Privacy Policy
This privacy policy explains how personal data is collected, used, and protected by Clint Bailo, trading as Tayeno ("we", "our", or "us"), operator of tayeno.com. For questions regarding your personal data, contact us at [email protected].
1. Data Controller vs. Data Processor Roles
Under the UK General Data Protection Regulation (UK GDPR):
- Data Controller: Tayeno acts as the Data Controller for direct customer account information, billing details, waitlist subscriptions, and website visitor analytics.
- Data Processor: When you subscribe and connect your email, calendar, or workflows to your agent instance, you (the customer) act as the Data Controller, and Tayeno acts as the Data Processor. We process such data exclusively on your behalf in accordance with our Data Processing Addendum (DPA).
2. Explicit Sub-Processors
We maintain full transparency regarding third-party service providers and sub-processors:
| Sub-Processor | Purpose | Location / Safeguards |
|---|---|---|
| Hetzner Online GmbH | Dedicated VPS hosting (Agent Plane runtime & isolated vaults) | Germany / EU (UK Adequacy Regulations) |
| DeepSeek (Hangzhou DeepSeek AI Co., Ltd.) | LLM Inference for drafting & synthesis (Direct API endpoint) | China (International Data Transfer). Model inference requests are transmitted directly to DeepSeek API infrastructure in Hangzhou, China without an adequacy decision or standard contractual safeguards, relying on explicit customer consent under UK GDPR Article 49(1)(a). Formal IDTA transfer arrangements are in progress. |
| Stripe Payments UK, Ltd. | Subscription billing and card processing | United Kingdom / PCI-DSS Level 1 |
| Telegram FZ-LLC | Messaging gateway and user interface | Global / End-user interface |
International Data Transfer Notice: Model inference requests (inbox triage, draft generation, and dossiers) are transmitted directly to DeepSeek API infrastructure located in Hangzhou, China. Because the UK has not issued an adequacy decision for China and formal transfer safeguards (such as an International Data Transfer Agreement or Standard Contractual Clauses) are not currently executed with DeepSeek, we rely on your explicit consent under UK GDPR Article 49(1)(a) as the legal basis for these transfers when you connect a mailbox. We are actively working toward formal contractual transfer arrangements and will update this notice once executed.
3. Security Architecture & Vaults
We enforce strict technical boundaries to safeguard your data:
- Zero Password Storage: We do not ask for or store main account passwords. Connections use app-specific passwords or scoped OAuth tokens.
- Secret Isolation: Credentials reside in an encrypted vault (AES-256-GCM) per tenant. Secrets are never passed into model context prompts.
- OS Isolation: Each customer agent executes under an isolated Linux user account with restricted filesystem permissions (0700).
- Draft-Only Outbound: Agents draft responses and require your explicit confirmation on Telegram before sending.
4. Data Retention & 30-Day Deletion
Upon subscription cancellation, all stored memory profiles, logs, and tenant vaults are permanently and securely purged within 30 days.
5. Your Rights and the ICO
You have statutory rights under UK GDPR to access, rectify, restrict, or erase your personal data. To exercise any of these rights, email [email protected].
Under Article 77 of the UK GDPR, you also have the right to lodge a complaint with the UK supervisory authority: the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF (ico.org.uk).