Privacy Policy
aperAI Cartho · Last updated: September 11, 2026
Cartho is a business CRM workspace. We use personal information to provide accounts, protect access and support your organization. We do not sell personal data or use Google account information for advertising or AI model training.
This policy describes how we handle personal information for accounts, security, organization workspaces and optional integrations. The data we process depends on your use of Cartho and your organization’s configuration.
Public website: visiting these pages does not create a Cartho account. The web infrastructure handles connection information, such as your IP address and the requested URL, to deliver and protect the website. The home page loads shared navigation, styling and branding from aperai.eu, whose website privacy policy also describes that site. Fonts are served locally; these pages do not use advertising trackers or analytics cookies.
1. Who is responsible for your data
Cartho is operated by aperAI OÜ, registration number 17446295, Narva mnt 5, 10117 Tallinn, Estonia. Contact us about privacy or the service at hello@aperai.eu.
aperAI is the controller for information used to operate user accounts, secure the service, manage our customer relationship and respond to enquiries. For personal data your organization manages through Cartho, the organization determines its purposes and lawful basis. We process that data on its instructions under the applicable service agreement and data processing agreement. Access to another product does not combine the organizations or automatically change their responsibilities.
2. Information we handle
Accounts and identity providers
When you choose Google or Microsoft sign-in, we receive your name, email address, provider account identifier and relevant identity claims, such as whether an email address is verified. Google may also provide a profile picture URL. For Microsoft work or school accounts, we use tenant and account identifiers to distinguish identities.
We store account information and authentication records needed to recognize you and manage access. These records can include identity, access or refresh tokens returned by the provider. Access and refresh tokens stored by the authentication service are encrypted. Cartho does not receive or store your Google or Microsoft password.
Security and support
We handle session identifiers and expiry times, account status, IP address and browser information where available, sign-in and security events, and abuse-prevention counters. If you enable multi-factor authentication, we store a protected TOTP secret, protected recovery codes and records of successful verification. We also process information you send us when requesting support; do not include passwords or recovery codes in those messages.
Organization information and optional integrations
Organization and CRM data may include organization names, memberships, roles, invitations, business contacts and records your organization supplies. Your organization is responsible for limiting this information to what it needs and for informing the people concerned.
For organizations using the SeeVee integration, Cartho retrieves authorized CV summaries and details and submits search criteria on behalf of your organization. This may include a candidate’s name, professional experience, education, skills and contact information present in an authorized CV. SeeVee is the source of those records. Cartho access is read-only unless a separately described capability is expressly enabled.
3. Google user data
Cartho requests only the basic sign-in scopes openid, email and profile. We use the resulting information to identify your account, display your profile and secure access. Signing in does not give Cartho access to Gmail messages, Google Drive files, Google Calendar or Google Contacts.
Google identity data is stored with your Cartho account. It is available to you and, where necessary, authorized service personnel and organization administrators for account or membership management. Hosting providers process the stored information to operate the service. We do not sell it, use it for targeted advertising, transfer it to data brokers, or use it to train AI models. We do not send Google sign-in tokens to SeeVee, Distill or an AI agent as an integration credential.
You can remove Cartho’s Google authorization in your Google Account connections. This stops future use of that authorization; it does not by itself delete your Cartho account or end an existing Cartho session. Sign out and contact us to request account deletion or revocation of all sessions. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements where applicable.
4. Purposes and legal grounds
- Providing a service you contract for: account administration and responding to your service requests, where necessary to perform that contract or take steps at your request.
- Legitimate interests: supporting authorized business users, preventing abuse, protecting accounts and infrastructure, and resolving service issues. We consider the impact on individuals and their reasonable expectations.
- Legal obligations: retaining or disclosing specific records when a law requires it, for example applicable accounting obligations.
- Consent: where a separate optional activity requires consent, we explain it when requesting that consent. Choosing an identity provider does not authorize unrelated processing.
Your organization must determine its own lawful basis for CRM and candidate data. An integration grant is a technical access permission, not a substitute for that lawful basis or the information owed to data subjects.
5. Access, integrations and AI
Organization access is based on explicit membership and roles. A Google email domain or Microsoft tenant does not automatically grant membership. Cartho and SeeVee have separate organizations and accounts. An authorized integration administrator must explicitly grant a Cartho organization access to a specified SeeVee organization. Revoking that grant removes the corresponding integration access; it does not delete the source CVs in SeeVee.
