Privacy Policy
What we collect, why, where it lives, and how to exercise your rights.
1. Who is responsible
The controller for personal data processed through this website and the Catalyst application at ctlst.eu is:
Groep Dhont CommV (trading as “Catalyst”)
Sint-Gerolfstraat 45 bus A
9031 Gent, Belgium
VAT / enterprise number: BE 0690.666.922 · RPR Gent, Gent division
Email: hello@ctlst.eu
For anything in this policy — questions, requests, complaints — write to hello@ctlst.eu.
2. What we collect and why
Account data
When you create an account we store your name, email address and — for email/password accounts — a hashed password (Argon2; we never store the password itself). If you sign in with Google or Microsoft, the provider sends us your name, email address and profile-picture URL, and we store a link to that identity. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Workspace content
Everything you and your team put into a workspace: connection settings, dataset schemas, contracts and rules, validation results, and uploaded files. Warehouse credentials are encrypted at rest and are never returned by our API. Legal basis: performance of a contract.
Validation and duplicate-detection results
When a validation check fails, Catalyst stores up to five example failing rows so your team can see what went wrong. Duplicate detection stores the field values of clustered records. If the tables you validate contain personal data, those samples contain personal data — for that data we act as a processor on your instructions, and you (our customer) remain the controller. A data processing agreement is available on request via hello@ctlst.eu.
Audit log
Workspaces keep an audit log of significant actions (who changed what, and when). For security, audit entries record the acting user's email address and, for most actions, the IP address and browser user-agent the action came from. Audit entries for the shared public demo account never record IP addresses or user agents. Legal basis: our legitimate interest in securing accounts and investigating misuse (Art. 6(1)(f)).
Billing
Paid plans are billed through Stripe. We store your subscription status and Stripe identifiers; your card details go directly to Stripe and never touch our servers. Legal basis: performance of a contract and our legal obligations (tax and accounting).
Contact form
The contact form sends your name, email address, company and message to our sales inbox by email so we can respond. It is not stored in the application database. Legal basis: our legitimate interest in answering the request you sent us.
Server logs
Like every web service, our infrastructure (Google Cloud) writes technical request logs that can include IP addresses. We use them only for security and operations.
3. Cookies and local storage
We use only strictly necessary cookies — there is no advertising or cross-site tracking:
| Name | Purpose | Lifetime |
|---|---|---|
catalyst_session | Keeps you signed in (HttpOnly, Secure) | 14 days |
catalyst_oidc | Protects the Google/Microsoft sign-in flow | Minutes, during sign-in only |
catalyst.workspace (localStorage) | Remembers your last-selected workspace | Until cleared |
Because none of these require consent under the ePrivacy rules, we do not show a cookie banner.
4. Analytics
We measure site usage with a self-hosted instance of Umami, a privacy-focused analytics tool. It is served from our own domain, sets no cookies, builds no cross-site profiles, and we configure it to strip query strings and mask record identifiers and invite tokens from tracked URLs. No analytics data is shared with any third party. Legal basis: our legitimate interest in understanding how the site is used (Art. 6(1)(f)).
The two web fonts we use are served from our own domain, not from a font CDN, so no request leaves our servers to fetch them and no third party receives your IP address that way. Our pages make no third-party requests at all.
5. The public demo
The one-click demo signs you into a shared workspace seeded with synthetic data. It is visible to every other demo visitor and is reset regularly — do not enter real personal data there. Demo activity is recorded in the workspace audit log without IP addresses or user agents.
6. Who we share data with
We sell no personal data to anyone. We share data only with the service providers (processors) we need to run Catalyst:
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud | Application hosting and infrastructure logs | EU (Belgium) |
| Neon | Application database | EU (Frankfurt) |
| Cloudflare R2 | Storage of uploaded files | See section 7 |
| Redis Cloud | Job queue and rate-limit counters | See section 7 |
| Stripe | Payments and invoicing | US (EU Data Privacy Framework) |
| Resend | Transactional email (verification, resets, invites) | US (standard contractual clauses) |
| Google / Microsoft | Optional single sign-on, at your choice | US (EU Data Privacy Framework) |
If you connect a GitHub repository for contract sync, contract files are pushed to that repository on your instructions, using credentials you provide.
7. International transfers
Our application and database run in EU data centres. Where a provider processes data outside the EEA (Stripe, Resend, the sign-in providers, and parts of Cloudflare's and Redis Cloud's infrastructure), we rely on the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.
8. How long we keep data
Account and workspace data is kept for as long as your account or workspace exists. Validation results, uploaded files and audit entries are kept for the life of the workspace; we are introducing automatic retention limits for security logs. Billing records are kept as long as tax law requires. To have your account and its data deleted, email hello@ctlst.eu — we action deletion requests within 30 days.
9. Your rights
Under the GDPR you can ask us for access to, correction of, deletion of, or a portable copy of your personal data, and you can object to or ask us to restrict processing based on legitimate interest. Write to hello@ctlst.eu; we respond within one month. You can also complain to a supervisory authority — in Belgium, the Gegevensbeschermingsautoriteit (gegevensbeschermingsautoriteit.be), or the authority of your own country.
10. Changes
We will update this policy as the product evolves and note the date above. For significant changes we will notify account holders by email or in the app.