Privacy Policy
This privacy policy explains how personal data is collected, used, and protected by Clint Bailo, trading as Tayeno ("we", "our", or "us"), operator of tayeno.com. For questions regarding your personal data, contact us at hello@tayeno.com.
1. Data Controller vs. Data Processor Roles
Under the UK General Data Protection Regulation (UK GDPR):
- Data Controller: Tayeno acts as the Data Controller for direct customer account information, billing details, waitlist subscriptions, and website visitor analytics.
- Data Processor: When you subscribe and connect your email, calendar, or workflows to your agent instance, you (the customer) act as the Data Controller, and Tayeno acts as the Data Processor. We process such data exclusively on your behalf in accordance with our Data Processing Addendum (DPA).
2. Explicit Sub-Processors
We maintain full transparency regarding third-party service providers and sub-processors:
| Sub-Processor | Purpose | Location / Safeguards |
|---|---|---|
| Hetzner Online GmbH | Dedicated VPS hosting (Agent Plane runtime & isolated vaults) | Germany / EU (UK Adequacy Regulations) |
| DeepSeek (Hangzhou DeepSeek AI Co., Ltd.) | LLM Inference for drafting & synthesis (Direct API endpoint) | China (International Data Transfer). <!-- TODO (Clint): Formalize appropriate UK GDPR transfer mechanism / IDTA / SCCs for China processing --> |
| Stripe Payments UK, Ltd. | Subscription billing and card processing | United Kingdom / PCI-DSS Level 1 |
| Telegram FZ-LLC | Messaging gateway and user interface | Global / End-user interface |
International Data Transfer Notice: Model inference requests (drafting, inbox triage, and dossiers) are transmitted directly to DeepSeek API infrastructure located in China. <!-- TODO (Clint): Select and document legal transfer mechanism (e.g. UK International Data Transfer Agreement (IDTA) or controller consent) -->
3. Security Architecture & Vaults
We enforce strict technical boundaries to safeguard your data:
- Zero Password Storage: We do not ask for or store main account passwords. Connections use app-specific passwords or scoped OAuth tokens.
- Secret Isolation: Credentials reside in an encrypted vault (AES-256-GCM) per tenant. Secrets are never passed into model context prompts.
- OS Isolation: Each customer agent executes under an isolated Linux user account with restricted filesystem permissions (0700).
- Draft-Only Outbound: Agents draft responses and require your explicit confirmation on Telegram before sending.
4. Data Retention & 30-Day Deletion
Upon subscription cancellation, all stored memory profiles, logs, and tenant vaults are permanently and securely purged within 30 days.
5. Your Rights and the ICO
You have statutory rights under UK GDPR to access, rectify, restrict, or erase your personal data. To exercise any of these rights, email hello@tayeno.com.
Under Article 77 of the UK GDPR, you also have the right to lodge a complaint with the UK supervisory authority: the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF (ico.org.uk).