Privacy Policy
1. Overview and Data Controller
This Privacy Policy explains how ContextRail AI Software S.L. ("ContextRail AI", "we", "our") collects, uses, processes, and safeguards personal data and technical payloads when you visit our website at https://contextrail.cloud or interact with our API and Model Context Protocol (MCP) services.
The designated Data Controller under Regulation (EU) 2016/679 (GDPR) is:
ContextRail AI Software S.L.
Tax ID (NIF): B-88514920
Paseo de la Castellana 95, Planta 18, 28046 Madrid, Spain
DPO Email: privacy@contextrail.cloud
2. Strict Commitment: Zero AI Model Training
ContextRail AI maintains an uncompromising, architectural commitment to data sovereignty:
- No Training on Customer Data: We do NOT use customer prompts, contextual memory chunks, retrieved documents, or inference outputs to train, fine-tune, or evaluate foundation models, embedding systems, or any machine learning algorithms.
- Pass-Through Semantic Routing: When context is routed to Anthropic Claude (Claude Sonnet or Haiku), payloads transit encrypted and are never retained by ContextRail AI beyond the active inference lifecycle.
- Isolated Memory Partitions: Persistent cross-session agent memory stored via our vector-graph engine is isolated with tenant-specific AES-256 encryption keys.
3. Information We Collect and Process
We process only minimal, necessary information required for SaaS delivery:
- Account Information: Business email address, authentication provider identifiers (Google Workspace, GitHub SSO), name, and company billing profile.
- Technical & API Telemetry: API token identifiers, token routing volume, Claude Prompt Cache hit statistics, compression efficiency ratios, and HTTP request headers for latency monitoring.
- Billing Information: Payment transactions are handled directly by PCI-DSS compliant merchants of record (Stripe). We do not store raw credit card numbers.
4. Legal Basis for Processing (GDPR Article 6)
We process data under the following legal bases:
- Contract Performance (Art. 6.1.b): To provision API keys, execute semantic context compression, maintain MCP endpoints, and bill active SaaS subscriptions.
- Legitimate Interests (Art. 6.1.f): To monitor API infrastructure health, prevent denial of service attacks, and ensure sub-50ms routing performance.
- Legal Compliance (Art. 6.1.c): For tax reporting, billing records, and compliance under Spanish and European Union regulations.
5. Security Standards and Infrastructure
All data handled by ContextRail AI is protected by enterprise-grade security controls:
- End-to-end encryption in transit via TLS 1.3 with strict HSTS enforcement.
- At-rest encryption for persistent memory vector indexes using AES-256.
- Zero long-term retention of raw uncompressed prompt payloads in routing memory.
- Infrastructure hosted exclusively in SOC2 Type II and ISO 27001 certified European data centers (Madrid & Frankfurt regions).
6. Data Subject Rights (GDPR Articles 15-22)
As a European or global user, you hold full statutory rights under the GDPR:
- Right of Access & Rectification: Request full copies of stored account data and prompt usage records.
- Right to Erasure ("Right to be Forgotten"): Instantly wipe episodic memory partitions, vector embeddings, and API keys via the developer console or by contacting
privacy@contextrail.cloud. - Right to Data Portability: Export memory graphs and routing telemetry in standard JSON / JSON-Lines formats.
- Right to Lodge a Complaint: File an inquiry with the competent European Data Protection Authority (AEPD,
aepd.es).
7. Contact Our Data Protection Officer
If you have any questions, requests, or privacy audit reviews, please contact our Data Protection Officer:
DPO Office · ContextRail AI Software S.L.
Paseo de la Castellana 95, Planta 18, 28046 Madrid, Spain
Email: privacy@contextrail.cloud