How Catalyst handles client data

Catalyst Data provides payments benchmarking and diagnostics for B2C subscription businesses. This page explains, in plain language, how client data is used. The legally binding terms are in each client's Data Processing Agreement.

What we receive. Clients are contractually required not to send customers' names, email addresses, postal addresses, telephone numbers, payment-card details or other prohibited data. The service is designed to remove direct identifiers before transmission; what arrives is pseudonymised transaction data — amounts, dates, currencies, payment method types, and outcome codes. If prohibited data is detected, it is isolated, secured, and deleted or returned in accordance with the client's instructions.

What we do with it. We analyse each client's data solely to deliver their diagnostics and reporting, under their instructions, as a data processor under GDPR Article 28. A signed Data Processing Agreement is a precondition to any data transfer — no DPA, no data.

How benchmarks are built. Before any data contributes to industry benchmarks, it passes an anonymisation gate: outputs are aggregated across a minimum number of companies, published only as rates, ratios and equal-weighted averages (never absolute values), and protected by query controls. Thresholds are set out in our controlled Anonymisation Threshold Register, available to clients on request.

Our commitments.

  • We only publish anonymised, aggregated benchmarks. We do not name clients or individuals in benchmark outputs, and outputs are released only after passing our documented anonymisation assessment and applicable threshold controls.
  • We maintain benchmark data in deidentified form and will not attempt to reidentify any individual, household, or business from it, except solely to test the effectiveness of our own deidentification controls, and we require the same of anyone who receives it.
  • We do not sell personal information or share it for cross-context behavioural advertising. We use approved sub-processors only under contractual data-protection obligations.
  • AI tools are used only under commercial API terms that do not train on our clients' data.
  • Clients may instruct us to return or delete their data at any time in accordance with their DPA. Outputs that have validly passed the anonymisation gate are retained only in anonymised aggregate form and are not designed to identify a client or individual.

Demo access and prospect information. To view our product demo, we ask for your name, work email address, and company. We use these to provide demo access and to contact you about Catalyst's services — nothing else. We verify that sign-up emails are business addresses; we don't accept personal or disposable email domains. This information is stored securely, is never sold or shared for advertising, and is deleted on request — email us and it's gone. If you become a client, your information is then handled under your Data Processing Agreement, as described above. If you contact us through the form on this site, we also receive the name, email address and message you submit — used solely to respond to you, retained no longer than needed for that, and deleted on request.

Questions: jon@catalystdata.co