Privacy Policy

How we collect and use your data in compliance with GDPR

Last updated: 2024-03-20

1. Introduction

At Cascady, we prioritize the protection of your personal data. This Privacy Policy explains how we collect, process, and protect your personal information in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Data Controller

The data controller for your personal information is:

Cascady - Lennart Brauer Neisseweg 1 38108 Braunschweig Germany Email: privacy@cascady.app

3. Information We Collect

We collect several types of personal data to provide our services. This includes your account information such as email address and name, your platform preferences and profile settings. We also collect usage data about your interactions with our service and technical data such as your IP address and browser information. For paid subscriptions, payment information is securely processed through our payment provider. Additionally, we store your content preferences and AI settings to provide our services.

4. Legal Basis for Processing

Our processing of your personal data is based on several legal grounds under GDPR Article 6. We process data necessary for contract fulfillment when providing our services. We comply with legal obligations where required by law. We process data based on our legitimate interests in improving and securing our services. Where necessary, we process data based on your explicit consent.

5. Data Processing Purposes

We use your personal data to provide and improve our AI content generation services. This includes managing your account, processing payments and subscriptions, personalizing your experience, and ensuring platform security. We also use data to communicate important service updates and optimize our platform performance.

6. Data Recipients

We work with carefully selected service providers to deliver our platform. Stripe processes payment information securely. Supabase hosts our database infrastructure. OpenAI assists with content generation. Google provides authentication services when you choose to use them. All our service providers are bound by data processing agreements ensuring GDPR compliance.

7. International Data Transfers

When we transfer data outside the EU/EEA, we implement appropriate safeguards. We use EU Standard Contractual Clauses and rely on adequacy decisions by the European Commission where applicable. We also implement binding corporate rules when necessary to ensure the protection of your data.

8. Data Retention

We retain your data only as long as necessary. For active accounts, we maintain data throughout your user relationship. Inactive accounts are retained for 12 months after the last activity. Payment-related data is kept for the duration required by tax laws, typically 10 years.

9. Your Rights

Under GDPR, you have comprehensive rights regarding your personal data. You can access your data, correct inaccuracies, and request deletion. You may restrict processing or object to certain uses of your data. You can request data portability and withdraw previous consent. To exercise any of these rights, contact us at privacy@cascady.app.

10. Data Security

We implement comprehensive technical and organizational security measures. Your data is protected through encryption both in transit and at rest. We conduct regular security assessments and maintain strict access controls. Our staff receives ongoing training in data protection practices.

11. Cookies and Tracking

We use various cookies and similar technologies to operate our platform. For detailed information about these technologies and your control options, please refer to our separate Cookie Policy.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of significant changes via email or through our platform. Updates become effective 30 days after notification.

13. Data Protection Authority

You have the right to file a complaint with a supervisory authority. The lead authority for Cascady is:

Die Landesbeauftragte für den Datenschutz Niedersachsen Prinzenstraße 5 30159 Hannover Germany

14. Contact Us

For any privacy-related inquiries or to exercise your data protection rights, please contact our data protection team at privacy@cascady.app or write to us at Cascady - Lennart Brauer, Neisseweg 1, 38108 Braunschweig, Germany.