Legal

Privacy Policy

How Tandevia handles personal data — what we collect, why, how long we keep it, and the rights you have over it. The controller and operator is Forscope a.s., Lidická 960/81, 602 00 Brno, Czech Republic (company ID 04885414).

Last updated 30 August 2026·Effective from 30 August 2026
01

Who we are, and which hat we are wearing

Forscope a.s., Lidická 960/81, 602 00 Brno, Czech Republic, company ID 04885414, is the operator of the Tandevia platform and of this website.

This distinction matters for the rest of this page, so it comes first:

·We are the controller for data about visitors to this website and about people who contact us, apply to partner with us, or administer a Tandevia account. We decide what is collected and why.
·We are the processor for the content your organisation puts into the platform — prompts, files, records, context. Your organisation is the controller there. It decides what goes in and why; we act on its instructions under our data processing terms.

If you are an employee whose company uses Tandevia and you want to know why a particular piece of data about your work is being processed, your employer holds that answer. Ask them first — and we will support them in answering you.

Data protection questions to us: privacy@tandevia.com. We have not appointed a statutory data protection officer, because our processing does not meet the Article 37 thresholds; the address above reaches the people who are accountable for it.

02

What we process as controller, and why

Data
Why we process it
Legal basis
Kept for
Contact and enquiry data
name, work email, organisation, your message
To answer you, and to keep a record of what we agreed.
Legitimate interest, or steps prior to a contract
3 years from last contact
Account and administrator data
name, work email, role, authentication identifiers
To operate your workspace, authenticate people and attribute administrative actions.
Performance of a contract
Duration of the agreement, then 30 days
Billing data
organisation, invoicing details, Active User counts
To invoice correctly and to meet our accounting duties.
Contract, and legal obligation
10 years (Czech accounting law)
Service telemetry
request metadata, volumes, errors, IP address
To keep the service running, to detect abuse, and to bill accurately.
Legitimate interest, and contract
13 months
Website analytics
truncated IP, pages viewed, referrer
To see which pages are read. Aggregate only, no profiling.
Consent
13 months
Partner applications
name, company, market, what you sell
To assess and manage the partner relationship.
Legitimate interest, or steps prior to a contract
2 years from last contact

Where we rely on legitimate interest, we have weighed it against your interests and concluded it does not override them: the processing is limited to what running a business service requires, and you can object at any time (see Section 7). Where we rely on consent, refusing costs you nothing.

We do not sell personal data, ever. We do not use it for advertising, we do not enrich it from data brokers, and we do not build profiles about you.

03

What we do with Customer Data as processor

When your organisation uses the platform, we host and transmit what it puts in: prompts, responses, uploaded files, records pulled from connected systems, thread history, workflow definitions and twin context. We process this only to provide, secure and support the service, and only as your organisation instructs.

·We do not train models on it. Not our models, not anyone else’s. There is no exception buried elsewhere in this document.
·We do not read it, except where an authorised person at your organisation asks us to for support and we log that access.
·We do not use it across tenants: one customer’s content is never available to another, and never feeds a shared index.
·Retention is configurable by your organisation. When your agreement ends we keep it for 30 days for export, then delete it, including from backups within our normal cycle.

Content you send to an AI provider through the gateway is governed by your own agreement with that provider. We enforce the data rules you configure before it leaves your network — detection, redaction, blocking — but once a provider receives it, its terms apply. Where you host models yourself, nothing leaves your infrastructure.

Our data processing terms, the current sub-processor list, and information for your DPIA are available on request. We notify you before a new sub-processor takes effect, so you have the chance to object.

04

Employee data, and the line we will not cross

The platform records how work happens, which means it necessarily processes data about the people doing it. How we build that is a privacy decision, not a feature decision:

·A person can read their own record. Whatever a twin holds about someone is visible to that someone.
·Organisation-level insight is aggregate. The platform is not designed to score, rank or monitor individuals, and we will not sell it for that purpose.
·Individual-level records are not exportable in bulk, including by administrators.
·Approval and audit logs exist to answer "what did this automation do", not "how productive is this person".

