1. Scope, and the two roles we play
This policy explains how Turtle Techsai (Nehru Nagar East, Bhilai, CG, India) handles personal data in connection with the Turtle AI Coworker platform and the turtleaicoworker.com website.
The distinction that matters throughout:
- We are a Data Fiduciary / Controller for the data of the people who sign up, log in, pay, and contact us — account holders, prospects and website visitors. This policy governs that data.
- We are a Data Processor for the content a customer puts into their workspace — tables, documents, prompts, and anything an agent reads or writes. We process it on the customer’s instructions and for no independent purpose of our own. That relationship is governed by the Data Processing Addendum, not by this policy.
If you are an employee or contact of a company that uses Turtle AI Coworker and you want to know how your data is handled inside their workspace, ask that company. They decide, not us.
2. What we collect
2.1 Data you give us
| Category | Examples | Why |
|---|---|---|
| Account | Name, work email, password hash, organisation name, role | Create and secure your account |
| Identity (SSO) | Name, email, profile picture and directory identifier from Google or Microsoft | Sign you in without a separate password |
| Billing | Billing name, address, GSTIN, invoice history | Charge you and issue a tax invoice |
| Support | Messages you send us and their contents | Answer you, and keep a record of the issue |
| Integration credentials | OAuth access and refresh tokens for services you connect | Let your agents act on those services |
We never see or store your full card number. Card details are collected and stored by our payment processor, Razorpay, which is PCI-DSS compliant. We receive only a payment reference, the last four digits, and the outcome.
2.2 Data we generate
| Category | Examples | Why |
|---|---|---|
| Usage | Features used, runs executed, tokens consumed, costs incurred | Bill accurately, enforce plan limits, improve the product |
| Audit | Run records and tool calls with sanitised inputs and outputs, timestamps, actor, and config version | Give you an auditable record; investigate incidents |
| Security | IP address, user agent, session records, login attempts | Detect abuse, enforce session limits, investigate compromise |
| Diagnostics | Error reports and performance traces | Find and fix faults |
2.3 Website
Our marketing website uses analytics cookies only after you consent. See the Cookie Policy. The application itself uses only strictly necessary cookies for authentication and session security.
2.4 What we do not collect
We do not buy personal data from brokers, we do not build advertising profiles, we do not sell personal data, and we do not use special-category or sensitive personal data for any purpose of our own.
3. Why we process it, and on what basis
| Purpose | DPDP Act 2023 | GDPR Article 6 |
|---|---|---|
| Providing the Service you signed up for | Consent / legitimate use | Contract |
| Billing, invoicing, tax records | Legal obligation | Legal obligation |
| Security, abuse prevention, audit | Legitimate use | Legitimate interests |
| Support and service communications | Consent / legitimate use | Contract |
| Product analytics and improvement | Consent | Consent / legitimate interests |
| Marketing email | Consent | Consent |
You can withdraw consent at any time. Withdrawing consent for analytics or marketing does not affect your account. Withdrawing consent necessary to provide the Service means we can no longer provide it.
4. AI and your data
Your content is never used to train models. Not ours, not our providers’, not anyone’s. This is a contractual restriction on every model provider we engage, not a policy preference.
When an agent runs, the content it needs is sent to the model provider that agent is configured to use, for inference only, and the result is returned. Only providers you configure are engaged. If you supply your own provider API key, that request runs under your own agreement with that provider. The full detail is in the AI Addendum.
5. Who we share it with
We share personal data only with:
- Subprocessors that help us run the Service — hosting, storage, email, payments, model inference, monitoring. Each is listed with its purpose and location at /legal/subprocessors, and each is bound by a written agreement with confidentiality and security obligations.
- Services you connect. When you authorise an integration, data flows to that service at your instruction. That provider’s own privacy policy then applies.
- Professional advisers — accountants and lawyers — under confidentiality.
- Authorities, where we are legally compelled. We will notify you unless legally prohibited from doing so.
- A successor, in a merger, acquisition or incorporation of the business, on notice to you and subject to this policy.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
6. Where your data is processed
The platform is hosted on Microsoft Azure, East US (Northern Virginia, United States). This means personal data is transferred outside India and, for European users, outside the EEA.
For transfers of EEA or UK personal data we rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where applicable, together with technical measures including encryption in transit and at rest. Under the DPDP Act, transfers are made to countries not restricted by the Central Government. Enterprise customers with specific residency requirements should contact us before onboarding — see the DPA.
7. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | For the life of the account |
| Workspace content after account deletion | 30 days, then permanently deleted |
| Integration credentials | Deleted immediately on disconnection or account deletion |
| Audit and run records | Per the retention period you configure, subject to any legal hold you apply |
| Invoices and tax records | 8 years, as required by Indian tax law |
| Backups | Up to 24 months, on a rolling cycle |
| Security logs | 12 months |
Deletion from live systems happens within 30 days of your request. Backups are immutable and expire on their own cycle; data in a backup is not restored to live systems after a deletion request, and is overwritten when the backup expires.
8. How we protect it
- TLS in transit; encryption at rest across all data stores.
- Integration OAuth tokens and custom-tool credentials are additionally encrypted at the application layer and only ever returned masked.
- Every record carries organisation and workspace scope; every query is filtered server-side through a central tenancy layer.
- Two-factor authentication, short-lived access tokens with rotating refresh tokens, a hard cap on concurrent sessions, and role-based access control.
- Audit records are sanitised before storage: passwords, tokens, API keys and card numbers are redacted.
- Access to production is limited to personnel who need it.
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and affected users as required by the DPDP Act, and affected customers within 72 hours of becoming aware, with what we know and what we are doing.
9. Your rights
Wherever you are, you may ask us to:
- Access the personal data we hold about you, and get a copy.
- Correct data that is inaccurate, incomplete or out of date.
- Erase your data, subject to records we must keep by law.
- Export your data in a portable format.
- Withdraw consent at any time, without affecting past processing.
- Nominate another person to exercise your rights in the event of death or incapacity, as provided under the DPDP Act.
- Object to or restrict processing based on legitimate interests, and to lodge a complaint (GDPR).
Write to legal@turtleaicoworker.com. We respond within 30 days. We may ask you to verify your identity first — we are not going to hand your data to somebody who claims to be you.
If you are not satisfied, you may complain to the Data Protection Board of India, or, in the EEA or UK, to your local supervisory authority.
10. Marketing
We send service and transactional email — receipts, security alerts, approval requests, incident notices — as part of providing the Service; these are not marketing and cannot be switched off while your account is active. Marketing email is sent only with consent and has an unsubscribe link in every message.
11. Children
The Service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, write to legal@turtleaicoworker.com and we will delete it.
12. Data Protection Contact
Data Protection Contact
Turtle Techsai
Nehru Nagar East, Bhilai, CG, India
legal@turtleaicoworker.com · +91 78418 53298
13. Changes
We will update this policy as the Service changes. Material changes are notified by email or in-product at least 30 days before they take effect. The “last updated” date at the top of this page always reflects the current version.
Questions about this document? Write to legal@turtleaicoworker.com.