Who is responsible for personal data?
Tindorah acts as controller for website, account, billing, and relationship-management data tied to our services. For customer or end-user data processed on behalf of an organization, Tindorah may act as processor or subprocessor as described in the applicable contract or data processing agreement.
The exact contracting entity, contact route, and any appointed privacy representative are provided in the commercial documentation used to onboard your organization.
What data we collect and process
We may collect contact details, company details, login identifiers, support communications, billing and contract records, and technical metadata needed to authenticate users and operate accounts and workspaces.
Depending on the product used, we may process operational configuration, security logs, audit trails, and customer-provided content under customer instructions.
Why we process personal data, by purpose
Account creation and the services you sign up for are processed under contract performance. Platform security, fraud prevention, and reliability improvements are processed under our legitimate interest. Responding to a lawful request from an authority, or complying with statutory bookkeeping requirements, is processed under legal obligation. Anything we ask you to opt into, such as an optional analytics cookie, is processed under consent, and only for as long as that consent stands.
Customers remain responsible for choosing a valid legal basis for their own data collection, outreach, notices, and any recordings or monitoring where applicable.
Retention, security, and transfers
We do not apply a single retention period to every kind of data. Account, billing, and contract records are kept for the life of the commercial relationship, then for as long as applicable statutory bookkeeping and tax rules require afterwards. Security and audit logs are kept only as long as investigating and resolving an incident can reasonably require. Support communications are kept for as long as the request they relate to may need to be revisited. Every category is retained no longer than the purpose it was collected for requires, extended where a dispute or legal claim is pending until that claim is closed.
We implement technical and organizational measures designed to protect personal data. Personal data is transferred outside the European Economic Area only where a sub-processor operates from there, and every such transfer relies on the European Commission's Standard Contractual Clauses — see the sub-processors named above for which ones and from where.
Your rights and choices
Depending on applicable law, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the European Union or EEA member state where you live, where you work, or where you believe an infringement took place.
To exercise your rights, please contact us through your assigned support or commercial channel.
Contact and requests
For legal, privacy, security, or contractual requests, please use the support or commercial contact channel assigned to your workspace or onboarding process.