How It Works What We Check Who It's For Privacy Terms Get Started
Legal

Privacy Policy

How Collect.Tim collects, uses, stores and protects information when you use the SciVerify document QA screening service and this website.

Last updated: [DATE] GDPR-ready

SciVerify exists to check the numbers inside scientific documents — work that is often unpublished, commercially sensitive or pre-regulatory. We have written this policy in plain language because our customers need to understand exactly what happens to a document after they upload it. If anything here is unclear, write to sales@collectim.tech and we will explain it.

Who we are

This service is operated by [LEGAL ENTITY NAME], a company registered in Israel under company number [COMPANY NUMBER], with its registered office at [REGISTERED ADDRESS] ("Collect.Tim", "we", "us").

For the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR and the Israeli Privacy Protection Law, Collect.Tim acts as:

  • Controller of the personal data of website visitors, prospects and account holders — for example your name, work email address and account activity.
  • Processor of any personal data that happens to be contained inside documents you upload for verification. In that case you are the controller, you decide what is uploaded, and we process it only on your instructions.

Our data protection contact is [DPO / PRIVACY CONTACT NAME], reachable at sales@collectim.tech.

Scope of this policy

This policy covers the collectim.tech website and the SciVerify service. It does not cover third-party websites we link to, or services your own organisation operates. Where you use SciVerify under a separately signed agreement or Data Processing Agreement, that agreement prevails over this policy to the extent of any conflict.

Information we collect

Information you give us

  • Contact and account data — name, work email address, organisation, role, and anything else you include when you contact us or register.
  • Documents you submit — the PDF or DOCX files you upload for verification, and the reports we generate from them. See section 4.
  • Correspondence — emails, support requests and feedback.
  • Billing data — where a paid plan applies, billing contact and invoicing details. Card payments are handled by our payment provider; we do not store full card numbers.

Information we collect automatically

  • Technical data — IP address, browser and device type, operating system, and approximate location derived from IP.
  • Usage data — pages visited, features used, number and size of documents processed, timestamps and error logs.

We do not knowingly collect special category data (such as health data) about you as a user. Documents you upload may contain such data; that is addressed in the next section.

Your documents and what we do not do with them

We do not use customer documents to train models.

Documents and reports you submit to SciVerify are processed to produce your QA report and to operate and support the service. They are not used to train, fine-tune or improve any machine learning model, and they are not shared with other customers or sold to anyone.

We understand that a manuscript, study report or regulatory document may be unpublished and commercially sensitive. Accordingly:

  • Access to customer documents is restricted to authorised personnel who need it to operate or support the service, and is logged.
  • Documents are encrypted in transit and at rest.
  • You can delete a document and its report from your account at any time.
  • Where we analyse usage to improve the service, we use aggregated or de-identified metrics — for example the number of findings per document class — not document content.

Personal data inside documents. You should upload de-identified documents wherever possible. If a document contains personal data — for example patient-level data, author details or investigator names — you are responsible for having a lawful basis to share it with us, and you should have a Data Processing Agreement in place with us before doing so. We will provide one on request.

How and why we use data

What we doData usedLegal basis (GDPR Art. 6)
Provide the verification service and deliver reports Account data, submitted documents, usage data Performance of a contract
Authenticate users and secure the service Account data, technical data, logs Legitimate interests (security and prevention of misuse)
Provide support and respond to enquiries Contact data, correspondence Performance of a contract; legitimate interests
Improve reliability and accuracy of the service Aggregated or de-identified usage metrics Legitimate interests (improving our product)
Send service notices (outages, changes to terms) Contact data Performance of a contract; legal obligation
Send marketing about SciVerify to business contacts Contact data Consent, or legitimate interests where permitted — you can opt out at any time
Billing, accounting and tax records Billing data Legal obligation
Establish, exercise or defend legal claims Relevant records Legitimate interests; legal obligation

We do not carry out automated decision-making that produces legal or similarly significant effects about you. SciVerify's findings are advisory outputs about a document, intended for review by a qualified person.

How long we keep data

  • Documents and reports — retained while your account is active, so that you can access your QA report history. They are deleted when you delete them, and in any event within [30/60/90] days after your account is closed, unless we are legally required to keep them longer.
  • Account and contact data — retained for the life of the account and for [PERIOD] afterwards, for legitimate business and legal purposes.
  • Billing and accounting records — retained for the period required by applicable Israeli tax and accounting law (currently seven years).
  • Security and system logs — retained for [PERIOD].

Where you have a signed agreement with us specifying different retention or deletion terms, those terms apply.

Who we share data with

We do not sell personal data. We share it only in these circumstances:

  • Sub-processors and service providers — cloud hosting, error monitoring, email delivery, payment processing and customer support tooling. Each is bound by a written contract to process data only on our instructions and to appropriate security standards. A current list of sub-processors is available at sales@collectim.tech.
  • Professional advisers — auditors, lawyers and accountants, under duties of confidentiality.
  • Corporate transactions — a purchaser or successor in the event of a merger, acquisition or reorganisation, subject to equivalent protection.
  • Legal requirements — where required by law, court order or a competent authority. Where we are legally permitted to do so, we will notify the affected customer first.

International transfers

Collect.Tim is established in Israel and our infrastructure may be located in [HOSTING REGION(S)]. Where personal data originating in the European Economic Area or the United Kingdom is transferred outside that territory, we rely on an appropriate transfer mechanism — the European Commission's adequacy decision in respect of Israel, Standard Contractual Clauses, or the UK International Data Transfer Addendum, as applicable — together with any supplementary measures required.

Customers with data residency requirements should contact us before uploading documents; we can discuss the options available.

Security

We apply technical and organisational measures appropriate to the sensitivity of scientific and pre-publication material, including:

  • Encryption of data in transit (TLS) and at rest.
  • Role-based access control and least-privilege access to production systems.
  • Logging and monitoring of access to customer documents.
  • Segregation of customer data and environment separation.
  • Vetting of personnel and binding confidentiality obligations.
  • Periodic review of our security posture and of our sub-processors.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the relevant supervisory authority and affected customers without undue delay, and in line with applicable law.

Your rights

Subject to the conditions in applicable law, you have the right to: access the personal data we hold about you; have inaccurate data corrected; have data erased; restrict or object to certain processing; receive your data in a portable format; withdraw consent where processing is based on consent; and opt out of marketing at any time.

To exercise any of these rights, email sales@collectim.tech. We will respond within one month, and may ask you to verify your identity first.

If the request concerns personal data contained in a document uploaded by a customer, we will refer you to that customer, who is the controller of that data, and support them in responding.

You also have the right to lodge a complaint with your local supervisory authority, or with the Israeli Privacy Protection Authority. We would appreciate the chance to address your concern first.

Cookies and analytics

Our website uses strictly necessary cookies to function, and [DESCRIBE ANALYTICS, e.g. privacy-focused analytics] to understand how the site is used. Non-essential cookies are set only where you consent, and you can withdraw consent at any time through your browser settings or our cookie controls.

Children

SciVerify is a business tool intended for professional and institutional users. It is not directed at children, and we do not knowingly collect personal data from anyone under 16.

Changes to this policy

We may update this policy as the service develops or the law changes. We will post the revised version here and update the "last updated" date. Where the change is material, we will notify account holders by email before it takes effect.

Contact us

Questions, requests or complaints about privacy: sales@collectim.tech, or write to [LEGAL ENTITY NAME], [REGISTERED ADDRESS], Israel.

Need a Data Processing Agreement or our sub-processor list?
We provide both on request, before you upload anything.

Request a DPA