Privacy Policy
Last updated: July 2026
This Policy explains how GeoAxis LLP, the company operating the Tindavo platform ("we"), processes personal data when you use our website and AI assistant platform. Customer data is stored in the European Union and processed under the GDPR.
1. Data we collect
Account data (name, email, company), billing data, usage data and technical logs, and what you send through the platform: messages and uploaded knowledge-base files. We do not sell personal data.
2. How we use data
To provide and run the service, sign you in, take payments, generate assistant replies, prevent abuse, comply with the law and — only with your consent — for analytics and product emails.
3. Legal bases
Contract performance, our legitimate interests, legal obligations and your consent (for non-essential cookies and marketing).
4. Who helps us process data (sub-processors)
Each provider is bound by a data-processing agreement. AI providers use content only to produce a reply and, under their API terms, do not train models on it. A new provider is added to this list before it starts processing data.
| Vercel (US, servers in the EU) | hosting of the website, dashboard and API. |
|---|---|
| Neon (US, database in the EU) | database: accounts, assistants, conversations, knowledge base. |
| Cloudflare R2 (US, storage in the EU) | your knowledge-base files. |
| Upstash (US, servers in the EU) | cache of the latest messages of an active conversation, request limits. |
| Clerk (US) | sign-in and account management: name, email, session data. |
| Anthropic (US) | the model that writes assistant replies: the question, conversation context, knowledge-base fragments. |
| OpenAI (US) | knowledge-base search: fragments of your documents and the search query. |
| Cohere (Canada / US) | ranking of search results: the query and candidate fragments. |
| Inngest (US) | background job queue: inbound channel messages and document processing. |
| Langfuse (Germany, EU) | model call log: question, answer, quality metrics. |
| Sentry (Functional Software, Inc., US) | error monitoring: technical identifiers and error metadata, no message text. |
| Resend (US) | emails from the service: recipient address. |
| Paddle (Paddle.com Market Ltd, United Kingdom) | payment operator: billing and invoicing data; card details never reach us. |
| Meta Platforms Ireland (WhatsApp Cloud API) | only if you connect WhatsApp: messages between a customer and your assistant. |
| Telegram (Telegram FZ-LLC, UAE) | only if you connect Telegram: messages between a customer and your assistant. |
5. Where data is stored
Core customer data — the database, files, cache and model log — is hosted in the European Union. Some providers above — in particular Sentry, the AI providers and Paddle — operate outside the EU/EEA; transfers to them are covered by data-processing agreements with the safeguards the GDPR requires.
6. Your rights (GDPR)
If you are in the EU/EEA, you may request access to your data, its correction, deletion, restriction of processing and portability, object to processing, and lodge a complaint with a supervisory authority. Write to us at the address below.
7. How long we keep data
As long as needed for the purposes above or required by law; then we delete or anonymise it. You can delete your account with all its data yourself — see the “Data deletion” page.
8. Contact
For privacy questions or to exercise your rights, email hello@tindavo.com.