TurboDemand Privacy Policy
Status: Draft — for legal review; not legal advice
Version: 0.1
Released: 2026-09-17
Effective date: 2026-09-17
Owner: Pranab
Document key: privacy (see docs/specs/contracting-flow.md)
Execution: Published at /privacy; accepted by clickwrap together with the Terms of Service; referenced from client Microsite consent banners where the Client chooses to link it.
This policy explains how [MISSING: entity.legal_name] ("TurboDemand", "we") collects and uses personal data. It covers two audiences with different roles:
- Part A — Client users. People who use the TurboDemand dashboard at
app.turbodemand.comon behalf of a client business. For this data we are the controller. - Part B — Microsite visitors and leads. People who visit a Microsite we build and host for a client on the client's domain, or who submit a form there. For this data the client is the controller and we are their processor under the Data Processing Agreement. Part B is written to help clients meet their own transparency duties and to explain what we do as processor.
Contact for privacy matters: privacy@turbodemand.com, [MISSING: entity.registered_address]. Data Protection Officer or Grievance Officer (India DPDP): the Grievance Officer, privacy@turbodemand.com. EU representative (if required under GDPR Art. 27): not currently appointed; TurboDemand will appoint an EU Article 27 representative if and when its processing of EU personal data requires one. UK representative: not currently appointed; TurboDemand will appoint a UK GDPR Article 27 representative if and when required.
Part A — Client users (we are the controller)
A1. What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email, password (stored as a bcrypt or argon2id hash, never in clear), role, organisation, two-factor secret (encrypted), recovery codes (hashed) | You |
| Organisation data | Company name, website domain(s), industry, brand knowledge extracted from your websites and uploads, billing contact (name, email, legal name, address, tax id, PO number) | You; crawl of your websites |
| Billing data | Plan, billing interval, invoices, payment references; card details are handled by the payment gateway and never stored by us | You; payment gateway |
| Session and security data | Session identifier, IP address, user agent, login timestamps, failed-login and lockout events, two-factor events | Automatic |
| Activity logs | Actions taken in the dashboard with IP address, user agent, and before/after values for audited changes; impersonation sessions record both our staff member and your user | Automatic |
| Support and communications | Emails, in-app messages, support requests, notes from calls with your account manager | You; our staff |
| Integration credentials | OAuth tokens or API keys for services you connect (encrypted at rest, masked in the UI) | You |
| BYOK keys | LLM API keys you choose to provide (encrypted with AES-256-GCM, never returned after save, never logged) | You |
| Deployment credentials | SSH deploy keys or host details for your web host, or Cloudflare zone data where you delegate DNS to us (encrypted at rest; only the deploy worker decrypts) | You |
| LLM call logs | Prompts and model responses generated while producing your content, with token counts and cost. These can include brand knowledge and, where you paste it, personal data | Automatic |
| Dashboard analytics | Feature usage events tied to your user id | Automatic |
A2. Why we use it and the legal basis
| Purpose | Legal basis (GDPR) | India DPDP |
|---|---|---|
| Providing the Service, authenticating you, producing and publishing content | Contract (Art. 6(1)(b)) | Consent at signup; legitimate use for the service you requested |
| Billing, invoicing, tax records | Contract; legal obligation | Legitimate use; legal obligation |
| Security: rate limiting, lockout, audit logs, incident response | Legitimate interests (Art. 6(1)(f)) | Legitimate use |
| Transactional email (verification, reset, invoices, reports, lead alerts) | Contract | Legitimate use |
| Product notices and onboarding sequences | Legitimate interests; you can unsubscribe from non-essential email | Consent / legitimate use |
| Improving the Service using aggregated, de-identified usage data | Legitimate interests | Legitimate use |
| Compliance with law and enforcement of our terms | Legal obligation; legitimate interests | Legal obligation |
We do not sell personal data and we do not use client personal data to train foundation models. LLM providers we use are contractually restricted from training on our API traffic where the provider offers that term; see A4.
