Privacy Policy.
Last updated: 24 July 2026
1. Data controller
The data controller is CAMBRA Global SASU, a French société par actions simplifiée registered under SIREN 105 452 916 and SIRET 105 452 916 00015, EU VAT FR50105452916, with registered office at 47 rue Vivienne, 75002 Paris, France. For any data-related request, contact us at privacy@cambra.global.
2. What we collect
We collect information you provide directly: name, professional email, brand information, payment and infrastructure cost data, uploaded statements and operational metrics entered through the Analyzer. When you connect a third-party account (e.g. Stripe), we collect the data authorized by your OAuth scope — read-only. We also process technical logs generated by normal platform operation (requests, errors, security events). If you reach us through another business's referral link, we also record that referral code: an opaque random code generated by CAMBRA, not derived from anyone's personal data. It is used solely to identify which business referred you and to apply the corresponding fee reduction to that business, and it is stored alongside your analysis session. It is kept in your browser (sessionStorage) between the moment you open the link and the moment you run your analysis — see our Cookie Policy.
3. How we use your data
Your data is used to deliver CAMBRA's infrastructure intelligence — generating audits, calculating benchmarks, identifying optimization opportunities and personalizing your dashboard. Legal basis: performance of contract (Art. 6(1)(b) GDPR) and legitimate interest for benchmarking (Art. 6(1)(f) GDPR). We never sell your data. Cross-tenant intelligence is kept separate from operational merchant data. We may retain only aggregated, fully anonymized statistics that contain no merchant identifier or stable pseudonym and are produced only when a minimum diversity threshold is met; identifiable or merely pseudonymized merchant data remains subject to normal retention/deletion rules.
4. File upload & AI processing
When you upload statements or invoices (PDF, Excel, CSV), they are processed by large language models to extract structured cost and operational data. The content sent to our AI providers is limited to the commercial data needed for the analysis — amounts, fees, dates and provider names; we do not send personal data of your end customers for this purpose. Our AI providers process this content under their standard data processing agreements, whose terms state that data submitted through their APIs is not used to train their models. Uploaded files are stored using the security controls provided by our hosting and storage provider, and remain your property.
5. Sub-processors
To operate the service, CAMBRA relies on the following sub-processors, each engaged under its respective data processing agreement: Base44 (application hosting & database); Anthropic PBC (AI processing — document extraction, product intelligence and the in-app Copilot); OpenAI (AI extraction cross-check); Resend, Inc. (transactional email delivery); Stripe Payments Europe Ltd. (payment processing where applicable); Microsoft Ireland Operations Limited (encrypted off-platform disaster-recovery backup of platform data and merchant attachments in a SharePoint tenant, data at rest hosted in France). A current, complete list is available on request at privacy@cambra.global and in Annex III of our DPA (Sub-processors page).
6. Storage & security
Your data is encrypted in transit and at rest in accordance with the standards of our infrastructure provider. In addition, third-party credentials you connect (OAuth tokens, API keys) are encrypted at the application level with AES-256-GCM, using a dedicated key that is never exposed to client code. Access to your data is restricted to the systems and personnel that need it to operate the service, and sensitive operations are logged.
7. Your rights (GDPR)
If you are located in the European Economic Area, the United Kingdom or Switzerland, you have the right to access, rectify, erase, restrict, port and object to the processing of your data. You may also withdraw consent at any time. To exercise any of these rights, contact privacy@cambra.global — we respond within one month, as required by Art. 12 GDPR.
8. Data retention
We retain personal and operational data only for as long as your account is active or as required to provide the service. When you request deletion of your account, we delete or anonymize identifiable data without undue delay. Billing and invoicing data is retained for 10 years as required by French commercial and tax law (Code de commerce, Art. L123-22). Aggregated, anonymized benchmarks from which you can no longer be identified may be retained.
9. Cookies & local storage
We use a small set of first-party cookies and browser storage (localStorage / sessionStorage) strictly to operate the platform — authentication, session continuity and your preferences. We do not use advertising cookies or third-party trackers. The complete, code-verified list is in our Cookie Policy.
10. International transfers
Some of our sub-processors process data outside the EEA (e.g. AI inference by Anthropic PBC or OpenAI, email delivery by Resend, Inc.). These transfers are governed by the transfer mechanisms provided in each provider's data processing agreement, such as the Standard Contractual Clauses approved by the European Commission. Microsoft Ireland Operations Limited (SharePoint disaster-recovery backup) hosts data at rest in France; ancillary support and telemetry, where applicable, are covered by the Standard Contractual Clauses executed in the Microsoft Products and Services Data Protection Addendum.
11. Data breach notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, CAMBRA will notify the competent supervisory authority (CNIL) within 72 hours and, where the risk is high, inform affected users without undue delay, in accordance with Art. 33-34 GDPR.
12. Contact & supervisory authority
For any privacy-related question, request or complaint: privacy@cambra.global. You also have the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL, www.cnil.fr) or your local data protection authority.