Skip to content
Legal

Privacy Policy

How BridgeME Technologies LLC collects, uses, and protects information when you use Castia.

Effective 3 August 2026

Castia is a product and brand owned and operated by BridgeME Technologies LLC ("BridgeME", "we", "us"), a limited liability company registered in the State of Wyoming, USA, with its registered address at 1021 E Lincolnway 10440, Cheyenne, WY 82001, USA.

This policy explains what we collect when you visit castia.cloud or use the Castia platform, why we collect it, and what control you have over it. It covers two very different kinds of data, and the distinction matters throughout: information about *you as a user of our service*, and the *content your organization loads into the platform*.

1. The two kinds of data

Service data is information we collect to run Castia for you: your account details, billing records, and logs of how the service is used. We act as the controller of this data.

Customer data is the content your organization connects to Castia — documents, files, records from connected systems, and the questions your team asks. Your organization decides what enters the platform and why. We act as a processor of that data, handling it on your organization's instructions and for no independent purpose of our own.

We do not sell either kind of data. We do not use your customer data to train foundation models, and we do not share it with other customers.

2. Information we collect

  • Account information: your name, work email address, organization name, and password (stored only as a one-way hash, never in readable form).
  • Authentication data: if you sign in with a single sign-on provider such as Google, we receive your email address, name, and a provider-issued identifier — never your password with that provider.
  • Agreement records: the date and time you accepted these terms, and the version you accepted.
  • Usage and diagnostic data: log entries, timestamps, error reports, and audit records of significant actions taken in your account.
  • Billing information: plan, subscription status, and billing contact. Card details are handled by our payment processor and never reach our servers.
  • Customer content: documents you upload, data pulled from systems you connect, and the queries, chats, and reports your team generates.
  • Website data: if you submit the contact form on castia.cloud, the details you provide so we can respond.

3. How we use it

We use service data to provide and secure the platform: to authenticate you, enforce permissions, meter usage against your plan, respond to support requests, send service and verification email, detect abuse, and meet our legal obligations.

We process customer content only to deliver the features your organization uses — indexing and embedding documents so they can be searched, retrieving relevant passages to ground an answer, generating reports and running the workflows you configure.

4. AI processing and sub-processors

Castia is a retrieval-grounded AI platform. To answer a question, relevant excerpts of your content are sent to a large language model or embedding provider for processing, together with your query. Which providers are used depends on your deployment and your organization's configuration.

Where Castia is deployed on-premise or in an air-gapped environment, or configured with self-hosted models, content need not leave your infrastructure at all. Your deployment model determines this, and your organization chooses it.

We use sub-processors for hosting, model inference, email delivery, and payment processing. We require them to protect data on terms no less protective than this policy. We will make the current list of sub-processors available on request.

5. Retention and deletion

We keep customer content for as long as your organization keeps it in the platform. Deleting a document removes it and the derived indexes and embeddings built from it. Some records — audit entries and billing history — are retained longer where we need them for security, accounting, or legal reasons.

When a subscription ends, you may export your data. After a reasonable wind-down period we delete or anonymize customer content, subject to any retention the law requires of us.

6. Security

We encrypt data in transit and at rest, seal connector credentials with authenticated encryption, enforce role-based access control and tenant isolation so one organization cannot reach another's data, and keep audit logs of significant actions. Access to production systems is limited to personnel who need it.

Castia is built to support GDPR obligations and is designed to be deployable in HIPAA and SOC 2 environments. Being built for those requirements is not the same as holding a certification; where you need formal attestation or a Business Associate Agreement, contact us before relying on it.

7. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. You can exercise several of these directly in the product, and we will help with the rest.

If your organization administers your Castia account, requests about content held in that account may need to be directed to them, since they decide what is stored. We will tell you if that is the case.

To make a request, write to hello@castia.cloud. If you are in the EEA or UK and believe we have not resolved your concern, you may complain to your local supervisory authority.

8. International transfers

We are based in the United States and may process data there or in other countries where our infrastructure providers operate. Where we transfer personal data out of the EEA or UK, we rely on an appropriate safeguard such as the European Commission's standard contractual clauses. Customers with data residency requirements can discuss deployment options with us.

9. Cookies

The Castia application uses cookies and browser storage that are strictly necessary to keep you signed in and to keep the product working. The marketing site uses minimal cookies. We do not use advertising cookies or sell information gathered through them.

10. Children

Castia is a business product and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the platform changes. We will revise the effective date above, and for material changes we will give notice in the product or by email before they take effect.

12. Contact us

BridgeME Technologies LLC, 1021 E Lincolnway 10440, Cheyenne, WY 82001, USA. Email hello@castia.cloud for any privacy question or request.