Privacy statement

Last updated: 11 August 2026

This page explains which personal data Turnado processes, why, on what legal basis, how long we keep it and what you can ask of us. It is written to be read, not to be survived.

Who is responsible

Turnado is a product of Return BV, registered at [[address]], company number [[company number]], VAT [[VAT number]]. For questions about privacy: [[privacy contact address]].

We have [[appointed / not appointed]] a data protection officer. [[If appointed: contact details.]]

What we process, and why

DataWhyLegal basis
Name, email address, password hash, login providerTo give you an account and to let you inPerformance of the contract
Organisation, membership, roleTo know what you may see and do, and to bill the right partyPerformance of the contract
Sessions, IP address and timestamp at loginTo keep the account secure and to detect abuseLegitimate interest (security)
Project content: work items, comments, attachments, documents, repository referencesThis is the product: the board and the AI colleagues work on itPerformance of the contract, with your organisation as controller
Agent runs: what an AI colleague received, did and returned, plus the outcomeTo show the work traceably, to bill it, and — with permission — to improve Turnado‑1Performance of the contract; consent for the improvement part
Invoicing and payment dataTo invoice and to keep our booksPerformance of the contract and legal obligation
Emails we send youConfirmation, invitations, notificationsPerformance of the contract

We do not build profiles for advertising, we do not sell data, and there is no automated decision-making with legal consequences for you in the sense of article 22 GDPR. The AI colleagues make proposals; a person approves them, and the board records who.

Your project content and the AI models

To do the work, Turnado sends the part an AI colleague needs to the model chosen for that lane. That is a real transfer to a third party and it deserves to be stated plainly rather than hidden in a sub-clause.

  • Only the context an agent needs for that task is sent, not your whole project.
  • Which model handles which lane is visible under AI models and your organisation chooses it.
  • An organisation can require EU-only: then only models whose inference runs inside the EU are eligible.
  • You can bring your own key. Then the call runs under your own contract with that provider, and their terms apply to it.

Which providers, and what they may do with it, is on the data processing page.

Improving Turnado‑1

Turnado‑1 is our own process model. With your organisation's permission we use its process runs to make it better. That permission is asked once, during onboarding, and can be changed at any time under AI models. It has three settings.

SettingWhat we use
NoneNothing. Runs are kept for your own board and your invoice, and for nothing else.
Figures onlyOnly how a run went — did it pass the gates, how long, how much did it cost. No content.
FullThe process runs themselves: what went in and what came out, for process work such as turning analysis into a backlog, classifying comments and deriving test cases.

Who else sees it

We use sub-processors: the AI model providers, our hosting, our payment provider and our mail provider. They are listed by name, with their role and region, on the data processing page. Each is bound by a processing agreement, and we do not add one without that.

Our own staff only access your project content when it is necessary to support you or to investigate a fault, and access is logged. We do not read along out of interest.

Transfers outside the EU

Process work on Turnado‑1 runs on EU infrastructure. For code work an organisation may choose a model whose provider processes outside the EU — that is a choice you make and can avoid with the EU-only setting. Where a transfer happens, it rests on the European Commission's standard contractual clauses and on the provider's own safeguards.

How long we keep it

WhatHow long
Account and membershipsAs long as the account exists, then [[retention]]
Project contentAs long as your organisation keeps it; on termination [[retention]]
Agent runs and the audit log[[retention]] — the audit log is append-only by design
Invoicing dataSeven years, because bookkeeping law requires it
Training material, where permission was given[[retention]], and removed on withdrawal

Your rights

Under the GDPR you can ask us the following, and we answer within one month.

  • Access — a copy of the personal data we hold about you.
  • Rectification — correction of what is wrong.
  • Erasure — deletion, unless we are legally required to keep it, such as invoicing data.
  • Restriction — that we hold still while a dispute is being resolved.
  • Portability — your data in a machine-readable form.
  • Objection — against processing based on our legitimate interest.
  • Withdrawal of consent — for the training permission, at any time and without losing the product.

Write to [[privacy contact address]]. If your request is about project content, we point you to your organisation's administrator: there we are the processor and they decide. You can also lodge a complaint with the [[supervisory authority]].

Cookies

We place what is needed to keep you logged in and nothing else: a session cookie, and your interface preferences. No tracking cookies, no advertising networks, no third-party analytics that follow you across sites. That is why there is no cookie banner asking permission for something we do not do.

Changes

When this text changes materially we raise the version and ask again for what needs asking. The version you accepted is recorded with the date, so it is always clear what you agreed to.

Last updated: 11 August 2026.