Skip to content

Standing terms · published in full · superseded only by your signed agreement

Vol. I · No. 131RahotoFrankfurt · EU-hosted

“The terms, published in full.”

Standing terms

Privacy Policy

What personal data Rahoto collects, why, how long we keep it, and the rights you have over it.

Last reviewed
2026-08-28

This document is a working template provided for transparency during evaluation. The binding version is the one referenced in your signed agreement. For the executed copy, contact[email protected].

This Policy explains how Rahoto handles personal data. We are an EU-hosted service and process personal data in line with the GDPR. Where we process data on your behalf as a processor, the Data Processing Agreement governs that processing.

1. Data we collect

  • Account data — name, work email, organisation, authentication identifiers.
  • Usage data — feature usage, audit events, and diagnostics used to operate and secure the Service.
  • Customer Data — the data you connect and the reports you build. We process this only to provide the Service.
  • Billing data — handled by our payment processor; we do not store full card numbers.

Published-report viewers

Customers choose between gated reports and certified anonymous static releases. Gated reports use password, authenticated, or SSO access. Anonymous public or unlisted reports can be opened by anyone who obtains the URL. They do not expose source rows, report configuration, or live-query services.

We process limited viewer security data, such as IP address, user agent, request time, rate-limit events, and audit events, to deliver and secure a release, investigate abuse, and support expiry or revocation. The customer is the controller for report content and its audience decision; Rahoto acts on that publishing instruction as processor. Rahoto is controller for the security data it independently uses to protect the Service.

Anonymous releases use no-index and no-store controls to reduce unintended exposure, but those controls are not access restrictions and cannot prevent screenshots or every third-party cache or archive. Customers must use a gated report for personal, confidential, restricted, or uncertain content.

2. Why we process it

To provide and secure the Service, to bill paid plans, to communicate about your account, and to meet legal obligations. We do not sell personal data and do not use Customer Data to train models.

3. Where it lives

Primary infrastructure is hosted in the EU. Enterprise plans can pin data residency by region. Sub-processors that may handle data are listed on thesub-processor page.

4. Retention

Account data is retained while your account is active. Audit logs are retained per your plan's compliance settings. Closure and erasure of a self-serve account follow the lifecycle in section 5.

5. Account closure and erasure

When you close your account, the account is deactivated immediately: active sessions are revoked and any paid subscription is cancelled so no further billing occurs.

Closure is followed by a 30-day grace period. During this window the account can be restored by logging back in; restoring reactivates the account and cancels the pending erasure.

After the grace period ends, personal data is erased: identifying fields are anonymised, the email address is released so it may be reused, and the encryption keys protecting your data are destroyed (crypto-shred), rendering the underlying data unrecoverable. A minimal, append-only record of the erasure itself, sufficient to evidence that it occurred and when, is retained as required by law.

Where you contributed content to shared documents owned by others(for example reports, comments, or edits in an organisation or team you belonged to), that content is de-attributed on erasure: your authorship is removed so the contribution is no longer linked to you, but the document content itself survives for the other people who rely on it. Erasing your account does not delete documents owned by other users or organisations.

Statutory records that we are legally required to keep, such as invoices and billing records, are retained for the period required by applicable law at the organisation level, separately from the erased personal data — this is the legal-obligation exemption to erasure under Article 17(3) of the UK GDPR. Where a legal hold applies to an account, erasure is paused for the duration of that hold.

6. Your rights

Subject to applicable law you may access, correct, export, or delete your personal data, and object to or restrict certain processing. To exercise these rights, contact [email protected].

7. Security

We apply encryption in transit and at rest, role-based access, row-level security, and an append-only, hash-chained audit log. Enterprise plans add customer-managed encryption keys. See the Trust Centerfor detail.

8. Cookies

This marketing site uses strictly-necessary cookies and no third-party tracker. If you opt into Analytics, Rahoto records anonymous page-view and selected CTA events without an analytics cookie, session identifier, IP address, user agent, or referrer. Nothing non-essential runs without your consent, and DNT/GPC signals are honoured. For the full event fields, retention, and how to control or withdraw consent, see theCookies Policy.

9. Contact

Privacy questions or requests: [email protected].