Data & privacy
What we hold about you, and what we never took
ctx10 reads how your Creatio is built, not what is inside it,
which settles most privacy questions before they are asked. This is the whole list.
Last updated 25 September 2026
The whole list
Five things are held, one is held briefly, and everything else is either never taken or
never selected in the first place.
- The index of your Creatio setup Your processes, business rules, pages, fields and roles — how the instance is built. Held
- Your account The name, work email and company you gave us, so we can run the service and reach you. Held
- Enquiries you send us The name, work email, company and message you type into a form on this site — and the address and browser you sent it from, stamped by our server so we can tell a person from a bot filling the form ten thousand times. Kept 24 months from your last message. Held
- What you do in the demo workspace If you try ctx10 on our demo workspace, we read what you did there so we can follow up: which questions you asked and which tools your agent called, from the query logs below, and the questions Ask couldn’t answer, stored as you typed them — the demo holds our own Creatio, so there is no name of yours in them to mask. Nothing of yours is connected to the demo. Held
- Query logs For a query against your data: the command we received, the command we ran, how many rows, how many bytes, and the caller’s address and browser — refusals included. For a tool call, a question asked through Ask, or a check: which tool or which fixed label, who ran it, when, and how it went. Never the sentence you typed, and no address. Held
- Sign-in records Signing in is written down: who, when, whether it worked, and the address, browser and device it came from. It is how "who was in this workspace, and from where" has an answer, and how we notice one login being shared around. Held
- Questions Ask couldn’t answer The shape of the sentence — “where is the {subject} changed” — with your field and object names masked out before anything is written down, so no name from your Creatio is stored. The sentence you typed reaches our servers to be answered, then is discarded rather than saved, unless you ask us to switch storing it on for your workspace. Kept 90 days, deleted with your workspace. Held briefly
- Your business records Contacts, accounts, leads, orders. The rows inside your Creatio. Never taken
- Personal data in the tables we do read We read Creatio’s configuration tables, and its own list of users and roles is one of them. The email, phone and password columns on it are left out of the capture query itself, so those values never leave your Creatio — there is nothing to search, export, or leak later. You can ask us to switch that exclusion off for your workspace if you want those columns indexed. Never selected
- Anything used to train AI We never train models on your data. Your index answers your questions and nothing else. Never
Where it lives, and who can reach it
A filter nobody can forget
The index we build for you is a database of its own. The captured rows behind it sit in one
shared store, split by workspace — and every query is rewritten to your rows before it runs.
A query that cannot be scoped that way is refused rather than run, so the filter is not
something anyone has to remember to apply.
Live access starts off
Reading a saved index is the normal way to work. Querying your live instance is switched off
until you turn it on, and that switch belongs to your workspace.
Keys belong to one seat
Every key you make belongs to a single seat and you can turn it off at any time. What a key
is allowed to do is fixed the moment it is made — it can never grant itself more.
Every query is written down
We log the command we got, the command we ran, and who asked. If you ever need to know what
was read and by whom, the answer exists.
Sign-in
You sign in with a password today. Single sign-on is built and switched off until we turn it
on; admins will keep a password login as a backup either way.
We only ever read
ctx10 never writes to your Creatio. Four separate locks enforce
it — how that is enforced.
Who else touches it
Nine companies, and what each one can actually reach. Three are not switched on yet; they
are listed anyway so the list never changes quietly. If we add one, we say so here before it
starts processing anything.
- Contabo The servers that run ctx10 and hold the databases. Germany. Sees: Your index, your account, and the query logs. In use
- OpenAI The AI provider behind AI mode — the optional chat surface on the Ask page. United States. Sees: Only if your workspace has switched AI mode on, and only then: the questions typed on that one page, the object, field and process names that appear in their answers, and — when a question can only be answered by the implementation — the source of the specific C# or JavaScript schema it reads. Never your index wholesale, never your Creatio credentials, never your records. Off by default. In use
- IT CAPACITIES The company our engineering and support team works through. Tunisia. Sees: Your index and your account, when someone is working on a problem you raised or keeping the service running. Access is per-person and logged. Not your Creatio directly. In use
- Netlify Hosts ctx10.com — the site you are reading now. Sees: Requests to this website. Nothing from your Creatio, and nothing from the product. In use
- Microsoft 365 Our email. Sees: Whatever you email us, and the address you email us from. In use
- Google Analytics on this website — and only if you accept the cookie banner. Sees: Your visit to this website — pages, rough location, device. Nothing at all unless you accept: the script is not loaded before then. Typefaces are served from our own domain, so reading this page does not show Google your address. Nothing from the product, nothing from your Creatio. In use
- Paddle Merchant of record for subscriptions — an independent company you also contract with at checkout, when checkout opens. Sees: Your name, email, billing address and payment details when you buy. Never your index, never your Creatio. Planned
- WorkOS Single sign-on, when it is switched on. Sees: Who is signing in. Not your index. Planned
- PostHog Product analytics — which parts of the app get used. Sees: How the app is used. Not your index. Planned
When an AI is involved, and when it is not
This one gets asked backwards, so it is worth being exact. By default,
ctx10 sends nothing to an AI provider. Indexing your Creatio,
the checks, the benchmarks, the release report, the MCP surface and the ordinary Ask page all run
without a model anywhere in the path — Ask reads your typed question with a fixed vocabulary we
wrote, not an LLM.
