CARTESIAN Privacy Notice
1. Who we are
1.1 This Privacy Notice explains how CARTESIAN ("we", "us", "our"), the operator of the CARTESIAN software and of the website cartesianecu.com, processes personal data when you visit cartesianecu.com, use the CARTESIAN customer account at cartesianecu.com/account/ (the "account"), use the CARTESIAN desktop application (the "app"), use the functions of the app that work with our systems (the "Connected Functions"), or contact us. Together, these are the "Service".
1.2 We decide why and how the personal data described in this notice is processed, and we are responsible for it as the data controller, except in the cases described in section 9.
1.3 You can contact us about any privacy matter at [email protected]. People who live in the European Union (EU) or the European Economic Area (EEA) can use the same address, and they can also lodge a complaint with their local data protection supervisory authority (section 13.1(h)).
2. Scope
2.1 The CARTESIAN software is a professional tool for automotive businesses such as workshops. This notice applies to the people who act for our business customers (for example owners, managers and employees), to people who contact us, and to visitors of our website.
2.2 Files and requests that you send us can also contain data about other people, such as your own clients. Section 9 explains how we treat that data and what you must do.
2.3 This notice does not apply to the websites, tools or services of other companies, including the read and write tools that you use together with the app.
2.4 Depending on where you live, the law may give you additional rights or require us to give you additional information. Nothing in this notice limits those rights.
3. The personal data we process
3.1 Account data: your e-mail address; your password, which we store only as a one-way hash made with a strong algorithm, so that nobody, including our team, can read it; your name and telephone number, when you give them; your preferred language; the status of the account; when and how the account was created (on the website or in the app); the time of your last sign-in; and the companies the account is linked to, with the history of those links.
3.2 Company and contact data: the data of the business that holds the licences, namely its name, contact person, e-mail address, telephone number, and the country and city that we record as its address; the further contact persons of the business, with their names, e-mail addresses, telephone numbers, languages and whether they want licence reminders; and the notes that our team keeps about the business relationship. Our team enters this data when you buy a licence or contact us, and you can enter parts of it yourself, for example the company's e-mail address in the app.
3.3 Acceptance records: which version of the Terms of Use and of this notice you accepted, a fingerprint (hash) of the exact text, the time, the IP address, the browser or app type, and whether you accepted on the website or in the app.
3.4 Sign-in and security data: IP addresses; browser or app type; the times of sign-ins, sign-outs and sessions; failed sign-in and code attempts; one-time codes, which we store only in a protected form; records of your sessions on the website and of the app's sign-ins on each PC; and the short-lived links that open your account from the app. We do not use a device cookie to recognise your computer.
3.5 Licence and PC data: the licences of your business (licence key, plan, status, start and end dates, limits, price and payment status) and, for each PC that runs the app:
(a) a hardware identifier derived from the serial numbers of the PC's processor and BIOS;
(b) an installation identifier, which is a one-way hash of the identifier of the Windows installation and the computer name;
(c) the name given to the PC in the licence, for example "Workshop PC";
(d) the app version;
(e) the IP address and the approximate location derived from it (the country and, where available, the region and city);
(f) the times the app was started, the signals it sends every minute while it is open, and the app sessions;
(g) the daily counts of processed files and of Original File downloads, and the names of the control units (ECUs) used.
When the app starts on a PC that has no licence, we record the same technical data so that the PC can be activated.
3.6 Files and results: the ECU files (flash and EEPROM reads) that you send to our systems, including the files you send to search for an Original File; the files and reports we return; the file names; the vehicle and control unit details recognised in them (brand, model, ECU, hardware and software numbers); and the solutions and fault codes (DTC) you select. ECU files can contain the vehicle identification number (VIN) and other data stored in the control unit. Some operations run entirely on your PC: for those, the file stays on your PC, and we receive only the type of operation, the name of the ECU and the count needed for the daily allowance. Clone and EEPROM edit operations use our systems and are also saved in History (3.7).
