Privacy Policy
What data is processed, for what purpose, who it is disclosed to and how long it is kept.
Last updated:
Controller
Capitalised terms have the meaning given to them in the Terms and Conditions.
1.1. The controller is CAUSFY GLOBAL TECHNOLOGIES, S.L., a Spanish company whose identification details appear in the final section.
1.2. Data protection enquiries should be sent to:
- Data protection:
1.3. This Policy applies to the domains causfy.com, causfy.org and causfy.app.
Data processed
2.1. Data provided by the User.
| Data | When it is collected |
|---|---|
| Name and email address | when creating an Account or supporting a Cause |
| Country | when supporting a Cause |
| Phone, postal address and profile picture | only if the User adds them |
| User Content | when published |
| Content of enquiries and complaints | when sent |
2.2. Data generated by use of the Platform.
| Data | What it is for |
|---|---|
| Device and browser data | operation of the service and detection of abusive use |
| IP address | security and abuse prevention. It is not kept in the clear, but as a derived value from which the original address cannot be obtained |
| Account activity log | security and traceability |
| Date and time of operations | record of activity |
2.3. Data from third parties.
| Source | Data |
|---|---|
| Payment service providers | confirmation of the transaction and its amount. Card numbers and bank details are not received; they are processed directly by the provider |
| Identity verification providers | only the result of the check |
| Google, LinkedIn and Facebook | name and email address, where the User signs in through one of those services |
2.4. Data is not acquired from commercial sources, profiles are not built from information obtained from third parties, and data is not passed to third parties for their own purposes.
Purposes and legal bases
3.1. Providing the service. Creating and maintaining the Account, publishing Causes, recording the Support received and responding to enquiries. The basis is performance of the contractual relationship with the User.
3.2. Verifying Support. Confirming ownership of the email address and, where the Cause requires it, verifying identity. The basis is performance of the contract and the legitimate interest in the integrity of the count.
3.3. Security and abuse prevention. Detecting fraud, automated access and uses contrary to the Terms. The basis is legitimate interest and compliance with legal obligations.
3.4. Content moderation. Reviewing Causes under the Terms. The basis is compliance with legal obligations and the legitimate interest in the orderly operation of the Platform.
3.5. Messages about supported Causes. Sending information about Causes the User has supported. The basis is consent, which may be withdrawn at any time from any of those messages.
3.6. Improving the service. Aggregate analysis of use of the Platform, without identifying individuals. The basis is legitimate interest.
3.7. Legal compliance. Meeting legal obligations and requests from competent authorities.
3.8. AI-assisted features. The Platform includes features assisted by artificial intelligence for drafting the content of a Cause. They operate on the instructions given by the User and do not process third-party personal data. Their scope and limits are governed by the Artificial Intelligence Policy.
3.9. No decisions based solely on automated processing. Measures concerning a Cause or an Account are not taken on a solely automated basis.
Public nature of causes and support
4.1. A Cause is public. Its content is accessible to any visitor and may be indexed by search engines.
4.2. Visibility of Support. Anyone supporting a Cause decides which details are shown publicly alongside their Support, and may choose for none to be shown. The email address is never displayed publicly.
4.3. Information given to the Creator. The Creator of a Cause receives the list of Support obtained, comprising the name given, where there is one, and the email address of the supporter. That list constitutes the record of the Support and may be downloaded by the Creator. Its scope may vary depending on the type of Cause, and this is notified before Support is given.
4.4. Limits on the Creator. The Creator may contact those who supported their Cause only through the Platform’s features, and may not use the data received for any purpose other than that for which the Support was given.
4.5. The Creator’s measurement tools. The Creator may add their own measurement tools to their Cause page. Those tools are not Causfy’s: the Creator determines the purpose for which they are used and is answerable for that processing. Loading them requires the User’s prior consent and is set out in the Cookie Policy.
Disclosure to third parties
5.1. Providers. Data is accessed by the providers involved in delivering the service, in the following categories: hosting, databases, sending messages, file storage, content delivery, identity verification, fraud prevention, payment services and the provision of AI-assisted features. They act on behalf of the controller, on its instructions, and may not use the data for their own purposes. The identity of the providers is given on request.
