Welcome to CSOKIT. We value your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, store, and protect information when you visit our website, create an account, subscribe to a plan, contact us, or use the CSOKIT platform and related services (collectively, the “Service”).
“CSOKIT,” “we,” “us,” and “our” refer to Grand Vision Tech Software Limited, the company that operates the Service. Where CSOKIT processes information solely on behalf of a business customer, that customer may act as the data controller and CSOKIT may act as its processor or service provider.
1. Data Collection
We may collect the following personal data and related information from users of the Service:
- Name and account information: your name, username, organization, role, account preferences, and authentication information, used to create, personalize, verify, and secure your account.
- Email address and communications: your personal or work email address, support requests, feedback, survey responses, and other communications, used to provide service messages, customer support, and marketing communications where permitted.
- IP address and technical information: IP address, browser type, operating system, device identifiers, language, approximate location derived from IP, login records, error logs, and security events, used to operate, analyze, and protect the Service.
- Payment and billing information: subscription plan, transaction status, billing address, tax information, invoices, and limited payment metadata. Full payment card details are generally collected and processed directly by our payment processor rather than stored by CSOKIT.
- Customer Content: prompts, keywords, topics, briefs, documents, brand guidelines, URLs, uploaded files, images, generated text, edits, citations, and other materials you submit to or create through the Service.
- SEO and GEO information: domains, webpages, competitors, tracked keywords, monitored prompts, search results, AI-generated answers, citations, links, brand mentions, rankings, visibility measurements, optimization suggestions, and historical performance data.
- Integration information: connected-service identifiers, authorization tokens, website or CMS details, publishing destinations, workspace settings, and content exchanged with services that you choose to connect.
- Business inquiry information: company name, work email address, job title, team size, budget or purchasing information, intended use case, and other information submitted in a sales, partnership, or enterprise inquiry.
- Usage information: pages visited, features used, buttons clicked, searches performed, session dates and times, referring pages, generated outputs, publishing actions, and general interaction with the Service.
- Information from other sources: information from your employer or workspace administrator, connected services, referral partners, fraud-prevention providers, and publicly available websites, search results, citations, or business sources where permitted by law.
We collect this information through direct input from you when you register, use the Service, upload or generate content, connect an integration, make a purchase, or contact us. We also collect information through automated technologies such as cookies, local storage, pixels, analytics tools, SDKs, and server logs, and from third parties or publicly available sources where relevant to the Service.
2. Purpose of Data Collection
We use the information collected for the following purposes:
- Account Creation and Management: to create and manage your account and workspace, authenticate users, administer subscriptions, process billing, provide customer support, and ensure secure access to the Service.
- Service Delivery: to process prompts and Customer Content, generate and edit content, perform keyword and competitor research, measure SEO and GEO visibility, monitor selected prompts and domains, identify citations and brand mentions, and support publishing workflows.
- AI Processing: to transmit the minimum information reasonably needed to contracted AI model, search, data, and infrastructure providers so that requested AI, research, analysis, or generation features can operate.
- Service Improvement: to understand how users interact with the Service, identify issues, troubleshoot errors, improve usability and performance, develop new features, evaluate output quality, and create aggregated or de-identified analytics.
- Security and Abuse Prevention: to prevent fraud and misuse, investigate suspicious activity, protect accounts and infrastructure, enforce our Terms, maintain logs, and comply with legal or regulatory requirements.
- Marketing and Communication: to send service announcements, security alerts, billing notices, product updates, educational materials, promotions, and special offers where permitted. You may opt out of marketing emails at any time by using the unsubscribe link in an email or contacting us directly.
- Business Operations: to respond to sales and partnership inquiries, manage contracts, maintain records, conduct audits, obtain professional advice, and support corporate transactions.
Where applicable law requires a legal basis, we process personal data as necessary to perform our contract with you, comply with legal obligations, pursue legitimate interests in operating and protecting the Service, or obtain your consent. You may withdraw consent at any time where consent is the applicable basis, without affecting prior lawful processing.
CSOKIT will use Customer Content for model training or generalized product improvement only if this is permitted by the applicable plan, workspace setting, product notice, or written agreement. We will honor applicable opt-outs and contractual restrictions.
3. Data Sharing
We may share or disclose personal data with the following categories of recipients:
- Data Processors and Service Providers: providers that process data on our behalf, including cloud hosting, database, storage, AI model, search, analytics, authentication, security, customer support, communications, accounting, administrative, and email services. These providers are required by contract to protect information and use it only for authorized purposes.
- Payment Processors: third-party payment providers that process subscriptions and transactions. Their handling of payment information is also governed by their own privacy policies and contractual obligations.
- AI, Search, and Data Providers: providers that receive prompts, content, URLs, technical metadata, or queries necessary to provide AI generation, research, SEO analysis, GEO monitoring, citation analysis, or related features.
