Os documentos legais da Cautera são disponibilizados em inglês.

Effective date: 11 August 2026 · Last updated: 11 August 2026 Published at: https://cautera.com/legal/privacy

This Privacy Policy explains how Cautera Labs, Unipessoal Lda. (“Cautera”, “we”, “us”) collects and processes personal data when you visit https://cautera.com, when you hold an account on https://app.cautera.com or https://admin.cautera.com, and when you otherwise interact with us (together, the “Sites and Services”).

This policy applies to Cautera acting as a controller of personal data: data about website visitors, prospects, account holders, and the administrative users of customer organisations, to the extent we determine the purposes and means of that processing.

Customer tenant data is governed separately. Where Cautera processes personal data on behalf of a customer organisation (its “tenant” content — controls, risks, evidence, vendor records, questionnaire responses, and the personal data contained within them), Cautera acts as a processor and the customer is the controller. That processing is governed by the Cautera Data Processing Agreement (provided as part of the customer contract), not this policy. If you are an individual whose data appears in a customer’s tenant, please contact that customer (the controller) to exercise your rights; we will assist them as required by the DPA.


1. Controller identity and contact details

Controller: Cautera Labs, Unipessoal Lda., a private limited company (Lda.) incorporated in Portugal, NIPC 519436539, registered office at Rua Augusto Macedo, n.º 8, Fração L, 1600-794 Lisboa, Portugal.

Data protection contact: privacy@cautera.com, or by post to the registered office above. This is the contact point for all matters relating to this policy and to your rights under Sections 8 and 9.

Data Protection Officer (Article 37 GDPR). Cautera has not appointed a Data Protection Officer, and is not required to appoint one. Cautera has assessed Article 37(1) and concluded that none of its limbs is met: Cautera is not a public authority; its core activities consist of providing a business-to-business SaaS platform to organisational customers and do not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale; and its core activities do not consist of large-scale processing of special categories of data (Article 9) or of data relating to criminal convictions and offences (Article 10). The data-protection contact named above, together with the registered address, is the point of contact for the purposes of Articles 13 and 14. Cautera will reassess this position at each annual review of this policy, and will appoint and publish a DPO if the assessment changes.

EU representative (Article 27 GDPR): Cautera is established in the EU (Portugal), so an Article 27 representative is not required. Should Cautera later cease to be established in the EU, the details of the appointed Article 27 representative will be published in this section before that change takes effect.


2. What personal data we collect

2.1 Account holders and administrative users

  • Identity & contact data: name, business email address, job title, organisation, phone (if provided).
  • Authentication data: hashed password, multi-factor authentication (MFA) enrolment status and secrets (encrypted), session and login metadata.
  • Account & usage data: role and permissions, tenant membership, activity and audit logs, feature usage, AI Copilot query metadata.
  • Technical data: IP address, device/browser information, request logs.
  • Diagnostic telemetry: where the application encounters an error, we capture an error report through our error-monitoring provider. That report can include your user ID, email address, organisation ID, the page or API route involved, and a session replay — a reconstruction of the affected browsing session. Replays are recorded for a sample of sessions and for sessions in which an error occurs; text content is masked and media is blocked before the recording leaves your browser.

Whether you have to provide this data (Article 13(2)(e)). Providing your name and business email address is a contractual requirement — it is necessary to create and operate an account, because an account has to be attributable to an identified person for authentication, access control, and audit purposes. If it is not provided, an account cannot be created. Everything else in Section 2.1 is either generated automatically by your use of the Services or optional (for example a phone number), and withholding it does not prevent you from using the Services.

2.2 Website visitors and prospects

The marketing site at cautera.com is a static website. It runs no web-analytics, tag-manager, or advertising code, and it sets no tracking cookies (see the Cookies section). It collects personal data in one place only: its contact / demo-request form.

  • Contact data you submit via the contact / demo-request form: your name, business email address, company, and the content of your message. We use it to respond to your enquiry, to arrange a demonstration, and to take steps at your request before entering into a contract. The legal bases are Article 6(1)(b) (steps taken at your request prior to entering a contract) and Article 6(1)(f) (our legitimate interest in responding to business enquiries about our own product). Providing the data is voluntary, but we cannot answer an enquiry without it. We keep it until the enquiry concludes — that is, until the matter is resolved or the exchange lapses — and in any event no longer than 24 months from the last meaningful contact, unless a business relationship develops, in which case it is handled under Sections 2.1 and 2.3.
  • Technical data: IP address and standard request metadata (pages requested, referrer, user-agent) processed in server and content-delivery logs for security, integrity, and the delivery of the site itself, on the basis of Article 6(1)(f).

