.org.uk
US-CaliforniaCalifornia Privacy Protection Agencyhttps://cppa.ca.gov
ChinaCyberspace Administration of China / local public security cyber department12377 / 12321

CategoryConsent Required?Currently Used?
Strictly Necessary Cookies❌ On by default✅ Used (see 9.2)
Functional Cookies✅ Consent required❌ Not used
Analytics Cookies✅ Consent required❌ Not used (using cookie-free Plausible / Umami)
Marketing Cookies✅ Consent required❌ Not used

9.2 Complete List of Currently Used Cookies

We use only 4 strictly necessary cookies, with no analytics or marketing cookies (see Appendix B for technical details):

Cookie NamePurposeTTLType
__stripe_midStripe fraud prevention (Checkout page)1 yearStrictly necessary (governed by Stripe DPA)
__stripe_sidStripe session identification30 minutesStrictly necessary
cyte_consentRecords your Cookie banner choice, preventing repeated display13 monthsStrictly necessary
i18n_redirectedRecords your selected website language, avoiding re-routing each visit1 yearStrictly necessary

9.3 Impact of Refusing Cookies

Since the above cookies are all strictly necessary, fully disabling cookies in your browser will affect:

  • ❌ You will not be able to complete Stripe Checkout payment (Stripe fraud prevention required);
  • ❌ You will need to re-select the language each visit;
  • ❌ The Cookie banner will reappear each visit.

Strictly necessary cookies do not require your prior consent — this is an explicit statutory exemption under GDPR Recital 30 and ePrivacy Directive Art. 5(3), second subparagraph.

On your first visit to this website, you will see a bottom banner indicating that this site uses strictly necessary cookies. After clicking "Got it" to dismiss the banner, the cyte_consent cookie records your dismissal action, and the banner will not reappear for 13 months.

We currently do not display "Accept / Reject Analytics Cookies" complex options, because we do not use any non-essential cookies. If we introduce analytics or marketing cookies in the future, we will:

  1. Update this Policy 30 days in advance;
  2. Force-reset all users' cyte_consent cookie, triggering the banner to reappear;
  3. Provide granular options (Accept all / Necessary only / Custom).

The legal authorization text for the Cookie banner is set forth in Appendix C.


10. Security Measures

We take the following technical and organizational measures to protect your data security:

CategoryMeasure
Transport encryptionSite-wide TLS 1.3 + HSTS (max-age=31536000) + HTTP/3
Storage encryptionCloudflare D1 encryption at rest (AES-256) + Workers Secrets isolation
Key managementLicense JWT private key stored only in Workers Secrets, never in the repository / never leaves the Worker boundary
Access controlAdmin endpoint ADMIN_TOKEN + optional TOTP two-factor authentication + rate limiting
Backup & recoveryD1 daily automatic snapshots + weekly encrypted export to Cloudflare R2 (retained 12 weeks)
Network securityCloudflare WAF + DDoS protection (automatic) + Bot Fight Mode
Intrusion monitoringSentry error aggregation + critical alert email trigger within seconds
Input validationAll API endpoints use Zod strict schema validation
Least privilegeWorkers have only necessary D1/KV/Email permissions; no write permissions beyond Stripe Refund
Personnel managementCurrently only the founder; keys rotated periodically; all credentials stored in 1Password team vault

10.1 Data Breach Notification

In the event of a "personal data breach" (as defined in GDPR Art. 4(12) / PDPO practical guidance), we commit to:

  • Reporting to the supervisory authority of the affected EU/UK data subjects' location within 72 hours (GDPR Art. 33);
  • If the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay (GDPR Art. 34);
  • The notification will include: the nature of the breach, likely consequences, measures taken or to be taken, and contact person.

11. Children's Data

CyteEditor does not provide services to children under 16. We do not knowingly collect personal data from children under 16.

If we discover that we have collected data from a child under 16, we will delete it within a reasonable time. If you are a parent / guardian and discover that your child has provided data to us, please email legal@cyteeditor.com, and we will delete it within 7 days.

Note: After the CyteEditor SDK is loaded into your own application, the age composition of your end users is assessed and complied with by you as the data controller — see Article 4 of the EULA.