A3. Retention
| Data | Retention |
|---|---|
| Account and organisation data | For the life of the subscription plus 90 days after cancellation (notices at 60 and 80 days), then deleted unless you request retention or a legal hold applies |
| Brand knowledge, content, leads, analytics, feedback rules, LLM call logs | Same 90-day post-cancellation window |
| Static-export archives you request on cancellation | 90 days from generation, with reminders at 14 and 3 days before expiry |
| Invoices and tax records | 7 years as required by tax law |
| Sessions | 7 days sliding; revoked sessions removed |
| Security and activity logs | 12 months; deletion audit tombstones (hashed identifiers only) retained indefinitely |
| Backups | Daily encrypted backups retained on a 7 daily / 4 weekly / 3 monthly schedule; deleted data can persist in an encrypted backup for up to about 90 days after deletion under that rotation; backups are used only for disaster recovery and deletions are re-applied after any restore |
Account deletion: a client administrator can request deletion of the whole organisation from the dashboard. There is a 72-hour grace period during which the request can be cancelled; after that all organisation data is purged and encrypted secrets are crypto-shredded, except records we are legally required to keep: invoices and payment records (for the statutory period above), signed contracts and their audit trails (for the limitation period in [MISSING: entity.jurisdiction]), and acceptance records of these terms. Those records are moved to a restricted archive keyed by the invoice or contract number, with personal data reduced to what the legal obligation requires (the counterparty's legal name, the signatory's name, and the amounts), access limited to finance and legal, and deletion at the end of the retention period. Everything else leaves production immediately and backups within the rotation window; a non-identifying tombstone records that the deletion happened.
A4. Sub-processors and recipients
We use the following providers to run the Service. The same list is Annex 3 of the Data Processing Agreement and is the authoritative list; we will update it there and notify clients under DPA §9 before adding a sub-processor.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Hetzner Online GmbH | Application servers, PostgreSQL database, background workers | All platform data | Germany |
| Cloudflare, Inc. | DNS, CDN, reverse proxy and Workers for Microsites, R2 object storage for images and assets, Turnstile bot protection, TLS | Microsite traffic metadata, visitor IPs at the edge, stored assets; client DNS records where DNS is delegated to us | Global edge; storage the European Union |
| DreamHost, LLC | Static hosting origin for Microsites we host | Published pages and assets | United States |
| Backblaze, Inc. (B2) | Encrypted database backups and archives, export packages | Encrypted copies of platform data | the European Union |
| Anthropic, PBC | Large language model provider for content generation and analysis | Prompts containing brand knowledge and page content | United States |
| OpenAI, L.L.C. | Large language model provider | Same | United States |
| Google LLC (Gemini API) | Large language model provider | Same | United States |
| OpenRouter, Inc. | LLM routing to the above and other model providers | Same | United States |
| fal.ai (Features and Labels, Inc.) | Image generation (primary) | Image prompts derived from page content | United States |
| Replicate, Inc. | Image generation (fallback) | Same | United States |
| Resend, Inc. | Transactional email (default provider) | Recipient email, name, message content | United States |
| Mailgun Technologies, Inc. | Transactional email (alternative provider) | Same | United States / EU |
| Stripe, Inc. | Payment processing and subscription billing | Billing contact, payment method (held by Stripe), transaction data | United States / global |
| Razorpay Software Pvt. Ltd. | Payment processing (India) | Same | India |
| PayPal Holdings, Inc. | Payment processing | Same | United States / global |
| Telegram Messenger Inc. | Operational alerts to our on-call staff: organisation names and event types ("payment failed", "contract signed"), and, for new-lead alerts, the lead's name, email address, and company | Lead name, email, company; organisation names | Global (United Arab Emirates / EU operations) |
| Dropbox, Inc. (Dropbox Sign) | Sending and storing signed Order Forms (first provider; others may be added with 30 days' notice per DPA §9) | Signatory name, email, IP, signed document | United States |
Telegram lead alerts are an internal operations channel; they carry lead contact details so our staff can react quickly, and we are working to reduce them to a lead identifier only. Until then they are a transfer of Lead Data to Telegram under the safeguards in A5.
Client-directed recipients (not our sub-processors): when you connect an integration we send data where you direct: Slack (notifications), Zapier or a generic webhook (lead and content events), HubSpot or Salesforce (lead sync), WordPress or Shopify (content delivery), Google Search Console (performance data in), Google Business Profile or Trustpilot (review ratings in), Google Ads (lead import), and your own SMTP, Gmail, or Microsoft 365 mailbox for outreach email sent as you. These providers act under your instructions and their own terms.
Other recipients: professional advisers, auditors, and authorities where required by law; a successor in a merger or asset sale, on notice.
A5. International transfers
Our servers are in Germany. Several sub-processors are in the United States or operate globally. Where personal data of EU, EEA, UK, or Swiss residents is transferred outside those areas we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with the recipient, or on an adequacy decision or the EU-US Data Privacy Framework where the recipient is certified. For data originating in India we transfer only to countries not restricted by the Central Government under the DPDP Act. Copies of transfer safeguards are available on request.