If your organisation is in a jurisdiction requiring works council or employee representative consultation before deploying a system like this, that consultation is your responsibility as controller. We provide the documentation to support it, and we would rather you did it properly than quickly.

05

Who else sees the data

We share personal data only with:

·Sub-processors that run part of the service — hosting, email delivery, error monitoring, payment processing. Each is bound by a written contract with obligations no weaker than ours, and each is on the list we give you on request.
·AI providers you have connected, where the request you or your systems made requires it.
·Professional advisers — accountants, auditors, lawyers — under confidentiality, where necessary.
·Authorities, where the law compels us. We check whether a request is valid and properly served, we disclose only what is required, and we tell the affected customer unless we are legally forbidden from doing so.
·An acquirer, if the business is sold, on notice to you and with this policy continuing to apply until it is lawfully replaced.
06

Where the data lives, and transfers outside the EU

Personal data is hosted in the European Union by default. Private cloud and fully on-premise deployments are available, in which case the data stays wherever you choose to run the platform.

Some sub-processors, and some AI providers your organisation may choose to connect, operate outside the EEA. Where a transfer happens, it rests on an adequacy decision where one exists, or on the European Commission’s Standard Contractual Clauses with a transfer impact assessment and additional safeguards where they do not. You can ask us which mechanism applies to a specific sub-processor, and we will tell you.

If your organisation cannot accept transfers outside the EU at all, say so before you configure providers: the platform can be set up so that only EU-hosted or self-hosted models are available.

07

Your rights

Where we are the controller, you can ask us to:

·give you a copy of the personal data we hold about you, and tell you how we process it;
·correct it if it is wrong or incomplete;
·delete it, where we have no overriding obligation or legitimate ground to keep it;
·restrict processing, or object to processing based on legitimate interest;
·give you the data in a portable format, where processing rests on consent or contract;
·withdraw a consent you gave, at any time and without consequence for anything else.

Write to privacy@tandevia.com. We reply within one month, and tell you promptly if a request is genuinely complex enough to need longer. We may need to verify your identity first — not to obstruct you, but because handing your data to the wrong person would be the worse failure. Exercising a right is free; we charge only for a repeated, clearly excessive request, and we say so before doing any work.

Where we are the processor, send the request to your organisation. If it reaches us instead, we forward it and support them in answering.

You can also complain to the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Prague 7, uoou.cz) or to the supervisory authority where you live or work. We would appreciate the chance to fix it first, but that is your choice, not a precondition.

08

Security, and what happens if something goes wrong

We maintain technical and organisational measures appropriate to the risk: encryption in transit and at rest, tenant isolation, role-based access with least privilege, logged administrative access, secure development practice and regular review. Our information security management system is certified to ISO 27001, and our quality management to ISO 9001. Ask us for the certificates and their scope statements.

No system is immune. If a breach affects your personal data, we notify the relevant supervisory authority within 72 hours where the law requires it, and we tell affected customers without undue delay — with what happened, what data was involved, what we have done, and what you should do. We would rather tell you early and revise the detail than wait until the picture is tidy.

09

Cookies, automated decisions, and children

This website sets five first-party cookies. What they do, how long they last and how to change your choice is set out in our Cookie Policy, and you can change your answer any time in cookie settings.

We do not make decisions about you by automated means alone that have legal or similarly significant effects. Inside the platform, automation proposes and a person approves — that is how it is designed, and where your organisation configures it otherwise, your organisation is the controller of that decision.

Tandevia is a business tool, not a consumer service. We do not knowingly process data about children, and the platform is not directed at them.

10

Changes to this policy

We update this policy when our processing, our sub-processors or the law change. The date at the top always shows the current version. For a change that materially affects how we handle your personal data we give notice by email to account administrators before it takes effect, and previous versions are available on request.

Privacy questions: privacy@tandevia.com or contact us. See also our Terms of Service and Cookie Policy.