Skip to content
Tandly
  • Features
  • Switching
  • Security
  • Pricing
  • Guides
Sign in Get started
  • Features
  • Switching
  • Security
  • Pricing
  • Guides
  • Sign in
Get started

Legal

  • Terms of Service
  • Privacy Policy
  • Data Processing Addendum
  • Subprocessors

On this page

  • 1. Who is responsible
  • 2. What we collect
  • 3. Why we use it and our legal bases
  • 4. Who we share it with
  • 5. Where your data is stored
  • 6. How long we keep it
  • 7. How we protect it
  • 8. Your rights
  • 9. Cookies and local storage
  • 10. Changes
  • 11. Contact

Privacy Policy

Effective: 1 October 2026

This policy explains how UHRIK - IT & Event s. r. o. ("Tandly", "we", "us") handles personal data when you visit our website or status page, use Tandly Cloud, join our beta waiting list, or contact us. We wrote it to be read, not just to be agreed to.

1. Who is responsible

UHRIK - IT & Event s. r. o., Bajzova 2417/13, 010 01 Žilina, Slovakia (registration Commercial Register of the District Court Žilina, Section Sro, Insert No. 84882/L; Company ID (IČO) 56 198 761).

  • Privacy questions and requests: [email protected]
  • Data protection officer: We have not appointed a data protection officer: we are not a public authority and our core activity is not large-scale monitoring or processing of special categories of data, so Article 37 GDPR does not require one. Write to [email protected] with anything a data protection officer would handle, and it reaches the people who can answer it

When we are the controller, and when your organisation is

One rule decides it: everything inside a workspace belongs to the organisation that runs the workspace; what we need to run our own business belongs to us.

Your organisation is the controller, and we are its processor (under our Data Processing Addendum) for everything inside a workspace: user accounts and profiles, directory data synced from your organisation's systems, messages, files and all other workspace content, presence and read status, sessions and devices used to reach the workspace, device-trust records, calendar features, and the audit and support access logs that workspace administrators can see. Your organisation decides why and how this is processed and which legal basis applies. For these data, please contact your workspace administrators first. If you contact us, we pass your request on to them.

We are the controller for:

  • our website and status page, and their server logs;
  • the beta waiting list;
  • our relationship with customers: billing contacts, invoices, the customer account and the record of who accepted our terms;
  • support correspondence and our internal notes about customer accounts;
  • security records we keep to protect the service as a whole (rate limits, abuse detection, incident investigation), and the audit log of what our own staff do;
  • the service e-mails we send about our own service (address confirmation, password reset, security alerts);
  • your account if you sign up yourself and do not (yet) belong to any workspace.

The rest of this policy says, for each kind of data, which of the two applies.

Self-hosted Tandly

If your organisation runs Tandly on its own servers (Community or Self-hosted Business edition), your data never reaches us. The only data we get are the details needed to issue and bill a licence (the licensee name, a contact e-mail address and the number of seats).

2. What we collect

"Processor" means we process the data for your organisation, as described in section 1. "Controller" means we decide what happens to it.

