Data processing and access

Last updated: 11 August 2026

This page describes how Turnado processes your project data on your instruction: which parties are involved, which access we ask for and why, and what we may and may not do with your runs. It is the factual basis under the processing agreement, not a replacement for it.

Controller and processor

For the content of your projects your organisation is the controller and we are the processor. We process on your instruction and for no purpose of our own, with one exception that requires your explicit permission: improving Turnado‑1, described below and switchable at any time.

A processing agreement under article 28 GDPR is part of the contract. [[Link to the signed agreement, or how to request it.]]

Sub-processors

These parties may process your data on our behalf. Which model providers actually come into play depends on the models your organisation chooses.

PartyRoleRegion
MistralInference for Turnado‑1 and for EU model choicesEU (France; Scaleway Paris/Amsterdam)
AnthropicInference for Claude models, when chosen[[region per contract]]
OpenAIInference for GPT models, when chosen[[region per contract]]
[[hosting provider]]Application hosting and database[[region]]
MolliePayment processingEU (Netherlands)
[[mail provider]]Transactional email[[region]]

We announce a new sub-processor before it goes live, so that you can object. [[How we announce: email to administrators, or this page with a subscription.]]

Which access we ask for, and why

Turnado only works if it can reach your repository. We ask for the narrowest access that still does the job, and every item below is there because a specific feature needs it.

AccessWhat we do with itWhy it cannot be narrower
Read repository contentsBuild the context for an agent: the files a task touches, conventions, the code mapAn agent that cannot read the code cannot reason about it
Create branches and commitsPut a proposed change on its own branchProposals have to live somewhere before a person can review them
Open and read pull requestsDeliver the work as a reviewable pull request and follow the reviewThe review is where a person decides; without it there is no gate
Read checks and CI resultsShow whether the gates passA green board with a red build is a lie
WebhooksNotice a push, a comment or a finished buildOtherwise we would have to poll, which is slower and noisier
  • We never push to your default branch. Work lands on its own branch and goes through a pull request.
  • We do not merge on your behalf. Merging is a human decision.
  • A CI token is scoped to one organisation and can be revoked at any time.
  • You can withdraw the connection whenever you like; the board keeps working, the code work stops.

What we may do with your runs

A run is one piece of work by an AI colleague: what went in, what it did, what came out, and how it was judged. What may happen with it depends entirely on the permission setting, and the boundary is enforced in code rather than in this text.

PermissionKept for your boardFigures for improvementContent for improvement
NoneYesNoNo
Figures onlyYesYesNo
FullYesYesProcess work only

Security incidents

If a breach affects your data we tell you without undue delay and within 72 hours of becoming aware, with what we know, what we are doing and what you can do. Details are on the security page.

Last updated: 11 August 2026.