Legal

Confidentialité

Ce que nous collectons, pourquoi nous en avons le droit, combien de temps nous le gardons, et ce que vous pouvez nous obliger à en faire.

Last updated - 27 août 2026

01

Qui est responsable

The controller for the personal data described in this notice is the company named below. Where you use CapyDB to store personal data belonging to your own users, you are the controller of that data and we are your processor - that relationship is governed by the Data Processing Agreement, not by this notice.

We have not appointed a Data Protection Officer. We are not required to: we do not perform large-scale monitoring, and we do not process special-category data as a core activity. Every request below reaches a person who can act on it.

Dénomination sociale
Entro314 Labs Single Member P.C.
Siège social
Chimarras 3, 13561 Agioi Anargyroi, Attica, Greece
Registre du commerce (Γ.Ε.ΜΗ.)
193782603000

02

Ce que couvre cet avis

This notice covers the marketing site at capydb.dev, the documentation site at docs.capydb.dev, the authenticated dashboard, and the public API used by the CLI, the SDKs, the MCP server, and the platform integrations.

It does not cover the contents of your database cells. We do not read, index, mine, or train on the data inside your databases. Operator access to a cell happens only for the reasons listed under Access, and it is logged.

03

Ce que nous collectons

  • -Account identity: name, email address, profile image, and authentication metadata, handled by our identity provider. We never receive or store your password.
  • -Organization records: workspace name and slug, membership and roles, invitations, and audit entries for actions taken in the workspace.
  • -Project and platform metadata: project names, region, plan, database cell state, jobs, previews, backups, restores, imports, extensions, and webhook endpoints.
  • -API credentials: organization API keys, stored only as hashes, and per-project database credentials, stored encrypted.
  • -Billing records: plan, subscription state, invoices, and metered usage. Card details are handled by the payments processor and never reach our systems.
  • -Operational telemetry: request logs, error traces, connection and wake events, and resource samples, retained for a limited window and tied to a project rather than to a person.
  • -Support and sales correspondence: whatever you write to us, plus the email address you write from.
  • -Server logs from the web surfaces: IP address, user agent, requested URL, and timestamp, used to keep the service up and to stop abuse.

04

Pourquoi nous traitons, et sur quelle base

We do not run behavioural advertising, we do not profile you, and we make no automated decisions that produce legal effects. Product announcements are sent only to people who asked for them, and every message carries a working unsubscribe link.

  • -To provide the service you signed up for - creating cells, running jobs, serving connections, taking backups. Legal basis: performance of a contract (Art. 6(1)(b)).
  • -To bill you and to keep the accounting records the law requires. Legal basis: contract, and legal obligation (Art. 6(1)(b) and (c)).
  • -To keep the platform available, secure, and free of abuse - rate limiting, capacity planning, incident response, fraud prevention. Legal basis: legitimate interests (Art. 6(1)(f)).
  • -To answer support requests and to tell you about incidents, breaking changes, and end-of-life notices for versions you run. Legal basis: contract and legitimate interests.
  • -To comply with tax, accounting, and lawful-request obligations. Legal basis: legal obligation (Art. 6(1)(c)).

05

Le contenu de votre base de données

Data you write into a database cell is processed on your instructions only. We do not access it to build features, to generate statistics, or to train models. Automated systems touch it for exactly three reasons: taking and verifying backups, moving or restoring a cell, and applying the platform objects the product needs to work.

A human operator reads your data only if you ask us to for support, or if we must to resolve an incident that cannot be resolved otherwise. Both are logged.

06

Combien de temps nous conservons

  • -Account and organization records: for as long as the account exists, then deleted or anonymized within 30 days of deletion.
  • -Database cells and their storage: deleted on project deletion. Backup copies age out of the archive on the retention window of your plan.
  • -Billing and invoice records: retained for the period Greek tax law requires, which is longer than the account itself.
  • -Operational logs and telemetry: a rolling window measured in days, then archived in aggregate or discarded.
  • -Support correspondence: kept while it is useful to the relationship, then deleted.

07

Qui d’autre y a accès

We use a small set of processors to run the platform - hosting, edge delivery, object storage, identity, payments, and transactional email. Each is bound by a written processing agreement, receives only what its function requires, and may not use the data for its own purposes.

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We disclose data to authorities only against a valid, binding legal request, and we tell you unless we are legally barred from doing so.

08

Transferts internationaux

Database cells and their backups are stored in the European Union. Some processors - identity, payments, and transactional email - operate from or support their services from outside the EEA.

Where personal data leaves the EEA, the transfer relies on an adequacy decision where one applies, and otherwise on the European Commission's Standard Contractual Clauses together with the supplementary measures the transfer risk assessment identifies.

09

Vos droits

Write to us with the subject line "Data subject request". We answer within one month, and we say so if we need the extension the Regulation allows. We may ask you to confirm control of the account before acting on a request.

If we get it wrong, you can complain to your local supervisory authority. In Greece that is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1-3, 115 23 Athens.

  • -Access: get a copy of the personal data we hold about you.
  • -Rectification: correct anything inaccurate, most of which you can edit yourself in the dashboard.
  • -Erasure: delete your account, which removes you from every workspace. Records the law requires us to keep survive that.
  • -Portability: receive your data in a structured, machine-readable format - see Data portability and exit.
  • -Restriction and objection: object to processing based on legitimate interests, and have processing restricted while we consider it.
  • -Withdraw consent: where processing rests on consent, withdraw it at any time without affecting what happened before.

10

Droits à la vie privée aux États-Unis

This section applies to residents of California and of other US states with comparable statutes. The categories of personal information we collect, and the purposes we collect them for, are the ones listed above; this section is the notice at collection.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. There is nothing to opt out of - but the right exists, so the route does too: write to us with the subject line "Do not sell or share my personal information" and we will confirm in writing.

We honour the Global Privacy Control signal. Because the site sets no advertising or analytics storage, there is nothing for the signal to switch off, and it costs you nothing to send it.

  • -Right to know what we collect, use, and disclose
  • -Right to delete, subject to the records we must keep
  • -Right to correct inaccurate information
  • -Right to opt out of sale or sharing - nothing to opt out of, route provided anyway
  • -Right not to be discriminated against for exercising any of the above

11

Comment nous protégeons

Every project runs in its own isolated database cell with its own process, storage, credentials, and resource limits. Connections are encrypted in transit and the proxy relays authentication without ever holding your credentials. API keys are stored as hashes and cannot be read back, and stored database credentials are encrypted at rest.

The full technical and organizational measures, including backup, restore, and access controls, are described on the Security page. No system is perfectly secure; if a breach affects your personal data and meets the notification threshold, we will tell you and the supervisory authority within the deadlines the Regulation sets.

12

Mineurs

CapyDB is a developer tool sold to businesses and to individual builders. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, write to us and we will delete it.

13

Modifications de cet avis

When this notice changes materially we update the revision date at the top and, for changes that affect how we process your data, tell account holders by email before the change takes effect. Older revisions are available on request.

14

Contact

All privacy correspondence goes to the address below. Use the subject line that matches your request so it is routed correctly on arrival.

Data subject request
hello@capydb.dev
Do not sell or share
hello@capydb.dev
Everything else
hello@capydb.dev