Legal
Data Processing Information
Last updated August 2026
Roles and instructions
Your organization determines the purposes of the data it places in chAIn and the goals, tools, and providers its agents may use. chAIn processes that data to provide, secure, meter, support, and improve the contracted service, subject to your configured controls.
Data categories
Processing may include account and membership details, agent configuration, prompts and run output, documents you upload, integration metadata, encrypted credentials, usage and billing records, and security audit events. The service is not designed to require special-category personal data unless your organization has separately approved that use.
Security controls
Organization data is isolated with database row-level security, credentials are sealed at rest, consequential actions are audited, and higher-risk tool calls can require human approval. Retrieved content and tool output are treated as untrusted data and scanned before use or release.
Retention, return, and deletion
Configured retention jobs remove eligible run, knowledge, and memory data. Organization owners can request an export or deletion; legal holds pause platform-applied deletion. Limited billing and security records may remain where law or fraud prevention requires them, with customer-controlled content removed or de-identified.
International processing
Hosting region and model routing determine where data may be processed. Geographic hosting controls are not yet generally available; organizations with residency requirements must confirm an appropriate deployment and provider configuration before submitting regulated data.