Privacy Policy
Teleon signs decisions about your data and is built to avoid holding the data itself. This policy says what that leaves us holding, where it goes, and what you can require of us, including the parts that are less comfortable to write down.
This document is published for review. Entity registration details and the designated EU and UK representatives are still to be supplied, and appear below as marked placeholders. Until they are filled in, treat this text as a draft rather than as the executed agreement, and ask legal@teleon.ai for the current signed position.
Who this policy is for
Teleon, Inc. (“Teleon”, “we”, “us”) operates the Teleon trust layer for AI agents. This policy explains what personal data we handle, why, on what legal basis, who else sees it, and what you can require of us.
Four kinds of people appear in this policy, and Teleon’s role differs for each. Working out which one you are is the first thing to do, because it determines who you should be talking to.
| You are | Meaning | Teleon acts as | Start here |
|---|---|---|---|
| A customer | An organisation that subscribes to Teleon. | Controller of your account and billing data | This policy |
| A customer user | A person who signs in to the Teleon console on a customer’s behalf. | Controller of your console account data | This policy |
| An end user | A person whose interaction with a customer’s AI agent passed through Teleon. | Processor, acting on the customer’s instructions | The company operating the agent, see section 10 |
| A website visitor | Somebody reading teleon.ai. | Controller | Section 11 |
Teleon almost certainly holds no plaintext record of you. What we hold on a customer’s behalf is hashes, policy decisions and, where the customer enabled it, vault tokens. We cannot identify you from those without the customer’s involvement, which is why an erasure request has to reach the company that operates the agent. Section 10 explains how to route one, and we will help.
Who is responsible, and where we are established
- Controller
- Teleon, Inc., a Delaware corporation. Registered office: «TODO: Delaware registered office address».
- Group processor
- Teleon SARL, a société à responsabilité limitée organised under the laws of Tunisia. Supplies engineering, operations and support to the parent. Registered office: «TODO: Tunisian registered office address».
- Privacy contact
- privacy@teleon.ai
- Data protection contact
- dpo@teleon.ai
European and UK representatives
Neither Teleon entity is established in the European Union or the United Kingdom, and both offer the Service to people in those territories. Article 27 of the GDPR and of the UK GDPR therefore each require a designated representative, appointed in writing and named in this policy.
Teleon has not yet appointed an Article 27 representative in the EU or the UK. Appointment is in progress and this section will name them when it completes. Until then, address any request you would otherwise make to a representative to dpo@teleon.ai; it will be handled on the same timetable and with the same rights, and no request will be refused for want of a representative to send it to.
Data Protection Officer
Teleon has not appointed a formal Data Protection Officer. Given that the Service involves systematic monitoring of agent behaviour at scale, an appointment under Article 37(1)(b) is likely to be required and is under assessment. The dpo@teleon.ai mailbox is monitored by the person who will hold the role, and requests sent to it are handled as if the appointment were in place.
What we collect
Account and billing data, we are the controller
| Category | Examples | Why |
|---|---|---|
| Identity | Name, work email address, job title | Creating and securing the account, service notices |
| Organisation | Company name, billing address, VAT or tax identifier | Invoicing and tax compliance |
| Credentials | Password hash (Argon2id), MFA enrolment, API key hashes | Authentication. Plaintext passwords and API keys are never stored |
| Console activity | Sign-ins, IP address, actions taken in the console, approvals granted | Security, and the operator audit log customers can read |
| Billing | Stripe customer and subscription identifiers, invoice history | Taking payment and producing invoices |
Agent audit metadata, we are the processor
This is what your agents emit through the gateway, sidecar or SDK adapters, and it is the bulk of what Teleon stores. It is deliberately not the content itself.
| Category | Stored as | Why |
|---|---|---|
| Prompt content | SHA-256 hash only | Audit-chain integrity. The plaintext is not written to the ledger |
| Tool-call arguments | SHA-256 hash; classified fields replaced by a vault token | Audit trail and policy evaluation |
| Policy decisions | Policy identifier, action taken, severity, reason code | The governance record customers rely on |
| Identifiers | Agent, tenant, request and session UUIDs | Tenant isolation and tracing |
| Model metadata | Provider and model name, token counts, latency | Usage accounting and scoring |
| Sequence and chain data | Monotonic sequence number, previous-entry hash, signature | Tamper evidence |
Privacy Vault records
Where a customer classifies a field as sensitive, the value is tokenized at the boundary: the plaintext is encrypted with a per-record data key under AES-256-GCM, and an opaque token takes its place everywhere downstream. The ciphertext is retrievable only through an authorised detokenization call, which is itself audited.
