Privacy Policy

Draft — not yet reviewed by a lawyer

This document is a structured draft. It has not been reviewed or approved by a qualified legal professional, and it must not be relied on as the governing privacy policy for a released product. Every highlighted item below is a placeholder that needs a real answer before this page goes live to real users.

The one section that is not hypothetical is the support form section: that describes data this website collects today, and it is written to match what the code actually does.

1. Who we are

CIAN is operated by legal entity name (“we”, “us”), registered in jurisdiction at registered address. For anything in this policy you can reach us through the support form or at privacy contact email.

Decide whether a Data Protection Officer or an EU/UK representative is required, and name them here if so.

2. The support form on this website

This is the only personal data this website itself collects. It is described in full because it is real, not illustrative.

What we collect

We do not attach your IP address, your browser's user-agent string or your location to the message we forward. Our servers process your IP address transiently in order to apply rate limiting and to run the anti-bot check described below, but it is not stored with your message and is not passed on to our support system.

Why we collect it

To read your message, answer it, and keep a record of the conversation so a follow-up makes sense. The lawful basis is our legitimate interest in providing support to people who ask for it, and, where you are asking about a contract with us, performance of that contract.

Where it goes

Your submission is sent from our servers to name the support destination — e.g. a Slack workspace, a shared mailbox, or a ticketing system — and the provider that operates it , which acts as a processor on our behalf. It is not sent anywhere else, it is not sold, and it is not used for marketing.

Anti-bot and rate limiting

The form is protected by Cloudflare Turnstile. Turnstile runs in your browser and issues a token that our server checks with Cloudflare before accepting your message. To do this, Cloudflare processes technical signals from your browser and your IP address. Cloudflare acts as our processor for this, and states that Turnstile does not use this data to track individuals across sites or to build advertising profiles. We also apply a per-IP rate limit to the form endpoint to stop it being used to send bulk messages.

How long we keep it

Set a real retention period for support correspondence — e.g. 24 months from the last message on a ticket — and confirm it matches what the support destination is actually configured to do.

Hosting

This website runs on Cloudflare's network. Cloudflare processes requests to cian.build, including your IP address, in order to serve the site and protect it from abuse.

3. Data the CIAN product processes

CIAN is not released. This section describes the intended design and must be re-verified against the shipped product before it is relied on.

List every third-party subprocessor the product relies on, including any model provider used to run agents, and state what is sent to each.

4. Cookies and analytics

This website sets no cookies of its own and runs no analytics or advertising scripts. Cloudflare Turnstile may set storage in your browser strictly to perform the anti-bot check on the support page. Re-confirm this section if analytics is ever added; it is currently true and easy to make false.

5. Your rights

Depending on where you live, you may have the right to access a copy of your personal data, correct it, delete it, restrict or object to how we use it, receive it in a portable form, and withdraw consent where we relied on it. You may also complain to your data protection authority.

To exercise any of these, contact us through the support form or write to privacy contact email. We will respond within statutory response period — confirm per jurisdiction.

Add the specific disclosures required by the jurisdictions being sold into — for example UK/EU GDPR transfer mechanisms and international transfer detail, and any US state-level notices such as a "do not sell or share" statement.

6. Children

CIAN is not directed at children. Set the minimum age, make it consistent with the Terms of Service and with the App Store age rating, and state what happens if we learn we hold a child's data.

7. Security

We take reasonable technical and organisational measures to protect personal data, including transport encryption, keeping credentials in dedicated secret storage rather than in code, and limiting who can reach production systems. No system is perfectly secure and we do not claim otherwise.

State the breach notification commitment and timeframe.

8. Changes to this policy

If we change this policy we will update the date at the top and, for significant changes, tell users directly. Confirm the notification mechanism.

9. Contact

Use the support form or write to privacy contact email.