Version 0.1Effective September 17, 2026

TurboDemand Privacy Policy

Status: Draft — for legal review; not legal advice Version: 0.1 Released: 2026-09-17 Effective date: 2026-09-17 Owner: Pranab Document key: privacy (see docs/specs/contracting-flow.md) Execution: Published at /privacy; accepted by clickwrap together with the Terms of Service; referenced from client Microsite consent banners where the Client chooses to link it.


This policy explains how [MISSING: entity.legal_name] ("TurboDemand", "we") collects and uses personal data. It covers two audiences with different roles:

  • Part A — Client users. People who use the TurboDemand dashboard at app.turbodemand.com on behalf of a client business. For this data we are the controller.
  • Part B — Microsite visitors and leads. People who visit a Microsite we build and host for a client on the client's domain, or who submit a form there. For this data the client is the controller and we are their processor under the Data Processing Agreement. Part B is written to help clients meet their own transparency duties and to explain what we do as processor.

Contact for privacy matters: privacy@turbodemand.com, [MISSING: entity.registered_address]. Data Protection Officer or Grievance Officer (India DPDP): the Grievance Officer, privacy@turbodemand.com. EU representative (if required under GDPR Art. 27): not currently appointed; TurboDemand will appoint an EU Article 27 representative if and when its processing of EU personal data requires one. UK representative: not currently appointed; TurboDemand will appoint a UK GDPR Article 27 representative if and when required.

Part A — Client users (we are the controller)

A1. What we collect

Category Examples Source
Account data Name, work email, password (stored as a bcrypt or argon2id hash, never in clear), role, organisation, two-factor secret (encrypted), recovery codes (hashed) You
Organisation data Company name, website domain(s), industry, brand knowledge extracted from your websites and uploads, billing contact (name, email, legal name, address, tax id, PO number) You; crawl of your websites
Billing data Plan, billing interval, invoices, payment references; card details are handled by the payment gateway and never stored by us You; payment gateway
Session and security data Session identifier, IP address, user agent, login timestamps, failed-login and lockout events, two-factor events Automatic
Activity logs Actions taken in the dashboard with IP address, user agent, and before/after values for audited changes; impersonation sessions record both our staff member and your user Automatic
Support and communications Emails, in-app messages, support requests, notes from calls with your account manager You; our staff
Integration credentials OAuth tokens or API keys for services you connect (encrypted at rest, masked in the UI) You
BYOK keys LLM API keys you choose to provide (encrypted with AES-256-GCM, never returned after save, never logged) You
Deployment credentials SSH deploy keys or host details for your web host, or Cloudflare zone data where you delegate DNS to us (encrypted at rest; only the deploy worker decrypts) You
LLM call logs Prompts and model responses generated while producing your content, with token counts and cost. These can include brand knowledge and, where you paste it, personal data Automatic
Dashboard analytics Feature usage events tied to your user id Automatic
Purpose Legal basis (GDPR) India DPDP
Providing the Service, authenticating you, producing and publishing content Contract (Art. 6(1)(b)) Consent at signup; legitimate use for the service you requested
Billing, invoicing, tax records Contract; legal obligation Legitimate use; legal obligation
Security: rate limiting, lockout, audit logs, incident response Legitimate interests (Art. 6(1)(f)) Legitimate use
Transactional email (verification, reset, invoices, reports, lead alerts) Contract Legitimate use
Product notices and onboarding sequences Legitimate interests; you can unsubscribe from non-essential email Consent / legitimate use
Improving the Service using aggregated, de-identified usage data Legitimate interests Legitimate use
Compliance with law and enforcement of our terms Legal obligation; legitimate interests Legal obligation

We do not sell personal data and we do not use client personal data to train foundation models. LLM providers we use are contractually restricted from training on our API traffic where the provider offers that term; see A4.

