CathfolioBack to Cathfolio

Privacy Policy

Last updated: 2026-08-23

Summary

Cathfolio separates two kinds of data. Your medical procedure records are stored locally on your device and are not uploaded to the Cathfolio license backend. A small amount of license and operations metadata is processed server-side to sell and restore the Founding Member license.

Controller (Art. 4 No. 7, Art. 13(1)(a) GDPR)

The controller responsible for processing is:

YA-Solutions
Represented by: Youcef Douha
Propst-Meyer-Straße 3

59929 Brilon

Deutschland

Contact: contact@ya-solutions.cloud

Procedure data — stored locally on your device

The following data is stored in your browser's local storage on your device and is not uploaded to the Cathfolio license backend:

  • Procedures and procedure dates
  • Target vessels and access routes
  • Techniques and imaging (e.g. IVUS, OCT, FFR/iFR)
  • Clinical indications and urgency
  • Certification classifications (operator role, complexity)
  • Portfolio content and statistics
  • EAPCI and DGK certification settings (exam dates, training centre, mentor, supervisor, checklist state)

This data never reaches Stripe, Turso or Resend. Deleting your browser storage deletes these records; Cathfolio cannot recover them, so use the export features for your own backups.

Cathfolio's procedure form intentionally contains no fields for patient names, dates of birth or patient identifiers, and asks you not to enter patient-identifying information.

Server-side processing: purposes, legal bases, retention

The following personal data is processed server-side. For each processing activity we state the purpose, the legal basis under Art. 6 GDPR and the storage period or the criteria used to determine it.

a) Hosting and access data. When you open Cathfolio, technical access data (such as your IP address and request metadata) is processed by our hosting provider Vercel to deliver the application and to keep it secure and stable. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating and securing the service). This data is processed as part of the hosting operation and is not used by Cathfolio for tracking or profiling.

b) Purchase and license management. To sell and operate the Founding Member license we process your purchase email address, Stripe identifiers and payment references (never card numbers — payment details are handled by Stripe) and the license status. Legal basis: Art. 6(1)(b) GDPR (performance of the contract). License records are stored for the duration of the license relationship; afterwards they are deleted unless and for as long as statutory commercial and tax retention duties require further storage (legal basis then: Art. 6(1)(c) GDPR).

c) Device activations. Device identifiers created for license activation and activation timestamps are processed to enforce the license's device-activation limit. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (preventing license abuse). Activation records are part of the license record and follow its retention criteria.

d) Restore verification codes (OTP). When you restore access, a one-time verification code is emailed to the purchase address. Only a cryptographic hash of the code is stored, the code expires after 10 minutes and verification attempts are limited. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (secure account-less restore). Expired or consumed code entries are unusable technical metadata.

e) Support. If you contact support by email, we process the correspondence and the data you provide to handle your request. Legal basis: Art. 6(1)(b) GDPR where the request concerns your license or purchase, otherwise Art. 6(1)(f) GDPR. Support correspondence is kept as long as needed to handle and document the request and any applicable statutory retention duties.

Withdrawal requests

If you use the electronic withdrawal function, we process the data you submit to identify the contract and handle the request: your name, the purchase email address, an optional order/payment reference and the email address for the acknowledgement, together with the date and time of receipt. This withdrawal metadata is stored server-side, an acknowledgement is sent to you by email (via Resend) and the request is forwarded to support for manual handling. The withdrawal function accepts no procedure, medical or portfolio data.

Legal basis: Art. 6(1)(b) GDPR (handling the withdrawal of the contract) and Art. 6(1)(c) GDPR (statutory consumer-law duties, including the acknowledgement of receipt). Withdrawal records are kept to document the handling of the statutory withdrawal and are deleted when documentation is no longer required and no statutory retention duty applies.

Data you must provide (Art. 13(2)(e) GDPR)

Using Cathfolio Free requires no personal data — no account, no registration. To purchase the Founding Member license you must provide a purchase email address and payment details (the latter directly to Stripe); without them the purchase contract cannot be concluded. Restoring access requires the purchase email address; without it, restore is not possible. Submitting a withdrawal requires the contract-identification data described above.