There is one exception, and it is off unless you ask for it.
AI mode is an optional chat surface on the Ask page. A workspace owner has to
ask us to switch it on; until then it does not run. Once it is on, questions typed on that page go
to OpenAI, along with the object, field and process names that appear while answering them.
Some questions can only be answered by the code — "how is this calculated" has no answer in a
list of objects. With AI mode on, and only then, the model can open the source of a
named C# or JavaScript schema in your configuration, one file at a time, the same
way you can open it yourself on the code page. That source goes to OpenAI with the answer it
produces. With AI mode off, no source is sent anywhere — the same page still shows it to you,
and an agent you connect over MCP reads it on your own key, not ours.
What still never goes, even with AI mode on: your Creatio credentials, your records, and your index
as a whole. The model is not handed your configuration to read — it asks the same questions you
can ask, one at a time, and sees only what each answer contains. We switch OpenAI's own storage
off, so those conversations are not kept on your account there, and we
never train models on your data — not ours, not theirs, not ever. OpenAI
may hold a copy for up to 30 days for its own abuse monitoring before deleting it; that is
their standard term for every API customer, and we will say so here if it changes.
Separately, and unchanged: you can point your own coding agent — Claude, Cursor,
Codex — at ctx10 over MCP, and it asks us questions. That agent is yours, under your own account
with your own AI provider, and what it does with the answers is between you and them.
Where it all physically is
Your product data — the index, your account, the query logs — lives across three countries,
and it is worth saying plainly which does what: the company, the servers and the people are
not in the same place.
- Germany Servers and databases (Contabo).
- Türkiye The controller, EXPERCEO BİLİŞİM TEKNOLOJİLERİ LİMİTED ŞİRKETİ.
- Tunisia Operational access — engineering and support.
The company is registered in Türkiye. Your index sits on servers in Germany. The team that
keeps it running works from Tunisia, partly through IT CAPACITIES and
partly as people engaged directly by the company. All three are listed above and in the
vendor table, because "where is your team and who can reach our data" is the first question
a security reviewer asks and it should not require asking.
Neither Türkiye nor Tunisia has an EU adequacy decision. So where personal data of
people in the EU or UK is involved, those transfers run on Standard Contractual
Clauses — between us and the EU-facing side, and between us and
IT CAPACITIES, which is also bound by a written data processing agreement.
One supporting fact, offered as what it is and not as more: Tunisia acceded to
Council of Europe Convention 108 and its Additional Protocol 181, on
supervisory authorities and cross-border data flows, on 1 November 2017. That is a real
commitment to a recognised standard. It is not adequacy, and it does not replace the
clauses above.
Those three countries are the product. This website and our email are not in any of them:
Netlify serves every page you are reading, Microsoft 365 carries our email, and Google
Analytics runs only if you accepted the banner. All three are United States companies, and
personal data reaching them is transferred under their published transfer mechanisms — the
EU-US Data Privacy Framework and standard contractual
clauses. None of them can reach your index or your Creatio, which is what the
vendor list above is for: it says what each one actually sees.
Who is responsible for what
There are two answers, and the difference is most of data-protection law. For the things we
decided to collect, we are the controller. For the index of your Creatio, you are — it
exists because you told us to build it.
We are the controller
Your account, the enquiries you send us, billing, and this website. We decided to
collect those and why, so the duty to justify them is ours and the lawful bases in the
next section are ours to name.
You are the controller. We process.
The index of your Creatio and everything in it — including Creatio's own list of users,
their roles and who changed what. You decide it exists, which instance it covers and who
may read it. We hold it on your instructions under the
Data Processing Agreement, which applies to every workspace
automatically and is published rather than offered on request.
- Controller
- EXPERCEO BİLİŞİM TEKNOLOJİLERİ LİMİTED ŞİRKETİ For your account, enquiries, billing and this website.
- Registered office
- Sultan Selim Mah., Eski Büyükdere Cad. No: 61, İç Kapı No: 234415 Kağıthane / İstanbulTürkiye
- Trade registry
- 474966-5 · İstanbul Ticaret Sicili Müdürlüğü
- Processor of your index
- EXPERCEO BİLİŞİM TEKNOLOJİLERİ LİMİTED ŞİRKETİ, acting on your instructions Under the Data Processing Agreement.
- The team we work through
- IT CAPACITIES Rue 18 Janvier 1952, Bureau C 408Ariana Centre, 2080 ArianaTunisia Our processor for the data we control; our sub-processor for your index.
