Privacy Policy

Last updated: February 8, 2026

This Privacy Policy describes how Nautis (PitchWitch Ventures LLC) ("we", "us", or "our") collects, uses, and protects your personal information when you use our platform.

1. Information We Collect

Information You Provide

CategoryDetails
Account InformationName, email address, password, phone number, designation
Organization DataCompany name, team member details, roles
ContentMessages, documents, files, forms, and other content you create
Payment InformationBilling details processed securely through Stripe

Information Collected Automatically

CategoryDetails
Usage DataPages visited, features used, interaction timestamps
Device InformationBrowser type, operating system, IP address
CookiesAs described in our Cookie Policy

2. How We Use Your Information

  • Providing and maintaining the platform
  • Processing transactions and sending related information
  • Sending administrative notifications (security alerts, service updates)
  • Responding to support requests
  • Improving and personalizing the platform
  • With your consent, sending marketing communications

3. Legal Basis for Processing (GDPR)

We process your data based on:

Legal BasisDescriptionArticle
Contract PerformanceProcessing necessary to provide our servicesArt. 6(1)(b)
Legitimate InterestsSecurity, fraud prevention, platform improvementArt. 6(1)(f)
ConsentMarketing emails, analytics cookiesArt. 6(1)(a)
Legal ObligationTax records, regulatory complianceArt. 6(1)(c)

4. Data Sharing

We share your data only with:

CategoryProvider(s)Data Shared
PaymentsStripeEmail, billing information
File StorageAWS S3Uploaded files
AI FeaturesOpenAI, Anthropic, Google GeminiIndividual prompts only (no bulk data)
AnalyticsGoogle AnalyticsUsage data (with your consent)
Error MonitoringSentryAnonymized error context

We never sell your personal data to third parties.

5. Data Retention

Data TypeRetention Period
Account DataRetained while active, deleted within 30 days of account deletion
Audit LogsIP addresses anonymized after 90 days, logs deleted after 3 years
Chat MessagesRetained while your account is active
Payment RecordsRetained for 7 years per tax regulations
Data ExportsAvailable for 7 days after generation

6. Your Rights

Under GDPR and applicable data protection laws, you have the right to:

RightDescription
AccessRequest a copy of your personal data
RectificationUpdate or correct your data via your account settings
ErasureRequest deletion of your account and data
PortabilityExport your data in machine-readable format (JSON/CSV)
Restrict ProcessingRequest limitation of processing
ObjectObject to processing based on legitimate interests
Withdraw ConsentWithdraw previously given consent at any time

7. Cookies

We use cookies as described in our Cookie Policy. You can manage your cookie preferences at any time through the cookie settings banner.

8. Security

We protect your data with:

MeasureDetails
Encryption at RestAES-256-GCM encryption for sensitive data
Password Hashingbcrypt with appropriate cost factors
Two-Factor AuthenticationTOTP-based 2FA with backup codes
Access ControlsRole-based access controls (RBAC)
MonitoringRegular security audits and monitoring
Encryption in TransitTLS/SSL encryption for all connections

9. International Transfers

Your data may be processed in countries outside the European Economic Area. We ensure adequate protection through Standard Contractual Clauses or equivalent safeguards.

10. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes by email or through the platform.

11. Contact Us

For privacy inquiries or to exercise your rights:

Email: privacy@getnautis.com

Data Protection Officer: dpo@getnautis.com