Ciele
Open app
Log in
Get a demo
Open app
Get a demo
Log in
Ciele

Product

  • Features
  • Pricing
  • Download
  • Log in

Enterprise

  • Governance
  • Security
  • Talk to sales

Resources

  • Docs
  • Getting started
  • Self-hosting

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Notice
© 2026 Ciele. AI you can trust.Rome, , :,

Newsletter

Security

GDPR

Last updated 5 August 2026

How the General Data Protection Regulation applies to Ciele, which role we play for which data, and what a data protection officer needs to sign us off. Where a certification is still in progress this page says so rather than rounding up.

On this page

  1. 01What is the GDPR?
  2. 02What is Ciele's role?
  3. 03Who has audited Ciele?
  4. 04Where is data stored?
  5. 05What measures protect personal data?
  6. 06How does Ciele meet a processor's obligations?
  7. 07How are data-subject requests handled?
  8. 08What resources are available?
  9. 09Can you complete our security questionnaire?

01What is the GDPR?

The General Data Protection Regulation (EU) 2016/679 has applied since May 2018. It governs how personal data belonging to people in the European Union and the European Economic Area is collected, used, stored and transferred, and it applies to us whether the person is a member of your organization or a student chatting with one of your assistants.

It gives every individual a set of rights over their own data:

  • To be informed about how their data is used.
  • To access the data held about them.
  • To have inaccurate data corrected.
  • To have their data erased.
  • To restrict how their data is processed.
  • To receive their data in a portable form.
  • To object to processing.
  • Not to be subject to a solely automated decision with legal or similarly significant effect.

02What is Ciele's role?

It depends which data you mean, and the distinction matters for who is accountable.

Ciele is the controller for account and website data: the name and email of a member, sign-in events, billing details, analytics about our own marketing site.

For the data flowing through your assistants, meaning the knowledge you connect, the conversations your visitors have and any user data you import for personalization, your organization is the controller and Ciele is the processor acting on your instructions. You decide what is ingested, what is retained and for how long; we process it to deliver the service and for nothing else.

03Who has audited Ciele?

Nobody yet, and we will not imply otherwise. We recently began a SOC 2 Type II program and formal GDPR compliance work; neither has produced an external report or attestation at this point. When one exists, this page will say so and name the auditor.

What we can offer in the meantime is specific rather than reassuring: the platform is open source, so the isolation, access-control and retention mechanisms described on the security page can be read in the source rather than taken on trust, and an institution that cannot rely on an unaudited processor can self-host the whole platform inside its own perimeter.

04Where is data stored?

The managed platform runs on European cloud infrastructure, and the primary database and file storage are hosted in the EU. Model providers that generate assistant answers process the prompt and the retrieved knowledge to produce a response; where a provider processes data outside the EEA, that transfer relies on Standard Contractual Clauses and, where applicable, an adequacy decision.

Every provider that touches customer data is named on the subprocessor page, with what it does and where it runs.

05What measures protect personal data?

The technical and organizational measures below are in place today, not planned:

  • Tenant isolation enforced at the database layer with Postgres row-level security, so one organization's queries cannot reach another organization's rows.
  • Role-based access control within each organization, so a member sees only what their role allows.
  • TLS for traffic to the platform, and encryption at rest by our managed database and storage providers.
  • Integration credentials and access tokens stored sealed, never in plain text.
  • Least-privilege internal access: a small number of staff, only where operating or supporting the service requires it.
  • Per-organization retention controls for conversation traces, so diagnostic data is swept on a schedule you set rather than kept indefinitely.
  • Grounded answers with Source citations, so the provenance of an answer can be audited rather than guessed at.

06How does Ciele meet a processor's obligations?

Our processor commitments are written down in the Data Processing Addendum: we process only on your instructions, keep processing confidential, apply the measures above, engage subprocessors under equivalent obligations and with notice of changes, assist you with data-subject requests and impact assessments, notify you of a personal data breach without undue delay, and delete or return your data at the end of the relationship.

In the product, the same obligations show up as features rather than promises: an organization can export or delete its conversations and knowledge itself, and does not have to open a ticket with us to honour an erasure request from one of its own users.

07How are data-subject requests handled?

If you are a member of a customer organization, or a visitor who chatted with one of its assistants, that organization is the controller. Send the request to them, and they can act on it directly in the product. If a request reaches us first we will route it to them rather than act on their data unilaterally.

For data where Ciele is the controller, write to privacy@ciele.app and we will respond within the statutory period.

08What resources are available?

  • Data Processing Addendum. The processor terms, transfer mechanisms and subprocessor notice.
  • Subprocessors. Every provider that processes data on our instructions.
  • Privacy Policy. What we collect as a controller, and why.
  • Cookie Notice. Every cookie, its purpose and its lifetime.
  • Security overview. The practices behind the measures listed above.

09Can you complete our security questionnaire?

Yes. Send it to security@ciele.app and we will complete it, including the questions where the honest answer is “not yet”. We can also walk a procurement or DPO team through the architecture directly.

The fine print

Even our cloud nods off here

Short where it can be, precise where it must be. If anything in these pages is unclear, write to us and a human will answer.

Contact us