Privacy Policy

Last updated: June 2026

This Privacy Policy describes how Marcos Pereira, with registered office at Praça Antonio Nobre, 2660-226 Loures, Portugal (the "Company", "we", "us", or "our"), collects, uses, discloses, retains, and otherwise processes personal data of visitors, users, and customers ("you" or "your") of the csaudit.io website, the Vault dashboard, and all related digital products and services (collectively, the "Service"). For purposes of the EU General Data Protection Regulation 2016/679 ("GDPR") and the UK Data Protection Act 2018, the Company is the data controller of your personal data.

We are committed to processing your personal data lawfully, fairly, and transparently. We collect only the data we genuinely need to deliver the Service, secure it appropriately, and give you meaningful control over how it is used.

1. Personal Data We Collect

We process the following categories of personal data: (a) Account data: your email address, authentication tokens, and any optional profile information you provide; (b) Transaction data: order identifiers, the products purchased, the price paid, and confirmation timestamps relayed to us by our payment processor (we do not store or have access to your full card number, CVV, or bank credentials); (c) Vault audit inputs: the metrics and answers you voluntarily save to your Vault dashboard, including MRR, headcount, and friction questionnaire responses; (d) Technical data: IP address, user-agent string, device type, browser type, language preference, and approximate geolocation derived from IP, collected through server logs and cookies; (e) Communications data: email correspondence you initiate with our support address, including any attachments you choose to send.

2. Legal Bases for Processing (GDPR Article 6)

We process your personal data on one or more of the following legal bases: Performance of a contract (Article 6(1)(b)) — to provide the Vault, deliver assets, fulfill purchases, and respond to support requests you initiate; Legal obligation (Article 6(1)(c)) — to comply with tax, accounting, anti-fraud, and consumer-protection laws; Legitimate interests (Article 6(1)(f)) — to operate, secure, monitor, and improve the Service, prevent abuse, and defend our legal rights, balanced against your interests and fundamental rights; Consent (Article 6(1)(a)) — where you have explicitly opted in, for example to marketing communications, which you can withdraw at any time.

3. How We Use Your Data

We use the data we collect to: (a) authenticate you and provision Vault access; (b) process your payment via our payment processor and deliver the digital assets you purchased; (c) maintain the security and integrity of the Service, including detecting and preventing fraud, abuse, and unauthorized access; (d) respond to support inquiries and provide technical assistance; (e) send transactional emails (receipts, magic-link sign-in emails, security notifications); (f) generate aggregated, anonymized analytics about Service usage that do not identify any individual; (g) comply with our legal obligations, enforce our Terms, and exercise or defend legal claims. We do not sell, rent, trade, or otherwise commercially exploit your personal data, and we do not use it to train artificial intelligence or machine learning models.

4. Cookies and Similar Technologies

We use only strictly necessary cookies and equivalent local-storage entries required to authenticate you, maintain your session, and remember basic preferences. We do not deploy advertising, retargeting, or cross-site tracking cookies, and we do not embed third-party analytics scripts that profile users across the web. Because our cookies are limited to those strictly necessary for the operation of the Service, prior consent is not required under the ePrivacy Directive, but you can still block or delete them via your browser settings.

5. Third-Party Processors and Sub-Processors

To operate the Service we rely on a small set of carefully selected sub-processors, each bound by appropriate data-processing agreements and, where relevant, EU Standard Contractual Clauses: Supabase (authentication, database, and storage), Whop (payments, invoicing, and merchant-of-record tax compliance), Resend (transactional email delivery, including magic-link sign-in), and Cloudflare (hosting, content delivery, and DDoS protection). A current list of sub-processors is available on request.

6. International Transfers

Some of our sub-processors are located outside the European Economic Area, including in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards as required by Chapter V of the GDPR — primarily the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where applicable, additional technical and organizational measures (such as encryption in transit and at rest) following the Schrems II decision.

7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, to comply with our legal, accounting, and regulatory obligations, and to resolve disputes. Concretely: account data is retained for the lifetime of your account and deleted within thirty (30) days of account closure; Vault audit snapshots are retained for the lifetime of your account; transaction records are retained for at least seven (7) years to comply with tax law; security logs are typically retained for ninety (90) days.

8. Your Rights Under the GDPR / UK GDPR / CCPA

Subject to applicable law, you have the right to: (a) access the personal data we hold about you and receive a copy in a structured, commonly used, machine-readable format; (b) request rectification of inaccurate or incomplete data; (c) request erasure ("the right to be forgotten") in certain circumstances; (d) request restriction of processing in certain circumstances; (e) object to processing based on our legitimate interests, including profiling; (f) request data portability; (g) withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing prior to withdrawal; (h) lodge a complaint with your local data-protection supervisory authority (in the EU, this is typically the authority of your country of habitual residence). To exercise any of these rights, contact us at support@csaudit.io. We will respond within thirty (30) days, extendable by a further two months for complex requests.

9. California Residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act, including the right to know what categories of personal information we collect, the right to delete personal information, the right to correct inaccurate information, and the right to opt out of any "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under California law.

10. Security

We implement industry-standard technical and organizational measures designed to protect personal data against unauthorized access, accidental loss, alteration, or disclosure. These measures include encryption in transit (TLS 1.2+) and at rest, row-level security policies on our database, single-sign-on with magic-link authentication, principle-of-least-privilege access controls for our operators, and regular review of our security posture. No system is perfectly secure, however, and we cannot guarantee absolute security.

11. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within seventy-two (72) hours of becoming aware, and we will notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with GDPR Articles 33 and 34.

12. Children's Privacy

The Service is intended for users aged eighteen (18) or older. We do not knowingly collect personal data from children under the age of sixteen (16). If we become aware that we have inadvertently collected such data, we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. Material changes will be communicated by updating the "Last updated" date and, where appropriate, by additional notice.

14. Contact and Data Protection Inquiries

For any privacy-related questions, requests, or complaints, contact: support@csaudit.io. Postal address: Praça Antonio Nobre, 2660-226 Loures, Portugal.