- Privacy contact
- hello@ctx10.com
We do not have a statutory data protection officer, because we are not required to appoint
one. Privacy questions go to the address above and reach a person, not a queue.
Why we are allowed to hold it
Under the GDPR you have to name a lawful basis for each purpose rather than gesture at
consent for everything. These are ours, for the data we control. For your index the basis is
yours to name as its controller — what we may do with it is set by the
DPA, not by a basis of our own.
Running the service — contract
Your account and the query logs exist so we can deliver what you subscribed to and show
you what was read. Without them there is no product and no audit trail.
Your index — your basis, our instructions
We do not name a basis for the personal data inside your index, because it is not ours to
name. We are your processor for it: we hold it because you instructed us to, we use it
for nothing else, and the DPA is what binds us to that.
Keeping it secure — legitimate interests
Logging who queried what, and keeping access per-person and revocable. Our interest is a
service that is not abused; yours is the same.
Replying to you — legitimate interests
If you send us a business enquiry we use your details to answer it. Nothing else, and no
newsletter you did not ask for. The address and browser it arrived from are stamped for
the same reason we log queries: telling a person from a bot.
Website analytics — consent
Only if you accept the banner, and nothing loads before you do. Withdraw it any time on
the Cookies page.
Invoicing — legal obligation
Tax and accounting records, kept for as long as the law says and no longer. Paddle is
merchant of record and holds the payment details; we never see your card.
Training AI — no basis, because we do not
Listed so the absence is explicit rather than inferred. There is no lawful basis here
because there is no processing.
How long we keep it
Actual windows, not "as long as necessary".
- The index of your Creatio setup While your account is open. Deleted within 30 days of you asking, or of the account closing.
- Your account While your account is open, then 90 days, then gone.
- Query logs 12 months, then deleted. They exist so you can answer "what was read, by whom" — after a year that question stops being asked.
- Sign-in records 12 months, then deleted. The same window as the query logs, for the same reason.
- Enquiries you send us 24 months from the last message, so we remember the conversation if you come back.
- AI mode conversations Thirty days. The questions typed in AI mode and the answers, deleted automatically — with or without a request.
- How much AI mode you used While your account is open, then it goes with the account. Counts and cost only — no questions, no answers, nothing you wrote. We keep it because it is what your invoice is built from, and a month you were billed for has to still be checkable after the conversations themselves are gone.
- Billing records Held by Paddle as merchant of record, and kept by us only as long as tax law requires.
Asking us to delete it
Ask and we delete your index. Email hello@ctx10.com from
the address on the account and say what you want removed. You do not need a reason and there is
no form to fill in. The same applies to an enquiry you sent us and would rather we did not keep:
say so and the row is erased, without waiting out its 24 months.
Your other rights
Deletion is the one people ask for, but it is not the only one. You can ask us for a copy of
what we hold about you, to correct it, to restrict or object to what we do with it, or to
receive it in a portable form. Where we rely on consent — analytics, and only analytics —
you can withdraw it without affecting what happened before.
Same address, same absence of a form. We answer within 30 days, and we will
not charge you for it. If we ever needed longer we would tell you why before the 30 days
were up, not after.
One routing note, because the roles above change who answers. If your request is about
a workspace's index — you are one of a customer's Creatio users, and you
want to know what the index holds about you, or want it corrected or erased — the controller
is that workspace's owner, not us. We pass the request to them without undue delay and tell
you we have done so, then help them answer it. Acting on it ourselves would mean processing
outside their instructions, which the DPA does not allow. Everything else
on this page — your account, an enquiry you sent us, analytics — we answer directly.
These rights come from the GDPR where it applies to you, from Türkiye's KVKK (Law No. 6698)
as the controller's home regime, and from Tunisia's Organic Act No. 2004-63 where the
team is. They overlap more than they differ, and we apply the most generous of them rather
than working out which one you fall under.
If we get it wrong
Tell us first — hello@ctx10.com — because
we can usually fix it faster than anyone else can make us. But you never have to go through
us. You can complain directly to your own EU or UK supervisory authority, to the
Turkish Personal Data Protection Board (KVKK), or to
Tunisia's INPDP, and doing so does not affect anything else
between us.
Doing a security review
The data processing agreement is already published and already in force: it is at
/dpa, it forms part of the Terms, and it applies
to every workspace without anything to sign. If your process needs it countersigned, or
needs a security questionnaire filled out, email
hello@ctx10.com and we will turn it around
fast. If your review needs something this page does not answer, ask — we would rather write it
down here than answer it once.
Changes to this page
The date at the top is the version in force. If we change something that materially affects
you — a new sub-processor, a shorter or longer retention window, a new purpose — we tell you
before it takes effect rather than editing quietly and hoping. That is the whole point of
publishing the vendor list and the retention windows as specifics.