Privacy Policy
Last updated: August 18, 2026 · Preliminary version
1. Data controller
Ravil Akhtyamov, responsible for Digital Economy Lab («DEL») and its product Cauce (cauceia.com), a compliance-verification and auditable-trail layer for credit in Latin America. Contact email: [email protected].
Our operational hub is Ecuador. If operations are later carried out through an incorporated entity, we will update this section with its corporate name, address and tax identification.
2. Two distinct roles: who answers for which data
Two situations must be distinguished, because Cauce's role — and who is accountable to you — is different in each:
| Situation | Cauce's role | Who is the controller |
|---|---|---|
| You browse cauceia.com, try the demo, request pilot access or write to us | Controller | Cauce (DEL) |
| You apply for credit with an institution and it uses Cauce to verify the compliance of that transaction | Processor, on behalf of and under the lender's instructions | The lending institution |
This policy covers the first situation in detail. In the second, your rights are exercised with the lending institution, which determines the purposes of processing, makes the credit decision and bears the regulatory obligations (AML/CFT, supervision and reporting to the authorities). Section 10 describes the safeguards we apply in that case.
3. Scope
This policy applies to cauceia.com and its Spanish and Portuguese versions, including the contact and demo-request form.
The interactive prototype (/en/demo) runs entirely in your browser with sample data: it is not a real transaction, simulation data is never sent to our servers and no results are stored.
It does not cover third-party sites, applications or products we link to (for example code repositories, Open Banking providers, or each lender's own channels).
4. Data we collect on the site
- Contact data you provide when requesting a demo or writing to us: name, email, company or institution (optional) and the content of your message.
- Basic technical data needed to operate and secure the site (for example IP address, browser type, language and access logs), processed in aggregate and for short periods.
We do not intentionally collect special categories of data (health, biometrics, beliefs) or information about minors through the site. The site is aimed at a professional (B2B) audience. Please do not include third-party personal data or confidential information in the form body.
5. Purposes
- Answer your enquiries and handle demo or early-access requests.
- Maintain pre-contractual and commercial relationships with institutions and partners.
- Send you product information only with your consent, with an opt-out in every message.
- Keep the site running and secure, and measure its use in aggregate.
We do not sell personal data, do not share it with third parties for advertising, and do not build commercial profiles of site visitors.
6. Legal basis and consent
Processing is based on your consent (given when you submit the form) and, where applicable, on pre-contractual or contractual necessity, compliance with a legal obligation, and legitimate interest in the security of the site. You may withdraw consent at any time by writing to [email protected], without affecting the lawfulness of prior processing.
7. Processors and third parties
We work with providers that process data on our behalf under contractual instructions:
| Provider | Function | Data involved |
|---|---|---|
| Cloudflare | Hosting, CDN, security and attack mitigation | Technical connection data |
| Web3Forms | Processing and delivery of site form submissions | The data you enter in the form |
| Email provider | Receiving and managing correspondence | Contact data and message content |
Connecting them requires the applicant's explicit consent and is governed by the agreements applicable in each case.
We may disclose data where required by a competent authority or a legal obligation, limited to what is strictly required.
8. International transfers
Some providers operate outside your country of residence. In those cases we apply reasonable contractual and technical safeguards (data processing clauses, encryption in transit and minimisation) and assess the adequacy of the destination under applicable law — including Ecuador's LOPDP, Brazil's LGPD, Colombia's Law 1581, Mexico's LFPDPPP and Argentina's Law 25.326.
9. Retention
We keep contact data for as long as needed for the stated purposes and for the duration of the relationship; afterwards it is deleted or anonymised, unless a legal obligation requires otherwise. Technical security logs are kept for short periods. Data processed on a lender's behalf is retained according to that lender's instructions and retention policy.
10. Data processed on behalf of lending institutions
When an institution uses Cauce inside its credit flow, we apply the following safeguards:
- Applicant data is used solely to verify compliance and process the transaction within that lender's flow.
- We do not use it for our own commercial purposes, nor to train models for purposes outside the contracted service, nor do we sell it.
- We do not share applications between lenders and we run no auctions. Each institution works in an isolated environment and only receives what matches its own rules.
- Every verification leaves an auditable trail tied to the transaction, available to the lender's internal governance and to the supervisor.
- We apply minimisation, encryption and role-based access control, and act only on the controller's documented instructions.
If you are a credit applicant and wish to exercise rights over that data, contact the institution where you applied first. If you write to us, we will forward your request to the controller and let you know.
11. Your rights
You may exercise the rights of access, rectification, updating, cancellation or erasure, objection, portability and restriction (ARCO / habeas data rights), as well as the right not to be subject to solely automated decisions with significant effects, by writing to [email protected]. We will respond within the periods set by applicable law.
You may also contact your national authority: Ecuador's Superintendency for Personal Data Protection, ANPD (Brazil), SIC (Colombia), Mexico's data protection authority, or AAIP (Argentina).
12. Artificial intelligence and decisions
Cauce uses AI models to verify compliance (the CASE engine) and explain results. Cauce's AI does not make the credit decision: it produces explainable, traceable verifications that the lender uses to decide. Governance, explainability, human oversight and open measurement are detailed in our AI Policy.
13. Security
We apply reasonable technical and organisational measures: encryption in transit, data minimisation, role-based access control, separate development and production environments, and audit logging of verifications. No system is infallible; should a security incident create a risk to your rights, we will notify affected individuals and the competent authority as required by applicable law.
14. Changes to this policy
We may update this policy to reflect product or regulatory changes. The current version, with its date, will always be published on this page, and material changes will be communicated through our usual channels.
← Back to home