The application (app.cautera.com / admin.cautera.com) likewise carries no third-party web-analytics, tag-manager, or advertising code; the only browser-side third-party telemetry anywhere in our estate is the error monitoring and session replay described in Section 2.1.

2.3 Marketing recipients

  • Business contact details and communication preferences for prospects and customers who have opted in or with whom we have an existing business relationship.

We do not intentionally collect special-category personal data (Article 9 GDPR) about account holders or visitors, and we ask that you do not submit such data through general contact channels.


3. How we collect it

  • Directly from you — when you register, configure an account, contact us, request a demo, or subscribe to communications.
  • Automatically — through your use of the Sites and Services (logs, cookies, and similar technologies).
  • From your organisation — where your employer provisions your account and provides your business contact details.

Article 13 / Article 14 transparency

Where we collect data directly from you (Article 13), this policy provides the required information at the point of collection. Where we obtain your data from a third party such as your employer or a referral (Article 14), we rely on the same purposes and legal bases set out below; the source is typically the customer organisation that provisioned your account or a business contact database, and the categories are those in Section 2.1/2.3.


# Purpose Categories Legal basis (Art. 6 GDPR)
1 Providing, operating, and securing the Services to account holders Identity, authentication, account/usage, technical Art. 6(1)(b) — performance of the contract with you or your organisation; Art. 6(1)(f) — legitimate interests in securing the platform
2 Authentication, MFA, rate-limiting, fraud and abuse prevention Authentication, technical Art. 6(1)(f) — legitimate interests in security; Art. 6(1)(c) — legal obligation (where applicable)
3 Customer support and service communications Identity, contact, account Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interests
4 Billing and account administration Identity, contact, account Art. 6(1)(b) — contract; Art. 6(1)(c) — legal/accounting obligations
5 Responding to website enquiries and demo requests Contact, message content Art. 6(1)(b) — pre-contractual steps; Art. 6(1)(f) — legitimate interests
6 Marketing communications to prospects and customers Contact, preferences Art. 6(1)(a) — consent (where required); Art. 6(1)(f) — legitimate interests for existing business contacts, subject to opt-out
7 Product improvement, using our own internal usage records (we run no third-party analytics) Usage, technical (aggregated/de-identified where possible) Art. 6(1)(f) — legitimate interests
8 Strictly-necessary cookies (session, single sign-on state) and storage in your browser — interface preferences, dismissed notices, recently used items, session-security timers, rate-limit counters, setup-wizard drafts, short-lived work queues (see Section 10). We set no non-essential cookies and no tracking storage Technical, identifiers, and any content you type into a saved draft Art. 6(1)(b)/(f); exempt from consent under the ePrivacy framework (Portugal: Lei n.º 41/2004, art. 5(3)) as strictly necessary to provide a service you requested
9 Complying with legal obligations and establishing/defending legal claims Various Art. 6(1)(c) — legal obligation; Art. 6(1)(f) — legitimate interests

Where we rely on legitimate interests, we have carried out a balancing test and will provide details on request. Where we rely on consent, you may withdraw it at any time without affecting prior processing.


5. Recipients and sub-processors

We share personal data with:

  • Service providers / sub-processors that help us operate the Services. The providers that process the data covered by this policy — that is, the account, website, and usage data for which Cautera is the controller — are: Supabase (database, authentication, storage, serverless functions — EEA), Google Cloud (application delivery and API proxying in europe-west1), Plus Five Five, Inc. (d/b/a Resend) (transactional email), Upstash (rate-limiting), Sentry (error monitoring and session replay — EU data region), and Grafana Cloud / Loki (log aggregation — EU, Ireland).

    Cautera engages further sub-processors — including Vertex AI / Gemini in europe-west1 for AI features, malware scanning of uploads, the storage backup mirror, and the audit archive — only in its role as processor of a customer organisation’s tenant data, under the DPA rather than under this policy. The complete list covering both roles, with purposes, data categories, and regions, is published at https://cautera.com/legal/subprocessors.

  • Professional advisers (legal, accounting, audit) under confidentiality.

  • Authorities and third parties where required by law, to enforce our agreements, or to protect rights, property, or safety.

  • Successors in connection with a merger, acquisition, or asset sale, under appropriate safeguards.

We do not sell personal data.


6. International transfers

We host and process personal data in the European Economic Area (EEA) by default. Our infrastructure is configured for EU regions (for example, AI processing via Vertex AI is pinned to europe-west1).

Two aspects of delivery are global rather than EU-pinned, and we state them rather than leave them implied. First, the static application and website are delivered from a global content-delivery network, whose edge servers and load balancers log visitor IP addresses and request metadata at the point of delivery. Second, our serverless functions execute on the provider’s global edge network rather than in a single pinned region, although the data they read and write remains at rest in the EU region.

