Privacy Policy
Effective: 1 October 2026
This policy explains how UHRIK - IT & Event s. r. o. ("Tandly", "we", "us") handles personal data when you visit our website or status page, use Tandly Cloud, join our beta waiting list, or contact us. We wrote it to be read, not just to be agreed to.
1. Who is responsible
UHRIK - IT & Event s. r. o., Bajzova 2417/13, 010 01 Žilina, Slovakia (registration Commercial Register of the District Court Žilina, Section Sro, Insert No. 84882/L; Company ID (IČO) 56 198 761).
- Privacy questions and requests: [email protected]
- Data protection officer: We have not appointed a data protection officer: we are not a public authority and our core activity is not large-scale monitoring or processing of special categories of data, so Article 37 GDPR does not require one. Write to [email protected] with anything a data protection officer would handle, and it reaches the people who can answer it
When we are the controller, and when your organisation is
One rule decides it: everything inside a workspace belongs to the organisation that runs the workspace; what we need to run our own business belongs to us.
Your organisation is the controller, and we are its processor (under our Data Processing Addendum) for everything inside a workspace: user accounts and profiles, directory data synced from your organisation's systems, messages, files and all other workspace content, presence and read status, sessions and devices used to reach the workspace, device-trust records, calendar features, and the audit and support access logs that workspace administrators can see. Your organisation decides why and how this is processed and which legal basis applies. For these data, please contact your workspace administrators first. If you contact us, we pass your request on to them.
We are the controller for:
- our website and status page, and their server logs;
- the beta waiting list;
- our relationship with customers: billing contacts, invoices, the customer account and the record of who accepted our terms;
- support correspondence and our internal notes about customer accounts;
- security records we keep to protect the service as a whole (rate limits, abuse detection, incident investigation), and the audit log of what our own staff do;
- the service e-mails we send about our own service (address confirmation, password reset, security alerts);
- your account if you sign up yourself and do not (yet) belong to any workspace.
The rest of this policy says, for each kind of data, which of the two applies.
Self-hosted Tandly
If your organisation runs Tandly on its own servers (Community or Self-hosted Business edition), your data never reaches us. The only data we get are the details needed to issue and bill a licence (the licensee name, a contact e-mail address and the number of seats).
2. What we collect
"Processor" means we process the data for your organisation, as described in section 1. "Controller" means we decide what happens to it.
| Category | Examples | Source | Role |
|---|---|---|---|
| Account and sign-in | Name, e-mail address, profile photo. Depending on how you sign in: your Google account ID and Google Workspace domain; your Apple ID identifier, an e-mail address (it may be an Apple relay address) and, if you share it, your name; your identifier at your organisation's single sign-on (SAML) provider; or a password, which we store only as an argon2id hash, together with short-lived tokens for confirming your e-mail address and resetting your password. If you turn on two-factor authentication: the authenticator secret (stored encrypted) and your recovery codes | You; Google or Apple; your organisation's identity provider, including accounts it creates, updates or deactivates automatically (SCIM) | Processor (Controller for a self-signed-up account that belongs to no workspace) |
| Profile and directory | Display name, title, department, location, manager, phone number, employee ID, pronouns, how to pronounce your name, start date, time zone, working hours, status, custom profile fields | You, or your organisation's directory (Google Workspace directory sync or its identity provider) | Processor |
| Availability | Out-of-office and away periods, who stands in for you, handover notes, messages held until someone is back | You and other members | Processor |
| Workspace content | Messages, threads, files, images, reactions, pins, saved items, drafts (kept on our servers so they follow you between devices), scheduled messages, reminders, stand-up answers, decisions, read acknowledgements, channel and folder settings | You and other members of your workspace | Processor |
| Invitations | E-mail addresses of people invited to a workspace who don't have an account yet, and who invited them | Members who send invitations | Processor |
| Activity and presence | Whether you are active or away, when you last read a channel, typing indicators (these are not stored), notification settings and "do not disturb" | Your use of the service | Processor |
| Connected apps | When you or an administrator connect another service (Google Calendar, Google Drive): the account it was connected as, what access was granted, and the keys that let us use it, which are stored encrypted | You, when you authorise it | Processor |
| Calendar | If you connect Google Calendar: the titles, times, locations, joining links and number of invitees of your upcoming meetings, read to prepare your morning agenda, meeting reminders, notices about changed meetings and the optional "In a meeting" status. To notice that a meeting moved or was cancelled, we keep the start, end and title of each event in the next 14 days, and delete each one about an hour after it starts. The agenda, reminders and change notices reach you as direct messages from Tandly Bot, so they contain those details and stay in that conversation like any other message until you delete them | Your Google Calendar, when you connect it | Processor |