- Connected Services: third-party services, such as a CMS, website platform, analytics service, or publishing destination, when you authorize an integration or direct us to import, export, synchronize, or publish information.
- Your Organization: your employer, customer organization, workspace owner, or administrators, who may manage your account and access workspace content, settings, integrations, usage, and activity.
- Professional Advisors: lawyers, accountants, auditors, insurers, consultants, and financial advisers where necessary to comply with legal obligations or manage our business.
- Public Authorities: courts, regulators, law enforcement agencies, tax authorities, and other public bodies where disclosure is required by law or reasonably necessary to protect rights, safety, security, or the integrity of the Service.
- Corporate Transaction Participants: actual or prospective buyers, investors, lenders, advisers, or other participants in a merger, financing, acquisition, restructuring, bankruptcy, or sale of all or part of our business.
- Other Parties at Your Direction: any other recipient when you request the disclosure, make content public through the Service, or provide consent.
We require third parties acting on our behalf to maintain appropriate confidentiality and security and to comply with applicable data protection laws. CSOKIT does not publish Customer Content unless you direct the Service to publish or share it.
If CSOKIT uses advertising partners or technologies that qualify as a “sale,” “sharing,” or targeted advertising under applicable law, we will identify the relevant practices and provide legally required privacy choices.
4. User Rights
Depending on your location and subject to applicable law, you may have the following rights regarding your personal data:
- Access: request access to the personal data we hold about you, including information about processing purposes, categories of data, and recipients.
- Correction: request correction of inaccurate or incomplete personal data so that it is accurate and up to date.
- Deletion: request deletion of personal data where it is no longer needed, consent has been withdrawn, processing has been successfully objected to, or deletion is otherwise required by law.
- Portability: request a copy of certain personal data in a structured and commonly used format where required by law.
- Restriction or Objection: request restriction of processing or object to certain processing, including direct marketing and, where applicable, processing based on legitimate interests.
- Consent Withdrawal: withdraw consent at any time for processing based on consent.
- Privacy Choices: opt out of certain marketing, sale, sharing, or targeted advertising where those rights apply.
- Appeal and Complaint: appeal a denied privacy request where local law provides that right, or complain to a competent data protection authority.
To exercise these rights, contact us at support@csokit.com. We may need to verify your identity, account, location, or authority before completing a request. We will respond in accordance with applicable data protection law and will not discriminate against you for exercising a privacy right.
If CSOKIT processes your personal data on behalf of a business customer, please submit your request to that customer first. We will assist the customer as required by our agreement and applicable law.
6. Data Security
We take information security seriously and use administrative, technical, and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, loss, misuse, or destruction. Depending on the system and risk, these measures may include encryption in transit and at rest, access controls, authentication safeguards, logging and monitoring, secure development practices, vendor review, backups, incident-response procedures, and multi-factor authentication for sensitive administrative access.
We permit employees, contractors, and service providers to access or process personal data only where reasonably necessary for their duties, in accordance with our instructions, and subject to confidentiality and security obligations.
If we experience a personal data breach, we will investigate, contain, document, and remediate the incident. Where applicable law requires notification to a regulator, affected customer, or individual, we will provide that notification within the legally required period. No online service or method of storage is completely secure, and we cannot guarantee absolute security.
You are responsible for using strong and unique passwords, protecting account credentials, reviewing workspace permissions, configuring integrations carefully, and notifying us promptly if you suspect unauthorized access to your account.
7. Legal Compliance
7.1 Governing Law
The formation, execution, validity, interpretation and performance, and the settlement of disputes concerning this Privacy Policy, shall be governed by and construed in accordance with the laws of Hong Kong, without giving effect to any conflict of law principles.
7.2 Dispute Resolution
7.2.1 Except as otherwise agreed between you and CSOKIT, any claim or controversy arising out of or relating to this Privacy Policy, or its breach, termination, enforcement, interpretation, or validity (collectively, “Disputes”), shall be settled by lawsuits.
7.2.2 You agree that Disputes between you and CSOKIT will be resolved by a binding, individual lawsuit, and you waive your right to participate in a class-action lawsuit.
7.2.3 Unless otherwise agreed by you and CSOKIT, any lawsuits shall be submitted to the exclusive jurisdiction of the courts of the Hong Kong Special Administrative Region of the People’s Republic of China. CSOKIT shall not be liable for any legal fees and/or other costs incurred before receiving complete notification of the claim.
8. Contact Information
If you have questions or concerns about this Privacy Policy, or wish to exercise a privacy right, please contact us at:
- Company: Grand Vision Tech Software Limited
- Email: support@csokit.com
Please include your account email, the nature of your request, and enough information for us to understand and respond. Do not send passwords, payment card numbers, government identifiers, health information, or other highly sensitive information by email.