1. Controller / processor
TD Intelligence acts as data controller for partner account data (the names, emails, roles, and sign-in metadata of your hub users) and as data processor for the device telemetry, validation content, design files, webhook captures, and other content that your organization puts into the Service. Cloudflare is our infrastructure sub-processor; Resend is our transactional email sub-processor; Vercel is our serverless relay sub-processor (used for SMTP delivery and certain backend integrations that require non-edge networking).
Where you choose to upload content related to your end customers, your organization is the data controller for that content; we process it on your instructions and under the security commitments set out in the Privacy Policy §4.
2. Lawful basis
- Contract— providing the Service to your organization.
- Legitimate interests— security, abuse prevention, quality of service, audit logging.
- Consent— your acceptance of these terms is recorded with version + timestamp on your user record. Consent can be withdrawn at any time by contacting the DPO; doing so will end your access to the Service.
3. Your rights
- Access— request a copy of the personal data we hold about you, including the audit-log entries attributable to your account.
- Rectification— correct inaccurate data.
- Erasure— “right to be forgotten” for personal data not required for an active contractual obligation.
- Portability— receive your data in a structured, machine-readable format.
- Restriction & objection— limit how we process your data.
- Withdraw consent— where processing is based on consent (including these terms).
4. How to make a request
Email dpo@tdintelligence.wiki from the email address registered on TDI Hub. Include:
- The right you wish to exercise.
- Your organization name (so we can locate the records).
- Any specific data sets you want included or excluded.
5. Response time
We will acknowledge within 5 business days and respond fully within 30 days. Complex requests may take up to 60 days; we will keep you informed.
6. Identity verification
For erasure or export requests we may ask you to confirm via the registered email or via your organization admin to prevent unauthorized data leakage.
7. Right to complain
If you are unsatisfied with our response, you may lodge a complaint with your national data protection authority (e.g. the UK ICO, Ireland DPC, France CNIL, Germany BfDI).
8. International transfers
Some processing happens in Cloudflare regions outside your home country. These transfers are covered by EU Standard Contractual Clauses with our processor. Application-layer encryption (AES-GCM) is applied to high-sensitivity credentials before they leave the Worker boundary.
9. Sub-processors
- Cloudflare, Inc.— hosting (Workers, R2, D1, Workers AI for the in-product knowledge-base assistant), DNS, edge security, TLS termination.
- Resend— transactional email delivery (sign-in magic links, OTA notifications, invitations).
- Vercel, Inc.— serverless relay used for SMTP email delivery (when the SMTP transport is selected) and for backend integrations that require non-edge networking (e.g. self-hosted RCS endpoints not reachable from Cloudflare’s edge fetch).
10. Audit transparency
On request, we will provide your organization administrator with an export of the audit-log entries scoped to your organization, including who accepted these terms and when, who changed memberships or roles, and who triggered admin-only actions. Audit-log entries are retained for two (2) years; older entries are automatically purged.
11. Security incident notification
In the event we discover a personal-data breach affecting your organization, we will notify your designated organization administrator without undue delay and, where feasible, within 72 hours of confirming the incident. The notification will describe the nature of the breach, the categories and approximate volume of data affected, the likely consequences, and the remedial steps already taken or planned. Where required by GDPR Article 33, we will also assist you with regulator notifications.
12. Contact
Data protection queries: dpo@tdintelligence.wiki.