| Sessions, devices and security | Session records (IP address, browser or device name, platform, how you signed in, when the session started and was last used). A fingerprint (a hash) of each browser and platform you have signed in from, so we can e-mail you when a new one is used; that e-mail names the device and IP address. For the mobile apps: the device name (which often contains your name), platform, app version and push notification token, and whether the device is enrolled by your organisation. If your organisation turns on device trust: a record, per person, channel and day, of access from a device your organisation does not manage, which workspace administrators can see. Audit logs of administrative actions, including the IP address of the person who acted | Your devices and our servers | Processor |
| Protection of the service | Counters of failed sign-ins, sign-ups and e-mail requests per IP address and e-mail address | Our servers | Controller |
| Service e-mails | Your e-mail address and the content of the e-mails we send you: address confirmation, password reset, password changed, two-factor turned on or off, new sign-in alerts, notices that you were signed out, and billing and administrator notices | Our servers | Controller |
| Support | What you tell us when you contact support, support tickets, our internal notes about your organisation's account, and the record of any support access to your workspace | You, and our staff tools | Controller |
| Acceptance of our terms | Who accepted which version of our Terms of Service, when, and from which IP address: recorded when you create a workspace (on behalf of your organisation) and when you sign up with an e-mail address and password | You | Controller |
| Billing | Billing contact name and e-mail address, company name, country, billing address, VAT ID, plan, number of active members and invoices. Once card payments are switched on, also the payment provider's customer ID (never the card itself) | Your organisation's administrators | Controller |
| Beta waiting list | E-mail address, name, company, team size, your note, the IP address the request came from, and our decision with a note | You, when you ask to join the beta | Controller |
| Website and status page | Web server logs (IP address, browser, the page requested, time) | Your browser | Controller |
We do not use advertising or analytics trackers. Fonts are served from our own servers, not from third parties.
Do you have to give us this data? To have an account you need an e-mail address and a name; without them we cannot create one. Most profile fields are optional, unless your organisation's directory fills them in. Everything else is up to you and to how your organisation uses Tandly. No law requires you to give us personal data.
We do not knowingly collect special categories of data (such as health data). Please don't post them unless your organisation has decided it is appropriate. Tandly Cloud is not intended for children under 16. If we learn that an account belongs to a child under 16, we delete it.
3. Why we use it and our legal bases
Data we process for your organisation
For everything marked "Processor" above, we act only on your organisation's instructions: to run the service it signed up for (delivering messages, notifications, search, calendar features and integrations, and keeping it secure and working). Your organisation, as the controller, decides the legal basis. For an employer this is usually its legitimate interests or the employment relationship; ask your organisation if you want to know. We do not use these data for any purpose of our own.
Calendar features run only because you chose to connect your calendar, and you can disconnect it at any time (Preferences → Calendar). Disconnecting stops them at once.
Data we are responsible for
| Purpose | Legal basis (GDPR Art. 6(1)) |
|---|---|
| Running the website and status page, and keeping them secure (server logs) | Legitimate interests (f): delivering the pages and detecting attacks |
| Protecting the service: rate limits on sign-in and sign-up, detecting abuse, investigating incidents, the audit log of our own staff | Legitimate interests (f): protecting our users, their data and our systems. The GDPR also requires us to keep the service secure (Art. 32) |
| Service e-mails: confirming your address, password resets, security alerts, notices that you were signed out | Legitimate interests (f): letting you sign in safely and warning you about activity on your account |
| Your account, when you signed up yourself and belong to no workspace | Performance of a contract (b) |
| Managing the beta waiting list: considering your request and inviting you | Steps you asked for before a contract (b) |
| Recording the IP address of waiting-list requests, to spot automated floods | Legitimate interests (f): keeping the list free of abuse |
| Recording who accepted our terms, which version and when, with the IP address | Legitimate interests (f): being able to show that, and on which terms, the contract was concluded |
| Managing the customer relationship: plans, invoices, payments, contact with billing contacts | Performance of a contract (b) where you are our customer yourself (for example as a sole trader); otherwise legitimate interests (f) in dealing with the people our customer names as its contacts |
| Keeping accounting and tax records | Legal obligation (c): Slovak accounting and VAT law (Act No. 431/2002 Coll. and Act No. 222/2004 Coll.) |
| Support: answering your requests and fixing problems | Legitimate interests (f): helping the people who use our service |
| Telling you about important changes to the service or these terms | Legal obligation (c) where the law requires the notice, otherwise legitimate interests (f) |
| Defending legal claims and answering authorities | Legal obligation (c), or legitimate interests (f) in establishing and defending legal claims |
| Marketing e-mail, if we ever send it | Only with your consent (a), which you can withdraw at any time |
Where we rely on legitimate interests, you can ask us how we balanced them against your rights, and you can object (see section 8).
We never sell personal data, and we don't use workspace content for advertising or to train AI models.
