Privacy Policy
A self-hosted product whose data never reaches us, and a marketing site that measures itself with two well-known analytics tools — described plainly below. Here is the detail.
The short version
We collect about as little as it is possible to collect and still run a business.
- The product is measured, not you. The marketing site loads Google Analytics 4 (with IP anonymization) and Microsoft Clarity to understand aggregate usage; see section 10. The product you install is different: the local runtime phones nowhere, and your agent traffic, policies, decisions and audit records never reach us.
- The product is self-hosted. Your agent traffic, your policies, your decisions and your audit records stay inside your own boundary. They are never transmitted to us.
- We never see your payment details. Dodo Payments is the Merchant of Record and handles payment entirely.
- We do not sell personal data and never have. There is no advertising business here to sell it to.
1. Who we are
This policy is issued by Umang Kumar, trading as Cirvix, a sole proprietor established in India ("Cirvix", "we", "us"). For the purposes of the EU and UK General Data Protection Regulation, we are the controller of the limited personal data described below.
Data protection enquiries: [email protected].
2. What we collect
When you browse this website. Our host records standard server logs — IP address, user agent, requested URL, timestamp — for security and abuse prevention. We also measure aggregate usage of the marketing site itself with Google Analytics 4 and Microsoft Clarity, described in section 10.
When you contact us. The details you choose to give: name, work email, and whatever you write, plus optional context such as company size, deployment preference and use case. We use them to answer you.
When you buy a paid plan. Dodo Payments Inc. collects and processes your payment details, billing address and tax information as Merchant of Record. We receive none of your card data. Dodo Payments passes us the limited information we need to provide the product and meet our records obligations — typically your name or business name, email, country, and what you bought.
When you use the product. In a self-hosted deployment, nothing. The Software runs inside your infrastructure and does not transmit your policies, decisions, prompts, tool calls, or audit records to us. Where you separately and expressly opt in to send us diagnostic information, that is described at the point of choice.
3. What we never receive
Stated positively, because it is the part that matters most:
- the contents of your agents' prompts, tool calls, or responses;
- your policy rules, audit chain, or decision history;
- your
CIRVIX_MASTER_KEYor any secret it protects — it is customer-managed, with no escrow and no recovery path, which also means we could not disclose it if we were compelled to; - your card number, bank details, or any payment credential.
4. Why we process it, and on what legal basis
- To answer your enquiry — legitimate interests (responding to someone who contacted us), or steps prior to entering a contract.
- To supply the product and support you — performance of a contract.
- To keep the service secure and prevent abuse — legitimate interests.
- To meet tax, accounting and legal obligations — legal obligation.
- To send product or commercial email where you asked for it — consent, withdrawable at any time.
6. International transfers
We are established in India, and our providers may process data in the European Economic Area, the United Kingdom, the United States and elsewhere. Where personal data protected by EU or UK law is transferred outside those areas, we rely on an appropriate safeguard — typically the European Commission's Standard Contractual Clauses, or the UK Addendum — together with any supplementary measures required.
7. How long we keep it
- Enquiries and correspondence — while the conversation is live and for a reasonable period after, then deleted.
- Customer and transaction records — for as long as you are a customer, and afterwards for as long as tax and accounting law requires.
- Server logs — a short rolling window, for security purposes.
8. Your rights
If you are in the EEA or the UK, you have the right to access your personal data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent at any time. You may complain to your local supervisory authority — in the UK, the Information Commissioner's Office.
If you are in California, you have the right to know what we collect and why, to request deletion or correction, and to be free from discrimination for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not process it for cross-context behavioural advertising.
If you are in India, you have the rights available to a Data Principal under the Digital Personal Data Protection Act 2023, including access, correction, erasure and grievance redressal.
To exercise any right, write to [email protected]. We will respond within the period the applicable law requires, and we may need to verify your identity first.
9. Security
We keep the amount of personal data we hold deliberately small, which is the most effective security measure available to us. What we do hold is protected by access control, encryption in transit, and the principle that data we never collect cannot be breached.
No system is perfectly secure. We do not claim certification: SOC 2 and ISO 27001 work is in progress and we do not describe ourselves as compliant.
11. Children
The Software is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, tell us and we will delete it.
12. Changes
We may update this policy. The effective date at the top of the page shows when it last changed, and material changes will be notified to customers by email or in-product notice.
Bring every agent
under control.
Set durable policy, preserve a verifiable record, and give teams a safer way to put intelligent systems to work.