Privacy policy
This policy explains what data iOriginally processes on behalf of an institution, why, and the controls an institution has over it. It is a plain-language summary and forms part of our data-processing terms.
Last updated: July 2026
Who controls the data
The institution is the data controller for the documents and user records it submits to iOriginally. iOriginally acts as a data processor, handling that data only to provide the service and only under the institution's instructions.
What we collect
- Account data — names, institutional email addresses, roles, and department membership for the users an institution invites.
- Submitted content — the documents uploaded for checking and the extraction, similarity, AI-writing, and integrity results derived from them.
- Operational data — audit logs of authentication, admin actions, and report or certificate downloads, plus service logs kept for reliability and security.
How we use it
We use submitted content solely to produce the requested integrity report and certificate for the institution that uploaded it.
Retention and deletion
Each institution sets its own retention window. A scheduled job purges documents and derived artifacts past that window, unless a legal-hold flag is set.
An institution can request a full export of its data as an archive, or a full deletion, at any time.
Security
Files are stored with signed, expiring access URLs and scanned for malware on upload. Access is isolated per tenant at the database level and enforced again in the service layer.
Passwords are hashed with argon2, admin roles can require two-factor authentication, and all sensitive actions are audit-logged. Read more on our security page.
DPDP (India) readiness
We present consent text at sign-up, maintain a data-processing terms page, and provide a breach-contact channel. Contact privacy@ioriginally.com for any data-protection request.
Related policies: Terms of service · Refund & service policy · Contact us with any question about this policy.