A6. Your rights
Depending on your location you may have the right to access, correct, delete, or port your personal data, to restrict or object to processing, to withdraw consent, and to lodge a complaint with a supervisory authority (the Irish Data Protection Commission in the EU; the Data Protection Board of India under the DPDP Act). Client users can edit their profile and export or delete organisation data from the dashboard; for anything else email privacy@turbodemand.com. We respond within one month (GDPR) or the period the DPDP rules prescribe. If you are an Authorised User of a client, some requests may need to go through your organisation's administrator because they control the account.
A7. Cookies on the dashboard
The dashboard uses only strictly necessary cookies: a session cookie (httpOnly, Secure, SameSite=Strict, 7-day sliding expiry) and a CSRF token cookie. We do not run third-party advertising or tracking cookies on the dashboard. Dashboard analytics events are recorded server-side against your user id.
A8. Security
We use HTTPS everywhere, server-side sessions stored in PostgreSQL with immediate revocation, password hashing (bcrypt cost 12 or argon2id), optional TOTP two-factor authentication for all users (our internal policy requires it for staff), rate limiting and lockout on authentication endpoints, CSRF protection on all state-changing routes, a content security policy and standard security headers, AES-256-GCM encryption at rest for credentials and keys with the master key held outside the database, per-organisation tenant isolation enforced in every query, encrypted daily backups with quarterly restore tests, and audited administrative access. A fuller description is Annex 4 of the Data Processing Agreement. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you without undue delay and, where GDPR applies, the supervisory authority within 72 hours where required.
Part B — Microsite visitors and leads (the client is the controller)
This part describes what happens on a Microsite we build for a client. The Microsite is published on the client's domain (for example clientdomain.com/feeds/), a subdomain, or a host the client controls, and the client is the publisher and controller. The client's own privacy notice governs; this part tells you what our software does.
B1. What is collected on a Microsite
| Data | Details | Stored? |
|---|---|---|
| First-party page analytics | Page views, unique visitors, time on page, scroll depth, form impressions, form submissions, user agent, an anonymous session id kept in sessionStorage (gone when the tab closes). No third-party cookies. The visitor's IP address is hashed for rate limiting and is not stored on the event. |
Yes, in the client's organisation, 24 months rolling |
| Cookie-consent choice | Stored in the browser's localStorage under gf-cookie-consent when the client enables the consent banner |
Browser only |
| Optional Google Analytics 4 | Only if the client enables it, and only loaded after consent where the banner is enabled | By Google, under the client's GA account |
| A/B variant assignment | A gf_variant cookie or localStorage entry so a visitor sees a consistent page variant |
Browser only |
| Lead form submission | The fields on the form (typically name, email, phone, company, message), consent-checkbox status, source page, form variant, referrer, UTM parameters, the visitor's page-by-page journey on the Microsite before submitting, and a hashed IP address | Yes, as Lead Data in the client's organisation |
| Spam signals | Honeypot, timing, disposable-email checks, per-IP rate limiting, and optional Cloudflare Turnstile; a spam verdict is stored with the lead | Yes |
B2. Who receives it
Lead Data is delivered to the client's dashboard and, where the client has configured it, to the client's notification channels (email, Slack) and CRM or automation tools (HubSpot, Salesforce, Zapier, webhooks). It passes through the sub-processors in A4 that host our platform and send email. We do not use Lead Data for our own purposes and we do not share it between clients.
B3. Consent and regional settings
The client can enable a cookie-consent banner, a consent checkbox on forms with their own wording, links to their privacy, terms, and cookie policies, and regional toggles (for example GDPR or CCPA behaviour). Where the consent checkbox is enabled, a submission is refused unless it is ticked, and the consent status is stored with the lead.
B4. Retention and your rights
Lead Data is kept for as long as the client subscribes plus 90 days, unless the client deletes it sooner. To access, correct, or delete your data, contact the client whose website you used; their contact details are on the Microsite. If you contact us instead at privacy@turbodemand.com, we will forward your request to the client and assist them under the Data Processing Agreement. After a client cancels, forms on the Microsite stop accepting submissions.
B5. AI-generated content notice
Pages on a Microsite are generated with the help of AI models and reviewed under the client's editorial process. They are marketing content published by the client.
Changes to this policy
We will post updates here with a new version number and effective date and notify client administrators of material changes at least 30 days in advance. Prior versions are available on request.