3.7 History: for each operation, the date, the type, the file name, the vehicle and ECU details, the operations performed, the files before and after the operation, and the report. History contains the operations done through our systems and the clone and EEPROM edit operations that the app completes on your PC and then sends to History. You can add private notes to an entry, which only your licence can see; our team has no access to them. You can also send feedback and ratings about an operation, which our team reads.
3.8 Support: your requests and messages; the files, photos and videos you attach, including those you send from a phone through the one-time link that the app shows as a QR code; and the technical context that the app adds to a request, namely the file name and size, the recognised ECU, the selected solutions and fault codes, the error shown, recent lines of the app's log, and the app version and language. For a tuning request, also the vehicle details you enter (type, make, model, year, engine, fuel, gearbox, registration plate, VIN, mileage and power), the read tool and method, the work you ask for, and your declarations, for example that the file is an original read, or about the intended use of emission-related or immobiliser work.
3.9 Communications: the e-mails we send you and the messages you send us by e-mail or through Support.
3.10 Logs: our systems record technical logs of requests to the website, to the account and to the Connected Functions (IP address, time, request, and browser or app type), for operation and security.
3.11 Website statistics: we measure visits to our website without cookies and receive only aggregate figures. The account pages are not included in these statistics. When you download the app from our website, we count the download once a day per visitor. For this we store a one-way code derived from your IP address, not the address itself, with the day, the number of downloads that day and the time of the last one. Legal basis: legitimate interest in improving the Service (section 5.1(g)). We keep these records as long as we need them to meet legal obligations, to deal with disputes and for security; then we delete or anonymise them.
3.12 What we do not collect: we do not ask for national identity numbers. We do not ask for health data or other special categories of personal data; please do not include such data in your messages or files. When payment through the account becomes available, card details will be entered on the secure page of a payment service provider and we will not store them; we will update this notice before then.
4. Where the data comes from
4.1 From you, when you create or use your account, use the app or contact us.
4.2 From the app on your PCs, which sends the data described in sections 3.4 to 3.8 when it starts, while it runs and when you use a Connected Function.
4.3 From our team, who enter company and licence data when you buy a licence or ask us for a change.
4.4 From other people of your business who use the Service or contact us for it, for example when a colleague adds the company's e-mail address in the app.
4.5 From your IP address, from which we derive the approximate location using IP location data kept on our systems and, where available, location data that our content delivery service adds to the request.
5. Why we use the data and on what legal basis
5.1 We use personal data only for the following purposes. When you act for a business, our contract is with that business, and we rely on our legitimate interest in providing the Service to it; when you are the customer yourself, we rely on the contract with you.
(a) Account: to create your account, verify your e-mail address, let you sign in on the website and in the app, reset your password, change your e-mail address, open your account from the app, and link the account to your company. Legal basis: performance of the contract; legitimate interest.
(b) Licence: to activate the app, check the licence when the app starts and while it runs, register PCs, apply the limits of your plan (registered PCs, simultaneous use and daily allowances), deliver updates, and show you your licences, PCs and usage. Legal basis: performance of the contract; legitimate interest in protecting our licences.
(c) Connected Functions: to process the files you send, return the results, identify control units, search for and deliver Original Files, and keep your History. Legal basis: performance of the contract.
(d) Support: to answer your requests, carry out the work you ask for and send you files. Legal basis: performance of the contract; legitimate interest.
(e) Service messages: to send you codes, security notices (for example about a sign-in from a new place, a changed password or e-mail address, or the link of your account to a company), notices about your account and licences, and reminders before a licence ends. Legal basis: performance of the contract; legitimate interest. You can ask us to stop the licence reminders.
(f) Security and prevention of misuse: to limit repeated attempts, protect accounts against password guessing, detect the use of a licence beyond its terms (for example by comparing the approximate location of the PCs with the country and city we recorded as the address of the business), keep logs and a record of changes, and investigate incidents. Legal basis: legitimate interest in protecting the Service, our customers and our rights; legal obligation where the law requires security measures.
