Privacy Policy — Causa Prima

Last updated: 2026-08-27

This Privacy Policy explains how Causa Prima Germany GmbH, registered with the commercial register of the Local Court (Amtsgericht) of Berlin-Charlottenburg under HRB 286382 B, with registered seat in Berlin ("Causa Prima", "we", "us"), processes personal data in connection with our agentic-AI product for finance teams at app.causaprima.ai (the "Service").

1. Controller and contact

Causa Prima Germany GmbH Leopoldstraße 31, 80802 Munich, Germany (business address) Geschäftsführer: Philip Stanislaus E-mail: security@causaprima.ai

We have not appointed a data protection officer; data-protection questions reach us at the e-mail address above.

2. Scope

This Policy covers the Service at app.causaprima.ai only. Our corporate website at causaprima.ai has its own privacy notice at causaprima.ai/privacy, and our other products (Byll, Scribo) have their own policies on those products' websites.

The Service is a B2B product. We do not intentionally process special categories of personal data (Art. 9 GDPR) or criminal-offence data (Art. 10 GDPR); please do not upload such data to the Service.

3. Data we process

  • Account and login data — name, work e-mail, organization, authentication identifiers and login timestamps. Sign-in runs on the Ory identity stack (OAuth2/OIDC); the session and organization-selection cookies this sets are listed in §13.
  • Service-usage data — actions you take in the Service (prompts, inputs, agent runs, outputs you create or save), session and device metadata, IP address, browser/OS.
  • Customer content — files, documents, transactional and financial records that you or your colleagues upload to or create in the Service for processing by our AI agents.
  • Connected Source Data — data we retrieve from sources you choose to connect to the Service, and anything we derive from that data. For Google connections: Gmail — message content, attachments and message headers/metadata; Google Drive — file content and file metadata, on a read-only basis. Details, including the exact permissions we request, are in §4.
  • Support and communication data — e-mails and support conversations with us.
  • Billing data — billing contact, invoice references and payment metadata (no card numbers; payment processing is handled by our payment provider).
  • Error diagnostics — if you consent (§13), sanitized reports about unexpected errors in the app.

Account data and customer content are necessary to use the Service. Connecting Gmail or Drive is optional — without a connection, the features that rely on it are simply unavailable. Error diagnostics are optional and off by default.

4. Connected sources

The Service connects to third-party accounts only when you (or your organization) choose to connect them (§3). Every connection runs through the source platform's own authorization flow, which shows you the exact permissions requested before you approve them; we request only the permissions the relevant features need, and you can disconnect at any time (see "Disconnecting" below).

Google (Gmail and Google Drive). If you connect a Google account, we request the following OAuth scopes — and no others:

ScopeWhat it allowsWhy we request it
openid, email, profileBasic identity of the Google account you connectTo confirm which account is connected and show it to you
https://www.googleapis.com/auth/gmail.readonlyRead-only access to your Gmail messages and attachmentsTo find and import financial documents (e.g. invoices and receipts) and their context into your workspace
https://www.googleapis.com/auth/gmail.sendSending e-mail from your Gmail addressRequested during onboarding, for features of the Service that send e-mail on your behalf at your instruction
https://www.googleapis.com/auth/drive.readonlyRead-only access to your Google Drive files and metadataTo import financial documents you keep in Drive into your workspace

The standalone inbox-connection flow requests only gmail.readonly — it never requests send or modify permissions. For Drive we request read-only access only: the Service never asks for permission to write to your Drive, and if a grant ever includes a write-capable Drive scope, the connection is rejected rather than enabled.

How we use Google user data. We use data obtained through Google Workspace APIs solely to provide the user-facing features described above, at your direction. Causa Prima's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

AI/ML. We do not use Google Workspace API data — including raw, aggregated, anonymized, or derived data — to develop, improve, or train generalized or non-personalized AI and/or machine-learning models. Data received via Google Workspace APIs never enters any cross-customer training pipeline in any form; the treatment of other connected sources is described in §7.

Human access. Our personnel do not read Connected Source Data — including your Google user data — except: (a) with your explicit consent (e.g. to help resolve a support request on specific data); (b) where necessary for security purposes, such as investigating abuse; (c) to comply with applicable law; or (d) for internal operations, where the data has been aggregated and anonymized.

What we never do. We do not sell Connected Source Data (including Google user data) or any other personal data. We do not transfer it to advertising platforms, data brokers or information resellers, and we do not use it to determine credit-worthiness or for lending purposes.

Disconnecting. You can disconnect any connected source in the Service at any time. For Google accounts, you can additionally revoke Causa Prima's access in your Google Account security settings (myaccount.google.com/permissions). Data already imported into your workspace remains subject to §10 and your organization's instructions under the DPA.

