Privacy Policy
Last updated: 12 August 2026
1. Controller
The controller responsible for the processing of personal data described in this policy is:
Andras Schmidt EG
Sonnenalpe Nassfeld 123
9620 Hermagor-Pressegger See, Austria
VAT ID: ATU82393116
Email: hello@cataloo.com
2. Scope
This policy covers the cataloo website (cataloo.com) and the cataloo web application, together referred to as the “Service”. It explains what personal data we process, why, on what legal basis, how long we keep it, and which rights you have under the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
3. Data we process
Account data. Email address, password hash (or Google sign-in identifier), display name, preferred language, and the workspaces you belong to. Required to create and secure your account.
Company and quotation branding. Company name, address, VAT number, logo and quote layout settings you enter to appear on exported quotations.
Customer content. Product catalogs, bills of materials and quantities, projects, quotations, prices, margins, discounts and webshop connection settings that you or your team members upload or create. This content may itself contain personal data (for example a customer contact name on a quotation); in that case you are the controller and we act as processor on your behalf.
Billing data. Credit purchases, amounts, invoice references and the billing email held by our payment provider. We never receive or store full card numbers.
Technical data. IP address, browser and device information, timestamps and error diagnostics generated when you use the Service.
4. Purposes and legal bases
- Providing the Service, your workspaces and your exports — performance of a contract (Art. 6(1)(b) GDPR).
- Processing credit purchases, refunds and invoicing — performance of a contract and legal obligation (Art. 6(1)(b) and (c) GDPR).
- Security, abuse prevention, error monitoring and service improvement — legitimate interests (Art. 6(1)(f) GDPR).
- Service and transactional emails such as team invitations, password resets and purchase confirmations — performance of a contract (Art. 6(1)(b) GDPR).
- Any optional product or marketing emails — consent (Art. 6(1)(a) GDPR), withdrawable at any time via the unsubscribe link.
5. Sharing within a workspace
cataloo is a collaborative product. Catalogs, projects, quotations, credit balances and company branding are scoped to a workspace and are visible to every member of that workspace. Workspace owners can invite and remove members and can see the workspace’s purchase history. Do not place personal data in a workspace that its members should not see.
6. Processors and recipients
We use a small number of carefully selected service providers who process data on our behalf under Art. 28 GDPR data processing agreements:
- Application hosting and content delivery (edge hosting provider).
- Managed database, authentication and file storage (EU-hosted infrastructure provider).
- Payment processing and invoicing (Stripe).
- Transactional email delivery.
- Exchange-rate lookups for multi-currency pricing (public rate API; no personal data sent).
Where a provider processes data outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses and supplementary safeguards. We do not sell personal data, and we do not use your customer content to train machine-learning models for other customers.
7. Cookies and local storage
We use strictly necessary cookies and browser local storage to keep you signed in and to remember your active workspace and language preference. These are required for the Service to function and are not used for advertising. If we ever add analytics or marketing cookies, we will ask for your consent first.
8. Retention
Account and workspace data is retained for as long as your account exists. When you delete your account, personal data is deleted or irreversibly anonymised within 30 days, except where a longer period is required by law — in particular invoices and accounting records, which are retained for seven years under Austrian tax law. Backups are rotated and expire within 30 days.
9. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time with effect for the future. To exercise any of these rights, contact hello@cataloo.com — we respond within one month.
You also have the right to lodge a complaint with a supervisory authority. The competent authority for us is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at).
10. Security
Data is transmitted over TLS, stored encrypted at rest, and access is restricted by row-level security so that workspace data is only reachable by that workspace’s members. Administrative access is limited to what is necessary to operate and support the Service.
11. Changes
We may update this policy as the Service evolves. Material changes will be announced in the application or by email before they take effect. The date above indicates the current version.