Privacy Policy

Applies to the Caldriax marketing site (caldriax.com) and the Caldriax application (app.caldriax.com) during the free invite-only beta.

Owner action required before launch. This draft is written for a UK-oriented beta SaaS and must be reviewed by the site owner and, where appropriate, a legal adviser. Fields marked [TO BE COMPLETED] require owner-supplied details — no company registration, address, representative or data protection contact has been assumed.

Who we are

Caldriax provides automated website and application auditing and monitoring. The data controller is [TO BE COMPLETED: legal entity name, company number if applicable, registered address]. Privacy enquiries: [TO BE COMPLETED: contact email].

Account and invite information

When you request beta access we collect your name, work email address, optional company name, the website you want audited, your role, an approximate number of sites and any optional free-text notes you provide. We use this solely to review and administer beta invitations. If you are invited and create an account, we also process your authentication details and account settings.

Website URLs submitted for auditing

Caldriax processes the URLs you add. You must be the owner of, or otherwise authorised to test, any site you submit. Submitted addresses are stored against your account.

Audit and monitoring data

Running an audit collects publicly retrievable responses from the target, derived findings, scores, performance measurements, uptime and SSL status, and browser-rendered evidence such as screenshots and runtime signals. This evidence is stored privately and scoped to the owning account.

Technical logs

We keep operational logs (timestamps, request outcomes, error diagnostics and coarse rate-limiting fingerprints) to run the service securely and to prevent abuse. Beta request submissions record a hashed network fingerprint for spam prevention rather than a stored IP address.

AI processing

Where you use Caldriax AI, selected audit findings and evidence are sent to a third-party model provider to generate explanations and remediation guidance. Inputs are redacted before transmission to reduce the chance of secrets or sensitive values being included. AI output never alters deterministic audit scores.

Integration data

If you connect a code-hosting integration, we process the repository metadata and permissions needed to draft issues and respond to deployment events you have configured. Integration credentials are held server-side and are never exposed to the browser.

Email communications

We send service and product emails such as invite decisions, audit summaries and incident notifications. During the free beta we do not send billing communications. You can opt out of non-essential email from your account settings.

Retention and deletion

Beta requests are retained while the beta programme runs and then deleted or anonymised. Audit and monitoring data is retained while your account is active and subject to the retention windows applied in the product. You can export or delete your account data from the application; deletion removes associated audit, monitoring and evidence records.

Subprocessors

At a high level we use providers for application hosting and database services, transactional email delivery, AI model inference, and performance data collection. A current subprocessor list can be supplied on request — [TO BE COMPLETED: whether a published list will be maintained].

Your rights

Depending on your location you may have rights to access, correct, delete, restrict or port your personal data, and to object to certain processing. Contact [TO BE COMPLETED: contact email]. You may also complain to your local supervisory authority; in the UK this is the Information Commissioner's Office.

Changes

We will update this policy as the product develops and will notify account holders of material changes. Last updated: [TO BE COMPLETED: publication date].