5. Purposes and legal bases

PurposeLegal basis (GDPR)
Providing and operating the Service, including running AI agents on your inputsArt. 6(1)(b) — contract performance
Retrieving and processing Connected Source Data from sources you connectArt. 6(1)(b); within a customer workspace, on the customer's instructions under the DPA
Account creation, authentication and access controlArt. 6(1)(b)
Communicating with you about your account, support and incidentsArt. 6(1)(b) and Art. 6(1)(f) — legitimate interests in customer communication
Security, abuse prevention and audit loggingArt. 6(1)(f) — legitimate interests in securing the Service
Billing, invoicing and statutory record-keepingArt. 6(1)(c) — legal obligation (HGB, AO); Art. 6(1)(b)
Producing anonymised data for Service improvement and model training (§7)Art. 6(1)(f) — legitimate interests in improving the Service and developing our technology; within a customer workspace, on the customer's instructions under the DPA
Error diagnostics (consent-gated, §13)Art. 6(1)(a) and §25(1) TDDDG

Processing on behalf of customers. When a customer organization uses the Service, the customer is the controller of the personal data processed within its workspace (including end-user identifiers, customer content and Connected Source Data). Causa Prima acts as processor on the customer's documented instructions under the Causa Prima Data Processing Agreement (the "DPA", app.causaprima.ai/dpa). End-users should direct data-subject requests concerning workspace data to the relevant customer; we support our customers in responding.

6. AI features and automated decision-making

The Service uses third-party large-language-model ("LLM") providers to deliver agentic AI features (see the sub-processor list, §8). User inputs, agent context and intermediate outputs may be sent to these providers for inference. The LLM providers we use are contractually barred from using identifiable customer data to train or fine-tune their models, and may not retain content sent for inference for their own purposes — apart from their own security and billing records and anything the law requires them to keep; where a provider offers a zero-data-retention configuration, we use it.

AI outputs are probabilistic and may be inaccurate. They are provided for informational purposes only and do not constitute legal, tax, accounting, investment or other professional advice. The Service is designed for human-in-the-loop use: users are expected to review AI outputs before relying on them for material decisions, financial reporting or external communication. The Service does not make decisions that produce legal effects concerning you or similarly significantly affect you without human review within the meaning of Art. 22 GDPR.

7. Training on customer data

We never train foundational or general-purpose AI models on identifiable customer data.

We do train and improve our Services and AI models across customers — during and after a customer engagement — but only on anonymised data: before any customer data is used outside your organization's workspace or combined with other customers' data, it is anonymised under a documented method (available on request), as governed by the DPA, so that it no longer identifies any individual and is no longer attributable to your organization, measured against the GDPR's anonymity standard (Article 4(1) and Recital 26). Anything that falls short of that standard remains personal data and stays inside the DPA's retention and deletion rules. Because such anonymised data identifies neither a person nor a customer, it may be retained and used after the engagement ends. Where the terms of a connected source restrict how data obtained through it may be used, those restrictions prevail; for data obtained via Google Workspace APIs the exclusion is absolute — that data never enters any cross-customer training pipeline in any form, and no addendum can change that. Learning specific to your organization stays within your organization's instance and is never shared with other customers.

8. Recipients and sub-processors

We share personal data with:

  • Sub-processors — listed, with legal entity, country, purpose and safeguard, at trust.causaprima.ai. Engagement of sub-processors, notice of changes and your organization's right to object are governed by the DPA.
  • Tax and statutory authorities — where we are legally required to disclose.
  • Professional advisers — lawyers, auditors, accountants, where necessary and under confidentiality obligations.
  • Acquirers — in connection with a merger, reorganisation or sale of all or substantially all of our assets.

We do not sell personal data and do not disclose personal data to advertising networks, data brokers or information resellers.

9. International transfers

On our own infrastructure, customer content is stored and processed in Google Cloud regions in the European Union (primary region: europe-west1, Belgium). Our data protection standards also permit processing on our own infrastructure in the United States; we do not process customer content there today, and before any such processing begins we will update this Policy and the locations disclosed on our sub-processor list, and the safeguards below will apply to it. Processing by our sub-processors is separate: some of them process customer content outside the EU/EEA, including in the United States, as set out below.

Some of our sub-processors process personal data outside the EU/EEA; each sub-processor's processing location is published on our sub-processor list at trust.causaprima.ai. Where a transfer of personal data to a country outside the EU/EEA does occur, it is identified there together with the applicable safeguard, and we rely on:

(a) an adequacy decision of the European Commission, where available; (b) the EU Standard Contractual Clauses 2021/914 in the appropriate module, supplemented by a transfer impact assessment; (c) the EU–US Data Privacy Framework, where the recipient is certified.

For transfers we make ourselves, Standard Contractual Clauses are the primary mechanism, with adequacy decisions relied on as additional comfort.