5.2. Payment services. The data needed to make a payment is processed directly by the payment service providers under their own policies. They are Stripe, Inc. and Bridge, part of the same group. Causfy neither receives nor keeps card details or bank credentials: only confirmation that the transaction took place and its amount.
5.3. Cause Creators. As set out in the section on the public nature of Causes.
5.4. Authorities. Where required under a rule or a decision.
5.5. Corporate transactions. In the event of a merger, acquisition or transfer of the business, with prior notice to the User.
5.6. Personal data is not sold. The use of measurement or third-party tools is conditional on the User’s prior consent and is governed by the Cookie Policy.
Where the data is held
6.1. Data is hosted in the European Union.
6.2. Certain providers may process data outside the European Economic Area. Where that happens, the transfer relies on recognised safeguards providing equivalent protection, details of which are given on request.
Retention periods
7.1. Data is kept for as long as necessary for the purpose for which it was collected and, thereafter, for the periods required.
7.2. Applicable periods:
| Data | Period |
|---|---|
| Account data | while the Account is active and 30 days after closure |
| Support started and not confirmed | 24 hours |
| Email address linked to a Signature | 30 days, unless consent has been given to receive messages |
| Published content | while the Cause remains published |
| Security and activity logs | 12 months |
| Accounting and company records | 6 years |
| Records of tax relevance | 4 years |
Erasure and its exceptions
8.1. Closing the Account. A closure request means the Account is deactivated immediately and access ends. Erasure of the associated data is completed within the period set out above.
8.2. Data that cannot be erased immediately. Data that must be kept to comply with a legal obligation or to bring, exercise or defend claims is excepted from erasure. Such data is blocked: kept out of all use and available only to courts and competent authorities, for as long as those liabilities may be pursued.
8.3. Record of Signatures. The permanent entry linked to a Signature cannot be erased. That entry contains no personal data and identifies no one, so its permanence does not affect the signatory’s right to erasure.
8.4. Withdrawing a Signature. The signatory may withdraw their Signature at any time, and it is then excluded from the count.
Your rights
9.1. The User may request access to their data, its rectification, its erasure, restriction of processing, portability and objection to processing, and may withdraw consent given, without affecting the lawfulness of processing carried out beforehand.
9.2. Unsubscribing from messages can be done directly from the link included in each one.
9.3. Requests are sent to the data protection mailbox. Exercising these rights is free and a reply is given within one month, extendable by a further two months where the complexity or number of requests so requires, with prior notice to the applicant.
9.4. Proof of identity will be requested only where there is reasonable doubt as to the identity of the applicant.
9.5. Complaint to the authority. The User may lodge a complaint with the competent data protection authority. In Spain this is the Agencia Española de Protección de Datos.
Minors
10.1. The Services are aimed at people over eighteen years of age.
10.2. Age is established by the User’s own declaration, with no further checks.
10.3. Where processing of a minor’s data is identified, it is erased. This can be reported to the data protection mailbox.
Security
11.1. Encryption keys are held in a system separate from the database.
11.2. Sensitive operations require a second authentication factor.
11.3. Account access does not use passwords: it is done with a one-time code sent to the email address or with the device passkey.
11.4. Data that allows recognition without identification is kept in derived form.
11.5. Internal access to data is limited to staff who need it to do their job.
11.6. Security breaches. Where a security breach occurs that entails a risk to the rights of data subjects, it will be notified to the supervisory authority within 72 hours of becoming known and, where the risk is high, also communicated to those affected without undue delay.
Final provisions
12.1. Cookies. The storage devices used on the Platform are described in the Cookie Policy, which forms part of this one.
12.2. Changes. This Policy may be amended. The date of the last revision appears in the header. Where a change affects processing based on consent, it will be notified to the data subject in advance and consent will be sought again.
12.3. Additional information depending on where the User lives. In the European Union, the European Economic Area, the United Kingdom and Switzerland, this Policy applies and the User may contact the supervisory authority of their country of residence. In other territories the same regime described here applies to all Users; where the law of the country of residence grants additional rights, these will be honoured by writing to the data protection mailbox.
12.4. Identification of the controller.
CAUSFY GLOBAL TECHNOLOGIES, S.L.
NIF B88744602
C/ Princesa 31, planta 2, puerta 2, 28008 Madrid, España
Registro Mercantil de Madrid, Hoja M-888274, Inscripción 1
- Data protection: