Privacy Policy
- 1. Controller, scope and contact
- 2. How responsibilities are divided
- 3. Personal data DT processes and where it comes from
- 4. Purposes and legal bases
- 5. Recipients and disclosure
- 6. International transfers
- 7. Retention
- 8. Security
- 9. Rights of individuals
- 10. Required and optional data; communications
- 11. Cookies and similar technologies
- 12. Changes and related documents
On this page
- 1. Controller, scope and contact
- 2. How responsibilities are divided
- 3. Personal data DT processes and where it comes from
- 4. Purposes and legal bases
- 5. Recipients and disclosure
- 6. International transfers
- 7. Retention
- 8. Security
- 9. Rights of individuals
- 10. Required and optional data; communications
- 11. Cookies and similar technologies
- 12. Changes and related documents
Rules for processing personal and telemetry data of Data Tools s.r.o.
(Personal Data and Telemetry)
Effective date: September 1st 2026
This Rules for processing personal and telemetry data (hereinafter as “Privacy Policy”) explains how Data Tools s.r.o. processes personal data in connection with the CAT Software, the CAT Portal, the CAT website and related support. It supplements the CAT Software Licence Terms and Conditions of Use (the “Terms”).
1. Controller, scope and contact
Controller: Data Tools s.r.o., Company ID: 19386788, with its registered office at V Přístavu 1585/10, 170 00 Prague 7, Czech Republic, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, Entry 385814/MSPH (“DT”).
Privacy contact: hello@justcat.it, or the postal address above.
Scope. This Policy applies to natural persons who visit www.justcat.it (the “CAT Web”), use portal.justcat.it (the “Portal”), create or administer an account, obtain or use a CAT Software plan, are assigned a Seat, download, install, access or use the CAT Software, or communicate with DT. “Customer”, “Authorised User” and “User” have the meanings given in the Terms. Separately negotiated or Enterprise arrangements may contain additional privacy terms.
Applicable law. DT processes personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”), Act No. 110/2019 Coll., on Personal Data Processing, and other applicable data protection and electronic communications laws.
2. How responsibilities are divided
2.1 Paddle transactions
Paid online purchases are made from the relevant Paddle entity, which acts as DT’s authorised reseller and merchant of record (“Paddle”). Paddle independently determines how it processes data for checkout, payment methods, charging, tax, receipts and invoices, recurring billing, subscription administration, cancellations, statutory withdrawal rights and refunds. Paddle’s processing is governed by its own privacy notice at https://www.paddle.com/legal/privacy. DT may receive limited order, buyer, entitlement and subscription-status information from Paddle to activate and administer the Licence and provide product support. Complete payment-card details are handled by Paddle and are not required by DT for these purposes.
2.2 Customer and account administration
Where an organisation obtains or administers a plan, its administrators may provide DT with an Authorised User’s details, assign or reassign Seats, and view or manage account, Seat and entitlement information. The organisation remains independently responsible for its own processing of personal data in its employment, contractor or other relationship with the Authorised User.
2.3 CAT Pilot and third-party AI providers
CAT Pilot is optional and is disabled unless the User configures and uses it with the User’s own account at a selected third-party AI provider. CAT Pilot communications are sent directly between the User’s environment and that provider and do not pass through the Portal or DT’s servers. DT does not receive the content of CAT Pilot prompts or conversations. The selected provider processes data under its own terms and privacy policy. DT’s standard telemetry may record that CAT Pilot was used and technical details of that use, but not the conversation content.
2.4 Data used in tests and Customer content
The Terms permit the User to use CAT Software with test, development or production data. The Customer and User are responsible for having the rights, permissions and legal bases required for those data. This Policy does not authorise the disclosure of personal data to DT. If a User voluntarily provides logs, files, screenshots, sample data or other content to DT for support, DT processes that material only as necessary to handle the request, protect security, comply with law and establish or defend legal claims.
3. Personal data DT processes and where it comes from
Depending on the User’s relationship and use of CAT, DT may process the following categories. Telemetry and technical information are personal data only to the extent that they identify or can reasonably be linked to an individual.
• Account and contact data: name, surname, business or organisation name, role, email address, telephone number, postal or registered-office address, country, preferred language, account identifier, and other information the User or Customer provides when registering, administering an account or contacting DT.
• Authentication and security data: sign-in credentials in a protected form, login and session information, IP address, device and browser information, dates and times of access, security events, suspected compromise, and records needed to protect Accounts and Seats.
• Licence, plan and Seat data: the applicable plan, Customer and Authorised User relationship, Seat assignment and reassignment, Licence or entitlement identifiers, Licence status, installation or activation information, technical usage limits and compliance records.
• Paddle transaction and subscription data: to the extent made available by Paddle, buyer and business contact details, Paddle customer, transaction and subscription identifiers, plan, billing cycle, currency, transaction and subscription status, tax or business information, cancellation or refund status, and related correspondence. DT does not require complete payment-card details.
• Telemetry and product-usage data: Licence or account identifier; CAT version and relevant technical environment; functions used and frequency of use; type and number of tests; time of launching a test; whether a test ended successfully or with an error; type of test data source or data-source technology; type of output; indicators relevant to interactive or Autonomous Runs, authentication, plan limits and technical controls; and technical information that CAT Pilot was used. Telemetry may contain also other information that may help DT to improve its products. Telemetry never contains test names, test queries, data structures or customer’s data. Telemetry may contain ID of user account or ID of license key. Standard CAT Pilot telemetry does not include prompt or conversation content.
• Support and communications data: support requests, complaints, defect reports, emails, call or meeting notes, diagnostic information and any materials the User chooses to provide.
• Marketing and preference data: subscription to product news, communication preferences, consents, objections and opt-out records, and, where applicable, information generated by cookies or similar technologies on the CAT Web or Portal.
Sources. DT obtains these data directly from the User, from the Customer or an account administrator, automatically from the Portal or CAT Software, CAT Portal, from Paddle for transaction and entitlement administration, and from DT’s own records of communications and use of the services.
4. Purposes and legal bases
DT processes personal data only where there is a legal basis. The main purposes and bases are set out below. More than one basis may apply depending on whether the data subject is the Customer, its representative or an Authorised User.
| Purpose | Main legal basis |
|---|---|
| Create and administer Accounts and Seats; authenticate Users; grant, maintain and terminate the Licence; make CAT Software and the Portal available; and provide the functions described in the Terms and Documentation. | Performance of a contract or steps requested before a contract (Article 6(1)(b) GDPR). For representatives and Authorised Users who are not personally party to the contract: DT’s and the Customer’s legitimate interests in administering the plan and providing access (Article 6(1)(f)). |
| Receive and reconcile Paddle transaction, subscription and entitlement status; enable paid access; respond to product-related issues and support cancellation or refund requests handled by Paddle. | Contract performance (Article 6(1)(b)) and legitimate interests in coordinating the separate transaction and Licence arrangements (Article 6(1)(f)). |
| Protect Accounts, Users, CAT Software and the Portal; detect fraud, credential sharing, abuse, circumvention, security threats and non-compliance with Seat, plan, authentication or Autonomous Run controls; investigate incidents. | Legitimate interests in security, fraud prevention, service integrity and enforcement of the Terms (Article 6(1)(f)); compliance with legal obligations where applicable (Article 6(1)(c)). |
| Provide technical and customer support; diagnose reported problems using information provided by the User; handle complaints, defects and legal notices. | Contract performance (Article 6(1)(b)); legal obligations, including mandatory consumer rights (Article 6(1)(c)); legitimate interests in support and dispute resolution (Article 6(1)(f)). |
| Analyse telemetry and product usage; maintain, secure, test, improve and develop CAT Software; understand adoption of functions and technical performance; prepare aggregated statistics. | Legitimate interests in operating, securing and improving CAT Software and planning product development (Article 6(1)(f)). Where applicable law requires consent for non-essential access to or storage of information on a device, DT relies on consent (Article 6(1)(a)). |
| Maintain business, contract, compliance, accounting and audit records; respond to authorities; establish, exercise or defend legal claims. | Compliance with legal obligations (Article 6(1)(c)) and legitimate interests in record-keeping and the protection of legal rights (Article 6(1)(f)). |
| Send product news, offers and similar direct marketing, and maintain opt-out or suppression records. | Consent (Article 6(1)(a)) or legitimate interests where direct marketing is permitted without consent (Article 6(1)(f)), in each case subject to applicable electronic marketing rules and the right to object or unsubscribe at any time. |
Legitimate interests. Where DT relies on legitimate interests, it considers the nature of the data, the reasonable expectations of Users, the necessity of the processing and its impact on individuals, and applies appropriate safeguards. A User may object as described in Section 9.
5. Recipients and disclosure
DT discloses personal data only as reasonably necessary for the purposes above, subject to confidentiality, access controls and contractual safeguards where required. Recipients may include:
• DT personnel and contractors who need the data for their work;
• cloud, hosting, storage, authentication, cybersecurity, communications, customer-support and IT providers, including Microsoft Azure where used;
• Paddle, as an independent controller for the transaction and subscription functions described above;
• the Customer and its authorised administrators in relation to Account, Seat and entitlement administration;
• professional advisers, auditors, insurers and prospective or actual parties to a corporate transaction, subject to appropriate safeguards; and
• courts, regulators, law-enforcement bodies and other public authorities where disclosure is required or permitted by law.
The selected third-party AI provider receives CAT Pilot content directly from the User’s environment, not from DT. Users should review the provider’s privacy terms before activating CAT Pilot.
6. International transfers
Some recipients or systems may be located outside the European Economic Area. Where personal data are transferred to a country that is not recognised as providing an adequate level of protection, DT uses an appropriate transfer mechanism, such as the European Commission’s standard contractual clauses, together with supplementary safeguards where necessary, or relies on another lawful derogation or transfer basis. Information about the applicable safeguard may be requested at hello@justcat.it. Paddle and a selected AI provider apply their own international-transfer arrangements under their respective privacy notices.
7. Retention
DT retains personal data only for as long as reasonably necessary for the relevant purpose, taking account of the duration of the Account, Licence and Customer relationship, security needs, legal obligations, limitation periods and pending complaints, investigations or claims. In particular:
• Account, contact, Licence, Seat and entitlement data are generally kept while the relevant Account or relationship is active and afterwards only as required for security, legal compliance, audit and legal claims.
• Paddle transaction and subscription-status data received by DT are kept for entitlement administration, support and the periods required for DT’s legal or evidentiary needs; Paddle applies its own retention periods to transaction data it controls.
• Support and complaint records are kept for the time needed to resolve the matter and for a reasonable period afterwards to document the response and protect legal rights.
• Telemetry linked to an identifiable Account may be kept during the relevant relationship and for a limited period afterwards where necessary for security, compliance, support or claims. DT may retain aggregated or effectively anonymised telemetry for product development and statistics.
• Marketing data are kept until consent is withdrawn or the User objects or unsubscribes. A minimal suppression record may be retained to ensure that the preference continues to be respected.
• Records required by accounting, tax, corporate or other law are kept for the statutory retention period.
When personal data are no longer needed, DT deletes them, anonymises them or isolates them from ordinary use, unless continued retention is required by law.
8. Security
DT uses appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected according to the nature of the data and the relevant risks and may include access controls, authentication, logging, encryption or pseudonymisation where appropriate, backup, supplier controls and incident-response procedures. No system can be guaranteed to be completely secure. Users must protect their credentials and promptly notify DT of suspected compromise.
9. Rights of individuals
Subject to the conditions and exceptions in applicable law, an individual may request:
• access to personal data and information about their processing;
• rectification of inaccurate or incomplete data;
• erasure of personal data;
• restriction of processing;
• data portability where processing is based on consent or contract and carried out by automated means;
• withdrawal of consent at any time, without affecting processing already carried out; and
• objection to processing based on legitimate interests. An objection to direct marketing will be honoured without requiring further grounds.
Requests to DT may be sent to hello@justcat.it or to DT’s registered office. DT may need to verify identity and may request information necessary to locate the relevant data. DT responds without undue delay and generally within one month; this period may be extended by up to two further months where permitted by the GDPR, with notice of the reason for the extension.
Rights concerning transaction and billing data controlled by Paddle should be exercised directly with Paddle under its privacy notice. Rights concerning data sent to a selected AI provider should be exercised with that provider.
Complaint. An individual may lodge a complaint with the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, https://uoou.gov.cz, or with another competent supervisory authority, particularly in the country of habitual residence, place of work or alleged infringement.
10. Required and optional data; communications
Data needed to create an Account, authenticate a User, assign a Seat, verify entitlement, provide a paid plan or comply with law are required for those purposes. If they are not provided or are inaccurate, DT may be unable to create or maintain the Account or provide access and support. Marketing data and optional profile information are voluntary and are not a condition of the Licence. Each marketing message will provide an unsubscribe method where required. Technical or contractual service messages, security notices and communications necessary to administer an active Account or Licence are not marketing and may still be sent.
11. Cookies and similar technologies
The CAT Web and Portal may use technologies that are necessary to operate, authenticate and secure the service. Where optional analytics or marketing technologies are used and applicable law requires consent, they will be activated on the basis of the User’s choice. Available controls and more detailed information are provided through the relevant cookie notice or preference mechanism, where implemented.
12. Changes and related documents
DT may update this Policy to reflect changes in CAT Software, the Portal, legal requirements or processing practices. The current version will be published at https://docs.justcat.it/docs/privacy-policy. Where a change materially affects Users, DT will provide additional notice where required by law or reasonably appropriate.
Related documents: CAT Software Licence Terms; Paddle Buyer Terms; Paddle Refund Policy; and Paddle Privacy Notice.
Data Tools s.r.o.