Privacy and transparency
Privacy policy
This first version explains how the public Cuveta marketing website handles personal data. It is deliberately limited to processing that is relevant to this website and does not replace a separate notice for authenticated use of the Cuveta web or mobile application.
Initial AI-generated draft. Confirm the controller details, vendors, retention periods and app-specific processing with the Cuveta operator before relying on this notice.
1. Who is responsible for your data?
The data controller is identified in the contact block on this page. The final legal name, registered address and privacy contact must be completed before this policy is treated as the production notice.
2. What data may we process?
Depending on how you use the website, we may process:
- technical request data such as IP address, date and time, requested URL, response status, user-agent and basic device or browser information in hosting, CDN and security logs;
- information you voluntarily send in a demo or contact request, such as name, work email, company, role and message;
- a local browser preference used to remember that this notice was dismissed; the current site does not use this preference for profiling or advertising.
3. Why do we process it and on what basis?
We use the data only for the following purposes:
- to deliver, maintain and secure the website, prevent abuse and investigate technical incidents — Article 6(1)(f) GDPR, our legitimate interest in a safe and reliable service;
- to answer a demo or business enquiry and take requested pre-contract steps — Article 6(1)(b) GDPR where applicable, or Article 6(1)(f) GDPR for ordinary business correspondence;
- to meet legal obligations and establish, exercise or defend legal claims — Article 6(1)(c) or 6(1)(f) GDPR, as applicable;
- to activate optional analytics, advertising or similar technologies only after a valid opt-in — Article 6(1)(a) GDPR. No such optional technology is active on this marketing site at the time of publication.
4. Who may receive the data?
We may disclose the minimum information needed to hosting, CDN, DNS, security, email and other technical providers that support the website or a requested business response. They act on our instructions where they are processors and must protect the information under contract. The public site currently links to the separate Cuveta application; processing inside an authenticated application may have additional recipients and a separate notice.
Where Cloudflare proxy or security services are enabled for the domain, Cloudflare may process technical request data as part of those services. The final vendor list and controller/processor roles should be confirmed in the deployment records before launch.
5. International transfers
A provider may process data outside the European Economic Area. Where that happens, the controller will use an adequacy decision or appropriate safeguards such as the European Commission Standard Contractual Clauses, together with any required supplementary measures. The final list of providers and transfer safeguards belongs in the production review of this notice.
6. How long do we keep data?
Technical and security logs are intended to be kept for a limited period, normally up to 30 days, unless a longer period is reasonably necessary to investigate abuse, maintain security or comply with a legal obligation. Business enquiries are kept until resolved and normally for up to 12 months after the last substantive contact, unless a longer period is needed for a contract, legal obligation or defence of claims. Data is deleted or anonymised when the applicable purpose ends.
7. Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction of processing, data portability where applicable, and object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time; withdrawal does not affect earlier lawful processing. You may also complain to the competent supervisory authority in your habitual residence, place of work or the place of the alleged infringement.
To exercise a right, use the privacy contact in the block on this page. We may need information to verify your identity. We normally respond within one month; the period may be extended by up to two further months where legally permitted and you are informed of the reason.
8. Security and automated decisions
We use proportionate technical and organisational measures, including TLS for public web traffic and access controls for administration. No internet transmission can be guaranteed to be completely secure. The public marketing website does not make decisions about people solely by automated processing and does not run advertising profiles.
9. Children and changes
The website is intended for business audiences and is not directed at children. We do not knowingly request children’s personal data through the marketing site. We may update this policy when the website, vendors or legal requirements change; the effective date above will be updated with the next material revision.
