PRIVACY FIRST
Privacy Policy
How CIO handles website, account, licence, payment and support information — and what stays on your computer.
Creative Imagination Organiser (CIO) is designed around a simple privacy principle: your private organiser content is stored locally on your computer by default rather than routinely uploaded to CIO servers.
Last updated 17 August 2026
AT A GLANCE
Privacy in Plain English
Your organiser stays local
Notes, plans, lists, statistics and other organiser content are stored locally on your computer by default. CIO does not routinely upload that content to the website.
Online data is kept separate
Website accounts, licences, billing, downloads, updates and support can operate without turning your organiser into a cloud database.
Payment-card details
Payments are handled by the payment provider. CIO may receive transaction and subscription information but does not need to store your full payment-card details.
Support messages
Information you send through Contact and Support is used to understand, route and respond to your enquiry and to protect the form from abuse.
1. Who We Are
Creative Imagination Organiser (CIO) is created and operated by Jonathan Lloyd trading as Creative Imagination Organiser. The main website is creativeimagination.global.
For privacy or data-protection enquiries, rights requests or data-protection complaints, please use our Contact and Support page.
2. Information Stored by the CIO Software
Your organiser content can include categories, subcategories, notes, lists, templates, statistics, plans and other information you choose to place in CIO. That content is stored locally on your computer by default.
The CIO website and normal licence services are designed not to require routine access to that private organiser content. Backups you create remain under your control unless you deliberately place them in a third-party storage service of your choice.
3. Personal Information the Website May Process
Account and licence information
Name, email address, account authentication information, licence identifiers, edition, entitlement status, paid-through date and device information needed to operate supported licence/device limits.
Purchase and subscription information
Product, amount, transaction references, dates, subscription status, renewal/cancellation status and information supplied by the payment provider that is needed to administer the purchase.
Contact and support information
Your name, email, enquiry type, optional CIO version and operating system, subject, message and limited security metadata used to reduce spam and abuse.
Website and security information
IP address, browser/request information, server logs, cookie or consent preferences, and security events that may be needed to operate, diagnose and protect the website.
Download and update information
Licence or entitlement checks and limited technical records associated with protected downloads, update checks or device activation/deactivation.
Most personal information is provided directly by you, generated through your use of the website or CIO licence services, or supplied by a service provider such as the payment provider in connection with a transaction or subscription.
4. Why We Use Personal Information
Depending on the activity, the lawful basis may include:
- Contract — to create and administer an account, process an order, issue and maintain a licence, provide entitled downloads or updates and provide support connected with the product.
- Legal obligation — where information must be retained or used to comply with tax, accounting, consumer-protection or other legal requirements.
- Legitimate interests — to secure the website and licence system, prevent fraud or abuse, investigate faults, improve reliability, keep appropriate business records and enforce licence terms fairly.
- Consent — where consent is the appropriate basis, for example for optional non-essential cookies or optional marketing communications if these are introduced.
CIO does not need your private organiser content for behavioural advertising and does not sell your personal information.
Where account, purchase or licence information is required to provide a service or perform a contract, failing to provide the required information may mean that we cannot create the account, complete the purchase, issue the licence or provide the relevant service.
CIO does not currently use solely automated decision-making that produces legal or similarly significant effects about you.
5. Who Information May Be Shared With
Personal information may be processed by service providers where this is necessary to operate the website and CIO services. Relevant categories can include website hosting and infrastructure providers, payment and subscription providers such as Stripe, email-delivery providers, and professional advisers.
Information may also be disclosed where required by law, to protect legal rights, or to prevent or investigate fraud, abuse or security incidents.
6. International Processing
Some service providers may process personal information in more than one country. Where the use of a provider results in a restricted transfer of personal information outside the UK, the transfer must be covered by a mechanism permitted under UK data-protection law. Depending on the destination and provider, this may include UK adequacy regulations, appropriate safeguards such as the UK International Data Transfer Agreement or UK Addendum, or an applicable legal exception.
Where required when relying on appropriate safeguards, the relevant transfer risk assessment or data protection test is carried out. You can ask for more information about safeguards applying to your personal information through our Contact and Support page.
7. How Long Information Is Kept
Information is kept only for as long as reasonably needed for the purpose for which it was collected and for any applicable legal, accounting, security, fraud-prevention or dispute-resolution requirement. Where a fixed retention period has not been set, the criteria below are used to decide how long the information remains necessary.
- Account and licence records are kept while the account or entitlement is active and afterwards only for as long as reasonably needed to administer expiry or cancellation, prevent misuse, respond to disputes and comply with legal or accounting obligations.
- Purchase and accounting records are kept for the period required by applicable tax and accounting rules and, where necessary, for chargeback, dispute or legal-record purposes.
- Support messages are kept while an enquiry or complaint is active and afterwards only where reasonably needed for follow-up, recurring fault history, complaint handling, legal claims or legitimate business records.
- Security and technical logs are kept for the shortest practical period consistent with website operation, security monitoring, abuse prevention and investigation of incidents.
8. Cookies and Similar Technologies
The website may use cookies or similar technologies that are necessary for functions such as account sign-in, security, session management and preference handling.
Where non-essential analytics, advertising or similar technologies require consent, they should not be used until the required choice has been obtained. The site’s cookie controls should be used to explain and manage those choices.
9. Your Data-Protection Rights
Depending on the circumstances and lawful basis, you may have rights to ask for access to your personal information, correction of inaccurate information, erasure, restriction of processing, data portability, or to object to particular processing. Where processing is based on consent, you can withdraw that consent at any time. Exercising a right is normally free of charge, and requests are normally answered within one month, subject to any extension permitted by law.
To exercise a data-protection right, use our Contact and Support page and make clear which right you wish to exercise.
10. Your Right to Object
You have the right to object to processing based on legitimate interests in certain circumstances. If you object, we will consider the circumstances and stop the relevant processing unless there are compelling legitimate grounds to continue or the processing is needed for legal claims.
If your personal information is used for direct marketing, you can object at any time. The right to object to direct marketing is absolute, and your information will no longer be used for that purpose.
11. Data-Protection Complaints
If you believe that your personal information has not been handled in accordance with data-protection law, you can make a data-protection complaint through our Contact and Support page. Choose the most relevant enquiry type, or choose Other, and state Data Protection Complaint in the subject.
We will acknowledge and deal with a data-protection complaint without undue delay. We will take appropriate steps to investigate, keep you informed where appropriate, and tell you the outcome without undue delay.
You also have the right to complain to the UK Information Commissioner’s Office (ICO). You can find the ICO’s current complaint guidance at How to make a data protection complaint.
12. Security
Reasonable technical and organisational measures are used to protect website, account, licence and support information. No online system can be guaranteed to be completely secure, so security controls are reviewed as CIO develops.
13. Changes to This Policy
This policy may be updated as CIO, the website, legal requirements or third-party services change. Material changes will be brought to users’ attention where appropriate before new uses of personal information begin.
14. Contact
For privacy questions, data-protection rights requests or data-protection complaints, use the Contact and Support page and choose the most relevant enquiry type.