Privacy Policy
This policy explains how Caugia handles personal data in a minimal, GDPR aligned way. Caugia operates on a B2B basis and collects only the information required to run engagements and operate the website.
Last updated: 5 October 2026
1. Data controller
The data controller is:
RCS Compiègne 100 887 082
17 Chemin des Chataigniers, 60580 Coye-la-Forêt, France
Email: contact@caugia.com
This privacy policy applies to individuals acting on behalf of a professional entity, including founders, executives and employees.
2. Data we collect
We collect only the minimum data required to operate the website and run engagements:
- Business contact data: name, company name, business email address, and any information you include in messages you send to us
- Technical data: limited information required for security, website functionality and performance
- Booking data: your name, email address and the time you pick when you book a call, plus anything you write in the booking form
- Engagement data: during an engagement we work inside the client’s own tools (CRM, sales and marketing systems) on the client’s instructions; the data we see there is processed for the engagement only, as described in the written scope and, where required, a data processing agreement
- Billing data: the company details needed to invoice an engagement (legal name, address, VAT number, billing contact)
We do not request sensitive personal data. If you voluntarily include personal data in free text fields, you remain responsible for the content you provide.
3. How we use your data
We use personal data for the following purposes:
- Service delivery: scope and run your engagement
- Booking: send your booking confirmation by email
- Support: respond to inquiries and troubleshoot issues
- Security and integrity: protect the website and prevent abuse
We do not sell personal data. We do not use personal data for advertising.
4. Legal basis
Under GDPR, we process personal data on the following legal bases:
- Contract: to run the engagement you commissioned
- Legitimate interest: to operate, secure and improve the website and service
- Consent: where required, for example when you submit information through a form
5. Storage and retention
We aim to store as little as possible.
- Contact and booking data: kept for as long as we are in contact about a call or an engagement, and for service integrity and support. Ask us and we delete them earlier
- Invoicing: invoicing data for engagements is kept for the statutory accounting period. Card payments made before 10 September 2026 were processed by Stripe; Caugia never stored card details
If you request deletion, we will delete personal data unless retention is required to comply with legal obligations or to establish, exercise or defend legal claims.
6. Sharing and processors
We share personal data only with service providers strictly required to operate the service. These providers act as processors under GDPR.
- Stripe: historic card payments only; nothing has been sold by card since 10 September 2026
- Supabase: database hosting for booking and CRM data (EU region)
- Vercel: hosting of os.caugia.com, which serves the booking page and the founder’s own admin console
- Vercel and Cloudflare: hosting, DNS and delivery of the marketing website (www.caugia.com), including security filtering and cookie-free visit statistics (Cloudflare Web Analytics)
- Resend: transactional email delivery (booking confirmations)
- Google Workspace: our business email, and Google Calendar and Meet for the calls you book on our booking page
- Anthropic (Claude API): AI assistance inside the founder’s own admin console, for example research on an account or a first draft of a reply; Anthropic does not use API data to train its models
- Slack: internal notifications to the founder (for example a new booking or reply), which can contain your name, company and email
We do not share personal data with third parties for marketing purposes.
7. Benchmarking
Caugia may use anonymized and aggregated data from its engagements for benchmarking and statistical analysis. This data is processed in a way that is intended not to identify an individual or a company.
If you do not want your data to be used for benchmarking in anonymized and aggregated form, you can contact us at contact@caugia.com.
8. International transfers
Some of our service providers may process data outside the European Economic Area. Where applicable, transfers are protected using appropriate safeguards such as Standard Contractual Clauses.
9. Your rights
You may have the following rights under GDPR, subject to applicable conditions:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your personal data
- Object to certain processing based on legitimate interest
- Request restriction of processing
- Request a copy of your data in a portable format where applicable
To exercise your rights, contact us at contact@caugia.com.
10. Cookies
We use essential cookies for security and session handling only. We do not use advertising cookies.
Visits are measured with Cloudflare Web Analytics, which runs without cookies, without fingerprinting and without storing personal data, so no consent banner is needed. We do not use Google Analytics.
11. Changes to this policy
We may update this policy from time to time. The latest version will always be available on this page.