cautia
Security and data

Your data, with the rules written down

Running an insurance agency's workload means touching its clients' data: names, ID numbers, sums insured, payment status. This page states which data we process, in which role, where it lives and who else is involved. What we don't have, we don't display.

01

We're a data processor, not the owner of your data

When cautia runs a workflow for your agency, your agency is the data controller and cautia is the processor: we process personal data following your instructions and the terms of our contract, under Law 1581 of 2012 and Decree 1377 of 2013.

That means three concrete things. We don't use your policyholders' data for our own purposes. We don't share it with other cautia clients. And if the contract ends, it is returned or deleted as agreed in writing.

There is one case where cautia is the controller: the data you give us through this site's contact form or by email. We process that to handle your request, and it's covered by our data processing policy.

02

Which data we touch and which we don't

From insurance documents
Policyholder or insured name and ID, risk location, insured asset details, coverages, deductibles, sums insured, premiums, policy terms, policy and endorsement numbers.
From receivables and group policies
Outstanding balances, payment status, ageing, additions, removals and increases in sum insured for group policy members.
From your team
Name, role and work email of the people who use the workflows or receive the outputs.
From the site
Contact form data and aggregate usage metrics, with no tracking cookies.

We don't ask for and don't need your policyholders' card or banking credentials. If a document contains sensitive data — health information in a life or health quote, for instance — it is processed only for the contracted workflow and with the reinforced measures the law requires.

03

Where the data lives and who else is involved

cautia's infrastructure sits outside Colombia. We say it here and we declare it in the data processing policy, with the international transfer and transmission information the law requires.

Cloudflare
Hosting for this site, delivery network and aggregate analytics with no cookies.
Outside Colombia
Google Cloud
Execution infrastructure for the workflows.
Outside Colombia
Google Gemini
Artificial intelligence models to classify documents and extract structured information.
Outside Colombia
Mistral
Text recognition (OCR) on scanned PDFs and images.
Outside Colombia
Transactional email provider
Delivery of the contact form notifications.
Outside Colombia

These providers act as sub-processors: they process data on our instructions and under the terms of each contract. The list is kept current in the data processing policy; if it changes, it changes here too.

04

Retention, human review and what we don't have

Retention
Input documents and outputs are kept for as long as needed to deliver the service and let you audit a case; technical logs, for a short period. Exact terms are agreed in the contract with your agency.
AI, declared
All our workflows use artificial intelligence and we say so openly. No decision about a person is taken automatically: there is human review before any document goes out. This is what Colombia's SIC External Circular 002 of 2024 on personal data in AI systems requires.
Access and credentials
Each agency has its own credentials for email and systems; they are never shared between clients.
What we don't have
cautia holds no SOC 2, ISO 27001 or any other security certification, which is why we don't display one. We also don't promise “guaranteed security”: what we offer is telling you exactly what we do and with which providers.
Human review

Where the person comes in

Every workflow ends at the same point: a person opens the output the AI analysts produced, checks it against the source document and decides whether it goes out. Nothing reaches an insurer or a client without going through that step.

05

Your rights and who you exercise them with

If you are a policyholder of an agency that works with cautia, the rights to access, update, correct and delete your data and to withdraw your authorisation are exercised with the agency: it is the data controller. We support it with whatever it needs to answer you within the terms set by law.

If you wrote to us through this site, we process that data ourselves and you can exercise your rights directly with cautia. The channels, the terms and the procedure are in the data processing policy.

Read the data processing policy

Questions about how we handle your data?

The data processing policy has the full detail: purposes, sub-processors, international transfer and the channels to reach us. If anything is unclear, write to us before signing anything.