Data & privacy

What we hold about you, and what we never took

ctx10 reads how your Creatio is built, not what is inside it, which settles most privacy questions before they are asked. This is the whole list.

Last updated 25 September 2026

The whole list

Five things are held, one is held briefly, and everything else is either never taken or never selected in the first place.

Where it lives, and who can reach it

A filter nobody can forget

The index we build for you is a database of its own. The captured rows behind it sit in one shared store, split by workspace — and every query is rewritten to your rows before it runs. A query that cannot be scoped that way is refused rather than run, so the filter is not something anyone has to remember to apply.

Live access starts off

Reading a saved index is the normal way to work. Querying your live instance is switched off until you turn it on, and that switch belongs to your workspace.

Keys belong to one seat

Every key you make belongs to a single seat and you can turn it off at any time. What a key is allowed to do is fixed the moment it is made — it can never grant itself more.

Every query is written down

We log the command we got, the command we ran, and who asked. If you ever need to know what was read and by whom, the answer exists.

Sign-in

You sign in with a password today. Single sign-on is built and switched off until we turn it on; admins will keep a password login as a backup either way.

We only ever read

ctx10 never writes to your Creatio. Four separate locks enforce it — how that is enforced.

Who else touches it

Nine companies, and what each one can actually reach. Three are not switched on yet; they are listed anyway so the list never changes quietly. If we add one, we say so here before it starts processing anything.

When an AI is involved, and when it is not

This one gets asked backwards, so it is worth being exact. By default, ctx10 sends nothing to an AI provider. Indexing your Creatio, the checks, the benchmarks, the release report, the MCP surface and the ordinary Ask page all run without a model anywhere in the path — Ask reads your typed question with a fixed vocabulary we wrote, not an LLM.

There is one exception, and it is off unless you ask for it. AI mode is an optional chat surface on the Ask page. A workspace owner has to ask us to switch it on; until then it does not run. Once it is on, questions typed on that page go to OpenAI, along with the object, field and process names that appear while answering them.

Some questions can only be answered by the code — "how is this calculated" has no answer in a list of objects. With AI mode on, and only then, the model can open the source of a named C# or JavaScript schema in your configuration, one file at a time, the same way you can open it yourself on the code page. That source goes to OpenAI with the answer it produces. With AI mode off, no source is sent anywhere — the same page still shows it to you, and an agent you connect over MCP reads it on your own key, not ours.

What still never goes, even with AI mode on: your Creatio credentials, your records, and your index as a whole. The model is not handed your configuration to read — it asks the same questions you can ask, one at a time, and sees only what each answer contains. We switch OpenAI's own storage off, so those conversations are not kept on your account there, and we never train models on your data — not ours, not theirs, not ever. OpenAI may hold a copy for up to 30 days for its own abuse monitoring before deleting it; that is their standard term for every API customer, and we will say so here if it changes.

Separately, and unchanged: you can point your own coding agent — Claude, Cursor, Codex — at ctx10 over MCP, and it asks us questions. That agent is yours, under your own account with your own AI provider, and what it does with the answers is between you and them.

Where it all physically is

Your product data — the index, your account, the query logs — lives across three countries, and it is worth saying plainly which does what: the company, the servers and the people are not in the same place.

  1. Germany Servers and databases (Contabo).
  2. Türkiye The controller, EXPERCEO BİLİŞİM TEKNOLOJİLERİ LİMİTED ŞİRKETİ.
  3. Tunisia Operational access — engineering and support.

The company is registered in Türkiye. Your index sits on servers in Germany. The team that keeps it running works from Tunisia, partly through IT CAPACITIES and partly as people engaged directly by the company. All three are listed above and in the vendor table, because "where is your team and who can reach our data" is the first question a security reviewer asks and it should not require asking.

Neither Türkiye nor Tunisia has an EU adequacy decision. So where personal data of people in the EU or UK is involved, those transfers run on Standard Contractual Clauses — between us and the EU-facing side, and between us and IT CAPACITIES, which is also bound by a written data processing agreement.

One supporting fact, offered as what it is and not as more: Tunisia acceded to Council of Europe Convention 108 and its Additional Protocol 181, on supervisory authorities and cross-border data flows, on 1 November 2017. That is a real commitment to a recognised standard. It is not adequacy, and it does not replace the clauses above.

Those three countries are the product. This website and our email are not in any of them: Netlify serves every page you are reading, Microsoft 365 carries our email, and Google Analytics runs only if you accepted the banner. All three are United States companies, and personal data reaching them is transferred under their published transfer mechanisms — the EU-US Data Privacy Framework and standard contractual clauses. None of them can reach your index or your Creatio, which is what the vendor list above is for: it says what each one actually sees.

Who is responsible for what

There are two answers, and the difference is most of data-protection law. For the things we decided to collect, we are the controller. For the index of your Creatio, you are — it exists because you told us to build it.

We are the controller

Your account, the enquiries you send us, billing, and this website. We decided to collect those and why, so the duty to justify them is ours and the lawful bases in the next section are ours to name.