Where a sub-processor or its parent company is located outside the EEA (for example, US-incorporated providers such as Supabase, Inc., Google LLC, Plus Five Five, Inc. (d/b/a Resend), Sentry, Upstash, Inc., or Grafana Labs), any transfer of personal data is protected by an appropriate safeguard under Chapter V GDPR — principally the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supplemented by additional technical and organisational measures where necessary following a transfer impact assessment. Transactional email is delivered through Resend, whose processing location we treat as outside the EEA and therefore under the SCCs. You may request a copy of the relevant safeguards by contacting privacy@cautera.com.


7. Retention

We retain personal data only as long as necessary for the purposes above:

  • Account data — for the duration of the account. On closure or termination there is first an export window of 30 days, during which the account holder or its organisation can export data through the Services; account data is then deleted or anonymised within a further 90 days. The outer bound is therefore 120 days from closure. This is the same scheme, and the same periods, as DPA §11.2, which governs tenant data. Both are subject to any legal hold and to the customer’s instructions for tenant data under the DPA.
  • Audit and security logs — retention is bounded by the customer organisation’s subscription plan, subject to an overall ceiling of three years. Entries are held in the live platform for 30 days (Free), 90 days (Starter), 180 days (Professional) or 365 days (Enterprise); entries aged out of the live platform are moved to a write-once, retention-locked archive in the EU (europe-west1), where they cannot be altered or deleted early and are erased on expiry of the plan’s maximum: 90 days (Free), 180 days (Starter), 365 days (Professional, or 1,095 days where the retention extension is purchased as a paid add-on provisioned via Order Form) or 1,095 days (Enterprise). While a legal hold is in force, deletion is suspended entirely for that organisation: its entries are neither removed from the live platform nor erased from the archive, so archived entries whose retention period has ended are kept for as long as the hold lasts and are erased once it is released. Status at the date of this policy, stated plainly: the archive has been operating since 11 August 2026. A job runs daily at 03:00 UTC; it archives entries that are past their organisation’s live-platform period, checks that each archived object carries the correct retention lock, and only then deletes those entries from the live platform, so nothing is deleted that has not first been verifiably archived. Each archived object’s lock is set to that organisation’s maximum and cannot be shortened by anyone at Cautera; the object is deleted when the lock expires. The periods above therefore describe what the platform does today, not what it will do: the first production run left no organisation holding audit entries past its retention window, and each nightly run maintains that position. One limit is worth stating: the archive holds only what has been written to it since 11 August 2026 — there is no earlier archive.
  • Diagnostic telemetry (error reports, session replays) — retained by our error-monitoring provider (Sentry) under its published retention schedule, which is plan-dependent: error events and session replays for a maximum of 90 days (30 days on its free tier) and performance/tracing data for 30 days. We do not extend these periods, and the data is deleted automatically on expiry.
  • Billing records — retained as required by Portuguese accounting and tax law (generally 10 years).
  • Marketing data — until you opt out or the data is no longer relevant.
  • Enquiry/contact data (including the cautera.com contact / demo-request form) — until the enquiry concludes, and in any event no more than 24 months from the last meaningful contact, unless a business relationship develops.

When retention expires, data is deleted or irreversibly anonymised.


8. Your rights

Subject to the conditions and exceptions in the GDPR, you have the right to:

  • Access your personal data (Art. 15);
  • Rectification of inaccurate or incomplete data (Art. 16);
  • Erasure (“right to be forgotten”) (Art. 17);
  • Restriction of processing (Art. 18);
  • Data portability (Art. 20);
  • Object to processing based on legitimate interests, and to object to direct marketing at any time (Art. 21);
  • Withdraw consent at any time where processing is based on consent (Art. 7(3)), without affecting prior processing;
  • Not be subject to solely automated decisions producing legal or similarly significant effects (Art. 22). We do not make such decisions about account holders or visitors; AI Copilot output is advisory and human-reviewed.

To exercise any right, contact privacy@cautera.com. We will respond within one month (extendable by two further months for complex requests, with notice). We may need to verify your identity. If your data appears within a customer’s tenant, please contact that customer (the controller); we will assist them as the processor.


9. Supervisory authority

If you have a concern about how we handle your personal data, please contact us first at privacy@cautera.com. You also have the right to lodge a complaint with the Portuguese supervisory authority:

Comissão Nacional de Proteção de Dados (CNPD) Av. D. Carlos I, 134 — 1.º, 1200-651 Lisboa, Portugal Website: https://www.cnpd.pt

You may also complain to the supervisory authority in your EU country of residence or work.


10. Cookies and local browser storage

This section is our complete disclosure of both the cookies we set and everything the application stores in your browser on your device. It has been checked against the application’s source code. We do not publish a separate cookie policy, because there is nothing further to disclose.