Website visitors
Reading teleon.ai produces server access logs, IP address, user agent, requested path, timestamp, retained for 30 days for security. There is no analytics script, no tag manager, no advertising pixel and no session recording on any Teleon web property. Section 11 covers cookies.
What we are built not to collect
These are architectural properties, not promises of good behaviour, and each is stated with its limit so it can be relied on.
| We do not | The limit on that statement |
|---|---|
| Store prompt or response plaintext in the audit ledger | Content is transmitted to Amazon Bedrock for classification and scoring, in memory and in transit. It is not persisted by Teleon or by AWS. See section 6. |
| Train models on customer data | Unconditional. No customer data is used to train, fine-tune or evaluate any Teleon or third-party model, and inference on Bedrock is contractually excluded from provider training. |
| Sell or share personal data | Unconditional. Teleon has no advertising business and no data-brokerage relationship. Under the CCPA/CPRA this is neither a “sale” nor a “share”. |
| Hold provider API keys outside the gateway | Customer-supplied provider credentials are held in AWS Secrets Manager and injected into the gateway process. They are never written to the ledger, logs or bundles. |
| Read customer data as staff | Production access is break-glass: role-scoped, approved per session, time-boxed and written to the audit ledger the customer can read. It is not zero access, and we do not claim it is. |
Legal bases
| Processing | Basis | Article |
|---|---|---|
| Providing the Service, enforcement, audit, scoring | Performance of a contract | Art. 6(1)(b) |
| Account management, invoicing, service notices | Performance of a contract | Art. 6(1)(b) |
| Security monitoring, abuse and fraud prevention | Legitimate interests | Art. 6(1)(f) |
| Retaining audit records for a regulated retention period | Legal obligation, or the customer’s instruction | Art. 6(1)(c) / 6(1)(b) |
| Handling a data-subject request | Legal obligation | Art. 6(1)(c) |
| Establishing, exercising or defending legal claims | Legitimate interests | Art. 6(1)(f) |
| Product and design-partner communications | Consent, withdrawable at any time | Art. 6(1)(a) |
Where Teleon processes end-user data on a customer’s behalf, the legal basis is the customer’s to determine and to document. Teleon does not select a basis for the customer, and cannot: we do not know why an agent was deployed.
Legitimate-interests balancing
- Security monitoring. The data is IP addresses, request routes and access logs; it is redacted of credentials and payload content and kept 30 days. The interest is keeping a platform that holds audit evidence from being tampered with. Nobody is profiled, and no decision about a person is made from it.
- Defending claims. Records that are the subject of a live or reasonably anticipated dispute are preserved beyond their normal retention. This is narrow, applied per record, and never used as a general reason to keep data.
You can object to either at any time under Article 21, at dpo@teleon.ai.
International transfers
This section deserves close reading if you are assessing Teleon for EU or UK personal data, because our group structure makes transfers unavoidable and we would rather you learned that here than in a questionnaire.
| Destination | What reaches it | Adequacy | Safeguard |
|---|---|---|---|
| AWS eu-west-1 (Ireland) | Storage and compute for tenants configured for EU residency | Within the EEA | None required |
| AWS us-east-1 (United States) | Storage and compute for other tenants; Bedrock evaluation for all tenants | Only via the EU–US Data Privacy Framework, for certified recipients | AWS is DPF-certified. EU Standard Contractual Clauses also in place through the AWS DPA |
| Teleon, Inc. (United States) | Account, billing and support data; production access under break-glass | Teleon is not currently DPF-certified | EU Standard Contractual Clauses, Module 2 or 3, plus the UK Addendum |
| Teleon SARL (Tunisia) | Production access under break-glass, for engineering and support | No adequacy decision | EU Standard Contractual Clauses executed intra-group, with the supplementary measures below |
Tunisia, specifically
The European Commission has made no adequacy decision for Tunisia. Any access to EU personal data from Tunisia is a restricted transfer under Chapter V of the GDPR, and Teleon relies on the Standard Contractual Clauses together with a documented transfer impact assessment.