CategoryExamplesSourceRole
Account and sign-inName, e-mail address, profile photo. Depending on how you sign in: your Google account ID and Google Workspace domain; your Apple ID identifier, an e-mail address (it may be an Apple relay address) and, if you share it, your name; your identifier at your organisation's single sign-on (SAML) provider; or a password, which we store only as an argon2id hash, together with short-lived tokens for confirming your e-mail address and resetting your password. If you turn on two-factor authentication: the authenticator secret (stored encrypted) and your recovery codesYou; Google or Apple; your organisation's identity provider, including accounts it creates, updates or deactivates automatically (SCIM)Processor (Controller for a self-signed-up account that belongs to no workspace)
Profile and directoryDisplay name, title, department, location, manager, phone number, employee ID, pronouns, how to pronounce your name, start date, time zone, working hours, status, custom profile fieldsYou, or your organisation's directory (Google Workspace directory sync or its identity provider)Processor
AvailabilityOut-of-office and away periods, who stands in for you, handover notes, messages held until someone is backYou and other membersProcessor
Workspace contentMessages, threads, files, images, reactions, pins, saved items, drafts (kept on our servers so they follow you between devices), scheduled messages, reminders, stand-up answers, decisions, read acknowledgements, channel and folder settingsYou and other members of your workspaceProcessor
InvitationsE-mail addresses of people invited to a workspace who don't have an account yet, and who invited themMembers who send invitationsProcessor
Activity and presenceWhether you are active or away, when you last read a channel, typing indicators (these are not stored), notification settings and "do not disturb"Your use of the serviceProcessor
Connected appsWhen you or an administrator connect another service (Google Calendar, Google Drive): the account it was connected as, what access was granted, and the keys that let us use it, which are stored encryptedYou, when you authorise itProcessor
CalendarIf you connect Google Calendar: the titles, times, locations, joining links and number of invitees of your upcoming meetings, read to prepare your morning agenda, meeting reminders, notices about changed meetings and the optional "In a meeting" status. To notice that a meeting moved or was cancelled, we keep the start, end and title of each event in the next 14 days, and delete each one about an hour after it starts. The agenda, reminders and change notices reach you as direct messages from Tandly Bot, so they contain those details and stay in that conversation like any other message until you delete themYour Google Calendar, when you connect itProcessor
Sessions, devices and securitySession records (IP address, browser or device name, platform, how you signed in, when the session started and was last used). A fingerprint (a hash) of each browser and platform you have signed in from, so we can e-mail you when a new one is used; that e-mail names the device and IP address. For the mobile apps: the device name (which often contains your name), platform, app version and push notification token, and whether the device is enrolled by your organisation. If your organisation turns on device trust: a record, per person, channel and day, of access from a device your organisation does not manage, which workspace administrators can see. Audit logs of administrative actions, including the IP address of the person who actedYour devices and our serversProcessor
Protection of the serviceCounters of failed sign-ins, sign-ups and e-mail requests per IP address and e-mail addressOur serversController
Service e-mailsYour e-mail address and the content of the e-mails we send you: address confirmation, password reset, password changed, two-factor turned on or off, new sign-in alerts, notices that you were signed out, and billing and administrator noticesOur serversController
SupportWhat you tell us when you contact support, support tickets, our internal notes about your organisation's account, and the record of any support access to your workspaceYou, and our staff toolsController
Acceptance of our termsWho accepted which version of our Terms of Service, when, and from which IP address: recorded when you create a workspace (on behalf of your organisation) and when you sign up with an e-mail address and passwordYouController
BillingBilling contact name and e-mail address, company name, country, billing address, VAT ID, plan, number of active members and invoices. Once card payments are switched on, also the payment provider's customer ID (never the card itself)Your organisation's administratorsController
Beta waiting listE-mail address, name, company, team size, your note, the IP address the request came from, and our decision with a noteYou, when you ask to join the betaController
Website and status pageWeb server logs (IP address, browser, the page requested, time)Your browserController

We do not use advertising or analytics trackers. Fonts are served from our own servers, not from third parties.

Do you have to give us this data? To have an account you need an e-mail address and a name; without them we cannot create one. Most profile fields are optional, unless your organisation's directory fills them in. Everything else is up to you and to how your organisation uses Tandly. No law requires you to give us personal data.

We do not knowingly collect special categories of data (such as health data). Please don't post them unless your organisation has decided it is appropriate. Tandly Cloud is not intended for children under 16. If we learn that an account belongs to a child under 16, we delete it.

3. Why we use it and our legal bases

Data we process for your organisation

For everything marked "Processor" above, we act only on your organisation's instructions: to run the service it signed up for (delivering messages, notifications, search, calendar features and integrations, and keeping it secure and working). Your organisation, as the controller, decides the legal basis. For an employer this is usually its legitimate interests or the employment relationship; ask your organisation if you want to know. We do not use these data for any purpose of our own.

