Legal · Updated September 10, 2026
Privacy policy.
Your data, from first contact to company context.
How we handle business information, website activity, and the knowledge we manage for customers.
What this policy covers
Cirql provides Context as a Service: connecting business sources, ingesting and organizing information, creating embeddings and context graphs, storing and updating that information, and making approved context available to tools and AI agents. We also offer assessments, custom builds, and support.
This policy explains our website, inquiries, and service operations. For personal information that a business customer asks us to process, that customer controls the purposes and authorized access. The applicable service agreement and any data processing agreement define our instructions and responsibilities.
Information we receive
Website inquiries may include your name, work email, company, systems you use, goals, service preferences, and information you choose to share. We also process correspondence and records needed to administer a customer relationship.
Connected customer data may include CRM and ERP records, emails, messages, files, product and service history, employee knowledge, identifiers, and related metadata. The exact categories depend on the sources and permissions the customer authorizes. Connection credentials or authorization tokens may be processed by the connection infrastructure.
Service-generated information can include extracted text, document passages, embeddings, entity records, graph relationships, summaries, access logs, query and tool activity, and storage or processing measurements. Embeddings and derived records may remain linked to identifiable source information; they are not automatically anonymous.
How information is used
We use inquiry information to review requests, communicate with you, prepare a free starting plan, and discuss services. Submitting an inquiry does not connect your systems, start paid processing, or subscribe you to a separate marketing list.
Within an agreed engagement, we process data to import and sync records, normalize and classify information, generate embeddings, connect relationships, retrieve context, support approved agents and workflows, operate the service, measure usage, and provide support. We also use necessary records to protect the service, resolve disputes, and comply with legal obligations.
AI, embeddings, and agent access
Embedding and AI providers may process selected content to perform the configured embedding, retrieval, or reasoning task. Agents may receive relevant source passages, metadata, and relationships, rather than an entire database. Customer-selected tools may have their own data practices.
Customers should agree with us on approved providers, processing locations, retention settings, and any model-training restrictions before connecting sensitive data. Customer content is processed under the applicable agreement; this policy does not grant permission to train a general-purpose model on it.
The customer determines which users, tools, and agents are authorized. Access configuration and review matter: an agent with broad permissions may retrieve broad context. AI outputs can be incomplete or incorrect and require appropriate human review.
Website analytics and marketing technology
Our website includes Google Analytics, Microsoft Clarity, PostHog, Vercel Analytics, LinkedIn Insight, and Apollo website tracking. Depending on configuration, these services can receive device and browser information, IP addresses, page URLs, referral information, interactions, cookie or similar identifiers, and session activity. They support website measurement, visitor insights, and marketing attribution.
Some providers can associate website activity with information collected elsewhere. Browser settings and privacy tools can restrict cookies or tracking, though this can affect functionality. Contact us to make an applicable privacy or opt-out request. Website tracking is separate from authorized customer data ingestion; customer source records are not submitted through the public intake form.
Who receives information
We use service providers for hosting, storage, integrations, email delivery, analytics, AI processing, and operational support. Resend processes intake emails so our team can receive and respond to requests. Authorized employees and contractors may access information when needed for their work.
Authorized agencies or consultants may administer a client’s context under that client’s instructions and the applicable agreement. A partner relationship does not itself authorize access to another client’s information. Customer-approved tools and agents can receive the context requested under their access configuration. We may also disclose information when legally required, to protect rights and security, or as part of a business transfer with appropriate safeguards.
We do not sell customer source datasets or context graphs. Website advertising and tracking disclosures may be treated as a sale, sharing, or targeted advertising under some privacy laws. The website practices described above should not be confused with customer-context processing.
Retention, deletion, and exports
We keep inquiry and relationship records for the time reasonably needed to respond, provide services, maintain business records, and meet legal obligations. Customer source data, embeddings, graphs, and logs follow the agreed retention and deletion arrangements.
Disconnecting a source stops future access but does not necessarily erase information already imported. Deleting a source record may require deletion or rebuilding of associated passages, embeddings, graph links, and cached results. Contact us or your company administrator to coordinate deletion or an export. Backup copies and records needed for security or legal obligations may have different retention periods.
Security and processing locations
The safeguards, hosting region, access controls, backup arrangements, and incident obligations for a managed deployment are established in its service agreement. No internet transmission or storage system can be guaranteed completely secure. Please do not send secrets or sensitive records through the public inquiry form.
Providers and personnel may process information in the United States or other locations used for the agreed service. Any required international transfer arrangements should be addressed before customer data is connected.
Your choices and rights
Depending on your location and applicable law, you may have rights to access, correct, delete, or obtain a copy of personal information, and to object to or limit certain processing, withdraw consent, or opt out of sale, sharing, targeted advertising, or certain profiling. Where provided by law, you may appeal a denied request and will not be discriminated against for exercising your rights.
Send requests or appeals to hello@cirql.ai. We may need to verify your identity or authority, and will respond within applicable legal deadlines. If information belongs to a customer-managed context layer, contact that business first; we assist it under our agreement. You may also contact your relevant privacy regulator.
Children and changes
Our services are intended for business users, not children under 13. If you believe a child has provided personal information, contact us.
We may update this policy as our service changes, revise the date above, and provide additional notice where required. Material changes to customer processing remain subject to the applicable agreement.
Contact
For privacy questions, data requests, or information about the providers used for your engagement, contact Cirql at hello@cirql.ai.