Tunisia is a party to Council of Europe Convention 108 and has a supervisory authority, the Instance Nationale de Protection des Données Personnelles, operating under Loi organique n° 2004-63 of 27 July 2004. Those facts support the assessment. They are not adequacy, and we do not present them as adequacy.
Supplementary measures
- Tunisian personnel reach production through a break-glass workflow that is role-scoped, approved per session, time-boxed and logged in the customer-readable audit ledger. There is no standing access.
- No customer data is stored on Tunisian infrastructure. Data stays in AWS; the access is remote and session-bound.
- Data at rest is encrypted with AWS KMS customer-managed keys held in the storage region, and vault ciphertext is decryptable only through an audited detokenization call.
- Sensitive fields classified for the Privacy Vault are tokenized, so a support session sees a token rather than a value.
The executed Standard Contractual Clauses, the transfer impact assessment and the intra-group agreement are available to customers under NDA from dpo@teleon.ai. If your assessment cannot accept a Tunisia transfer on any safeguard, say so before signing, it is a structural fact about Teleon, not a setting we can switch off.
How long we keep it
Audit retention included with each plan
These are the values the platform actually enforces. They are shorter than the figures Teleon published before 2026-08-30; see the correction below.
| Plan | Audit events retained |
|---|---|
| Free | 7 days |
| Developer | 7 days |
| Team | 30 days |
| Business | 365 days |
| Enterprise | 7 years (2,555 days) |
Teleon previously published a retention table showing 30 days on Free, 90 on Developer and 180 on Team, with separate cold-storage tiers. The platform has always enforced the figures above. The published table described an intended tiering that was not implemented, and it was wrong. If you selected a plan in reliance on the earlier figures and the difference matters to you, contact sales@teleon.ai, we will extend retention on your tenant to the published figure for the remainder of your current term at no charge.
Everything else
| Data | Retained for | Basis |
|---|---|---|
| Account data | Duration of the subscription, then 90 days | Contract |
| API key hashes | Until revoked, then 90 days | Security |
| Trust scores | 180 days by default | Contract |
| Trust profiles and red-team findings | 365 days by default | Contract |
| Compliance bundles | 7 years by default | Regulatory |
| DSR case records | 3 years after completion | Legal obligation, proof of handling |
| DSR deliverables (the export file itself) | 90 days, then the object expires | Data minimisation |
| API request logs | 90 days | Security |
| Session data | 30 days | Security |
| Server access logs | 30 days | Legitimate interests |
| Privacy Vault ciphertext | Until erasure or account closure | Contract |
| Billing and tax records | As required by the tax law applicable to the contracting entity | Legal obligation |
| Support correspondence | 2 years after resolution | Legitimate interests |
A tenant may configure retention between 30 and 3,650 days per data type. Where a compliance regime is selected, its statutory minimum overrides a shorter setting upward and cannot be configured below: GDPR holds audit entries 365 days and DSR records 1,095; HIPAA holds audit entries 6 years; SOX holds audit entries and bundles 7 years; PCI DSS holds audit entries and request logs 365 days.
How deletion works
- Cryptographic erasure for vault-held values: the data key is destroyed and the ciphertext becomes permanently unrecoverable. This is what an erasure request triggers.
- Deletion for plaintext records, within 30 days of the retention period ending, by a job that runs daily.
- Preservation of the audit chain itself. Erasing an entry’s content does not remove the entry: the hash chain would break and every downstream signature with it. What remains is the hash, the decision and the erasure certificate, which is the record of the erasure, not a copy of the data.
On account closure you have 30 days to export through the bundle generator. After that, customer data is deleted within 90 days, except records under a legal-retention obligation, which are held encrypted, are not accessible to operational staff, and are deleted when the obligation lapses.
Security
- AES-256-GCM at rest; TLS 1.2 or better in transit, with TLS 1.3 preferred.
- Per-region AWS KMS customer-managed keys for audit signing, vault key-encryption keys and object-storage encryption. Key material never leaves KMS.