A3. Retention

Data Retention
Account and organisation data For the life of the subscription plus 90 days after cancellation (notices at 60 and 80 days), then deleted unless you request retention or a legal hold applies
Brand knowledge, content, leads, analytics, feedback rules, LLM call logs Same 90-day post-cancellation window
Static-export archives you request on cancellation 90 days from generation, with reminders at 14 and 3 days before expiry
Invoices and tax records 7 years as required by tax law
Sessions 7 days sliding; revoked sessions removed
Security and activity logs 12 months; deletion audit tombstones (hashed identifiers only) retained indefinitely
Backups Daily encrypted backups retained on a 7 daily / 4 weekly / 3 monthly schedule; deleted data can persist in an encrypted backup for up to about 90 days after deletion under that rotation; backups are used only for disaster recovery and deletions are re-applied after any restore

Account deletion: a client administrator can request deletion of the whole organisation from the dashboard. There is a 72-hour grace period during which the request can be cancelled; after that all organisation data is purged and encrypted secrets are crypto-shredded, except records we are legally required to keep: invoices and payment records (for the statutory period above), signed contracts and their audit trails (for the limitation period in [MISSING: entity.jurisdiction]), and acceptance records of these terms. Those records are moved to a restricted archive keyed by the invoice or contract number, with personal data reduced to what the legal obligation requires (the counterparty's legal name, the signatory's name, and the amounts), access limited to finance and legal, and deletion at the end of the retention period. Everything else leaves production immediately and backups within the rotation window; a non-identifying tombstone records that the deletion happened.

A4. Sub-processors and recipients

We use the following providers to run the Service. The same list is Annex 3 of the Data Processing Agreement and is the authoritative list; we will update it there and notify clients under DPA §9 before adding a sub-processor.

Provider Purpose Data involved Location
Hetzner Online GmbH Application servers, PostgreSQL database, background workers All platform data Germany
Cloudflare, Inc. DNS, CDN, reverse proxy and Workers for Microsites, R2 object storage for images and assets, Turnstile bot protection, TLS Microsite traffic metadata, visitor IPs at the edge, stored assets; client DNS records where DNS is delegated to us Global edge; storage the European Union
DreamHost, LLC Static hosting origin for Microsites we host Published pages and assets United States
Backblaze, Inc. (B2) Encrypted database backups and archives, export packages Encrypted copies of platform data the European Union
Anthropic, PBC Large language model provider for content generation and analysis Prompts containing brand knowledge and page content United States
OpenAI, L.L.C. Large language model provider Same United States
Google LLC (Gemini API) Large language model provider Same United States
OpenRouter, Inc. LLM routing to the above and other model providers Same United States
fal.ai (Features and Labels, Inc.) Image generation (primary) Image prompts derived from page content United States
Replicate, Inc. Image generation (fallback) Same United States
Resend, Inc. Transactional email (default provider) Recipient email, name, message content United States
Mailgun Technologies, Inc. Transactional email (alternative provider) Same United States / EU
Stripe, Inc. Payment processing and subscription billing Billing contact, payment method (held by Stripe), transaction data United States / global
Razorpay Software Pvt. Ltd. Payment processing (India) Same India
PayPal Holdings, Inc. Payment processing Same United States / global
Telegram Messenger Inc. Operational alerts to our on-call staff: organisation names and event types ("payment failed", "contract signed"), and, for new-lead alerts, the lead's name, email address, and company Lead name, email, company; organisation names Global (United Arab Emirates / EU operations)
Dropbox, Inc. (Dropbox Sign) Sending and storing signed Order Forms (first provider; others may be added with 30 days' notice per DPA §9) Signatory name, email, IP, signed document United States

Telegram lead alerts are an internal operations channel; they carry lead contact details so our staff can react quickly, and we are working to reduce them to a lead identifier only. Until then they are a transfer of Lead Data to Telegram under the safeguards in A5.

Client-directed recipients (not our sub-processors): when you connect an integration we send data where you direct: Slack (notifications), Zapier or a generic webhook (lead and content events), HubSpot or Salesforce (lead sync), WordPress or Shopify (content delivery), Google Search Console (performance data in), Google Business Profile or Trustpilot (review ratings in), Google Ads (lead import), and your own SMTP, Gmail, or Microsoft 365 mailbox for outreach email sent as you. These providers act under your instructions and their own terms.

Other recipients: professional advisers, auditors, and authorities where required by law; a successor in a merger or asset sale, on notice.

A5. International transfers

Our servers are in Germany. Several sub-processors are in the United States or operate globally. Where personal data of EU, EEA, UK, or Swiss residents is transferred outside those areas we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with the recipient, or on an adequacy decision or the EU-US Data Privacy Framework where the recipient is certified. For data originating in India we transfer only to countries not restricted by the Central Government under the DPDP Act. Copies of transfer safeguards are available on request.

