How Tandevia handles personal data — what we collect, why, how long we keep it, and the rights you have over it. The controller and operator is Forscope a.s., Lidická 960/81, 602 00 Brno, Czech Republic (company ID 04885414).
Forscope a.s., Lidická 960/81, 602 00 Brno, Czech Republic, company ID 04885414, is the operator of the Tandevia platform and of this website.
This distinction matters for the rest of this page, so it comes first:
If you are an employee whose company uses Tandevia and you want to know why a particular piece of data about your work is being processed, your employer holds that answer. Ask them first — and we will support them in answering you.
Data protection questions to us: privacy@tandevia.com. We have not appointed a statutory data protection officer, because our processing does not meet the Article 37 thresholds; the address above reaches the people who are accountable for it.
Where we rely on legitimate interest, we have weighed it against your interests and concluded it does not override them: the processing is limited to what running a business service requires, and you can object at any time (see Section 7). Where we rely on consent, refusing costs you nothing.
We do not sell personal data, ever. We do not use it for advertising, we do not enrich it from data brokers, and we do not build profiles about you.
When your organisation uses the platform, we host and transmit what it puts in: prompts, responses, uploaded files, records pulled from connected systems, thread history, workflow definitions and twin context. We process this only to provide, secure and support the service, and only as your organisation instructs.
Content you send to an AI provider through the gateway is governed by your own agreement with that provider. We enforce the data rules you configure before it leaves your network — detection, redaction, blocking — but once a provider receives it, its terms apply. Where you host models yourself, nothing leaves your infrastructure.
Our data processing terms, the current sub-processor list, and information for your DPIA are available on request. We notify you before a new sub-processor takes effect, so you have the chance to object.
The platform records how work happens, which means it necessarily processes data about the people doing it. How we build that is a privacy decision, not a feature decision:
If your organisation is in a jurisdiction requiring works council or employee representative consultation before deploying a system like this, that consultation is your responsibility as controller. We provide the documentation to support it, and we would rather you did it properly than quickly.
We share personal data only with:
Personal data is hosted in the European Union by default. Private cloud and fully on-premise deployments are available, in which case the data stays wherever you choose to run the platform.
Some sub-processors, and some AI providers your organisation may choose to connect, operate outside the EEA. Where a transfer happens, it rests on an adequacy decision where one exists, or on the European Commission’s Standard Contractual Clauses with a transfer impact assessment and additional safeguards where they do not. You can ask us which mechanism applies to a specific sub-processor, and we will tell you.
If your organisation cannot accept transfers outside the EU at all, say so before you configure providers: the platform can be set up so that only EU-hosted or self-hosted models are available.
Where we are the controller, you can ask us to:
Write to privacy@tandevia.com. We reply within one month, and tell you promptly if a request is genuinely complex enough to need longer. We may need to verify your identity first — not to obstruct you, but because handing your data to the wrong person would be the worse failure. Exercising a right is free; we charge only for a repeated, clearly excessive request, and we say so before doing any work.
Where we are the processor, send the request to your organisation. If it reaches us instead, we forward it and support them in answering.
You can also complain to the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Prague 7, uoou.cz) or to the supervisory authority where you live or work. We would appreciate the chance to fix it first, but that is your choice, not a precondition.
We maintain technical and organisational measures appropriate to the risk: encryption in transit and at rest, tenant isolation, role-based access with least privilege, logged administrative access, secure development practice and regular review. Our information security management system is certified to ISO 27001, and our quality management to ISO 9001. Ask us for the certificates and their scope statements.
No system is immune. If a breach affects your personal data, we notify the relevant supervisory authority within 72 hours where the law requires it, and we tell affected customers without undue delay — with what happened, what data was involved, what we have done, and what you should do. We would rather tell you early and revise the detail than wait until the picture is tidy.
This website sets five first-party cookies. What they do, how long they last and how to change your choice is set out in our Cookie Policy, and you can change your answer any time in cookie settings.
We do not make decisions about you by automated means alone that have legal or similarly significant effects. Inside the platform, automation proposes and a person approves — that is how it is designed, and where your organisation configures it otherwise, your organisation is the controller of that decision.
Tandevia is a business tool, not a consumer service. We do not knowingly process data about children, and the platform is not directed at them.
We update this policy when our processing, our sub-processors or the law change. The date at the top always shows the current version. For a change that materially affects how we handle your personal data we give notice by email to account administrators before it takes effect, and previous versions are available on request.