Privacy Policy
Effective Date: September 10, 2026 • Version 2.4 (Enterprise Assurance)
At Cursis (operated by Cursis Inc., "we", "our", or "us"), we are committed to safeguarding the privacy, integrity, and confidentiality of your personal and enterprise information. This Privacy Policy delineates how we collect, process, store, and protect information when you access www.cursis.in and our integrated business workspace applications.
1. Information We Collect
We adhere strictly to the principle of data minimization. We only collect information strictly requisite to providing high-reliability enterprise workspace capabilities:
- Account Identification: Business email address, name, organization identifier, and secure authentication tokens when you register or sign in via email or federated Google OAuth.
- Workspace Operational Data: Team rosters, project tasks, roadmaps, modules, and workflow state created by your authorized team members within your private workspace.
- Security & Telemetry Logs: Timestamped access logs, client IP address (anonymized for telemetry), user-agent strings, and request URLs utilized exclusively for security intrusion detection, DDOS defense, and audit assurance.
2. Cookies & Local State Management
Cursis operates with zero third-party tracking or advertising cookies. We do not sell your personal information or monetize browsing behaviors. Our cookie utilization is limited to strictly necessary security cookies:
| Cookie Name | Purpose | Type | Duration |
|---|---|---|---|
| cursis_session | Cryptographically signed session verification for authorized workspace access | Strictly Necessary (HttpOnly, SameSite=Lax, Secure) | Session / 7 Days |
3. GDPR Data Protection Rights (EU Residents)
Under the General Data Protection Regulation (GDPR), individuals within the European Economic Area (EEA) possess specific statutory rights regarding their personal data:
- Right of Access (Article 15): You have the right to obtain confirmation and copies of your personal data held by Cursis.
- Right to Rectification (Article 16): You have the right to request immediate correction of inaccurate or incomplete personal information.
- Right to Erasure ("Right to be Forgotten", Article 17): You may request the permanent deletion of your personal account and associated data.
- Right to Restrict Processing (Article 18): You may request temporary suspension of data processing under statutory dispute conditions.
- Right to Data Portability (Article 20): You have the right to export your workspace records in structured, machine-readable JSON/CSV formats.
- Right to Object (Article 21): You may object at any time to the processing of your data based on legitimate interests.
To exercise any GDPR statutory right, please contact our Data Protection Officer at privacy@cursis.app. Requests are responded to within thirty (30) days without charge.
4. Technical & Organizational Security Measures
Cursis implements multi-layered defensive security architecture aligned with SOC-2, ISO 27001, and PCI DSS best practices:
- Encryption in Transit: Strict HTTPS with TLS 1.3, automated HSTS (Strict-Transport-Security) enforced for 63,072,000 seconds with subdomain preloading.
- Headers Defense: Deterministic Content-Security-Policy (CSP), X-Frame-Options DENY, and X-Content-Type-Options nosniff headers preventing clickjacking, MIME sniffing, and cross-site scripting (XSS).
- Encryption at Rest: Database volumes and credential keys encrypted using AES-256 standards with KMS isolation.
- Access Control: Zero-trust role-based access control (RBAC) preventing horizontal privilege escalation across workspaces.
5. Automated Bot & Scraping Policy
Cursis strictly prohibits unauthorized automated harvesting, web scraping, or training of machine learning and large language models (LLMs) on private user or workspace content. We publish explicit machine-readable rules in our robots.txt file blocking unauthorized crawler agents including GPTBot, ChatGPT-User, CCBot, anthropic-ai, and related scrapers.
6. Contact Information & Data Protection Officer
If you have any questions, grievances, or inquiries regarding our data handling practices or this Privacy Policy, our dedicated security office can be contacted directly:
Cursis Security & Privacy Office
Email: privacy@cursis.app / security@cursis.app
Website: https://www.cursis.in