Personal data
Minimum collection, described before registration.
Every planned data item has a concrete purpose; undecided retention remains labelled for approval.
Minimum account-journey collection
The public site collects nothing; the separate form must present these data before submission.
Registration data
Organisation name, email address, password stored only as a hash, language, technical identifiers, date and version of the accepted terms and privacy notice, and professional-use declaration.
Service data
Free entitlement, radar label, topic, language and creation date, together with private bulletins generated from those radars. No card or payment data is stored by this account journey.
Security
Session and CSRF protection hashes, session expiry, and an email hash for failed login attempts. A session expires after seven days. On each account-service activity, failed attempts aged twenty-four hours or more are purged.
Purposes
Create and secure the account, maintain the session, provide saved radars, enforce plan limits and prevent abuse. This batch has no marketing purpose.
Retention and deletion
The account, organisation, acceptances, radars and their private bulletins are retained while the account exists and deleted with it. Sessions expire after seven days. Failed-login traces have a twenty-four-hour retention period and are purged on the next account-service activity. The client area provides account export and deletion request controls.
Recorded versions
The form submits and the service records terms calthia-free-preview-2026-08-27 and privacy notice calthia-privacy-2026-08-27. Authorised storage remains limited to the necessary data described on this page.