Privacy Policy
Last updated: August 1, 2026
This Privacy Policy is provided in English. The English version is the sole legally binding text. Any translation is provided for convenience only and is not authoritative.
Cautium ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our AI-powered Third-Party Risk Management service at cautium.org.
1. Information We Collect
We collect the following types of information:
- Account information: your email address, which we use for passwordless sign-in (a one-time code sent to your inbox). We do not store a password for your account.
- Organization and team data: your organization name, the members you invite, and their roles.
- Documents you upload: the policies, certifications, and previous responses (PDF or DOCX) that form your knowledge base. Unlike a one-off analysis tool, Cautium is built around a persistent knowledge base, so these documents are stored — see Section 3 for exactly how.
- Questionnaires and answers: the security questionnaires you upload, the answers Cautium drafts, the sources it cites, and the edits and approvals you make.
- Vendor and analysis data: the vendor records, risk scores, flags, and summaries generated within your account.
- Usage data: basic, privacy-friendly analytics (via Vercel Analytics) such as which pages are visited, collected without advertising cookies or cross-site tracking.
2. How We Use Your Information
- To build and maintain your private knowledge base.
- To draft answers to your questionnaires, grounded in and citing your own documents.
- To store your history so your team can reuse and stay consistent across questionnaires.
- To authenticate you and manage your account, organization, and team.
- To send you transactional emails (sign-in codes, team invitations, and important service updates). We do not send marketing emails without your consent.
3. How We Handle Your Documents
Your documents are the heart of Cautium, and their confidentiality is our most important commitment. Here is exactly what happens to a document you upload:
- Your documents are stored, because that is the product. To answer questionnaires from your own sources, Cautium keeps the files you upload in encrypted storage (Supabase Storage, EU region) as your knowledge base, along with the text extracted from them so answers can cite the exact passage. This is different from a tool that discards your file after a single analysis.
- Your data is isolated to your organization. We enforce row-level security in our database and organization-scoped paths in file storage, so your documents and answers are invisible to other customers at the infrastructure level, not just at the application level.
- Your documents are never used to train AI models. Document text is sent to Anthropic's Claude API solely to extract text and draft your answers, under Anthropic's Data Processing Addendum (DPA), which is automatically incorporated into Anthropic's Commercial Terms of Service and includes Standard Contractual Clauses for international data transfers. Anthropic's standard API data retention is 7 days, used only for abuse monitoring and trust & safety purposes — not for model training.
- Zero Data Retention available on request. For customers with heightened confidentiality requirements, we can route your processing through Anthropic's Zero Data Retention (ZDR) configuration, under which no prompt or output is retained by Anthropic beyond the immediate response. Contact us to enable ZDR for your organization.
- You stay in control. You can archive or delete documents from your knowledge base at any time, and you can request deletion of your entire account and its data — see Section 6.
4. Data Storage and Security
Your data is stored in Supabase (EU region, Ireland). We use HTTPS/TLS encryption for all data in transit and Supabase's at-rest encryption at the database and storage layer. Access to your data is protected by database row-level security that scopes every record to your organization, and sign-in uses one-time email codes rather than reusable passwords. We apply rate limiting on sensitive endpoints, such as sending sign-in codes, to prevent abuse.
5. Third-Party Services
To provide our service, we rely on the following sub-processors. Each one receives only the data strictly necessary for its function, and none of them sells your data or uses it for their own purposes.
- Anthropic — AI engine. Receives the text of your documents and questionnaires to extract text and draft answers. Governed by Anthropic's Data Processing Addendum. Privacy policy
- Supabase — database, authentication, and file storage, hosted in the European Union (Ireland, AWS eu-west-1). Stores account information, your knowledge base, and your answers. Privacy policy
- Vercel — application hosting and privacy-friendly usage analytics. Provides the compute that serves the app. Privacy policy
- Stripe — payment processing for paid subscriptions. Handles card details directly; we only receive a customer identifier and subscription metadata. Privacy policy
- Resend — delivery of transactional emails (sign-in codes and team invitations). Processes recipient email addresses and email contents. Email contents never include your document data. Privacy policy
6. Your Rights
If you are located in the European Union, the United Kingdom, or another jurisdiction with similar data protection laws, you have the following rights:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate personal data.
- Erasure ("right to be forgotten") — request that we delete your account and all associated data. We process erasure requests within 30 days.
- Portability — receive your data in a machine-readable format.
- Restriction and objection — ask us to limit how we process your data, or object to specific processing activities.
- Withdraw consent — where processing is based on consent, you may withdraw it at any time.
- Lodge a complaint with your national data protection authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD).
To exercise any of these rights, email us at support@cautium.org. We will verify your identity before processing the request. If you delete your account, all your data — including your knowledge base and answer history — will be permanently removed within 30 days.
7. Cookies
We use only essential cookies — for authentication and to remember your language preference. Our usage analytics (Vercel Analytics) does not use advertising cookies or track you across other websites.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on our website.
9. Contact
If you have any questions about this Privacy Policy, please contact us at: support@cautium.org