Tindorah Tindorah

Privacy policy

Privacy practices for Tindorah services.

This policy explains how Tindorah handles personal data when individuals and organizations visit our websites, create accounts, and use Tindorah services within the ecosystem.

Last updated: September 8, 2026

Sub-processors are now named directly in this policy, retention is stated as criteria per data category rather than a single period, legal bases are mapped to each purpose, and international transfers are named. The right to lodge a complaint with a supervisory authority is now stated. The controller's legal identity, and with it the name of the supervisory authority competent for the controller, are not yet published, pending a management decision on the controlling entity.

Who is responsible for personal data?

Tindorah acts as controller for website, account, billing, and relationship-management data tied to our services. For customer or end-user data processed on behalf of an organization, Tindorah may act as processor or subprocessor as described in the applicable contract or data processing agreement.

The exact contracting entity, contact route, and any appointed privacy representative are provided in the commercial documentation used to onboard your organization.

What data we collect and process

We may collect contact details, company details, login identifiers, support communications, billing and contract records, and technical metadata needed to authenticate users and operate accounts and workspaces.

Depending on the product used, we may process operational configuration, security logs, audit trails, and customer-provided content under customer instructions.

Why we process personal data, by purpose

Account creation and the services you sign up for are processed under contract performance. Platform security, fraud prevention, and reliability improvements are processed under our legitimate interest. Responding to a lawful request from an authority, or complying with statutory bookkeeping requirements, is processed under legal obligation. Anything we ask you to opt into, such as an optional analytics cookie, is processed under consent, and only for as long as that consent stands.

Customers remain responsible for choosing a valid legal basis for their own data collection, outreach, notices, and any recordings or monitoring where applicable.

How data is shared

We share data only with authorized personnel, contracted subprocessors, infrastructure providers, and professional advisors who need it to deliver, secure, or support the services.

Where Tindorah processes customer data on behalf of a customer, processing scope is governed by the commercial agreement, any DPA, and documented customer instructions.

Sub-processor Purpose Processing location
Hetzner Online GmbH Infrastructure hosting for every application and database workload Nuremberg, Germany (EU)
Cloudflare, Inc. DNS, and the DNS-01 challenge used to issue Let's Encrypt certificates Global anycast network (Standard Contractual Clauses)
Google LLC (Google Calendar API) Creates and manages calendar events and video-call links for demo bookings United States (Standard Contractual Clauses)

Who processes personal data on our behalf.

Retention, security, and transfers

We do not apply a single retention period to every kind of data. Account, billing, and contract records are kept for the life of the commercial relationship, then for as long as applicable statutory bookkeeping and tax rules require afterwards. Security and audit logs are kept only as long as investigating and resolving an incident can reasonably require. Support communications are kept for as long as the request they relate to may need to be revisited. Every category is retained no longer than the purpose it was collected for requires, extended where a dispute or legal claim is pending until that claim is closed.

We implement technical and organizational measures designed to protect personal data. Personal data is transferred outside the European Economic Area only where a sub-processor operates from there, and every such transfer relies on the European Commission's Standard Contractual Clauses — see the sub-processors named above for which ones and from where.

Your rights and choices

Depending on applicable law, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the European Union or EEA member state where you live, where you work, or where you believe an infringement took place.

To exercise your rights, please contact us through your assigned support or commercial channel.

Standard Art. 28 GDPR data processing agreement.

Cookies and similar technologies

We use cookies and similar technologies to keep the site working, maintain security-related behavior such as CSRF protection, remember your language choice, and support authentication and session management.

Where optional analytics or non-essential cookies are used, we will provide notice and, where required, a choice before enabling them.

Contact and requests

For legal, privacy, security, or contractual requests, please use the support or commercial contact channel assigned to your workspace or onboarding process.