Privacy Policy
Applies to the Caldriax marketing site (caldriax.com) and the Caldriax application (app.caldriax.com) during the free invite-only beta.
Who we are
Caldriax provides automated website and application auditing and monitoring. The data controller is [TO BE COMPLETED: legal entity name, company number if applicable, registered address]. Privacy enquiries: [TO BE COMPLETED: contact email].
Account and invite information
When you request beta access we collect your name, work email address, optional company name, the website you want audited, your role, an approximate number of sites and any optional free-text notes you provide. We use this solely to review and administer beta invitations. If you are invited and create an account, we also process your authentication details and account settings.
Website URLs submitted for auditing
Caldriax processes the URLs you add. You must be the owner of, or otherwise authorised to test, any site you submit. Submitted addresses are stored against your account.
Audit and monitoring data
Running an audit collects publicly retrievable responses from the target, derived findings, scores, performance measurements, uptime and SSL status, and browser-rendered evidence such as screenshots and runtime signals. This evidence is stored privately and scoped to the owning account.
Technical logs
We keep operational logs (timestamps, request outcomes, error diagnostics and coarse rate-limiting fingerprints) to run the service securely and to prevent abuse. Beta request submissions record a hashed network fingerprint for spam prevention rather than a stored IP address.
AI processing
Where you use Caldriax AI, selected audit findings and evidence are sent to a third-party model provider to generate explanations and remediation guidance. Inputs are redacted before transmission to reduce the chance of secrets or sensitive values being included. AI output never alters deterministic audit scores.
Integration data
If you connect a code-hosting integration, we process the repository metadata and permissions needed to draft issues and respond to deployment events you have configured. Integration credentials are held server-side and are never exposed to the browser.
Email communications
We send service and product emails such as invite decisions, audit summaries and incident notifications. During the free beta we do not send billing communications. You can opt out of non-essential email from your account settings.
Retention and deletion
Beta requests are retained while the beta programme runs and then deleted or anonymised. Audit and monitoring data is retained while your account is active and subject to the retention windows applied in the product. You can export or delete your account data from the application; deletion removes associated audit, monitoring and evidence records.
Subprocessors
At a high level we use providers for application hosting and database services, transactional email delivery, AI model inference, and performance data collection. A current subprocessor list can be supplied on request — [TO BE COMPLETED: whether a published list will be maintained].
Your rights
Depending on your location you may have rights to access, correct, delete, restrict or port your personal data, and to object to certain processing. Contact [TO BE COMPLETED: contact email]. You may also complain to your local supervisory authority; in the UK this is the Information Commissioner's Office.
Changes
We will update this policy as the product develops and will notify account holders of material changes. Last updated: [TO BE COMPLETED: publication date].
