Legal · Privacy Policy

Privacy Policy

What personal data we handle, why, where it goes, how long we keep it, and how you get it back or removed.

Last updated 24 July 2026 · Effective 24 July 2026

1. Scope, and the two roles we play

This policy explains how Turtle Techsai (Nehru Nagar East, Bhilai, CG, India) handles personal data in connection with the Turtle AI Coworker platform and the turtleaicoworker.com website.

The distinction that matters throughout:

  • We are a Data Fiduciary / Controller for the data of the people who sign up, log in, pay, and contact us — account holders, prospects and website visitors. This policy governs that data.
  • We are a Data Processor for the content a customer puts into their workspace — tables, documents, prompts, and anything an agent reads or writes. We process it on the customer’s instructions and for no independent purpose of our own. That relationship is governed by the Data Processing Addendum, not by this policy.

If you are an employee or contact of a company that uses Turtle AI Coworker and you want to know how your data is handled inside their workspace, ask that company. They decide, not us.

2. What we collect

2.1 Data you give us

CategoryExamplesWhy
AccountName, work email, password hash, organisation name, roleCreate and secure your account
Identity (SSO)Name, email, profile picture and directory identifier from Google or MicrosoftSign you in without a separate password
BillingBilling name, address, GSTIN, invoice historyCharge you and issue a tax invoice
SupportMessages you send us and their contentsAnswer you, and keep a record of the issue
Integration credentialsOAuth access and refresh tokens for services you connectLet your agents act on those services

We never see or store your full card number. Card details are collected and stored by our payment processor, Razorpay, which is PCI-DSS compliant. We receive only a payment reference, the last four digits, and the outcome.

2.2 Data we generate

CategoryExamplesWhy
UsageFeatures used, runs executed, tokens consumed, costs incurredBill accurately, enforce plan limits, improve the product
AuditRun records and tool calls with sanitised inputs and outputs, timestamps, actor, and config versionGive you an auditable record; investigate incidents
SecurityIP address, user agent, session records, login attemptsDetect abuse, enforce session limits, investigate compromise
DiagnosticsError reports and performance tracesFind and fix faults

2.3 Website

Our marketing website uses analytics cookies only after you consent. See the Cookie Policy. The application itself uses only strictly necessary cookies for authentication and session security.

2.4 What we do not collect

We do not buy personal data from brokers, we do not build advertising profiles, we do not sell personal data, and we do not use special-category or sensitive personal data for any purpose of our own.

3. Why we process it, and on what basis

PurposeDPDP Act 2023GDPR Article 6
Providing the Service you signed up forConsent / legitimate useContract
Billing, invoicing, tax recordsLegal obligationLegal obligation
Security, abuse prevention, auditLegitimate useLegitimate interests
Support and service communicationsConsent / legitimate useContract
Product analytics and improvementConsentConsent / legitimate interests
Marketing emailConsentConsent

You can withdraw consent at any time. Withdrawing consent for analytics or marketing does not affect your account. Withdrawing consent necessary to provide the Service means we can no longer provide it.

4. AI and your data

Your content is never used to train models. Not ours, not our providers’, not anyone’s. This is a contractual restriction on every model provider we engage, not a policy preference.

When an agent runs, the content it needs is sent to the model provider that agent is configured to use, for inference only, and the result is returned. Only providers you configure are engaged. If you supply your own provider API key, that request runs under your own agreement with that provider. The full detail is in the AI Addendum.

5. Who we share it with

We share personal data only with:

  • Subprocessors that help us run the Service — hosting, storage, email, payments, model inference, monitoring. Each is listed with its purpose and location at /legal/subprocessors, and each is bound by a written agreement with confidentiality and security obligations.
  • Services you connect. When you authorise an integration, data flows to that service at your instruction. That provider’s own privacy policy then applies.
  • Professional advisers — accountants and lawyers — under confidentiality.
  • Authorities, where we are legally compelled. We will notify you unless legally prohibited from doing so.
  • A successor, in a merger, acquisition or incorporation of the business, on notice to you and subject to this policy.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

6. Where your data is processed

The platform is hosted on Microsoft Azure, East US (Northern Virginia, United States). This means personal data is transferred outside India and, for European users, outside the EEA.

For transfers of EEA or UK personal data we rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where applicable, together with technical measures including encryption in transit and at rest. Under the DPDP Act, transfers are made to countries not restricted by the Central Government. Enterprise customers with specific residency requirements should contact us before onboarding — see the DPA.

7. How long we keep it

DataRetention
Account and profileFor the life of the account
Workspace content after account deletion30 days, then permanently deleted
Integration credentialsDeleted immediately on disconnection or account deletion
Audit and run recordsPer the retention period you configure, subject to any legal hold you apply
Invoices and tax records8 years, as required by Indian tax law
BackupsUp to 24 months, on a rolling cycle
Security logs12 months

Deletion from live systems happens within 30 days of your request. Backups are immutable and expire on their own cycle; data in a backup is not restored to live systems after a deletion request, and is overwritten when the backup expires.

8. How we protect it

  • TLS in transit; encryption at rest across all data stores.
  • Integration OAuth tokens and custom-tool credentials are additionally encrypted at the application layer and only ever returned masked.
  • Every record carries organisation and workspace scope; every query is filtered server-side through a central tenancy layer.
  • Two-factor authentication, short-lived access tokens with rotating refresh tokens, a hard cap on concurrent sessions, and role-based access control.
  • Audit records are sanitised before storage: passwords, tokens, API keys and card numbers are redacted.
  • Access to production is limited to personnel who need it.

No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and affected users as required by the DPDP Act, and affected customers within 72 hours of becoming aware, with what we know and what we are doing.

9. Your rights

Wherever you are, you may ask us to:

  • Access the personal data we hold about you, and get a copy.
  • Correct data that is inaccurate, incomplete or out of date.
  • Erase your data, subject to records we must keep by law.
  • Export your data in a portable format.
  • Withdraw consent at any time, without affecting past processing.
  • Nominate another person to exercise your rights in the event of death or incapacity, as provided under the DPDP Act.
  • Object to or restrict processing based on legitimate interests, and to lodge a complaint (GDPR).

Write to legal@turtleaicoworker.com. We respond within 30 days. We may ask you to verify your identity first — we are not going to hand your data to somebody who claims to be you.

If you are not satisfied, you may complain to the Data Protection Board of India, or, in the EEA or UK, to your local supervisory authority.

10. Marketing

We send service and transactional email — receipts, security alerts, approval requests, incident notices — as part of providing the Service; these are not marketing and cannot be switched off while your account is active. Marketing email is sent only with consent and has an unsubscribe link in every message.

11. Children

The Service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, write to legal@turtleaicoworker.com and we will delete it.

12. Data Protection Contact

Data Protection Contact
Turtle Techsai
Nehru Nagar East, Bhilai, CG, India
legal@turtleaicoworker.com · +91 78418 53298

13. Changes

We will update this policy as the Service changes. Material changes are notified by email or in-product at least 30 days before they take effect. The “last updated” date at the top of this page always reflects the current version.

Questions about this document? Write to legal@turtleaicoworker.com.