A6. Your rights

Depending on your location you may have the right to access, correct, delete, or port your personal data, to restrict or object to processing, to withdraw consent, and to lodge a complaint with a supervisory authority (the Irish Data Protection Commission in the EU; the Data Protection Board of India under the DPDP Act). Client users can edit their profile and export or delete organisation data from the dashboard; for anything else email privacy@turbodemand.com. We respond within one month (GDPR) or the period the DPDP rules prescribe. If you are an Authorised User of a client, some requests may need to go through your organisation's administrator because they control the account.

A7. Cookies on the dashboard

The dashboard uses only strictly necessary cookies: a session cookie (httpOnly, Secure, SameSite=Strict, 7-day sliding expiry) and a CSRF token cookie. We do not run third-party advertising or tracking cookies on the dashboard. Dashboard analytics events are recorded server-side against your user id.

A8. Security

We use HTTPS everywhere, server-side sessions stored in PostgreSQL with immediate revocation, password hashing (bcrypt cost 12 or argon2id), optional TOTP two-factor authentication for all users (our internal policy requires it for staff), rate limiting and lockout on authentication endpoints, CSRF protection on all state-changing routes, a content security policy and standard security headers, AES-256-GCM encryption at rest for credentials and keys with the master key held outside the database, per-organisation tenant isolation enforced in every query, encrypted daily backups with quarterly restore tests, and audited administrative access. A fuller description is Annex 4 of the Data Processing Agreement. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you without undue delay and, where GDPR applies, the supervisory authority within 72 hours where required.

Part B — Microsite visitors and leads (the client is the controller)

This part describes what happens on a Microsite we build for a client. The Microsite is published on the client's domain (for example clientdomain.com/feeds/), a subdomain, or a host the client controls, and the client is the publisher and controller. The client's own privacy notice governs; this part tells you what our software does.

B1. What is collected on a Microsite

Data Details Stored?
First-party page analytics Page views, unique visitors, time on page, scroll depth, form impressions, form submissions, user agent, an anonymous session id kept in sessionStorage (gone when the tab closes). No third-party cookies. The visitor's IP address is hashed for rate limiting and is not stored on the event. Yes, in the client's organisation, 24 months rolling
Cookie-consent choice Stored in the browser's localStorage under gf-cookie-consent when the client enables the consent banner Browser only
Optional Google Analytics 4 Only if the client enables it, and only loaded after consent where the banner is enabled By Google, under the client's GA account
A/B variant assignment A gf_variant cookie or localStorage entry so a visitor sees a consistent page variant Browser only
Lead form submission The fields on the form (typically name, email, phone, company, message), consent-checkbox status, source page, form variant, referrer, UTM parameters, the visitor's page-by-page journey on the Microsite before submitting, and a hashed IP address Yes, as Lead Data in the client's organisation
Spam signals Honeypot, timing, disposable-email checks, per-IP rate limiting, and optional Cloudflare Turnstile; a spam verdict is stored with the lead Yes

B2. Who receives it

Lead Data is delivered to the client's dashboard and, where the client has configured it, to the client's notification channels (email, Slack) and CRM or automation tools (HubSpot, Salesforce, Zapier, webhooks). It passes through the sub-processors in A4 that host our platform and send email. We do not use Lead Data for our own purposes and we do not share it between clients.

The client can enable a cookie-consent banner, a consent checkbox on forms with their own wording, links to their privacy, terms, and cookie policies, and regional toggles (for example GDPR or CCPA behaviour). Where the consent checkbox is enabled, a submission is refused unless it is ticked, and the consent status is stored with the lead.

B4. Retention and your rights

Lead Data is kept for as long as the client subscribes plus 90 days, unless the client deletes it sooner. To access, correct, or delete your data, contact the client whose website you used; their contact details are on the Microsite. If you contact us instead at privacy@turbodemand.com, we will forward your request to the client and assist them under the Data Processing Agreement. After a client cancels, forms on the Microsite stop accepting submissions.

B5. AI-generated content notice

Pages on a Microsite are generated with the help of AI models and reviewed under the client's editorial process. They are marketing content published by the client.

Changes to this policy

We will post updates here with a new version number and effective date and notify client administrators of material changes at least 30 days in advance. Prior versions are available on request.