Privacy Policy
Taleshape Enterprise Software Support, Services & Website · Last Updated: September 2026
1. Introduction & Scope
Taleshape OÜ ("Taleshape", "we", "us", or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, process, and safeguard personal information in connection with our website, enterprise software support, and managed deployment services.
We comply with the European Union's General Data Protection Regulation (Regulation (EU) 2016/679 - "GDPR") and applicable global data protection laws.
Data Controller:
Taleshape OÜ
Sepapaja tn 6, 15551 Tallinn, Estonia
Commercial Registry Code: 16962132
Email: contact@taleshape.com
Security & Privacy Inquiries: security@taleshape.com
Crucial Distinction: Your Analytics Data Remains in Your Perimeter
Taleshape's primary commercial service is enterprise support for Shaper running inside customer-managed infrastructure (your private cloud VPC or on-premise servers).
We do not host, access, collect, or store your analytical data, dashboard contents, database credentials, or end-user records (including any Protected Health Information / PHI). All analytical query processing occurs entirely within your own security perimeter.
2. What Personal Data We Collect
As a B2B software and support provider, we collect limited personal data strictly necessary to maintain commercial relationships, deliver enterprise support, and ensure infrastructure security:
Business Contact & Account Information
- Full name, corporate email address, and job title
- Company name, corporate physical address, and telephone number
- Authorized technical and administrative contact records
Billing & Financial Information
- Corporate billing contact details and Value Added Tax (VAT) / Tax ID numbers
- Payment transaction history and invoices (processed via Stripe or Wise; we do not store raw credit card numbers)
Support & Operational Correspondence
- Email correspondence sent to our support and security mailboxes
- Git pull requests, issue tracker discussions, and feature request threads (via GitHub)
- Technical onboarding syncs and meeting notes (scheduled via Cal.com)
- Sanitized diagnostic logs or configuration files voluntarily submitted for troubleshooting
Technical & Website Log Data
- Standard web server access logs (IP address, timestamp, requested URL, user-agent string) retained temporarily for security auditing, DDoS prevention, and rate-limiting
3. Legal Basis for Processing Under GDPR
We process personal data under the following lawful bases set forth in Article 6 of the GDPR:
- Contract Performance (Art. 6(1)(b)): Processing necessary to fulfill our obligations under enterprise support contracts, execute order forms, and provide technical assistance.
- Legitimate Interests (Art. 6(1)(f)): Processing necessary for information security, fraud prevention, code supply chain integrity, and technical customer relationship management.
- Legal Obligations (Art. 6(1)(c)): Compliance with Estonian corporate accounting, tax filing, and statutory record-keeping requirements.
- Consent (Art. 6(1)(a)): Where you explicitly opt-in to optional communications such as our developer newsletter. You may withdraw consent at any time.
4. Third-Party Processors & Service Providers
We engage carefully selected third-party service providers ("sub-processors") to support our business operations. All processors are bound by compliant Data Processing Addendums (DPAs) incorporating standard contractual safeguards:
| Service Provider | Location | Purpose | Safeguard Mechanism |
|---|---|---|---|
| Proton AG (Proton Mail, Proton Pass) | Switzerland | Encrypted corporate email, calendar, credential vaulting | EU Adequacy Decision / Swiss FADP |
| GitHub, Inc. (Microsoft) | USA | Source code hosting, GitOps PR delivery, issue tracking | Standard Contractual Clauses (SCCs) |
| Stripe, Inc. & Wise Payments Ltd. | USA / UK | Payment processing, recurring billing, bank transfers | PCI-DSS Level 1 / SCCs |
| Xolo OÜ | Estonia (EU) | Corporate accounting, invoicing, and Estonian tax compliance | Direct EU GDPR compliance |
| Cal.com, Inc. | USA | Technical sync and onboarding call scheduling | Standard Contractual Clauses (SCCs) |
| Hetzner Online GmbH | Germany (EU) | Operational system hosting and monitoring infrastructure | Direct EU GDPR compliance |
| Cloudflare, Inc. | USA / Global | Website DNS routing, edge caching, DDoS protection | Standard Contractual Clauses (SCCs) |
Note: When collaborating via enterprise chat (Slack or Microsoft Teams), Taleshape joins customer-managed workspaces as guest collaborators. Communication remains within your tenant and is not processed by a Taleshape sub-processor.
5. Data Retention
We retain personal data strictly as long as necessary to fulfill the purposes for which it was collected:
- Active Customer Contacts: Retained for the duration of the commercial agreement and active support subscription.
- Accounting & Billing Records: Retained for seven (7) years following the transaction date to comply with statutory Estonian accounting and tax legislation.
- Support Threads & Tickets: Retained for up to twenty-four (24) months after case closure to preserve technical context for ongoing customer maintenance.
- Server Access Logs: Retained for up to ninety (90) days for security analysis, after which they are automatically rotated and deleted.
6. Technical & Organizational Security Measures
We implement rigorous technical and organizational measures (TOMs) pursuant to Article 32 of the GDPR:
- Zero-Access Encrypted Mail: Corporate communications are hosted on Proton Mail, providing end-to-end encryption.
- Zero-Knowledge Credential Vaulting: Proton Pass is enforced for all corporate accounts, requiring unique, high-entropy secrets.
- Full Disk Encryption: All laptops and developer devices have full-disk encryption (AES-256) enabled.
- Mandatory Multi-Factor Authentication: Enforced across all internal tools and infrastructure (FIDO2 / Hardware Security Keys or Authenticator apps).
- Clean-Room Support SOPs: Strict policies against retaining customer data or production logs on local developer storage.
7. Your Rights Under GDPR
Under Chapter III of the GDPR, data subjects located in the European Economic Area possess the following rights:
- Right of Access (Art. 15): Request confirmation and a copy of personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
- Right to Erasure (Art. 17): Request deletion of your personal data where retention is no longer justified by law.
- Right to Restriction of Processing (Art. 18): Request temporary restriction of processing in certain circumstances.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests.
- Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time where processing was based on consent.
To exercise any of these rights, contact our privacy team at contact@taleshape.com. We respond to verified requests within thirty (30) days.
You also have the right to lodge a complaint with a supervisory authority. In Estonia, our lead authority is:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon - AKI)
Tatari 39, 10134 Tallinn, Estonia · Website: www.aki.ee/en
8. Cookies and Tracking Technologies
Our public marketing website (taleshape.com) does not use non-essential tracking cookies, third-party analytics trackers, or targeted advertising beacons.
9. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect operational, legal, or regulatory modifications. We will post the revised policy on this page with an updated "Last Updated" date.
10. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our security practices, contact us at:
Taleshape OÜ
Sepapaja tn 6, 15551 Tallinn, Estonia
Email: contact@taleshape.com
Security Team: security@taleshape.com