- Tenant isolation enforced in the database by row-level security, not only in application code.
- Role-based access, owner, admin, member, viewer, with MFA required for staff, through self-hosted Zitadel.
- Every audit entry is signed and hash-chained; each region’s daily Merkle root is anchored to Bitcoin through OpenTimestamps.
- Static analysis, dependency and container scanning, secret scanning and keyless image signing on every build.
- Break-glass production access: approved per session, time-boxed, and written to the audit ledger.
No control is perfect and none of the above is a warranty that a breach cannot happen. Where one does, Teleon notifies affected customers within 72 hours of becoming aware, with the categories and approximate volume of data involved, the likely consequences and the measures taken. Report a suspected vulnerability to security@teleon.ai; we acknowledge within 24 hours.
Certification status is published without embellishment at Terms, section 10: SOC 2 Type 2 and ISO/IEC 27001 are both in progress, and Teleon holds neither today.
Your rights
If you are in the EU, EEA, UK or Switzerland
| Right | What it gets you | How |
|---|---|---|
| Access, Art. 15 | A copy of the personal data we hold about you | DSR portal, or dpo@teleon.ai |
| Rectification, Art. 16 | Correction of inaccurate data | Console settings, or support@teleon.ai |
| Erasure, Art. 17 | Deletion, by cryptographic erasure where vault-held | DSR portal |
| Restriction, Art. 18 | Processing paused while a dispute is resolved | dpo@teleon.ai |
| Portability, Art. 20 | Your data as JSON or CSV | DSR portal |
| Objection, Art. 21 | A stop to legitimate-interests processing | dpo@teleon.ai |
| Withdraw consent, Art. 7(3) | Consent-based processing ends, without affecting what came before | Console settings, or dpo@teleon.ai |
| Automated decisions, Art. 22 | Not applicable | Teleon makes no solely automated decision producing legal or similarly significant effects on an individual. Trust scores describe agents, not people |
If you are in California
You may request the categories and specific pieces of personal information collected, request deletion, request correction, and not be discriminated against for asking. Teleon does not sell or share personal information as the CCPA/CPRA defines those terms, so there is no opt-out to exercise. Requests go to the same addresses.
How to make a request
Data subjects: use the portal at dsr.teleon.ai/<tenant>, or write to dpo@teleon.ai. We respond within 30 days, extendable once by a further 60 where a request is complex, and we will tell you if we extend and why. Identity verification is required and is deliberately proportionate, we will not demand a passport scan to release a hash.
Teleon is the processor there, not the controller. We cannot erase on our own initiative without breaking the customer’s records, and we usually cannot identify the person from what we hold. Send the request to us anyway: we will route it to the controller, tell you who they are, and start the SLA clock on their side.
Complaints
You may complain to your supervisory authority. In the EU that is the authority in your country of residence, work or the alleged infringement; in the UK, the Information Commissioner’s Office; in Switzerland, the Federal Data Protection and Information Commissioner. We would rather hear from you first, but nothing here requires you to come to us before going to them.
Children
Teleon is a business product, sold to organisations, and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child’s data has reached us through a customer’s agent, write to dpo@teleon.ai and we will work with that customer to remove it.
Changes to this policy
Material changes are notified to account administrators at least 30 days before they take effect, and every version carries the version number and effective date shown at the top of this page. Superseded versions are retained and available on request.
| Version | Effective | What changed |
|---|---|---|
| 2.0 | 2026-08-30 | Rewritten for the actual corporate structure, Teleon, Inc. (Delaware) and Teleon SARL (Tunisia), replacing an earlier draft that named a French entity. Added the Tunisia transfer analysis, the Article 27 representative status, and the Amazon Bedrock disclosure. Corrected the per-plan retention figures and the cookie inventory. First publication on the website. |
| 1.0 | 2026-05-22 | Initial policy, maintained internally and never published. |
Contact
- Privacy questions
- privacy@teleon.ai
- Data protection, rights requests, objections
- dpo@teleon.ai
- Security and vulnerability reports
- security@teleon.ai
- Data subject request portal
- dsr.teleon.ai
- Postal
- Teleon, Inc., «TODO: Delaware registered office address»