Calendar features run only because you chose to connect your calendar, and you can disconnect it at any time (Preferences → Calendar). Disconnecting stops them at once.

Data we are responsible for

PurposeLegal basis (GDPR Art. 6(1))
Running the website and status page, and keeping them secure (server logs)Legitimate interests (f): delivering the pages and detecting attacks
Protecting the service: rate limits on sign-in and sign-up, detecting abuse, investigating incidents, the audit log of our own staffLegitimate interests (f): protecting our users, their data and our systems. The GDPR also requires us to keep the service secure (Art. 32)
Service e-mails: confirming your address, password resets, security alerts, notices that you were signed outLegitimate interests (f): letting you sign in safely and warning you about activity on your account
Your account, when you signed up yourself and belong to no workspacePerformance of a contract (b)
Managing the beta waiting list: considering your request and inviting youSteps you asked for before a contract (b)
Recording the IP address of waiting-list requests, to spot automated floodsLegitimate interests (f): keeping the list free of abuse
Recording who accepted our terms, which version and when, with the IP addressLegitimate interests (f): being able to show that, and on which terms, the contract was concluded
Managing the customer relationship: plans, invoices, payments, contact with billing contactsPerformance of a contract (b) where you are our customer yourself (for example as a sole trader); otherwise legitimate interests (f) in dealing with the people our customer names as its contacts
Keeping accounting and tax recordsLegal obligation (c): Slovak accounting and VAT law (Act No. 431/2002 Coll. and Act No. 222/2004 Coll.)
Support: answering your requests and fixing problemsLegitimate interests (f): helping the people who use our service
Telling you about important changes to the service or these termsLegal obligation (c) where the law requires the notice, otherwise legitimate interests (f)
Defending legal claims and answering authoritiesLegal obligation (c), or legitimate interests (f) in establishing and defending legal claims
Marketing e-mail, if we ever send itOnly with your consent (a), which you can withdraw at any time

Where we rely on legitimate interests, you can ask us how we balanced them against your rights, and you can object (see section 8).

We never sell personal data, and we don't use workspace content for advertising or to train AI models.

Features that process data automatically

  • Link previews. When someone posts a link, our servers fetch the page, and the preview image, to show a preview. The linked site sees our server's address, not yours, and neither does the site that hosts the image. Profile pictures from other services reach you through our servers in the same way.
  • Secret guard. Before a message is sent, it is checked on our servers for things that look like passwords or API keys, so the sender can be warned. The check only warns: it does not block, report or delete anything by itself. It has no legal or similarly significant effect on anyone. We don't make decisions based solely on automated processing within the meaning of Art. 22 GDPR.
  • Connected calendars. If you connect a calendar, we read it with your own permission, show it only to you, and never post it into a channel unless an automation rule you wrote says so.
  • Directory sync and provisioning. If an administrator connects Google Workspace or the organisation's identity provider (SCIM), profiles are updated from the organisation's directory, and people who are removed there are deactivated here.

4. Who we share it with

  • Members and administrators of your workspace see what you post and your profile, as the workspace's settings allow. Administrators can manage accounts and see audit logs, the device list, and device-trust records.
  • Service providers (subprocessors) who host the service, store files, carry traffic, send e-mail and deliver notifications, listed on our subprocessors page. Service e-mails are sent through Twilio Inc. (SendGrid). Providers may only use the data to provide their service to us.
  • Push notification services. To show notifications on your devices, a short notification passes through your browser's push service or, for our mobile apps, through Expo, Google Firebase Cloud Messaging and Apple Push Notification service. It contains who sent the message, the channel name, the beginning of the message, and the identifiers and link needed to open the message; web notifications also carry a link to the sender's profile picture. Web notifications are encrypted end to end to your browser (RFC 8291), so the browser's push service cannot read them; mobile notifications are not encrypted in this way. Self-destructing messages, and messages in channels your organisation restricts to managed devices, never include text, and detected secrets are hidden.
  • Google, Apple and your organisation's identity provider handle sign-in under their own terms when you choose to sign in with them.
  • Our website's providers. Our status page runs on Cloudflare Workers, so Cloudflare sees the IP address of everyone who visits it. Apart from Cloudflare's short-lived request logs (see section 6), the status page stores nothing about its visitors.
  • Authorities, only when the law requires it. Where the law allows, we tell the affected organisation first and challenge requests that are too broad.
  • A buyer or successor, if our business is sold or merged. This policy continues to protect your data.