10. Retention

We retain personal data only as long as necessary for the purposes in §5, and in any event:

  • Customer content — for the duration of the customer contract; deleted — or returned at your organization's choice under the DPA — within 30 days after termination, deleted by default. Anonymised data (§7) that identifies neither any individual nor your organization is not customer content and is outside this deletion.
  • Account data — for the duration of the customer contract and deleted within 30 days after termination, except where the records below must be kept for longer. Account and billing records we process as controller (DPA clause 2.2) are outside the DPA's delete-or-return election.
  • Records we must keep by law — invoices and supporting accounting documents for 8 years; accounting books, balance sheets and financial statements for 10 years (§ 147 AO, § 257 HGB, from the end of the calendar year of creation).
  • Logs — infrastructure audit logs (Google Cloud) for 400 days; application logs for 30 days. Application-level security and audit records (append-only, containing only pseudonymous identifiers) are retained for as long as necessary to preserve the security and integrity of the Service.
  • Backups — deleted data leaves the backups through a standard rolling backup cycle.

Where we process workspace data as processor, deletion and return at contract end follow the DPA.

11. Security

We implement technical and organisational measures appropriate to the risk to protect personal data — including data we access on your authorisation, such as messages retrieved from a connected mailbox or files from a connected drive — against unauthorised access, loss, misuse or disclosure (Art. 32 GDPR). These measures include:

  • Encryption in transit — connections between your device and the Service, and between the Service and our sub-processors, are encrypted using TLS.
  • Encryption at rest — personal data in production databases and object storage, including backups, is encrypted.
  • Access control — authentication is passwordless-first (Single Sign-On, passkeys); multi-factor authentication or an equivalently strong passwordless method is required for all access to our systems, including by administrators. Access to personal data follows least privilege through role-based access control, is reviewed regularly and revoked promptly on role change or departure.
  • No standing production access — nobody holds permanent administrative access to production systems; such access is approved for a specific purpose and period and is logged.
  • Tenant separation — customer data is separated per tenant and the separation is enforced at the database layer: every tenant-scoped table carries PostgreSQL row-level-security policies that are forced for all roles, so queries only ever see the current tenant's rows. Production, staging and development environments are kept separate.
  • Data minimization in logging — our logging framework is designed to keep personal data out of logs: log call sites accept only typed, opaque identifiers (no names, e-mail addresses or IP addresses in log fields), a rule enforced through code review.
  • Logging and monitoring — security- and access-relevant events are logged (retention periods in §10) and reviewed both in response to incidents and on a regular basis.
  • Certified cloud hosting — we do not operate our own data centres; production data is hosted on Google Cloud Platform, which is certified against ISO/IEC 27001 and audited under SOC 2.

Security-related enquiries reach us at security@causaprima.ai. A fuller description of our measures is set out in the technical and organisational measures annexed to the DPA.

12. Your rights

Under the GDPR you have the rights to:

  • access your personal data (Art. 15);
  • rectification (Art. 16);
  • erasure / "right to be forgotten" (Art. 17);
  • restriction of processing (Art. 18);
  • data portability (Art. 20);
  • object to processing based on legitimate interests (Art. 21);
  • withdraw consent at any time, where processing is based on consent (Art. 7(3)) — withdrawal does not affect the lawfulness of processing before withdrawal.

To exercise these rights, contact us at security@causaprima.ai. We respond without undue delay and in any event within one month. Where your personal data is processed inside a customer's workspace, your organization is the controller (§5) — direct your request there first; we will support the response.

You also have the right to lodge a complaint with a data-protection supervisory authority. The competent authority for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin, where we have our registered seat); you may also complain to any other competent authority, including the one in the EU member state of your residence or workplace.

13. Cookies and similar technologies

The Service uses a small number of cookies and similar technologies, grouped into three categories. A consent banner lets you accept or decline each optional category, and you can change your choice at any time in our Cookie Policy at app.causaprima.ai/cookies, which also lists the specific cookies and technologies in each category; your choice is stored on your device.

  • Strictly necessary — always active; required for the Service to function: session and sign-in (cp_web_session), your organization selection (cp_active_org), security, load-balancing, and your consent state. Set on the basis of §25(2) TDDDG; no consent required.
  • Functional — off by default; user-experience preferences that improve but are not essential to the Service. Set only with your consent (§25(1) TDDDG, Art. 6(1)(a) GDPR).
  • Analytics — off by default; if you consent, we use PostHog (EU-hosted) to report unexpected errors in the app so we can fix them. No page tracking, no session replay, no advertising — and error reports are sanitized before sending so that they do not contain personal data.

14. Data sources and changes to this Policy

Where your data comes from (Art. 14 GDPR). Most personal data we process is provided directly by you or your organization. Connected Source Data may also contain personal data about people other than the connecting user — for example, names and contact details of suppliers, customers or colleagues appearing in e-mails and financial documents. Your organization is the controller of that data and responsible for a lawful basis to process it; we process it only on your organization's instructions under the DPA. If your personal data reached us this way, the categories, purposes and legal bases above apply, and the fastest route for questions is your organization's administrator — you can also contact us (§1).

Changes. We may update this Privacy Policy from time to time. The current version is indicated by the "Last updated" date at the top. Material changes will be communicated through the Service or by e-mail to registered users where appropriate.

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Cookie Policy
  • Imprint