Skip to content
← Back to the front page

Caelis Privacy Policy

Last updated: 18 August 2026

This is a convenience translation. In case of conflict between language versions, the Norwegian version prevails.

This privacy policy describes how Caelis processes personal data — both on our websites and in the Caelis platform (the “Service”).

The data controller for the processing described here is Good2know AS, org. no. 929 826 280, Linderudsletta 9 B, 0597 Oslo, Norway (“Caelis”, “we” or “us”).

The policy is read together with the Terms of Purchase. For personal data Caelis processes on behalf of a customer, the data processing agreement between Caelis and the customer additionally applies.

1. Who this policy applies to

The policy applies to:

  • visitors to our websites
  • people who use the contact form or the free AI visibility scan
  • people who register or administer a customer account on behalf of a business
  • contact persons at customers, partners and prospective customers

For visitors to pages Caelis publishes on behalf of a customer (the customer's own websites and digital surfaces), the customer is the data controller and Caelis is the data processor — see section 5.

2. What data we process

Account and customer data
Name, email address, business name, organisation number and role. Sign-in uses a one-time email link; we store no passwords.
Enquiries and scans
When you use the contact form we store your name, email address, any company name and your message. When you use the free AI visibility scan we store the business name, website, service, location and industry you provide, plus the email address used for verification.
Payment data
Payment is handled by our payment provider Stripe. Card details are stored with Stripe and never with Caelis; we receive and store customer and subscription references and payment status.
Usage data
Sign-in events, actions performed in the platform (Caelis keeps a log of what the system and users have done, as part of delivering the Service) and technical events such as error reports.
Data in customer material
Content, documents and data a customer makes available to Caelis may contain personal data. This is processed on the customer's behalf — see section 5.

4. Automated analyses and AI

Caelis uses artificial intelligence from third-party providers to perform analyses, generate recommendations and produce content. Content and business data may therefore be sent to the AI model providers listed in section 6, to the extent necessary for the functionality the customer uses.

We do not use customer data to train our own AI models. Anonymised and aggregated patterns may be used for statistics, benchmarking and product improvement, in accordance with the Terms of Purchase.

Caelis makes no automated decisions with legal effect for individuals.

5. Caelis as data processor

Where Caelis processes personal data on behalf of a customer — for example data in the customer's content, the customer's own customer data, or measurements from the customer's published pages — the customer is the data controller and Caelis the data processor.

Such processing is governed by the data processing agreement between Caelis and the customer, and only takes place on the customer's documented instructions. Requests concerning such data should be directed to the relevant customer as data controller.

6. Sub-processors

We use a limited set of providers to deliver the Service:

Supabase
database, authentication and storage
Vercel
hosting and operation of the websites and platform
Anthropic
analysis, generation and AI visibility measurement
OpenAI
analysis, generation and AI visibility measurement
Google (Gemini API)
analysis, generation and AI visibility measurement
Perplexity
AI visibility measurement
Microsoft (Azure AI Foundry)
AI visibility measurement
DataForSEO
search-result data underlying visibility measurement in Google's AI answers
Exa
web search for source retrieval
Stripe
payment processing
Resend
sending email
Sentry
error reporting and stability
Cloudflare
bot protection (Turnstile) and traffic security
OpenRouter
backup text-generation provider used when the primary AI provider is unavailable

Providers only process the data necessary for their function. For each provider we enter into a data processing agreement, or adopt the provider's own data processing terms. That work is in progress, and we will state the status per provider once the review is complete.

7. Transfers outside the EEA

Some providers process data in countries outside the EEA, including the United States. The transfer basis for each individual provider — the EU Commission's Standard Contractual Clauses (SCCs), the EU–US Data Privacy Framework where the provider is certified, or an adequacy decision — is currently being reviewed and documented provider by provider. We will update this section as that review is completed.

8. Cookies and analytics

Caelis uses necessary cookies for sign-in and session handling.

Usage measurement on our own websites uses first-party tooling. We do not use third-party advertising trackers on our websites.

9. Retention

We keep data as long as necessary for the purpose:

  • account and customer data: for the duration of the customer relationship, and thereafter as long as statutory requirements (such as bookkeeping law) demand
  • enquiries and free scans: until the purpose is fulfilled, after which they are deleted or anonymised
  • data processed on behalf of a customer: in accordance with the data processing agreement and the Terms of Purchase's provisions on data at termination

10. Security

Caelis uses technical and organisational security measures appropriate to the nature and risk of the Service, including encryption in transit and at rest, access control, per-business isolation of customer data, and access logging.

11. Your rights

You have the right to access, rectify and erase the data we hold about you, and the right to restriction, data portability and to object to processing based on legitimate interest. Consent can be withdrawn at any time.

Requests are answered without undue delay and at the latest within the deadlines of the GDPR.

You also have the right to complain to the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no) if you believe the processing violates the rules.

12. Changes to this policy

We may update the policy when the Service, providers or regulations change. Material changes are announced in a reasonable manner. The date at the top shows when the policy was last changed.

13. Contact

Questions about privacy and requests concerning your rights can be directed to Good2know AS, org. no. 929 826 280, Linderudsletta 9 B, 0597 Oslo, Norway.

admin@getcaelis.com