Privacy Policy
Effective 5 August 2026· Governed by UAE Federal Decree-Law No. 45 of 2021 (the “PDPL”) and its Executive Regulations.
CTO Reports turns uploaded bank statements into closing-turnover workbooks. Bank statements are among the most sensitive documents a person has, so this policy is written to be specific about one thing above all: what happens to the documents you upload. The short version — the original statements are never stored; the workbook we generate from them is, so you can re-download it from your History.
The documents you upload
When you upload bank statements, they travel to our servers over an encrypted connection (TLS). Because payment happens on Ziina’s own checkout page — which means briefly leaving this site and coming back — your statements are held in private, encrypted storage for that short window so your report can be generated the moment payment is confirmed. They are never accessible to other users, and are deleted immediately once your report is generated — or immediately if payment fails or is canceled, in which case nothing is generated from them at all.
To extract each day’s closing balance, statements are read by a specialised AI document-analysis service acting as our processor under contract. Under that provider’s commercial terms, your documents are not used to train AI models; it retains inputs and outputs only briefly for abuse-prevention purposes before deletion, in accordance with its data retention policy.
The generated Excel workbook — the output, not the source statements — is saved to private storage so it appears in your History and can be re-downloaded later. It is readable only by your account: no other user, and no one at CTO Reports, can browse it directly. You can delete a saved report, or all of them, by emailing us (see “Your rights” below).
Your responsibility as the uploader:statements usually contain personal data of your applicant or client, not just your own. By uploading, you confirm you are lawfully entitled to process that person’s data for this purpose — typically because they have authorised you to prepare their bank statement analysis.
What else we collect
Account data — your email address, name, and sign-in identity. If you sign in with Google, we receive your name and email from Google; if you use a password, it is stored only in hashed form by our authentication provider. We never see or store the password itself.
Payment records— when paid plans are active, payments are processed by Ziina, a licensed UAE payment provider, on Ziina’s own checkout pages. We record the amount, currency, status, and a payment reference. Card details never touch our servers.
Technical data — standard server logs (timestamps, IP address, request status) kept for security and troubleshooting, and the session token that keeps you signed in. We use no advertising trackers and no third-party analytics cookies.
Why we process your data
We process personal data to perform our contract with you (generating the reports you request, operating your account, taking payment), to comply with legal obligations (accounting and tax records), and — where the PDPL requires it — on the basis of your consent, which you may withdraw at any time.
We do not sell personal data, use it for advertising, or share it with anyone beyond the processors named in this policy.
Who we share data with
Only with three service providers, each under contract and only for its own purpose: our authentication and database provider (account sign-in and our records), the AI document-analysis service that reads statements to extract balances, and Ziina, the licensed UAE payment provider whose checkout pages you see when paying. Some of these providers process data outside the UAE. Where personal data leaves the UAE, we rely on the transfer safeguards permitted by the PDPL and its Executive Regulations, including contractual protections with each provider.
How long we keep data
Uploaded statements: held only for the short window between upload and payment confirmation, then deleted immediately— whether your report is generated or payment doesn’t go through. Generated workbooks: kept until you delete them, delete your account, or request removal, so History stays useful. Account data: kept until you ask us to delete your account. Payment records: kept as long as UAE commercial and tax law requires. Server logs: kept for a short rolling window for security purposes.
Your rights
Under the PDPL you have the right to access the personal data we hold about you, to receive it in a portable format, to have it corrected or erased, to restrict or object to processing (including any automated processing), and to withdraw consent. To exercise any of these, email us at fakhrigulmammad@gmail.com — we respond within the timelines the Executive Regulations set. You also have the right to lodge a complaint with the UAE Data Office, the federal supervisory authority.
Security
All traffic is encrypted in transit. Database access is protected by row-level security so each account can only ever read its own records, and administrative credentials are restricted server-side. If a personal data breach ever occurs that poses a risk to you, we will notify the UAE Data Office and affected users as the PDPL requires.
Changes to this policy
If we change how we handle your data — for example, if we ever add optional storage of generated reports — we will update this page, change the effective date above, and flag the change in the product before it applies to you.