Data processing

Data processing addendum

What we process, where, for how long, and what we commit to as your processor.

Last reviewed 31 August 2026

What this page is. A plain-English statement of how we process customer data as a processor under GDPR Article 28 and equivalent laws. It is not itself an executed agreement. A countersignable DPA, including the standard contractual clauses where they apply, is available from legal@cainstudio.online and we will sign yours if you would rather use it.

How we handle data

What we process

Account identifiers and billing contact details; the decision records your agents generate, including the service, path, verdict and stage results; usage counts for metering; and API key fingerprints. We do not require or store your agents' prompts, model outputs or training data.

What we never store in the clear

API keys. They are held as SHA-256 fingerprints, so a database disclosure does not hand anyone a working credential. Card numbers never reach our servers at all -- they are entered on Stripe's own hosted page.

Where it is processed

United States, on infrastructure operated by the hosting provider named in the sub-processor list. The hosted deployment is single-region. If your data may not leave a jurisdiction, the self-hosted deployment processes nothing on our side.

How long we keep it

Decision records and evidence are retained for the life of the account so they remain available for an incident review, which is their entire purpose. Usage counters are retained for billing and reconciliation. Deletion on request is covered below.

Deletion

Write to the privacy address and we will delete your account data, including decision records and evidence, and confirm when it is done. Billing records are retained where tax and accounting law requires it, which we will identify specifically rather than citing a blanket exemption.

Isolation between customers

Every fabric store is tenant-scoped and the tenant is resolved from billing on the server -- never taken from a header the caller controls. Cross-tenant reads return a 404, not a 403, so an identifier cannot be probed for existence.

Sub-processors

Four, listed in full with what reaches each of them. There is no third-party LLM provider, no third-party analytics and no advertising tracker on either site.

Breach notification

We will notify affected customers without undue delay and in any case within 72 hours of becoming aware of a personal data breach, with what we know at the time rather than waiting for a complete picture.

Your rights and our obligations

You are the controller; we are the processor. We process customer data only on your documented instructions, ensure that anyone with access is bound to confidentiality, assist you with data-subject requests and with your own security obligations, and delete or return the data at the end of the engagement. We will not engage a new sub-processor without publishing it on the sub-processors page first.

Audit

We have no third-party audit report to give you, and we are not going to imply otherwise -- see what we don't do yet. What we can offer instead is our threat model, our control mapping against SOC 2 and ISO 27001 criteria as a readiness exercise, and answers to your own questionnaire from the people who wrote the code.

Privacy policy · Sub-processors · Terms