Privacy Policy
Last updated: May 17, 2026.
This policy explains how CASI ("we") collects, uses, shares, and protects the personal information of people who visit getcasi.com and its associated subdomains. It is written in plain language for users in Latin America and the European Union.
1. Data controller
CASI is the data controller for your personal data. For any question or to exercise your rights, write to [email protected].
2. Data we collect
- Data you provide: name, email, phone, and any other fields you complete on contact forms, newsletter sign-ups, or demo requests.
- Browsing data: IP address (truncated before storage), country, device type, pages visited, traffic source, and UTM parameters.
- Technical data: error logs and performance events captured by Sentry and PostHog to help us improve the site.
3. Purposes and legal basis
We process your data to respond to inquiries, send communications you have requested, measure campaign effectiveness, prevent abuse, and comply with legal obligations. The legal basis depends on your country:
- LATAM (Peru, Mexico, Chile, Colombia, and others): express consent for marketing and analytics purposes; pre-contractual measures to answer your requests; compliance with applicable legal obligations.
- European Union / EEA (GDPR): consent (Art. 6.1.a), pre-contractual measures (Art. 6.1.b), legitimate interest in keeping the site safe and operational (Art. 6.1.f), and legal obligation (Art. 6.1.c).
4. Retention
Contact-form submissions are retained for 24 months from your last interaction. Operational logs are retained for 90 days. Cookies follow the retention windows listed in the Cookies section below.
5. Recipients and processors
We share data strictly with the following processors:
- Strapi (self-hosted CMS): stores form submissions.
- Cloudflare: CDN, Workers, Turnstile (anti-bot), Web Analytics.
- Sentry: client- and Worker-side error capture.
- PostHog: product analytics using anonymous identifiers.
6. International transfers
Cloudflare, Sentry, and PostHog process data outside your country of residence. We apply standard contractual clauses approved by the European Commission and the equivalent safeguards required by competent Latin American authorities. The self-hosted Strapi CMS storage region will be declared by the CMS team; [placeholder: region pending confirmation by the CMS team].
7. Your rights
You have the right to access, rectify, cancel, and object to the processing of your data (the ARCO rights in LATAM), plus portability, restriction, and erasure under GDPR. To exercise them, email [email protected] stating the right you wish to exercise and a means to verify your identity. We respond within the legally applicable windows (typically 20 business days in LATAM, 30 days in the EU).
For the detailed erasure procedure (ARCO-cancellation) consult our public runbook: [placeholder: link to ARCO runbook pending publication by the CMS team].
8. Security
We apply TLS encryption in transit, role-based access controls, and audit logs over the systems that process your data. No system is 100% secure; in the event of an incident we will notify according to the applicable regulations.
9. Cookies
We use a minimal set of cookies and only activate non-essential cookies after your explicit consent through the banner. The cookies the site may place in your browser are:
| Cookie | Purpose | Retention | Classification |
|---|---|---|---|
casi_consent | Stores your decision about analytics cookies. | 12 months | Essential |
| Turnstile challenge cookies (Cloudflare) | Mitigates form abuse without a visible CAPTCHA. | Session / up to 30 minutes | Essential |
casi_attribution | Preserves the source and UTM parameters of your first visit. | 90 days | Non-essential (requires consent) |
__ph_* (PostHog) | Anonymous session identifier for product analytics. | 12 months | Non-essential (requires consent) |
You can change your choice at any time by reopening the banner from the "Read more" link in the footer.
10. Changes
Any material change to this policy is deployed via pull request and recorded in the public history of the site's repository. The "Last updated" date at the top reflects the current version.