Features that process data automatically
- Link previews. When someone posts a link, our servers fetch the page, and the preview image, to show a preview. The linked site sees our server's address, not yours, and neither does the site that hosts the image. Profile pictures from other services reach you through our servers in the same way.
- Secret guard. Before a message is sent, it is checked on our servers for things that look like passwords or API keys, so the sender can be warned. The check only warns: it does not block, report or delete anything by itself. It has no legal or similarly significant effect on anyone. We don't make decisions based solely on automated processing within the meaning of Art. 22 GDPR.
- Connected calendars. If you connect a calendar, we read it with your own permission, show it only to you, and never post it into a channel unless an automation rule you wrote says so.
- Directory sync and provisioning. If an administrator connects Google Workspace or the organisation's identity provider (SCIM), profiles are updated from the organisation's directory, and people who are removed there are deactivated here.
4. Who we share it with
- Members and administrators of your workspace see what you post and your profile, as the workspace's settings allow. Administrators can manage accounts and see audit logs, the device list, and device-trust records.
- Service providers (subprocessors) who host the service, store files, carry traffic, send e-mail and deliver notifications, listed on our subprocessors page. Service e-mails are sent through Twilio Inc. (SendGrid). Providers may only use the data to provide their service to us.
- Push notification services. To show notifications on your devices, a short notification passes through your browser's push service or, for our mobile apps, through Expo, Google Firebase Cloud Messaging and Apple Push Notification service. It contains who sent the message, the channel name, the beginning of the message, and the identifiers and link needed to open the message; web notifications also carry a link to the sender's profile picture. Web notifications are encrypted end to end to your browser (RFC 8291), so the browser's push service cannot read them; mobile notifications are not encrypted in this way. Self-destructing messages, and messages in channels your organisation restricts to managed devices, never include text, and detected secrets are hidden.
- Google, Apple and your organisation's identity provider handle sign-in under their own terms when you choose to sign in with them.
- Our website's providers. Our status page runs on Cloudflare Workers, so Cloudflare sees the IP address of everyone who visits it. Apart from Cloudflare's short-lived request logs (see section 6), the status page stores nothing about its visitors.
- Authorities, only when the law requires it. Where the law allows, we tell the affected organisation first and challenge requests that are too broad.
- A buyer or successor, if our business is sold or merged. This policy continues to protect your data.
5. Where your data is stored
Tandly Cloud stores your data in the European Union: Germany, the Netherlands and Belgium, with netcup GmbH in Germany (our current production servers, which we are replacing), Google Cloud in the Netherlands and Belgium, and Cloudflare R2 for files, stored in Cloudflare's EU jurisdiction. While we move production from netcup to Google Cloud, both are in use.
Some providers are based in the United States: Cloudflare, whose network carries all traffic to the service and may handle it in the data centre nearest to you, including outside the EU; Twilio Inc. (SendGrid), which sends our e-mail; and the providers that deliver push notifications or handle sign-in. Where data leaves the EU/EEA, we rely on an adequacy decision (including the EU–US Data Privacy Framework for certified companies) or on the European Commission's Standard Contractual Clauses, with additional safeguards where needed. You can ask us for a copy of these safeguards.
6. How long we keep it
| Data | How long |
|---|---|
| Account and profile | While your account is active. When you delete your account, see below |
| Messages and files | Until they are deleted by you or an administrator, by a retention policy your organisation sets, or with the workspace. Messages you posted stay in the workspace after you delete your account, because they belong to the organisation's records. Whether they are kept is up to your organisation |
| Deleted messages and files | The text of a deleted message is removed at once. A marker without content (who posted it and when) stays so that threads keep making sense. A deleted file is removed from storage at once (if storage is briefly unreachable, we retry until it is gone). Files that were attached to a deleted message are removed 7 days later, unless another message, a draft or scheduled message, or a profile, emoji or workspace image still uses them, or your organisation has placed the workspace under a legal hold. Files of self-destructing messages are removed together with the message |
| Deleted workspaces | Kept for up to 30 days so they can be restored if deleted by mistake, then permanently erased. People who belonged to no other workspace have their accounts anonymised at the same time, as if they had deleted them |
| Sessions | Until you sign out or the session expires (at most 30 days); expired sessions are purged automatically |
| Push notification tokens | Until you sign out on that device, the session ends, or the push service reports the token as invalid |
| Sign-in fingerprints and the device list | Until you delete your account |
| Device-trust records | As long as the workspace exists, or until you delete your account |
| Connected apps | Until you or an administrator disconnects them; the stored keys are deleted at once, and we ask the provider to revoke them where it supports that |
| Calendar | Event start, end and title: until about an hour after the event starts. Reminder markers (an event identifier and time): 7 days. All stored calendar data is deleted when you disconnect the calendar or delete your account. Agenda and reminder messages stay in your conversation with Tandly Bot until you delete them |
