Privacy statement
Last updated: 11 August 2026
This page explains which personal data Turnado processes, why, on what legal basis, how long we keep it and what you can ask of us. It is written to be read, not to be survived.
Who is responsible
Turnado is a product of Return BV, registered at [[address]], company number [[company number]], VAT [[VAT number]]. For questions about privacy: [[privacy contact address]].
We have [[appointed / not appointed]] a data protection officer. [[If appointed: contact details.]]
What we process, and why
| Data | Why | Legal basis |
|---|---|---|
| Name, email address, password hash, login provider | To give you an account and to let you in | Performance of the contract |
| Organisation, membership, role | To know what you may see and do, and to bill the right party | Performance of the contract |
| Sessions, IP address and timestamp at login | To keep the account secure and to detect abuse | Legitimate interest (security) |
| Project content: work items, comments, attachments, documents, repository references | This is the product: the board and the AI colleagues work on it | Performance of the contract, with your organisation as controller |
| Agent runs: what an AI colleague received, did and returned, plus the outcome | To show the work traceably, to bill it, and — with permission — to improve Turnado‑1 | Performance of the contract; consent for the improvement part |
| Invoicing and payment data | To invoice and to keep our books | Performance of the contract and legal obligation |
| Emails we send you | Confirmation, invitations, notifications | Performance of the contract |
We do not build profiles for advertising, we do not sell data, and there is no automated decision-making with legal consequences for you in the sense of article 22 GDPR. The AI colleagues make proposals; a person approves them, and the board records who.
Your project content and the AI models
To do the work, Turnado sends the part an AI colleague needs to the model chosen for that lane. That is a real transfer to a third party and it deserves to be stated plainly rather than hidden in a sub-clause.
- Only the context an agent needs for that task is sent, not your whole project.
- Which model handles which lane is visible under AI models and your organisation chooses it.
- An organisation can require EU-only: then only models whose inference runs inside the EU are eligible.
- You can bring your own key. Then the call runs under your own contract with that provider, and their terms apply to it.
Which providers, and what they may do with it, is on the data processing page.
Improving Turnado‑1
Turnado‑1 is our own process model. With your organisation's permission we use its process runs to make it better. That permission is asked once, during onboarding, and can be changed at any time under AI models. It has three settings.
| Setting | What we use |
|---|---|
| None | Nothing. Runs are kept for your own board and your invoice, and for nothing else. |
| Figures only | Only how a run went — did it pass the gates, how long, how much did it cost. No content. |
| Full | The process runs themselves: what went in and what came out, for process work such as turning analysis into a backlog, classifying comments and deriving test cases. |
Who else sees it
We use sub-processors: the AI model providers, our hosting, our payment provider and our mail provider. They are listed by name, with their role and region, on the data processing page. Each is bound by a processing agreement, and we do not add one without that.
Our own staff only access your project content when it is necessary to support you or to investigate a fault, and access is logged. We do not read along out of interest.
Transfers outside the EU
Process work on Turnado‑1 runs on EU infrastructure. For code work an organisation may choose a model whose provider processes outside the EU — that is a choice you make and can avoid with the EU-only setting. Where a transfer happens, it rests on the European Commission's standard contractual clauses and on the provider's own safeguards.
How long we keep it
| What | How long |
|---|---|
| Account and memberships | As long as the account exists, then [[retention]] |
| Project content | As long as your organisation keeps it; on termination [[retention]] |
| Agent runs and the audit log | [[retention]] — the audit log is append-only by design |
| Invoicing data | Seven years, because bookkeeping law requires it |
| Training material, where permission was given | [[retention]], and removed on withdrawal |
Your rights
Under the GDPR you can ask us the following, and we answer within one month.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of what is wrong.
- Erasure — deletion, unless we are legally required to keep it, such as invoicing data.
- Restriction — that we hold still while a dispute is being resolved.
- Portability — your data in a machine-readable form.
- Objection — against processing based on our legitimate interest.
- Withdrawal of consent — for the training permission, at any time and without losing the product.
Write to [[privacy contact address]]. If your request is about project content, we point you to your organisation's administrator: there we are the processor and they decide. You can also lodge a complaint with the [[supervisory authority]].
Cookies
We place what is needed to keep you logged in and nothing else: a session cookie, and your interface preferences. No tracking cookies, no advertising networks, no third-party analytics that follow you across sites. That is why there is no cookie banner asking permission for something we do not do.
Changes
When this text changes materially we raise the version and ask again for what needs asking. The version you accepted is recorded with the date, so it is always clear what you agreed to.
Last updated: 11 August 2026.