You are the controller. We process.

The index of your Creatio and everything in it — including Creatio's own list of users, their roles and who changed what. You decide it exists, which instance it covers and who may read it. We hold it on your instructions under the Data Processing Agreement, which applies to every workspace automatically and is published rather than offered on request.

Controller
EXPERCEO BİLİŞİM TEKNOLOJİLERİ LİMİTED ŞİRKETİ For your account, enquiries, billing and this website.
Registered office
Sultan Selim Mah., Eski Büyükdere Cad. No: 61, İç Kapı No: 234415 Kağıthane / İstanbulTürkiye
Trade registry
474966-5 · İstanbul Ticaret Sicili Müdürlüğü
Processor of your index
EXPERCEO BİLİŞİM TEKNOLOJİLERİ LİMİTED ŞİRKETİ, acting on your instructions Under the Data Processing Agreement.
The team we work through
IT CAPACITIES Rue 18 Janvier 1952, Bureau C 408Ariana Centre, 2080 ArianaTunisia Our processor for the data we control; our sub-processor for your index.
Privacy contact
hello@ctx10.com

We do not have a statutory data protection officer, because we are not required to appoint one. Privacy questions go to the address above and reach a person, not a queue.

Why we are allowed to hold it

Under the GDPR you have to name a lawful basis for each purpose rather than gesture at consent for everything. These are ours, for the data we control. For your index the basis is yours to name as its controller — what we may do with it is set by the DPA, not by a basis of our own.

Running the service — contract

Your account and the query logs exist so we can deliver what you subscribed to and show you what was read. Without them there is no product and no audit trail.

Your index — your basis, our instructions

We do not name a basis for the personal data inside your index, because it is not ours to name. We are your processor for it: we hold it because you instructed us to, we use it for nothing else, and the DPA is what binds us to that.

Keeping it secure — legitimate interests

Logging who queried what, and keeping access per-person and revocable. Our interest is a service that is not abused; yours is the same.

Replying to you — legitimate interests

If you send us a business enquiry we use your details to answer it. Nothing else, and no newsletter you did not ask for. The address and browser it arrived from are stamped for the same reason we log queries: telling a person from a bot.

Website analytics — consent

Only if you accept the banner, and nothing loads before you do. Withdraw it any time on the Cookies page.

Invoicing — legal obligation

Tax and accounting records, kept for as long as the law says and no longer. Paddle is merchant of record and holds the payment details; we never see your card.

Training AI — no basis, because we do not

Listed so the absence is explicit rather than inferred. There is no lawful basis here because there is no processing.

How long we keep it

Actual windows, not "as long as necessary".

Asking us to delete it

Ask and we delete your index. Email hello@ctx10.com from the address on the account and say what you want removed. You do not need a reason and there is no form to fill in. The same applies to an enquiry you sent us and would rather we did not keep: say so and the row is erased, without waiting out its 24 months.

Your other rights

Deletion is the one people ask for, but it is not the only one. You can ask us for a copy of what we hold about you, to correct it, to restrict or object to what we do with it, or to receive it in a portable form. Where we rely on consent — analytics, and only analytics — you can withdraw it without affecting what happened before.

Same address, same absence of a form. We answer within 30 days, and we will not charge you for it. If we ever needed longer we would tell you why before the 30 days were up, not after.

One routing note, because the roles above change who answers. If your request is about a workspace's index — you are one of a customer's Creatio users, and you want to know what the index holds about you, or want it corrected or erased — the controller is that workspace's owner, not us. We pass the request to them without undue delay and tell you we have done so, then help them answer it. Acting on it ourselves would mean processing outside their instructions, which the DPA does not allow. Everything else on this page — your account, an enquiry you sent us, analytics — we answer directly.

These rights come from the GDPR where it applies to you, from Türkiye's KVKK (Law No. 6698) as the controller's home regime, and from Tunisia's Organic Act No. 2004-63 where the team is. They overlap more than they differ, and we apply the most generous of them rather than working out which one you fall under.

If we get it wrong

Tell us first — hello@ctx10.com — because we can usually fix it faster than anyone else can make us. But you never have to go through us. You can complain directly to your own EU or UK supervisory authority, to the Turkish Personal Data Protection Board (KVKK), or to Tunisia's INPDP, and doing so does not affect anything else between us.

Doing a security review

The data processing agreement is already published and already in force: it is at /dpa, it forms part of the Terms, and it applies to every workspace without anything to sign. If your process needs it countersigned, or needs a security questionnaire filled out, email hello@ctx10.com and we will turn it around fast. If your review needs something this page does not answer, ask — we would rather write it down here than answer it once.

Changes to this page

The date at the top is the version in force. If we change something that materially affects you — a new sub-processor, a shorter or longer retention window, a new purpose — we tell you before it takes effect rather than editing quietly and hoping. That is the whole point of publishing the vendor list and the retention windows as specifics.