Where an agent or search assistant is enabled, it must operate within the requesting user’s current permissions and the organization’s integration grants. CV search is an assistance tool, not a decision about hiring or eligibility. Cartho does not make solely automated decisions with legal or similarly significant effects on individuals.
AI and transcription processing is limited to the services configured for your organization and the permissions applicable to the request. We identify the relevant providers and processing purposes before customer content is shared with them. Changes that add recipients or alter how personal data is used require appropriate notice and updates to this policy.
6. Recipients and international transfers
The public website is hosted with Hetzner Online GmbH on our infrastructure in the European Union. Shared website assets on aperai.eu are served through our Websupport hosting. Hosting providers process connection information to deliver those resources. Google and Microsoft provide the sign-in option you select and process information under their own privacy terms for their identity services. They are not simply Cartho’s processors for all of their activities.
Authorized aperAI personnel may access information where necessary for support, security or service administration. We may disclose information when required by law or necessary to establish or defend legal claims. We identify optional delivery, backup and AI providers before they process customer data.
Identity providers may process information outside the EEA. For transfers for which we are responsible, we use an applicable lawful mechanism, such as an adequacy decision or standard contractual clauses with any necessary supplementary measures. You can contact us for information about the safeguards relevant to your data. See also Google’s Privacy Policy and Microsoft’s Privacy Statement.
7. Retention and deletion
- Account and organization records
- Kept while needed to provide the account or agreed service. On a verified deletion or termination request, we delete or anonymize information that is no longer needed, subject to the organization’s instructions, legal obligations and the establishment or defence of claims.
- Authentication records
- Sessions have a seven-day validity period, which can be renewed during use, and may be revoked earlier. MFA verification authorizes sensitive actions for five minutes and protected reading for fifteen minutes. Unconfirmed MFA setup expires after ten minutes. Expiry prevents further use; stored authentication records are removed through cleanup or account deletion rather than necessarily at the instant they expire. MFA reset removes the old factor and its verification records.
- Security and support records
- Kept for the period needed to investigate incidents, resolve the request, prevent repeated abuse or meet applicable obligations. We assess necessity based on the incident or enquiry, open disputes and applicable legal deadlines; these records are not kept indefinitely for unrelated purposes.
- Integrated records and backups
- Source CV retention is controlled in SeeVee by the relevant organization. Ending Cartho access does not erase those source records. Where backups are enabled, deletion from backups follows their documented rotation cycle; retained copies are restricted to recovery and required legal purposes.
For account deletion, correction or a copy of your information, write to hello@aperai.eu. We may need to verify your identity. Removing a user’s membership does not automatically delete the organization’s records.
8. Cookies and security
Cartho uses necessary cookies for signed sessions and protection of the sign-in flow. We do not add advertising pixels, marketing cookies or third-party analytics scripts to Cartho. Your chosen identity provider may use its own cookies on its sign-in pages. Blocking necessary cookies may prevent sign-in.
Safeguards include server-side session validation, revocation, access controls, rate limits, MFA for elevated access and protected authentication secrets. Public access uses HTTPS. Access to personal data is limited according to the purpose and the user’s permissions. No system can guarantee absolute security.
9. Your rights
Subject to the applicable conditions, you may request access, correction, deletion, restriction or portability of your personal data, object to processing based on legitimate interests, and withdraw consent for consent-based processing. Withdrawal does not affect earlier lawful processing. We normally respond within one month; if a lawful extension is necessary, we will explain it within that period.
If an employer, recruiter or another organization controls your CRM or CV record, contact that organization first. We will assist with routing requests and with our obligations as its processor. You may complain to your local data protection authority, including the Estonian Data Protection Inspectorate.
Basic identity information is necessary to create and secure an account. If you do not provide it, you cannot use authenticated features; you may still read our public pages.
10. Children, changes and contact
Cartho is intended for business use, not for children. Accounts must be used by people aged at least 16 who have the legal capacity and authorization required for their use of the service. Organizations must not submit children’s personal data unless a specifically agreed use and appropriate safeguards permit it.
We will update the date above when this policy changes. For material changes affecting existing users, we will provide an appropriate notice before new processing begins, unless an immediate change is legally necessary.
aperAI OÜ
Narva mnt 5, 10117 Tallinn, Estonia
Registration number: 17446295
Privacy and support: hello@aperai.eu