Privacy Policy

What we collect, why, where it lives, and how to exercise your rights.

1. Who is responsible

The controller for personal data processed through this website and the Catalyst application at ctlst.eu is:

Groep Dhont CommV (trading as “Catalyst”)
Sint-Gerolfstraat 45 bus A
9031 Gent, Belgium
VAT / enterprise number: BE 0690.666.922 · RPR Gent, Gent division
Email: hello@ctlst.eu

For anything in this policy — questions, requests, complaints — write to hello@ctlst.eu.

2. What we collect and why

Account data

When you create an account we store your name, email address and — for email/password accounts — a hashed password (Argon2; we never store the password itself). If you sign in with Google or Microsoft, the provider sends us your name, email address and profile-picture URL, and we store a link to that identity. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Workspace content

Everything you and your team put into a workspace: connection settings, dataset schemas, contracts and rules, validation results, and uploaded files. Warehouse credentials are encrypted at rest and are never returned by our API. Legal basis: performance of a contract.

Validation and duplicate-detection results

When a validation check fails, Catalyst stores up to five example failing rows so your team can see what went wrong. Duplicate detection stores the field values of clustered records. If the tables you validate contain personal data, those samples contain personal data — for that data we act as a processor on your instructions, and you (our customer) remain the controller. A data processing agreement is available on request via hello@ctlst.eu.

Audit log

Workspaces keep an audit log of significant actions (who changed what, and when). For security, audit entries record the acting user's email address and, for most actions, the IP address and browser user-agent the action came from. Audit entries for the shared public demo account never record IP addresses or user agents. Legal basis: our legitimate interest in securing accounts and investigating misuse (Art. 6(1)(f)).

Billing

Paid plans are billed through Stripe. We store your subscription status and Stripe identifiers; your card details go directly to Stripe and never touch our servers. Legal basis: performance of a contract and our legal obligations (tax and accounting).

Contact form

The contact form sends your name, email address, company and message to our sales inbox by email so we can respond. It is not stored in the application database. Legal basis: our legitimate interest in answering the request you sent us.

Server logs

Like every web service, our infrastructure (Google Cloud) writes technical request logs that can include IP addresses. We use them only for security and operations.

3. Cookies and local storage

We use only strictly necessary cookies — there is no advertising or cross-site tracking:

NamePurposeLifetime
catalyst_sessionKeeps you signed in (HttpOnly, Secure)14 days
catalyst_oidcProtects the Google/Microsoft sign-in flowMinutes, during sign-in only
catalyst.workspace (localStorage)Remembers your last-selected workspaceUntil cleared

Because none of these require consent under the ePrivacy rules, we do not show a cookie banner.

4. Analytics

We measure site usage with a self-hosted instance of Umami, a privacy-focused analytics tool. It is served from our own domain, sets no cookies, builds no cross-site profiles, and we configure it to strip query strings and mask record identifiers and invite tokens from tracked URLs. No analytics data is shared with any third party. Legal basis: our legitimate interest in understanding how the site is used (Art. 6(1)(f)).

The two web fonts we use are served from our own domain, not from a font CDN, so no request leaves our servers to fetch them and no third party receives your IP address that way. Our pages make no third-party requests at all.

5. The public demo

The one-click demo signs you into a shared workspace seeded with synthetic data. It is visible to every other demo visitor and is reset regularly — do not enter real personal data there. Demo activity is recorded in the workspace audit log without IP addresses or user agents.

6. Who we share data with

We sell no personal data to anyone. We share data only with the service providers (processors) we need to run Catalyst:

ProviderPurposeLocation
Google CloudApplication hosting and infrastructure logsEU (Belgium)
NeonApplication databaseEU (Frankfurt)
Cloudflare R2Storage of uploaded filesSee section 7
Redis CloudJob queue and rate-limit countersSee section 7
StripePayments and invoicingUS (EU Data Privacy Framework)
ResendTransactional email (verification, resets, invites)US (standard contractual clauses)
Google / MicrosoftOptional single sign-on, at your choiceUS (EU Data Privacy Framework)

If you connect a GitHub repository for contract sync, contract files are pushed to that repository on your instructions, using credentials you provide.

7. International transfers

Our application and database run in EU data centres. Where a provider processes data outside the EEA (Stripe, Resend, the sign-in providers, and parts of Cloudflare's and Redis Cloud's infrastructure), we rely on the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.

8. How long we keep data

Account and workspace data is kept for as long as your account or workspace exists. Validation results, uploaded files and audit entries are kept for the life of the workspace; we are introducing automatic retention limits for security logs. Billing records are kept as long as tax law requires. To have your account and its data deleted, email hello@ctlst.eu — we action deletion requests within 30 days.

9. Your rights

Under the GDPR you can ask us for access to, correction of, deletion of, or a portable copy of your personal data, and you can object to or ask us to restrict processing based on legitimate interest. Write to hello@ctlst.eu; we respond within one month. You can also complain to a supervisory authority — in Belgium, the Gegevensbeschermingsautoriteit (gegevensbeschermingsautoriteit.be), or the authority of your own country.

10. Changes

We will update this policy as the product evolves and note the date above. For significant changes we will notify account holders by email or in the app.