Skip to content

Privacy Policy

Effective 16 August 2026 · Version 2026-08-16.1

This document explains the current operating policy. Nothing in it removes a right or remedy that applicable law does not allow us to exclude.

This Privacy Policy explains how Codezela Technologies (Pvt) Ltd ("Codezela", "we", "us" or "our") handles personal data when you visit Cite Worthy, request access, use an issued account, contact support or otherwise interact with the service. Cite Worthy is operated from Sri Lanka. This policy is designed with the Personal Data Protection Act, No. 9 of 2022, as amended, and other applicable requirements in mind.

1. Scope and responsibility

This policy covers Cite Worthy at cw.codezela.com and the related account, support, billing and operational services we control. A customer may separately act as the controller of personal data placed in its website workspace or article materials. In that situation, we process that customer data to provide the contracted service and follow the customer's lawful instructions, subject to our security and acceptable-use duties.

2. Data we collect

We may collect contact and account details, invitation and authentication records, security settings, website and business profile details, content briefs and drafts, source and crawl records, support correspondence, billing identity and invoice details, manual payment evidence, usage and entitlement records, device and network information, audit events, error records and cookie or preference data. We do not ask for raw card details. Public forms also record limited anti-abuse and network information. We receive information directly from you or an authorised administrator, from the public websites you authorise us to analyse, from service providers used to deliver the platform, and from security or billing checks. Do not submit another person's data unless you have authority and a lawful purpose to do so.

3. Why we use data

We use personal data to review access requests, create and secure administrator-issued accounts, provide and improve the service, preserve work, enforce entitlements, issue and reconcile invoices, verify payments, respond to support, prevent fraud and misuse, monitor reliability, investigate incidents, keep required audit evidence, comply with law and establish or defend legal claims. We use data only for stated or compatible purposes and apply proportionate access controls. We do not sell personal data. We do not use customer drafts or private website material to train a general-purpose model unless a separate, explicit and lawful agreement says otherwise. Platform AI is disabled unless both the environment and the relevant feature flag are enabled. Customer-owned provider connections send only request-scoped material needed for the chosen operation.

4. Providers and international processing

We use carefully selected hosting, database, email, security, storage and optional AI providers. This may involve processing outside Sri Lanka. We limit provider access, use contractual and technical safeguards appropriate to the service, and review provider capabilities before enabling them. Cloudflare Turnstile processes limited browser and network information to protect public forms. Resend processes delivery information for transactional email. Provider policies may also apply to their independent processing.

5. Retention

Temporary objects are normally removed within 24 hours. Operational logs are normally retained for 30 days, safe webhook records for 90 days, and encrypted backups for 30 days. Customer content is retained during active use and normally for up to 30 days after a completed explicit deletion workflow. Subscription expiry does not itself delete content. Billing, audit, consent, transaction, refund, settlement and dispute evidence is retained only for the legally or operationally required period or while a documented hold applies. Some backup copies may remain until the relevant backup cycle expires.

6. Security

We use role and tenant controls, encryption where appropriate, private storage, guarded administrative actions, audit records, secure transport, bounded provider access and incident procedures. No internet service can guarantee absolute security. Keep account credentials confidential, use available multi-factor or passkey protection, and notify us promptly if you suspect unauthorised access.

7. Your choices and rights

Subject to applicable law and valid exceptions, you may ask for information about processing, access to or correction of personal data, erasure, restriction or objection, withdrawal of consent where processing relies on consent, and review of an applicable automated decision. You may also request an account export or deletion through available account tools. We may verify identity and authority before acting, and we may retain information that law or legitimate dispute, security or accounting needs require us to keep. Send privacy requests to [email protected] with enough information to identify the relevant account or interaction. You may also contact the competent Sri Lankan data protection authority where that right is available. We will not discriminate against you for making a good-faith privacy request.

8. Children

Cite Worthy is a business service and is not directed to children. Do not provide children's personal data through the service unless it is lawful, necessary and covered by appropriate authority and safeguards.

9. Changes and contact

We may publish a new dated version when law, providers or service operations change. A material change affecting an active customer will be communicated through an appropriate account or email notice. The published version does not silently rewrite an earlier invoice or entitlement snapshot. Privacy contact: [email protected] Operator: Codezela Technologies (Pvt) Ltd, Sri Lanka

Questions: [email protected] · Codezela Technologies (Pvt) Ltd