Legal
Privacy notice
This notice applies to the Cecur portal at cecur.io, including account registration, billing, the partner and referral programme, support, and the public marketing pages and contact form.
Each Cecur product has its own privacy notice for what happens inside that product. For signing, proposals and the evidence behind them, see CecurSign.
Last updated: 26 August 2026
1. Who we are
The Cecur portal is operated by Cecur Limited, a company registered in Ireland with the Companies Registration Office under registration number 815071.
Registered office: The Hive, Carrick-on-Shannon, Co. Leitrim, Ireland.
To reach us about anything in this notice, including to exercise a right, use our contact form.
We have not appointed a Data Protection Officer. We have assessed Article 37 GDPR and do not consider a DPO mandatory: our core activities do not involve regular and systematic monitoring of data subjects on a large scale, and we do not process special category data on a large scale. We have instead designated the privacy contact above.
For everything described in this notice, Cecur Limited is the data controller.
2. What personal data we process, and why
Account and identity data
When you register, or when your organisation’s administrator invites you, we process your name, email address, role, organisation, and authentication data. Login identities are created and managed with Auth0, our identity provider, which also records when you last logged in across Cecur products. Where multi-factor authentication is enabled, Auth0 manages the enrolment.
- Lawful basis: contract (Article 6(1)(b)); for team members added by an administrator, legitimate interests in administering the customer’s account (Article 6(1)(f)).
Billing and subscription data
We process billing contact name and email, billing address, country, VAT number (with its validation record against the EU VIES service), currency, plan and subscription details, usage records that feed billing, credits, and invoices. Where payment is by card, payment is processed by Stripe; we store a Stripe customer reference, not card numbers.
- Lawful basis: contract; legal obligation (Article 6(1)(c)) for tax, VAT and accounting records.
VAT number validation
If you provide a VAT number, we validate it against the European Commission’s VIES service and keep the consultation reference as proof of due diligence.
- Lawful basis: legal obligation.
Contact form
If you use the contact form we process your name, email address, company (optional), chosen topic and message, together with your IP address, browser user agent and the referring page, which we use to handle the enquiry and to filter abuse. The abuse checks on the form are our own: a hidden field that only an automated submission fills in, a minimum time to complete the form, and limits on how many messages one address or one internet connection can send in a day. No third party bot-detection service is used.
- Lawful basis: legitimate interests in answering enquiries and preventing abuse; steps prior to entering a contract where the enquiry is about buying.
Support
Support tickets raised in any Cecur product arrive at the central desk in the portal. We process the ticket contents, your account identity and the product and app version the ticket came from.
- Lawful basis: contract.
Partner and referral programme
For partners we process name, email, country, VAT number, payout currency, a bank account reference for payouts, referral codes, commission and payout records.
- Lawful basis: contract with the partner; legal obligation for tax records.
Platform administration and audit
We keep an administrative audit log of significant account and staff actions, and operational logs that include IP addresses and request metadata.
- Lawful basis: legitimate interests in the security and accountability of the platform.
We do not sell personal data and we do not use it for advertising.
3. Where the data about you comes from
Most data comes from you or your organisation’s administrator. In addition: Auth0 provides authentication events and last-login times; Stripe provides payment outcomes; the VIES service provides VAT validation results; and Cecur products report usage counts relevant to your subscription.
4. Recipients and sub-processors
Cecur products (CecurSign and others) and internal Cecur services (the notification service that dispatches our email, and DocVault document storage) are operated by Cecur Limited itself and are not third parties. The maintained list of third party services, including notice arrangements for changes, is our sub-processor list. The third party services in the path are:
| Service | Provider | What they process | Location |
|---|---|---|---|
| Identity and login | Auth0 (Okta, Inc.) | Name, email, credentials, MFA enrolment, authentication events. | Not yet confirmed. We make no claim about where authentication data is held. |
| Payments | Stripe Payments Europe, Ltd / Stripe, Inc. | Payment card details (collected by Stripe directly on its own pages), billing identity, subscription state. Stripe is an independent controller for its own fraud and compliance processing; see Stripe’s privacy notice. | Stripe is a United States company with an Irish entity, Stripe Payments Europe, Ltd. |
| Email delivery | Resend (Resend, Inc., USA) | Names, email addresses and the content of the emails we send you (welcome, verification, invoices, support replies). | United States. |
| VAT validation | European Commission VIES service | VAT number and country. | European Union. |
| Managed database hosting | OVHcloud | All portal data. | European Union. |
Our application servers and the databases behind them are hosted in the European Union. The company that provides that hosting is not yet named above, so this table is not yet complete on that one point, and we will add it when we can name it.
We do not use analytics or advertising services on cecur.io.
5. International transfers
Our own application servers and the databases behind them are hosted in the European Union. That is where we hold your account, billing, support and contact form records.
It does not follow that every piece of personal data stays in the European Union, and this notice does not claim that it does. Email is delivered through Resend, which sends from the United States, so any message we send you involves a transfer there. The region of our production Auth0 tenant has not been confirmed, so we make no claim about where your login identity and authentication events are held.
6. Retention
Stated plainly:
- Account, billing and subscription data are retained for the life of the account, and invoicing and tax records for the period required by Irish law, which we state as six years.
- Expired trial accounts are not deleted automatically. A scheduled job reports trial accounts dormant for more than six months as candidates; deletion itself, including the Auth0 identity, is a deliberate staff action, and this automated purge is switched off by default.
- Contact form submissions are retained until handled and are not currently deleted on a schedule.
- No other automated retention or deletion schedule is currently implemented.
7. Security
What is in place: TLS encryption for data in transit, including the database connection to the managed cluster; authentication through Auth0 with optional multi-factor authentication; separation between customer organisations; and card details handled by Stripe rather than by us.
Our application servers and the databases behind them are hosted in the European Union. We do not currently hold ISO 27001, SOC 2 or comparable certifications, we do not offer a contractual uptime commitment, and we make no claim in this notice about encryption of data at rest. Nor do we claim that every provider in the path is in the European Union, because email delivery is not: see section 5. Our security page sets out both the controls we have and the ones we do not.
8. Your rights
You have the right of access to your personal data, and the rights to rectification, to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent where processing is based on consent. Some records, such as issued invoices and tax records, must be retained despite an erasure request (Article 17(3)(b) GDPR), and we will tell you when that applies.
To exercise a right, get in touch through our contact form. We will respond within one month.
You also have the right to lodge a complaint with a supervisory authority: in Ireland, the Data Protection Commission (dataprotection.ie); if you are in the United Kingdom, the Information Commissioner’s Office (ico.org.uk); or the authority where you live or work.
9. Automated decision-making
We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects (Article 22 GDPR). The abuse checks on the contact form decide only whether a form submission is accepted.
10. Children
The portal is a business tool and is not directed at children.
11. Changes to this notice
We will publish changes to this notice on this page with a new version date, and will notify account holders of material changes.