(g) Quality: to examine an operation that failed or that you reported, read your feedback, correct or add solutions, and understand, in aggregate, how the Service is used. Legal basis: legitimate interest in improving the Service.
(h) Legal obligations: to keep the records that the law requires (for example acceptance records and, once payment through the account is introduced, tax and accounting records) and to answer lawful requests of authorities. Legal basis: legal obligation; legitimate interest in being able to prove compliance.
(i) Legal claims: to establish, exercise or defend legal claims. Legal basis: legitimate interest.
(j) Change of business: if our business or part of it is sold or reorganised, to transfer the related data to the new owner, who must protect it as described in this notice. Legal basis: legitimate interest.
5.2 When we rely on a legitimate interest, we have weighed it against your interests and rights. You can ask us for details, and you can object as described in section 13.
5.3 We do not send marketing e-mails. We would send them only with your separate consent, which we do not ask for at present, and you could withdraw that consent at any time.
5.4 We do not sell personal data and we do not use it for advertising.
6. Automated steps
6.1 Some steps run automatically: the licence checks (whether a licence is valid, whether a PC is registered and how much of a daily allowance is used); the limits on repeated attempts; the registration of a PC on your licence when you sign in to the app on that PC and only one licence of your company has room for another PC; and the link of your account to a company when your verified e-mail address is the e-mail address we have on file for that company and for no other company. When an account is linked automatically, we send a notice to the company's e-mail address on file and inform our team.
6.2 These steps apply the terms of your licence and protect the Service. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, and we do not create profiles of you. A difference between the location of a PC and the recorded address of the business is only a signal for a person on our team to review.
6.3 If you think that an automated step has treated you wrongly, contact us and a person will review it.
7. Who receives the data
7.1 Within our business, only the team members who need the data for their work have access to it, with permissions that match their role. Our team sees hardware identifiers and IP addresses in shortened form unless their role requires the full value. Our team cannot see your password or your private History notes, and cannot sign in to your account.
7.2 We share personal data with the following categories of recipients, and only as far as needed:
(a) hosting and data centre providers that run our systems;
(b) e-mail services that send our e-mails, and that receive and store the e-mails you send us;
(c) content delivery, network security and website statistics services;
(d) specialised technical partners that carry out part of the processing of certain ECU files, or supply data for identifying control units and for the Original File catalogue; they receive the file, the file name or the search terms needed for the task, but not your account or company details;
(e) payment service providers, once payment through the account is introduced;
(f) professional advisers, such as lawyers, accountants and auditors, who are bound to confidentiality;
(g) courts, authorities and other public bodies, when the law requires it or when it is needed to protect our rights;
(h) a buyer or successor of our business, as described in section 5.1(j).
7.3 Where the law requires it, we bind our service providers by contract to process personal data only on our instructions and to protect it.
7.4 Notices about your account can also go to the e-mail address we have on file for your company, for example when an account is linked to it, and licence reminders go to the company's contacts.
8. International transfers
8.1 The Service is hosted with data centre providers. Our customers, service providers and partners are in different countries, so personal data can be transferred to countries other than the one where you live. In particular, to provide the service you ask for, for example to process an ECU file or to search for an Original File, some files and data may be processed by technical service providers in other countries, including countries outside the European Union, the European Economic Area and Türkiye. The law of those countries may not offer the same level of protection for personal data as the law of the country where you live.
8.2 Where the law requires safeguards for these transfers, we put appropriate safeguards in place. Where the law allows it, a transfer can instead be based on an exception, for example when the transfer is necessary to provide a service you asked for.
8.3 You can write to [email protected] for more information about these transfers and, where safeguards apply, for a copy of them.
9. Data about other people in your files and requests
9.1 ECU files, History entries and Support requests can contain data about your clients or other people, such as the VIN, the registration plate or the mileage of a vehicle. Send us such data only when the work needs it.
