Last updated: March 2026
At Reskatu, privacy is not mere regulatory compliance, but the foundation of our security infrastructure. For the purposes of the General Data Protection Regulation (GDPR) and the LOPDGDD 3/2018, the Data Controller is Wallison Yago Vieira Nogueira (NIE: Z0842353Y), residing at Urb. Villas Madrid, casa 56, Estepona, Málaga, 29688, Spain. You can contact our data protection office directly at: legal@reskatu.com.
Reskatu uses a decentralised cryptographic authentication model based on FIDO2 standards (Passkeys). When logging in using biometric data (Face ID, Touch ID, or Windows Hello), validation occurs exclusively on your device's hardware (Secure Enclave). Reskatu never receives, processes, or stores your original biometrics. Consequently, our platform is exempt from processing special categories of data (Art. 9 GDPR), guaranteeing that, even in the event of an attack on our infrastructure, your biometric identity remains mathematically unassailable.
We apply a strictly professional data collection policy. Under Article 19 of the LOPDGDD, we only process the corporate contact data (name, job title, email, and professional telephone number) necessary to maintain the commercial and technical relationship. Reskatu expressly prohibits continuous geolocation tracking of executives, scraping of personal social networks, and demanding copies of full identity documents (ID/Passport) within its systems, mitigating any invasion of the user's private sphere.
In strict compliance with the European Artificial Intelligence Act (EU AI Act), we inform you that when using our platform you interact with "Katu", an Artificial Intelligence system designed for technical support and consultancy. The data entered into conversations is processed exclusively to generate contextual responses and execute authorised commands. Your prompts, business data, and conversations are never used to train open foundational models.
Corporate data will be retained for as long as there is a mutual interest in maintaining the purpose of the processing, or for the time strictly necessary to comply with applicable legal and tax obligations in Spain. Reskatu's infrastructure applies mathematical isolation (Row-Level Security in PostgreSQL) and encryption in transit and at rest, guaranteeing the inviolability of your business metadata.
As a corporate user, you have the right to obtain confirmation as to whether we at Reskatu are processing your data. You may exercise your rights of Access, Rectification, Erasure, Restriction, Objection, and Portability at any time and free of charge by sending a formal request to legal@reskatu.com. Furthermore, you have the right to lodge a complaint with the supervisory authority (Spanish Data Protection Agency - AEPD - www.aepd.es) if you consider that the processing does not comply with current regulations.