5. Where your data is stored

Tandly Cloud stores your data in the European Union: Germany, the Netherlands and Belgium, with netcup GmbH in Germany (our current production servers, which we are replacing), Google Cloud in the Netherlands and Belgium, and Cloudflare R2 for files, stored in Cloudflare's EU jurisdiction. While we move production from netcup to Google Cloud, both are in use.

Some providers are based in the United States: Cloudflare, whose network carries all traffic to the service and may handle it in the data centre nearest to you, including outside the EU; Twilio Inc. (SendGrid), which sends our e-mail; and the providers that deliver push notifications or handle sign-in. Where data leaves the EU/EEA, we rely on an adequacy decision (including the EU–US Data Privacy Framework for certified companies) or on the European Commission's Standard Contractual Clauses, with additional safeguards where needed. You can ask us for a copy of these safeguards.

6. How long we keep it

DataHow long
Account and profileWhile your account is active. When you delete your account, see below
Messages and filesUntil they are deleted by you or an administrator, by a retention policy your organisation sets, or with the workspace. Messages you posted stay in the workspace after you delete your account, because they belong to the organisation's records. Whether they are kept is up to your organisation
Deleted messages and filesThe text of a deleted message is removed at once. A marker without content (who posted it and when) stays so that threads keep making sense. A deleted file is removed from storage at once (if storage is briefly unreachable, we retry until it is gone). Files that were attached to a deleted message are removed 7 days later, unless another message, a draft or scheduled message, or a profile, emoji or workspace image still uses them, or your organisation has placed the workspace under a legal hold. Files of self-destructing messages are removed together with the message
Deleted workspacesKept for up to 30 days so they can be restored if deleted by mistake, then permanently erased. People who belonged to no other workspace have their accounts anonymised at the same time, as if they had deleted them
SessionsUntil you sign out or the session expires (at most 30 days); expired sessions are purged automatically
Push notification tokensUntil you sign out on that device, the session ends, or the push service reports the token as invalid
Sign-in fingerprints and the device listUntil you delete your account
Device-trust recordsAs long as the workspace exists, or until you delete your account
Connected appsUntil you or an administrator disconnects them; the stored keys are deleted at once, and we ask the provider to revoke them where it supports that
CalendarEvent start, end and title: until about an hour after the event starts. Reminder markers (an event identifier and time): 7 days. All stored calendar data is deleted when you disconnect the calendar or delete your account. Agenda and reminder messages stay in your conversation with Tandly Bot until you delete them
Out-of-office periods, stand-ins and handover notesUntil your account or the workspace is deleted
InvitationsAs long as the workspace exists. Administrators can revoke a pending invitation at any time
Audit logs and support access logsAs long as the workspace exists, so administrators can review them
Record of accepting our termsFor a workspace: as long as the workspace exists. For a sign-up with e-mail and password: until you delete your account
Failed sign-in and rate-limit countersAt most one hour
Support correspondence and internal notesAs long as the customer relationship lasts, and up to 3 years afterwards to deal with follow-up questions and claims
Beta waiting listUntil you are invited and have created your account, or up to 12 months after our decision if you are not
BackupsUp to 14 days, after which they are deleted
Web server logsUp to 14 days
Billing recordsAs long as tax and accounting law requires, usually up to 10 years