9.2 For this data, we act on your behalf and on your instructions: we use it only to provide the Service to you, under the data processing terms in section 9 of our Terms of Use. We protect it and keep it for the periods described in this notice.
9.3 You are responsible for having a legal basis to give us this data and for informing the people concerned as the law requires.
10. How long we keep data
10.1 We keep personal data only as long as it is needed for the purposes in section 5, or as the law requires. We apply the following periods:
(a) Account: as long as the account exists. This includes the IP address from which the account was created and the IP address of your last sign-in. If you ask us to erase the account, we close it and anonymise it: we remove your e-mail address, your password and these IP addresses, end all its sessions on the website and the app's sign-ins, and end its links to companies. A sign-up that is never confirmed is deleted after 7 days, together with its acceptance records.
(b) Sessions on the website: deleted 90 days after they end.
(c) The app's sign-ins on each PC: they expire after 90 days without use and are deleted 90 days after they expire or are ended.
(d) Links that open your account from the app: usable once, for at most 10 minutes, and deleted after 7 days.
(e) One-time codes: valid for 10 minutes and deleted 1 day after they expire.
(f) Records of sign-in and code attempts: 30 days.
(g) Requests about your account that our team handles, such as link and erasure requests: kept while they are open, and deleted 1 year after they are closed.
(h) Acceptance records: 10 years, also after the account is erased. The acceptance records of a sign-up that is never confirmed are deleted with it, as described in (a).
(i) Company, contact and licence data, including the records of the reminders we sent: as long as we have a business relationship with your company, and afterwards as long as we need it to meet legal obligations, to deal with disputes and for security; then we delete or anonymise it. Data that forms part of accounting records is kept as long as the law requires, which can be up to 10 years.
(j) PC data: records of app sessions are deleted 365 days after they end. Other PC data, such as the hardware identifier, the installation identifier, the name of the PC, its IP address and the times the app was started, is kept as long as the PC is registered on a licence, and afterwards as long as we need it to meet legal obligations, to deal with disputes and for security; then we delete or anonymise it.
(k) Daily usage counts per licence, PC and ECU, including the ECU names: 730 days. The daily counters per PC that we use to apply the daily allowances and other daily limits are kept like the other PC data in (j).
(l) History: the files of an operation are kept for 180 days. When you delete an entry, its files are removed after 7 days. When the storage space of a licence is full, the oldest files are removed first. Private notes are removed together with the files. The entry without its files, and your feedback and ratings, are kept as long as your licence exists, and afterwards as long as we need them to meet legal obligations, to deal with disputes and for security; then we delete or anonymise them.
(m) Support: the files attached to a request are kept for 180 days after the request is closed. The request and its messages, and the e-mails you exchange with us, are kept as long as your licence exists, and afterwards as long as we need them to meet legal obligations, to deal with disputes and for security; then we delete or anonymise them. Notifications on the Support page are kept for 365 days. A one-time link for a phone stops working after at most 3 hours.
(n) Copies made to identify a control unit or to search for an Original File by its content: up to 1 hour.
(o) Logs: as long as we need them for operation and security; then we delete them. A log entry that we need to investigate an incident or to deal with a dispute is kept until the matter is closed.
(p) The record of changes made to accounts, companies and licences, which shows who changed what and when: as long as the account, company or licence concerned exists, and afterwards as long as we need it to meet legal obligations, to deal with disputes and for security; then we delete or anonymise it.
(q) Payment and invoice records, once payment through the account is introduced: as long as the law requires, which can be up to 10 years.
10.2 We may keep data longer when the law requires it, or when we need it to establish, exercise or defend a legal claim, for as long as the matter lasts. When a period ends, we delete or anonymise the data.
