Legal
Privacy notice
Last updated: 2026-09-06
Controller
The controller under the GDPR is TELEROiDS Limited (trading as Teleroids.io), Punchbowl Centre, Soho St Julians, Triq Elija Zammit, STJ 3154 San Ġiljan, Malta, company number 7706-0755-1884-1488. Registered details are in the imprint. For data-protection matters write to privacy@teleroids.io; general enquiries go to start@teleroids.io. This notice applies to caicle.io and to the Caicle service.
What we process on the website
Three kinds of data occur on the website: personal data you give us (name, work email, company and role, phone if you add it, and the content of your messages), usage data that the server records (IP address, browser type, pages visited, time and date, device identifiers and diagnostics), and cookies. In detail:
- Server logs. When you open a page, the server records the requested URL, the time, the HTTP status, the referrer, the user agent and a truncated IP address. Logs are used to run and secure the service and are deleted after 14 days.
- Consent state. Your cookie choice is stored in a first-party cookie so we do not ask again on every visit.
- Analytics. Only after consent, and only as described below.
- Demo and partner requests. The details you enter in the walkthrough or design-partner form, as described below.
Legal bases
- Art. 6 (1) (b) GDPR for steps taken at your request before entering a contract, including demo requests and the trial.
- Art. 6 (1) (f) GDPR for running and securing the website (server logs) and for defending legal claims.
- Art. 6 (1) (a) GDPR for analytics and any other purpose that needs your consent. Consent can be withdrawn at any time with effect for the future.
- Art. 6 (1) (c) GDPR where we are legally obliged to retain records, for example for tax purposes.
Cookies and consent
By default we set only technically necessary cookies (§ 25 (2) TDDDG): the session for signed-in users, a CSRF token, your language and your consent choice. Analytics, advertising and functional services load only after you consent under § 25 (1) TDDDG and Art. 6 (1) (a) GDPR. You can change or withdraw your choice at any time via "Cookie settings" in the footer.
Analytics
After consent we measure page views with self-hosted, cookieless analytics on our own servers in the EU. It records the page, the referrer, the browser type and a daily rotating identifier derived from a truncated IP address that cannot be linked back to you. No third party receives this data and no profile is built.
Demo requests
If you request a walkthrough or apply to the design-partner programme, we process your name, work email, company, the domains you optionally give us and your message to arrange the call and to prepare it. Requests are stored as leads for twelve months after the last contact and then deleted, unless a contract follows. Domains you submit are researched from public sources only for the purpose of the call.
Account data
For customers, account and workspace data (users, settings, profiles, pipeline and research results) are processed under the data processing agreement, in which the customer is the controller and Teleroids.io the processor. Company research data is collected from public registers and the company's own filings; person data is limited to professional roles, and each dossier generates a GDPR Art. 14 notice for the customer to use.
Recipients and subprocessors
We use a small number of subprocessors for hosting, email delivery, payments, model inference and web search. The current register, with location and safeguard for each, is published in the trust centre. Changes are announced 30 days ahead by email to workspace owners.
International transfers
The platform, its database and backups are in the EU. Model inference may run with a provider in the EU or the US depending on the configured key; transfers to a third country rest on the EU Standard Contractual Clauses and, where applicable, an adequacy decision. Customers may bring their own model key on any plan to keep inference with a provider of their choice.
Retention
- Server logs: 14 days.
- Consent state: 12 months, then we ask again.
- Demo and partner requests: 12 months after the last contact.
- Account data: for the term of the contract and 30 days after deletion of the workspace, longer only where the law requires it.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR), and the right to withdraw consent at any time with effect for the future. To exercise a right, write to privacy@teleroids.io; we answer within one month.
Supervisory authority
You have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Office of the Information and Data Protection Commissioner (IDPC), Malta, idpc.org.mt. You may also complain to the authority of the member state of your habitual residence, your place of work or the place of the alleged infringement.
Minors
Caicle is a business service. We do not knowingly process personal data of anyone under 18, and the service may not be used by minors. If you believe a minor has provided us with data, write to privacy@teleroids.io and we will delete it.
Links to other sites
The website links to external sites, including the public registers and company websites that research results cite. We have no control over their content or their privacy practices, and this notice does not apply to them.
Changes to this notice
We update this notice when the service or the law changes. The date at the top shows the current version. Material changes that affect customers are announced by email to workspace owners.