Cookies in the application (app.cautera.com, admin.cautera.com) — we use strictly-necessary cookies only:

Cookie Purpose
Session cookie (HttpOnly, secure) Keeps you signed in and ties your requests to your authenticated session. Without it you cannot use the application.
Single sign-on state cookie (short-lived) Set only when you sign in through your organisation’s identity provider (SAML/OIDC). It carries a one-time random value that protects the sign-in exchange against cross-site request forgery, and is cleared as soon as sign-in completes.

Local browser storage. Alongside cookies, the application stores a small amount of data in your browser’s own storage (localStorage and sessionStorage). The stored copy stays on your device — we do not read it from a server and it is not sent anywhere as a by-product of being stored. Where a saved draft contains information you typed, that information reaches Cautera only if and when you submit it. The categories are:

What is stored Why
Interface preferences — your language choice and your light/dark theme So the application looks and reads the same way on your next visit.
Dismissed notices — a flag, and in one case a date, recording which informational banners you have closed So a notice you have dismissed does not reappear.
Recently used items — the items you have navigated to via the command palette, with timestamps, capped at the ten most recent A local convenience shortcut. It stays on your device; it is not transmitted to us and is not used for analytics or profiling.
Session-security timers — the timestamp of your last activity, shared between open tabs So the idle-timeout that signs you out applies consistently across every tab you have open. Strictly necessary security storage.
Rate-limit counters — local counters for sensitive actions such as sign-in attempts A fallback that keeps abuse protection working if the server-side limiter is briefly unreachable. Strictly necessary security storage.
Setup-wizard drafts — your autosaved progress through the initial setup wizard So you can close the wizard and resume without losing your place. This draft may include the email addresses of colleagues you have typed in to invite to your organisation; those addresses are held locally as part of the draft and are submitted to Cautera only when you send the invitations.
Short-lived work queues — for example the list of remaining vendors in a bulk assessment, held in sessionStorage So a multi-step task survives navigation within the same tab. This is cleared automatically when you close the tab.

Reading and writing this data is storage on your terminal equipment and so falls within the ePrivacy framework (Portugal: Lei n.º 41/2004, art. 5(3)), but each category above is either strictly necessary to provide the interface and security you asked for or is data you entered yourself in the course of using the Services. It is therefore exempt from the consent requirement on the same basis as the cookies above. You can clear all of it at any time by clearing your browser’s site data for app.cautera.com / admin.cautera.com; doing so resets preferences to their defaults and discards any unsaved wizard draft.

We set no advertising cookies, no analytics cookies, and no cross-site tracking identifiers. Nothing we store on your device is used for advertising, cross-site tracking, or profiling — the “recently used items” list is a local navigation shortcut that stays on your device, and the remaining categories are preferences, security controls, or your own drafts. We run no third-party web-analytics or tag-manager code in the application.

On the marketing site (cautera.com) we set no cookies at all and use no local storage. It is a static site with no analytics and no tracking.

Because every cookie we set and everything we store on your device is strictly necessary to deliver a service you have requested, all of it is exempt from the consent requirement under the ePrivacy framework (Portugal: Lei n.º 41/2004, art. 5(3)), and no consent banner is required or shown. You can still block or delete cookies and site data in your browser, but blocking the session cookie will prevent you from signing in.

If we ever introduce a non-essential cookie or any non-essential storage on your device, we will obtain your consent first, update this section, and — if the change is material — notify you under Section 13.


11. Security

We implement technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, application-level encryption of sensitive fields (AES-256-GCM), database-enforced tenant isolation (Row Level Security), role-based access control, multi-factor authentication, audit logging, rate-limiting, and malware scanning of uploads. See the DPA Annex II for the full description. No method of transmission or storage is completely secure, but we work to protect your data and to notify you and the authorities of any breach as required by law.


12. Children

The Services are intended for business use and are not directed to children. We do not knowingly collect personal data from children under 16.


13. Changes to this policy

We may update this policy from time to time. We will post the updated version with a new effective date and, for material changes, provide additional notice (e.g. by email or in-app). Please review it periodically.


Controller: Cautera Labs, Unipessoal Lda., Rua Augusto Macedo, n.º 8, Fração L, 1600-794 Lisboa, Portugal, NIPC 519436539. Data protection contact: privacy@cautera.com. Support: support@cautera.com. Published at https://cautera.com/legal/privacy.

Request our DPA: privacy@cautera.com

Cautera Labs, Unipessoal Lda., NIPC 519436539, Rua Augusto Macedo, n.º 8, Fração L, 1600-794 Lisboa, Portugal. Supervisory authority: CNPD (Portugal).