Recipients — third-party infrastructure

The current implementation uses the following processors:

  • Vercel — Application hosting and delivery of the Cathfolio web app.
  • Turso (libSQL) — Storage of licence metadata: purchase email, licence status, device activations.
  • Stripe Managed Payments — Checkout and payment processing for the Founding Member purchase; Stripe acts as merchant of record, and the merchant-of-record service is provided by Sold through Link, LLC.
  • Resend — Delivery of the verification codes used to restore access.

No medical procedure data is sent to any of these services.

Transfers to third countries (Art. 13(1)(f) GDPR)

The providers above are headquartered in the United States, so personal data covered by the server-side processing may be transferred to the USA. The safeguards below reflect the providers' official documentation:

  • Vercel: transfers are covered by the EU Standard Contractual Clauses (2021) incorporated in Vercel's Data Processing Addendum.
  • Stripe: the European contracting entity is Stripe Payments Europe, Ltd (Ireland); transfers to Stripe, Inc. (USA) are covered by Standard Contractual Clauses, and Stripe documents certification under the EU-U.S. Data Privacy Framework.
  • Resend (Plus Five Five, Inc., USA): transfers are covered by the EU Standard Contractual Clauses incorporated in Resend's Data Processing Agreement; Resend also documents compliance with the EU-U.S. Data Privacy Framework.
  • Turso (USA): Turso's public privacy documentation does not state a transfer mechanism. The applicable safeguard (data processing agreement with Standard Contractual Clauses) and the configured database region are being verified and documented before public launch.

Your rights (Art. 15–21, 77 GDPR)

As a data subject you have the right to:

  • Access to your personal data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)
  • Withdrawal of any consent with effect for the future (Art. 7(3) GDPR), where processing is based on consent

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your habitual residence, your place of work or the place of the alleged infringement. The supervisory authority responsible for the controller is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, https://www.ldi.nrw.de.

Note that your locally stored procedure data is under your own control on your device: you can view, edit, export and delete it directly in the app at any time.

No automated decision-making, no profiling

Cathfolio performs no automated decision-making within the meaning of Art. 22 GDPR and no profiling. The license device-activation limit is a simple counting rule, not an evaluation of personal aspects.

Usage measurement (optional, consent-based)

Cathfolio offers an optional usage measurement that is off by default. When you first open the app area you are asked whether you want to help improve Cathfolio. Nothing is sent before you actively choose “Allow anonymous usage measurement”; choosing “No thanks” sends nothing, now or later. Cathfolio works identically either way.

If you allow it, the app sends at most two technical signals per installation, each only once: “app opened”(first use after consent) and “first procedure saved”. If you later start a purchase, the checkout request the app already makes is additionally marked as “checkout started” on our side.

What we store: a SHA-256 hash (with a server-side secret) of the random installation id that your browser already holds, and the calendar date of each signal. What we never store or transmit for this purpose: procedure content of any kind (no vessels, techniques, indications, dates or counts), your email address, IP address, browser fingerprint or cookies. No third-party analytics provider receives these signals; they go only to our own backend (Vercel/Turso, see above).

Purpose: product improvement and capacity planning (how many installations exist, how many save a first procedure, how many reach checkout). No profiling, no advertising, no individual evaluation — the data is only ever read as aggregate counts.

Legal basis: your consent — Art. 6(1)(a) GDPR for the processing, and § 25(1) TDDDG for reading the installation id from your device for this purpose. We do not rely on a legitimate interest or on a TDDDG exemption for this measurement.

Withdrawal: you can withdraw your consent at any time in the app under Settings → “Usage measurement”. From that moment no further signal is sent; the lawfulness of processing before the withdrawal is unaffected (Art. 7(3) GDPR). Withdrawing has no effect on your use of Cathfolio.

Storage period: usage rows are kept as long as Cathfolio is operated and at most until the data is no longer needed for the purpose above; they are then deleted. Because only a hash and a date are stored, a row cannot be traced back to a person by us.

No advertising, no third-party tracking, no sale of data

Cathfolio does not sell user data, does not use your data for advertising, and uses no third-party analytics or tracking services (no Google Analytics, no Vercel Analytics, no Plausible or similar). The application stores its data in your browser's local storage; Cathfolio itself sets no advertising or analytics cookies. The only measurement is the optional, consent-based first-party measurement described above.

Contact

Privacy questions: contact@ya-solutions.cloud