1Controller & Contact
1.1 Controller.Agbisit Acquisitions Ltd (Company No. 16795399), England & Wales, is the data controller for personal data processed through the Library.
1.2 Contact.For privacy, legal, or data-rights requests, contact legal@catna.cc. For general support, contact support@catna.cc.
2Scope
This Notice applies to personal data we process when you sign up for, access, or use the Library, including its admin pages and any data it exposes. It applies worldwide; where your local law gives you additional rights, we honour those rights to the extent required.
3Data We Collect
3.1 Account data.When you register or are added as a member, we record:
- your email address;
- a scrambled, one-way version of your password (we never see or store the password itself);
- your role (member or admin) and your account status (pending, approved, or rejected);
- the dates your account was created and last updated.
3.2 Usage history.The Library keeps a usage log so we can run the service, understand how it is used, and spot misuse. Each entry can include:
- the kind of action (viewing a page, opening an SOP, opening a category, opening the CATNA GPT, or clicking a main button);
- which item was opened and the item’s name at that moment;
- the page address you were on (without any search parameters);
- whether you were on a phone or a computer;
- your country (when the hosting provider tells us it on the request);
- a short string identifying the browser you used;
- your account identifier, for signed-in visits only (going forward);
- the time the action happened.
3.3 Your activity.We also keep track of the SOPs you mark as favourites and the tags on SOPs you interact with, so that your “Favorites” and “Recently viewed” sections work.
3.4 Sign-in safety checks.To block repeated failed sign-in attempts we briefly hold your network address in memory during the sign-in attempt. This information is not saved to a database and is cleared automatically after a short window.
3.5 What we do not collect.The Library does not store card or payment details, does not use third-party advertising cookies, and does not build behavioural profiles or track you across other websites.
4Purposes
We use personal data to:
- create, verify, and administer your account;
- deliver the Library and its features (search, favourites, recents, tags);
- enforce access controls and the approval workflow;
- secure the service, including login rate-limiting and abuse detection;
- understand aggregate usage and improve the Library (for example, which SOPs are most used, which need review);
- investigate suspected leaks, breaches, or misuse;
- comply with legal obligations and respond to lawful requests.
5Legal Bases (UK GDPR)
We process personal data on one or more of:
- Contract necessity - to deliver the Library to you as part of your CATNA 2.0 enrolment;
- Legitimate interests - to secure the Library, detect fraud and leakage, analyse aggregate usage, and improve the service. We balance these interests against your rights and freedoms;
- Legal obligation - where processing is required to comply with applicable law;
- Consent - where we ask for it (for example, for identifiable testimonial use).
7Processors & Sharing
7.1 Key service providers.We use the following providers to run the Library:
- Vercel Inc. - hosts the website;
- Neon, Inc. - hosts the database that stores your account and usage records.
Sign-in is handled by software we run ourselves inside the Library.
7.2 Authorised personnel.Authorised staff and contractors of the Company may access data strictly to operate, support, and secure the Library.
7.3 Legal disclosures.We may disclose data where required by law, to respond to valid legal process, or to protect our rights, safety, or property.
7.4 No sale of data.We do not sell personal data.
8International Transfers
Some processors may host infrastructure outside the United Kingdom and the European Economic Area. Where transfers occur, we rely on appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or equivalent mechanisms under applicable law.
9Retention
9.1 Account data.We keep account data for as long as your Library access remains active. After your Program enrolment ends or your account is removed, we keep the records for up to twenty-four (24) months for dispute prevention, audit, and compliance. After that they are deleted or anonymised unless the law requires a longer period.
9.2 Usage history.Usage records are kept for up to twenty-four (24) months, after which they may be combined into aggregate totals or deleted.
9.3 Sign-in safety checks.Sign-in safety data is held only in the server’s memory and is cleared automatically at the end of each short check window (typically fifteen (15) minutes).
10Your Rights
Subject to applicable law (including the UK GDPR and the Data Protection Act 2018), you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request erasure of certain data (for example where it is no longer necessary for the purpose collected);
- restrict or object to certain processing;
- request portability of data you provided to us;
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
To exercise a right, email legal@catna.cc. We may need to verify your identity before responding. Certain data (for example confidential programme records required for dispute prevention or legal obligations) may be retained notwithstanding an erasure request.
11Security
We use reasonable administrative and technical safeguards appropriate to the nature of the data, including storing passwords only in scrambled form, transporting data over a secure HTTPS connection, limiting who inside our team can access which data, blocking repeated failed sign-in attempts, and requiring manual approval for every new account. No system is perfectly secure; you accept that risk by using the Library.
12Children
The Library is not intended for individuals under 18. We do not knowingly process the personal data of children.
13Changes
We may update this Notice from time to time. The “Last updated” date above reflects the most recent change. Continued use of the Library after an update constitutes acceptance of the revised Notice.
14Complaints
If you believe our processing infringes your data protection rights, please contact legal@catna.cc first so we can address your concern. You also have the right to lodge a complaint with a supervisory authority. In the United Kingdom this is the Information Commissioner’s Office (ICO) ico.org.uk. In the EU/EEA you may complain to your local data protection authority.