Legal
Privacy Policy
What data Caterfli holds, where it goes, who can see it, and how long it is kept — including exactly what an AI provider receives.
- Version
- 1.0
- Effective
- Last updated
This is a working starting point provided with the software. It is not
legal advice. Have a qualified adviser review it against your
jurisdiction and business before you rely on it.
What this policy covers
How this Caterfli installation handles personal data — what is collected, why, who it is shared with, and how long it is kept.
What we collect
Account data. Name, email address, hashed password, and the workspaces you belong to. Provided by you when you register or when a colleague invites you.
Workspace content. Agents you configure, conversations with them, execution history and reports. Created by you as you use the service.
Connection credentials. The secrets needed to reach systems you connect. See the section below — these are handled differently from everything else.
Technical data. IP address, browser type and timestamps, recorded with security-relevant events such as sign-in and permission changes.
Payment data. Handled by our payment provider. We store the subscription status and an identifier, never full card details.
How connection credentials are protected
This is the part of the system with the strictest handling, so it is worth being explicit:
- Credentials are encrypted at rest with a key kept separately from the
application key.
- They are decrypted only at the moment a connector opens a connection,
and are held in memory only for that call.
- They are never placed in a prompt, an AI model response, a log
line, an analytics event, a queued job payload, or anything sent to your browser.
- Administrators of this platform cannot view your decrypted
credentials through any interface. There is no "reveal" button, because there is no code path that would populate one.
What the AI provider receives
When an agent runs, the following is sent to the configured AI provider:
- your agent's instructions and the message your team sent
- the names and argument schemas of the tools the agent may use
- results returned by tools that were actually executed
The following is never sent: connection credentials, API keys, password hashes, or data belonging to another workspace.
Tool results can contain data from your connected systems, because that is what the agent was asked to work with. Restrict what an agent can read if that matters for a given system.
Why we process it
- To provide the service you have asked for (performance of a contract).
- To keep the platform and your workspace secure, including the audit
trail (legitimate interests, and legal obligation where applicable).
- To take payment and meet accounting obligations (legal obligation).
- To send service messages you cannot opt out of, such as security
notices and billing failures (legitimate interests).
- To send product announcements, only where you have subscribed
(consent, withdrawable at any time).
Who we share it with
- Infrastructure and AI providers that run the service, under
contract, and only as needed to deliver it.
- The payment provider, for subscriptions.
- Authorities, where the law requires it.
We do not sell personal data.
Isolation between customers
Every record belongs to exactly one workspace, and that boundary is enforced at the database query level rather than in application logic. Where no workspace can be determined, queries return nothing rather than everything — the system fails closed.
How long it is kept
- Workspace content: while your account is open, plus the retention
period configured for your workspace.
- Audit records: retained for the configured retention period, and not
editable by anyone, including us. The chain is tamper-evident, so alteration is detectable.
- Backups: overwritten on a rolling cycle.
- After account closure: deleted within 90 days, except where we must
keep records for accounting or legal reasons.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your data, to object to or restrict processing, and to withdraw consent.
Exercise any of these through the contact address on our contact page. We respond within one month. You may also complain to your local data protection authority.
International transfers
Where data is transferred outside your region, we use recognised safeguards such as standard contractual clauses.
Security
Encryption in transit and at rest, envelope encryption for credentials, role-based access control with per-member overrides, optional two-factor authentication, single sign-on, and a tamper-evident audit chain.
No system is perfectly secure. We will notify affected users and the relevant authority of a breach where the law requires it.
Changes
Material changes are announced before they take effect, and the version and effective date at the top of this page will change.