Legal · last updated 2026-06-30
Privacy Policy
This policy describes the data AegisRail processes to provide AI observability, evaluation, governance, evidence, billing, support, and security operations, and the choices you have.
Practical template pending legal review. Not legal advice.
Who We Are And Our Role
AegisRail is operated by Eastbase Studio ("we", "us", "our"). For the workspace data you submit, we generally act as a processor or service provider, and you act as the controller or business, depending on applicable law.
For account, billing, security, and service administration data, we may act as an independent controller where that is required to operate the Service. Where we process personal data on your behalf, the Data Processing Addendum applies.
Data We Collect
We collect account information, workspace membership, organization settings, billing identifiers, audit logs, support communications, and operational metadata needed to run the Service. With your consent, we also collect product analytics.
We process the workspace records you configure, including AI system entries, trace metadata, eval results, incidents, governance settings, and evidence artifacts, to provide TrustOps features.
AI Trace And Eval Data
AegisRail is designed to avoid raw prompt and completion storage by default, but you control what you submit. You must not send secrets, credentials, API keys, raw personal data, regulated data, confidential customer content, prompts, completions, or sensitive evidence unless approved retention, redaction, access controls, and disclosure processes are in place.
By default we store metadata such as summaries, costs, latency, token counts, provider and model names, risk flags, and internal IDs, rather than raw model inputs and outputs. Raw payload storage is off unless you enable it per workspace.
AI Providers And Model-Graded Evals
Evaluations run on a deterministic runner by default. When you enable model-graded evals, selected eval content may be sent to the providers you configure, such as Google Gemini or OpenAI.
We do not train our own models on your trace or eval content. For production you should use paid, billing-enabled Gemini API and OpenAI API settings that do not use API data for training by default. We do not make commitments about provider-side processing beyond the applicable provider terms.
Legal Bases For Processing
Where the GDPR or similar laws apply, we rely on: performance of a contract to provide the Service to you; our legitimate interests in securing, supporting, and improving the Service; your consent for optional analytics; and compliance with legal obligations.
You can withdraw consent for optional analytics at any time through the cookie preferences control without affecting the lawfulness of earlier processing.
How We Use Data
We use data to authenticate users, enforce workspace access, provide product features, process billing, detect and prevent abuse, debug incidents, improve reliability, and meet security and legal obligations.
We do not sell personal data, and we do not train AegisRail models on customer AI trace content. Provider-side processing is governed by the applicable provider terms and the AI-provider settings you configure.
International Transfers
We and our subprocessors may process and store data in countries other than yours, including the United States. The current subprocessor list shows the providers we use and their roles.
Where required, we rely on appropriate safeguards for international transfers, such as standard contractual clauses or equivalent mechanisms.
Retention
Workspace data is retained while the workspace is active and according to your configured retention settings. Raw trace payload retention is controlled separately from trace metadata.
Some records, such as billing, audit, security, and fraud-prevention records, are retained longer where required for legal or operational reasons. When data is deleted, backups age out on their normal cycle.
Your Rights
Subject to applicable law, you may request access to, correction of, deletion of, or a copy of your personal data, and you may object to or ask us to restrict certain processing, or withdraw consent for analytics.
For workspace data where you are the controller, we will support your requests as a processor and direct end-user requests back to you. We may need to verify your identity and may decline parts of a request where an exception applies.
Public Trust Center And Evidence Sharing
If you publish a Trust Center or share evidence, public Trust Centers, trust manifests, verification endpoints, evidence summaries, and shared evidence links may be indexed, cached, copied, screenshotted, or accessed by third parties outside our control.
You are responsible for not publishing confidential, sensitive, regulated, proprietary, or third-party data through these public surfaces.
Requests, Export, And Deletion
You can export evidence bundles as PDF and machine-readable files, and trace data as CSV on eligible plans. Workspace export and deletion requests can be sent to support@eastbase.studio, and some flows are available in-product.
Deletion may exclude records we must retain for security, audit, billing, fraud prevention, or legal obligations, and we may need to confirm the request comes from an authorized person.
Security
We use organization-scoped authorization, hashed API key storage, encrypted outbound webhook secrets, an append-only audit log, a tamper-evident proof chain, production security headers, and monitored operational jobs.
You are responsible for configuring workspace access, rotating API keys, setting raw trace retention, and approving integration destinations.
Changes And Contact
We may update this policy as the product and our operations evolve, and we will communicate material changes through the product or by email.
Privacy questions and data requests can be sent to support@eastbase.studio.