Data processing
Data processing addendum
What we process, where, for how long, and what we commit to as your processor.
Last reviewed 31 August 2026
What this page is. A plain-English statement of how we process customer data as a processor under GDPR Article 28 and equivalent laws. It is not itself an executed agreement. A countersignable DPA, including the standard contractual clauses where they apply, is available from legal@cainstudio.online and we will sign yours if you would rather use it.
How we handle data
What we process
Account identifiers and billing contact details; the decision records your agents generate, including the service, path, verdict and stage results; usage counts for metering; and API key fingerprints. We do not require or store your agents' prompts, model outputs or training data.
What we never store in the clear
API keys. They are held as SHA-256 fingerprints, so a database disclosure does not hand anyone a working credential. Card numbers never reach our servers at all -- they are entered on Stripe's own hosted page.
Where it is processed
United States, on infrastructure operated by the hosting provider named in the sub-processor list. The hosted deployment is single-region. If your data may not leave a jurisdiction, the self-hosted deployment processes nothing on our side.
How long we keep it
Decision records and evidence are retained for the life of the account so they remain available for an incident review, which is their entire purpose. Usage counters are retained for billing and reconciliation. Deletion on request is covered below.
Deletion
Write to the privacy address and we will delete your account data, including decision records and evidence, and confirm when it is done. Billing records are retained where tax and accounting law requires it, which we will identify specifically rather than citing a blanket exemption.
Isolation between customers
Every fabric store is tenant-scoped and the tenant is resolved from billing on the server -- never taken from a header the caller controls. Cross-tenant reads return a 404, not a 403, so an identifier cannot be probed for existence.
Sub-processors
Four, listed in full with what reaches each of them. There is no third-party LLM provider, no third-party analytics and no advertising tracker on either site.
Breach notification
We will notify affected customers without undue delay and in any case within 72 hours of becoming aware of a personal data breach, with what we know at the time rather than waiting for a complete picture.
Your rights and our obligations
You are the controller; we are the processor. We process customer data only on your documented instructions, ensure that anyone with access is bound to confidentiality, assist you with data-subject requests and with your own security obligations, and delete or return the data at the end of the engagement. We will not engage a new sub-processor without publishing it on the sub-processors page first.
Audit
We have no third-party audit report to give you, and we are not going to imply otherwise -- see what we don't do yet. What we can offer instead is our threat model, our control mapping against SOC 2 and ISO 27001 criteria as a readiness exercise, and answers to your own questionnaire from the people who wrote the code.