When you delete your account

Your profile is anonymised straight away (shown as "Deleted user") and you can no longer sign in. We delete your sessions, devices (push notification registrations, sign-in fingerprints and the device list), two-factor data, connected apps (the keys are deleted and we ask the provider to revoke them), calendar data, drafts, scheduled messages, saved items, reminders, notifications, personal folders, out-of-office periods, custom profile fields and the record of your own sign-up to our terms, and your uploaded profile photo and other files you uploaded but never posted (such as attachments of unsent drafts), unless your organisation has placed them under a legal hold. Messages and files you posted stay in the workspace as part of the organisation's records, and so does the record of terms you accepted when you created a workspace. Audit log entries about your actions stay, with your name replaced, for as long as the workspace exists. Backups containing the old data are deleted within 14 days.

7. How we protect it

All traffic is encrypted with TLS. Session tokens are stored only as hashes, and files are served only after an access check, through links that expire after five minutes. Our staff work with workspaces through a dedicated console that requires a role and a written reason, both to change anything and to look at a workspace or a person's account; a reason for looking covers that staff member's views of that workspace or account for 30 minutes. Direct access to the database is limited to operating or restoring the service and handling incidents. Every change, and every time a staff member opens a workspace or a person's account, is shown to the workspace's administrators in their Support access log, as an action by "Tandly Support" with what was done and when (it does not name the individual staff member or show the reason; our own audit log records both). Staff cannot read message or file content through the console at all. Our DPA lists the measures in more detail. To report a security problem, write to [email protected].

8. Your rights

Under the GDPR you have the right to:

  • access your data and get a copy of it;
  • rectify inaccurate data. Most of your profile can be edited in the app; fields managed by your organisation's directory are changed there;
  • erase your data. Delete your account in the app (on the web: workspace menu → Preferences → Account; in the mobile app: You → Delete my account) or ask us. Section 6 says what deletion removes and what stays;
  • restrict or object to processing based on legitimate interests;
  • data portability, a machine-readable copy of the data you gave us;
  • withdraw consent at any time, where processing is based on consent;
  • lodge a complaint with a supervisory authority, in particular in the EU country where you live or work. Our lead authority is Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic), Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk.

Write to [email protected]. We answer within one month (up to three months for complex requests, in which case we tell you why). We may ask you to confirm your identity. There is no self-service download of your personal data yet: when you ask for a copy, we send it as a machine-readable file (JSON) within that month.

For data we process for your organisation, the organisation decides, and we help it respond. Workspace administrators on plans that include data export can export the workspace themselves; on other plans, we export it for them on request.

9. Cookies and local storage

We use only what is strictly necessary for the service, so no consent banner is needed:

NamePurposeLifetime
sc_sessionKeeps you signed in (HttpOnly, Secure, SameSite=Lax)Up to 30 days, or until you sign out
sc_oauth (path /api/auth/google)Protects the Google sign-in flow against forgery (HttpOnly, Secure, SameSite=Lax)10 minutes
sc_saml (path /api/auth/saml)Keeps track of a single sign-on in progress (HttpOnly, Secure, SameSite=None, because your identity provider sends you back to us from its own site)10 minutes
Browser local storageRemembers interface choices on your device: theme and appearance, sidebar layout, the last workspace and channel you opened, your recent search queries and similar settingsUntil you clear it

Drafts are stored on our servers with your account, not in your browser.

The website uses no cookies. It keeps the currency you chose on the pricing page in your browser's local storage.

10. Changes

If we change this policy in a way that matters, we will tell workspace owners by e-mail or in the app at least 30 days before the change takes effect. If the change affects how we process data as a controller (see section 1), we also tell the people affected, in the app or by e-mail. Earlier versions are available on request.

11. Contact

UHRIK - IT & Event s. r. o., Bajzova 2417/13, 010 01 Žilina, Slovakia · [email protected]

Tandly
  • Features
  • Switching
  • Security
  • Pricing
  • Guides
  • Changelog
  • Status
  • Sign in
  • Terms
  • Privacy
  • DPA
  • Subprocessors

© 2026 Tandly. Screens show a fictional company.