Trust centre
How Caicle handles your data
Hosting, data flows, subprocessors, the DPA, AI Act obligations, isolation and the agent sandbox. Written for the person who has to sign off.
On this page
Hosting
The platform, its database and the agent sandbox run on servers in EU data centres operated by a European provider. Backups stay in the EU. The provider is listed in the subprocessor register and in your DPA.
Data flows
Three kinds of data move through Caicle, and they move differently.
- 01
Account and workspace data
Your users, settings, profiles and pipeline. Stored in the EU.
- 02
Company research data
Fetched from public sources and the company's own filings. Stored in your tenant.
- 03
AI inference
Prompts and research context are sent to a model provider to generate scores, summaries and plans. See the subprocessor register. Bring your own model key on any plan.
Subprocessors
| Purpose | Provider | Location | Safeguard | Since |
|---|---|---|---|---|
| Hosting, database and agent sandbox | EU hosting provider | EU | DPA, ISO 27001 | 2026 |
| Email delivery | Transactional email provider | EU | DPA | 2026 |
| Payments | Stripe | EU/US | DPA, SCCs | 2026 |
| Model inference | Model provider (per configured key) | EU or US depending on provider | DPA, SCCs where applicable; bring-your-own key available | 2026 |
| Web search | Search providers (per configured key) | Varies | DPA where available; query text only | 2026 |
| Analytics | Self-hosted, cookieless | EU | No third party | 2026 |
Changes are announced 30 days ahead by email to workspace owners.
Data processing agreement
Every plan includes a DPA under Art. 28 GDPR, accepted at signup and downloadable from Settings. Enterprise customers may sign a countersigned copy.
Annexes
- Subject matter, nature and purpose of processing
- Types of personal data and categories of data subjects
- Technical and organisational measures
- Approved subprocessors
AI Act Art. 50
- Output is marked AI-generated until you approve it
- Approval is logged with the approver and the time
- Reports carry a disclosure
- Person research is limited to professional roles
- Private-life data is out of scope by system rule
Tenant isolation
Row-level security in the database, not application filters. Every query runs inside the tenant's row-level policy, so a bug in application code cannot reach another tenant's rows.
Agent sandbox
Agents and the Ops Console run in an isolated container with no route to the database, no shell, and outbound access only through an allowlist proxy. Tenant MCP tools extend what an agent can reach without extending the blast radius.
Secrets
Provider keys and MCP credentials are encrypted at rest and never returned by the API. A test probe confirms a connection without exposing the credential.
Consent
Only necessary cookies by default, under § 25 TDDDG and Art. 6 GDPR. Analytics is self-hosted and cookieless, and runs only after consent. Your choice is revocable from the footer at any time.
Incidents and enquiries
Report a security issue to start@teleroids.io. We acknowledge reports within two business days. Data-protection enquiries go to the address in the imprint.
start@teleroids.ioThis page describes the platform as built. It is not legal advice.
See Caicle on the accounts you actually sell to
Start a free trial in minutes, or send us three domains and we will run them live with you.