11. Security
11.1 We protect personal data with technical and organisational measures that match the risk, including:
(a) encrypted connections between your browser or the app and our systems;
(b) passwords stored only as strong one-way hashes; one-time codes stored in a protected form, valid for 10 minutes and locked after 5 wrong attempts; session keys stored only as hashes;
(c) limits on repeated attempts that never lock your account, so that nobody else can lock you out;
(d) e-mail notices when your password or e-mail address changes, when your account is linked to a company, and when someone signs in to your account from a new place;
(e) your password is asked again before sensitive changes;
(f) files stored outside the public areas of our systems, separated by licence and checked for integrity when they are read;
(g) access for our team based on roles and protected by a second factor, with identifiers shown in shortened form and a record of every change;
(h) on your PC, the app's sign-in key is protected by Windows for the signed-in Windows user;
(i) no passwords, codes or session keys in our logs.
11.2 No system is completely secure. If a personal data breach occurs, we will act to limit its effects and will inform you and the authorities when the law requires it.
11.3 You can help protect your account: use a password that you do not use anywhere else, keep it secret, sign out on shared computers, and tell us at once if you suspect misuse.
12. Cookies and similar technologies
12.1 We use only cookies and similar technologies that are strictly necessary for the Service:
(a) a sign-in cookie for the account (named `__Host-cxc`), set when you sign in and removed when you sign out; it lasts at most 12 hours, or at most 30 days if you choose to stay signed in;
(b) a cookie on the page that opens on your phone from the app's QR code (its name starts with `cup`), which ties the one-time link to your phone; it lasts at most 3 hours and is used only on that page;
(c) your language and colour theme choices, kept in your browser's local storage until you clear them;
(d) the app's settings and, after you sign in, its sign-in key, kept on your PC.
12.2 We do not use advertising or tracking cookies. Our website statistics do not use cookies.
12.3 Our pages load their images, including the flags in the language menu, and their fonts, style sheets and scripts from our own website. There is one exception, the website statistics of section 3.11: on the pages of our website other than the account pages and the page that opens on your phone (section 12.1(b)), your browser loads a statistics script from our content delivery service and sends that service data about the visit, such as the page and its loading time, without cookies. That service then receives technical data such as your IP address and browser type. The account pages and the page that opens on your phone load nothing from other websites.
12.4 You can delete cookies and local storage in your browser at any time. Without the sign-in cookie, you cannot use the account.
13. Your rights
13.1 Under the conditions set by the law, you have the right to:
(a) access your personal data and receive a copy of it;
(b) have inaccurate data corrected and incomplete data completed;
(c) have your data erased;
(d) have the processing of your data restricted;
(e) receive the data you gave us in a structured, commonly used and machine-readable format, and have it transmitted to another controller;
(f) object to processing based on our legitimate interests, and object to direct marketing at any time;
(g) withdraw a consent at any time, without affecting the processing carried out before the withdrawal;
(h) lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work or where you believe the law was infringed.
13.2 In the account, the privacy page lets you download a copy of your account data in a machine-readable file and ask for the account to be erased. For any other request, write to [email protected].
13.3 We may ask you to confirm your identity, for example by writing to us from the e-mail address of your account. We answer within one month. If a request is complex or we receive many requests, we may extend this period by two further months and will tell you why. Exercising your rights is free of charge, unless a request is clearly unfounded or excessive.
13.4 Some data cannot be erased at once, for example data that we must keep by law, acceptance records, or data that we need for a legal claim. Erasing your account does not end the licences of your company and does not remove the records of the business relationship with your company. We will tell you what we keep and why.
14. Children
14.1 The Service is meant for professionals and is not directed at anyone under 18. We do not knowingly collect personal data of children. If you believe that a child has given us personal data, contact us and we will delete it.
15. Changes to this notice
15.1 We may change this notice when the Service, the law or our practices change. The version number and the effective date at the top show the current version.
15.2 We will inform you of material changes in advance by e-mail, in the account or in the app. Where the law requires it, we will ask for your consent.
15.3 You can ask us for earlier versions of this notice.
16. Contact
16.1 CARTESIAN, the operator of the CARTESIAN software and of the website cartesianecu.com. E-mail: [email protected].