Personal data

Minimum collection, described before registration.

Every planned data item has a concrete purpose; undecided retention remains labelled for approval.

Minimum account-journey collection

The public site collects nothing; the separate form must present these data before submission.

Registration data

Organisation name, email address, password stored only as a hash, language, technical identifiers, date and version of the accepted terms and privacy notice, and professional-use declaration.

Service data

Free entitlement, radar label, topic, language and creation date, together with private bulletins generated from those radars. No card or payment data is stored by this account journey.

Security

Session and CSRF protection hashes, session expiry, and an email hash for failed login attempts. A session expires after seven days. On each account-service activity, failed attempts aged twenty-four hours or more are purged.

Purposes

Create and secure the account, maintain the session, provide saved radars, enforce plan limits and prevent abuse. This batch has no marketing purpose.

Retention and deletion

The account, organisation, acceptances, radars and their private bulletins are retained while the account exists and deleted with it. Sessions expire after seven days. Failed-login traces have a twenty-four-hour retention period and are purged on the next account-service activity. The client area provides account export and deletion request controls.

Recorded versions

The form submits and the service records terms calthia-free-preview-2026-08-27 and privacy notice calthia-privacy-2026-08-27. Authorised storage remains limited to the necessary data described on this page.