Skip to content

Legal

Data Processing Information

Last updated August 2026

Roles and instructions

Your organization determines the purposes of the data it places in chAIn and the goals, tools, and providers its agents may use. chAIn processes that data to provide, secure, meter, support, and improve the contracted service, subject to your configured controls.

Data categories

Processing may include account and membership details, agent configuration, prompts and run output, documents you upload, integration metadata, encrypted credentials, usage and billing records, and security audit events. The service is not designed to require special-category personal data unless your organization has separately approved that use.

Security controls

Organization data is isolated with database row-level security, credentials are sealed at rest, consequential actions are audited, and higher-risk tool calls can require human approval. Retrieved content and tool output are treated as untrusted data and scanned before use or release.

Retention, return, and deletion

Configured retention jobs remove eligible run, knowledge, and memory data. Organization owners can request an export or deletion; legal holds pause platform-applied deletion. Limited billing and security records may remain where law or fraud prevention requires them, with customer-controlled content removed or de-identified.

International processing

Hosting region and model routing determine where data may be processed. Geographic hosting controls are not yet generally available; organizations with residency requirements must confirm an appropriate deployment and provider configuration before submitting regulated data.