12. Policy Change Notification

Change TypeNotification MethodEffective Date
Material Change (e.g., new Subprocessor / new data category / new non-essential Cookie / data controller entity change)① Top banner notice 30 days in advance; ② Email notification to all active customers; ③ Cookie banner reset30 days after notification
Non-Material Change (e.g., term clarification, typo correction, Subprocessor business address change in Appendix A)"Last updated" label at the top of the homepage /legal/privacy pageImmediately

All historical versions of this Policy are permanently accessible at: https://cyteeditor.com/legal/privacy/history, allowing you to trace the Policy content at any point in time.


13. Complaints and Contact

MatterContact
Data subject rights exerciselegal@cyteeditor.com
Customer servicesupport@cyteeditor.com
Legal / compliancelegal@cyteeditor.com
Postal addressDatability Limited, Flat 2401-16, Wing Shing Industrial Building, 26 Ng Fong St, San Po Kong, Hong Kong
Data protection representative (current)Served by a company director, reachable via legal@cyteeditor.com

Appendix A — Complete Subprocessor List

This appendix is maintained and periodically updated by us; the latest version is always published at https://cyteeditor.com/legal/privacy#appendix-a.

#SubprocessorLegal EntityPlace of RegistrationPurposeData ResidencyDPA / SCC Status
1StripeStripe, Inc.US-DelawarePayment processing + subscription management + invoicingUS (with EU backup)✅ DPA + SCC + DPF certified
2CloudflareCloudflare, Inc.US-DelawareWebsite hosting + CDN + Worker + D1 + KV + R2Global (Workers edge)✅ DPA + SCC
3ResendResend Inc.US-DelawareTransactional email sendingUS✅ DPA + SCC
4SentryFunctional Software, Inc.US-CaliforniaError monitoringUS (after redaction)✅ DPA + SCC
5Plausible or Umami (self-hosted)Plausible Insights OÜ (Estonia) / self-hostedEU / CloudflareWebsite visit statistics (no cookies / no IP)EU / Cloudflare✅ Plausible EU-based, no SCC required

When adding a new Subprocessor, we will notify active customers 30 days in advance per the procedure in Chapter 12; you have a 14-day objection window; if you object, we may choose not to introduce the Subprocessor or terminate the contract (with refund handled per EULA terms).


Cookie NameSourceDomainPathTypeTTLHttpOnlySecureSameSitePurpose
__stripe_midStripe Checkout.stripe.com/1st-party (Stripe domain)1 yearNoneStripe fraud prevention machine fingerprint
__stripe_sidStripe Checkout.stripe.com/1st-party (Stripe domain)30 minNoneStripe session identification
cyte_consentOur company.cyteeditor.com/1st-party13 monthsLaxRecords Cookie banner dismissal status
i18n_redirectedOur company (@nuxtjs/i18n).cyteeditor.com/1st-party1 yearLaxRecords user language selection

Our servers never write __stripe_* cookies to your browser — they are written by Stripe Checkout on its hosted page checkout.stripe.com, forming a compliance loop with our servers at cyteeditor.com through SCC + Stripe DPA.


This appendix contains only the legal authorization text for the banner, not the Vue component implementation. For the technical implementation of the banner, see the Website Implementation Spec.

C.1 Banner Main Text

We use only strictly necessary cookies to make this site work — no analytics, no advertising, no tracking. See our Cookie Notice for the complete list.

Got it

C.2 Close Button aria-label

  • Close cookie notice and accept strictly necessary cookies

C.3 Banner Trigger and Re-display Rules

  • First visit: Display
  • User clicks "Got it": Write cyte_consent=v1 cookie (TTL 13 months)
  • Same browser revisits cyteeditor.com: Do not display
  • After 13 months: Cookie naturally expires, banner re-displays
  • We proactively adjust Cookie policy: Reset cyte_consent to v2, banner re-displays
  • User clears browser cookies: Banner re-displays

C.4 Entry Paths and Accessibility

  • The footer permanently displays "Privacy Policy" / "Cookie Notice" links
  • The bottom-right footer permanently displays "Cookie Settings" (currently clicking only displays the current Cookie list, with no "reject" option; if non-essential Cookies are introduced in the future, a full Settings UI will be enabled)
  • After dismissing the banner, you can review the Cookie list at any time via the footer "Cookie Settings" link