Draft for legal review — not final
This working draft has not been approved by legal counsel, is not an effective agreement or notice, and must not be represented as final. Highlighted bracketed items require an owner decision or legal confirmation.
Core Currency Index
Draft Privacy Notice
Draft version: July 28, 2026 · Proposed effective date: [TO BE APPROVED]
1. Scope and controller
This proposed Privacy Notice would explain how the Core Currency Index Service collects, uses, discloses, and protects personal information. The proposed data controller or business is [LEGAL ENTITY NAME AND FORM], at [BUSINESS ADDRESS].
This draft covers participants, individual account holders, organization members and administrators, and platform administrators. Counsel should confirm whether separate notices or data-processing agreements are required for sponsoring organizations.
2. Information the Service collects
Account and identity information
Email address, account identifier, authentication records, display name when provided, account role, organization membership, and administrator authorization.
Assessment and result information
Assessment answers; item, section, and currency scores; profile and blend results; scoring and content version identifiers; preserved report snapshots; completion status; timestamps; timing and navigation events; and participant feedback.
Entitlement and organization information
Seat allocations, sponsor organization, cohort or program labels, entitlement status and expiration, gifting details, code status and masked code hints, and entitlement audit events. Plaintext access codes are shown only when issued and are not stored after issuance.
Technical and security information
Browser and device information, IP address, request and diagnostic logs, security events, and abuse-prevention results. Cloudflare Turnstile may process technical signals to distinguish legitimate people from automated abuse.
Future transaction information
Payment processing is not currently integrated. Before commerce launches, this notice must identify the payment processor and describe transaction records, billing details, taxes, refunds, and fraud-prevention data. CCI should not directly store full payment-card numbers.
3. Sources of information
Information comes from the participant or account holder; a sponsoring organization or administrator; the user’s interaction with the Service; authentication, hosting, email, and security providers; and, after commerce launches, a payment processor.
4. Why the Service uses information
- authenticate accounts and deliver secure sign-in links;
- issue, redeem, and administer assessment access;
- administer and score assessments under the applicable version;
- generate, preserve, and display owned historical results;
- operate organization seats and authorized dashboards;
- provide support and respond to feedback;
- protect the Service, users, content, and intellectual property;
- monitor reliability and improve the participant experience; and
- comply with law and enforce applicable agreements.
Applicable legal bases, where required, are [COUNSEL TO MAP CONTRACT, CONSENT, LEGITIMATE INTERESTS, AND LEGAL-OBLIGATION BASES BY JURISDICTION].
5. How information is disclosed
Service providers
The current Service uses Supabase for authentication and database services, Vercel for application hosting, Resend for transactional email, and Cloudflare Turnstile for abuse prevention. These providers process information to perform services for CCI under their own agreements and privacy terms.
Sponsoring organizations
Current organization dashboards show organization membership and aggregate seat lifecycle counts, such as unissued, claimed, in progress, and completed totals. They do not identify which participant redeemed or completed a seat and do not display participant answers, currency profiles, blends, or complete reports. Any future participant-level operational disclosure or result sharing must be separately documented and, where applicable, use an explicit participant consent process.
Other disclosures
Information may be disclosed when reasonably necessary to comply with law, protect rights or safety, investigate fraud or abuse, or complete a merger, financing, acquisition, or transfer of assets with appropriate notice and safeguards.
Position for legal confirmation
CCI does not currently sell personal information or use it for cross-context behavioral advertising. Counsel should confirm the legally required definitions, opt-out language, and signals before this statement becomes final.
6. Retention
Historical assessment results and their versioned report snapshots are designed to remain available to the owning account. Other information should be retained only as long as needed for the purposes described above, support, security, legal compliance, and dispute resolution.
Required schedule: [COUNSEL AND OWNER TO APPROVE RETENTION PERIODS FOR ACCOUNTS, ANSWERS, RESULTS, SECURITY LOGS, EMAIL EVENTS, FEEDBACK, ENTITLEMENTS, ORGANIZATION RECORDS, AND FUTURE TRANSACTIONS].
7. Security
CCI uses administrative, technical, and organizational safeguards intended to protect information, including passwordless authentication, role and organization access controls, hashed access codes, server-side verification for protected operations, and versioned historical snapshots. No system is completely secure, and the final notice should avoid guaranteeing absolute security.
8. Individual choices and rights
Depending on location, a person may have rights to access, correct, delete, restrict, or obtain a copy of personal information; object to certain processing; withdraw consent; or appeal a privacy decision. Authentication may be required before a request is fulfilled, and lawful exceptions may apply.
Request method and response process: [PRIVACY REQUEST EMAIL/FORM, IDENTITY VERIFICATION, AUTHORIZED-AGENT PROCESS, AND APPEAL CONTACT].
9. Organization-sponsored participants
The final notice and organization agreement should identify when CCI acts as an independent controller, a service provider or processor, or a joint controller. An organization is responsible for providing any notice and obtaining any authority it needs to sponsor participation or supply member information. CCI should separately explain any optional sharing of participant results before consent is requested.
10. Children and minors
The Service is not intended for children under [MINIMUM PARTICIPANT AGE]. Before allowing minors, the owner and counsel must approve age screening, parental authorization, school or organization requirements, and deletion procedures.
11. International and state-specific disclosures
[COUNSEL TO IDENTIFY TARGET JURISDICTIONS, CROSS-BORDER TRANSFER MECHANISMS, U.S. STATE PRIVACY ADDENDA, AND REQUIRED SENSITIVE-DATA OR PROFILING DISCLOSURES].
12. Changes to the final notice
The effective notice should identify its revision date. Material changes should be communicated through the Service, email, or another legally appropriate channel before they take effect when required. Prior versions should be retained for auditability.
13. Contact
Privacy questions and requests: [PRIVACY CONTACT NAME, EMAIL, AND MAILING ADDRESS]. Data protection officer or representative, if required: [NAME AND CONTACT OR NOT APPLICABLE].
Legal-review checklist
- Confirm the controller/business identity and contact.
- Approve the data inventory and processor list.
- Choose the retention and deletion schedule.
- Define organization roles and result-sharing consent.
- Complete jurisdiction, legal-basis, and rights analysis.
- Approve minor-use rules and future commerce disclosures.
- Complete vendor and data-processing agreement review.