| Out-of-office periods, stand-ins and handover notes | Until your account or the workspace is deleted |
| Invitations | As long as the workspace exists. Administrators can revoke a pending invitation at any time |
| Audit logs and support access logs | As long as the workspace exists, so administrators can review them |
| Record of accepting our terms | For a workspace: as long as the workspace exists. For a sign-up with e-mail and password: until you delete your account |
| Failed sign-in and rate-limit counters | At most one hour |
| Support correspondence and internal notes | As long as the customer relationship lasts, and up to 3 years afterwards to deal with follow-up questions and claims |
| Beta waiting list | Until you are invited and have created your account, or up to 12 months after our decision if you are not |
| Backups | Up to 14 days, after which they are deleted |
| Web server logs | Up to 14 days |
| Billing records | As long as tax and accounting law requires, usually up to 10 years |
When you delete your account
Your profile is anonymised straight away (shown as "Deleted user") and you can no longer sign in. We delete your sessions, devices (push notification registrations, sign-in fingerprints and the device list), two-factor data, connected apps (the keys are deleted and we ask the provider to revoke them), calendar data, drafts, scheduled messages, saved items, reminders, notifications, personal folders, out-of-office periods, custom profile fields and the record of your own sign-up to our terms, and your uploaded profile photo and other files you uploaded but never posted (such as attachments of unsent drafts), unless your organisation has placed them under a legal hold. Messages and files you posted stay in the workspace as part of the organisation's records, and so does the record of terms you accepted when you created a workspace. Audit log entries about your actions stay, with your name replaced, for as long as the workspace exists. Backups containing the old data are deleted within 14 days.
7. How we protect it
All traffic is encrypted with TLS. Session tokens are stored only as hashes, and files are served only after an access check, through links that expire after five minutes. Our staff work with workspaces through a dedicated console that requires a role and a written reason, both to change anything and to look at a workspace or a person's account; a reason for looking covers that staff member's views of that workspace or account for 30 minutes. Direct access to the database is limited to operating or restoring the service and handling incidents. Every change, and every time a staff member opens a workspace or a person's account, is shown to the workspace's administrators in their Support access log, as an action by "Tandly Support" with what was done and when (it does not name the individual staff member or show the reason; our own audit log records both). Staff cannot read message or file content through the console at all. Our DPA lists the measures in more detail. To report a security problem, write to [email protected].
8. Your rights
Under the GDPR you have the right to:
- access your data and get a copy of it;
- rectify inaccurate data. Most of your profile can be edited in the app; fields managed by your organisation's directory are changed there;
- erase your data. Delete your account in the app (on the web: workspace menu → Preferences → Account; in the mobile app: You → Delete my account) or ask us. Section 6 says what deletion removes and what stays;
- restrict or object to processing based on legitimate interests;
- data portability, a machine-readable copy of the data you gave us;
- withdraw consent at any time, where processing is based on consent;
- lodge a complaint with a supervisory authority, in particular in the EU country where you live or work. Our lead authority is Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic), Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk.
Write to [email protected]. We answer within one month (up to three months for complex requests, in which case we tell you why). We may ask you to confirm your identity. There is no self-service download of your personal data yet: when you ask for a copy, we send it as a machine-readable file (JSON) within that month.
For data we process for your organisation, the organisation decides, and we help it respond. Workspace administrators on plans that include data export can export the workspace themselves; on other plans, we export it for them on request.
9. Cookies and local storage
We use only what is strictly necessary for the service, so no consent banner is needed:
| Name | Purpose | Lifetime |
|---|---|---|
sc_session | Keeps you signed in (HttpOnly, Secure, SameSite=Lax) | Up to 30 days, or until you sign out |
sc_oauth (path /api/auth/google) | Protects the Google sign-in flow against forgery (HttpOnly, Secure, SameSite=Lax) | 10 minutes |
sc_saml (path /api/auth/saml) | Keeps track of a single sign-on in progress (HttpOnly, Secure, SameSite=None, because your identity provider sends you back to us from its own site) | 10 minutes |
| Browser local storage | Remembers interface choices on your device: theme and appearance, sidebar layout, the last workspace and channel you opened, your recent search queries and similar settings | Until you clear it |
Drafts are stored on our servers with your account, not in your browser.
The website uses no cookies. It keeps the currency you chose on the pricing page in your browser's local storage.
10. Changes
If we change this policy in a way that matters, we will tell workspace owners by e-mail or in the app at least 30 days before the change takes effect. If the change affects how we process data as a controller (see section 1), we also tell the people affected, in the app or by e-mail. Earlier versions are available on request.
11. Contact
UHRIK - IT & Event s. r. o., Bajzova 2417/13, 010 01 Žilina, Slovakia · [email protected]