Legal

Privacy Policy

Version 3.0 — pending legal review · Effective 19 July 2026

This Privacy Policy explains how personal data is collected, used, stored, and shared across the TACI Platform and the advisory engagements delivered under the TACI brand, in compliance with the EU General Data Protection Regulation (GDPR) and Finnish data protection law.

Data controllers and processors

Personal data across the TACI surface is handled by two distinct entities:

LEGAL REVIEW: confirm the controller split above matches the operational architecture Tarja and the DPO sign off on. Confirm Takko Technologies Oy Y-tunnus timing so the controller is a live entity at launch.

1. Personal Data We Collect

Account data: Full name, email address, job title, department, mobile number, organisation name, preferred language.

Usage data: Login timestamps, pages visited, actions performed, IP address, browser type.

Project data: Proposals, decisions, KPI entries, capital records, and governance documents created within the Platform.

Communications: Support requests, feedback, advisory-engagement correspondence, marketing-form messages, and emails.

2. Legal Basis for Processing

Contract performance (Art. 6(1)(b) GDPR): Processing your account data to provide the Platform service or fulfil an advisory engagement.

Legitimate interests (Art. 6(1)(f) GDPR): Security monitoring, fraud prevention, and service improvement.

Legal obligation (Art. 6(1)(c) GDPR): Compliance with Finnish tax, accounting, and bookkeeping law.

Consent (Art. 6(1)(a) GDPR): Marketing communications (where applicable). You may withdraw consent at any time.

3. How We Use Your Data

Personal data is used to: provide and maintain the Platform; authenticate accounts; deliver advisory engagements; send service notifications; respond to support requests; improve the service through aggregated analytics; comply with legal obligations.

Personal data is not sold to third parties. Automated decision-making that produces legal or similarly significant effects is not used.

4. Data Sharing

Personal data is shared only with: EU/EEA-resident infrastructure providers (cloud hosting on Railway EU West); email delivery services (SendGrid for transactional emails); analytics tools (aggregated, anonymised data only). All third-party processors are bound by Data Processing Agreements. Personal data is not transferred outside the EU/EEA without appropriate safeguards.LEGAL REVIEW: confirm the sub-processor list (Railway, SendGrid, Vercel, Anthropic API where used, Stripe when Stripe goes live) is complete and each has a signed DPA on file.

5. Data Retention

Account data is retained for the duration of the account plus 2 years after termination (for legal compliance). Project data is retained for the duration of the project plus 5 years (governance record requirements). Advisory-engagement records are retained per the engagement contract terms.

Audit-log retention: Platform audit events (governance actions, capital-ledger entries, membership changes, administrative actions) are retained for 12 months, partitioned monthly, with automatic enforcement of the retention window. Older partitions are dropped by scheduled maintenance.

You may request deletion of your personal data at any time, subject to legal retention obligations.

6. Your Rights (GDPR)

You have the right to: access your personal data; rectify inaccurate data; erase your data (“right to be forgotten”); restrict processing; data portability (receive your data in a machine-readable format); object to processing based on legitimate interests; lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi).

To exercise your rights, contact: privacy@taci.app. Requests are responded to within 30 days.

7. Security

Appropriate technical and organisational measures are in place including: bcrypt password hashing; session authentication via HTTP-only, secure, SameSite cookies with 480-minute expiry; CSRF token protection on all state-changing endpoints; HTTPS in transit; access controls and audit logging; regular security reviews. Optional two-factor authentication (TOTP) is available on all accounts.

8. Field-photo / consent handling

Where the Platform surfaces field-work photos (member-supplied images of activities, participants, or beneficiaries), EXIF and GPS metadata are stripped on upload, and consent for images depicting identifiable individuals is the responsibility of the uploading organisation. The Platform does not surface geolocation from photo metadata.LEGAL REVIEW: confirm the consent-capture UX matches what the Visuality workstream ships when it lands; update this paragraph to reference the live consent flow once available.

9. Cookies

We use cookies and similar technologies. See our Cookie Policy for details.

10. Changes

This policy may be updated. Material changes are communicated by email and require re-acceptance within the Platform.

11. Contact

Data Protection contact: privacy@taci.app. Postal address: Takko Advisory Oy, Helsinki, Finland, until Takko Technologies Oy has a registered address of its own.LEGAL REVIEW: confirm postal-address entity — Advisory receives Platform-side notices until Technologies has its own registration?

Terms of ServiceData Processing AgreementCookie Policy