Skip to content

Platform Privacy Statement

Last updated: 2026-08-05

This statement covers personal data processed inside the Taiga platform. It is written for the administrators, security reviewers, and data protection officers who assess the platform for their organization. Personal data collected through our public website is covered separately in our website privacy policy.

Our role: processor, not controller

For personal data processed in the platform, the customer organization is the data controller and Taiga AI Oy is the processor. We process that data on the customer's documented instructions, under the data processing agreement annexed to the services agreement. That agreement is the binding instrument. This page describes what it means in practice; it does not replace or vary it.

Who we are

Taiga AI Oy Business ID: 3607851-2 Lapinlahdenkatu 16 00180 Helsinki, Finland Email: hello@tai.ga

What is processed

Personal data reaches the platform in three ways:

  • Account and identity data: the name, email address, and role of each person the customer gives an account to, plus the identifiers needed to authenticate them.
  • Customer content: whatever the customer puts into the platform. Specifications, uploaded reference documents, conversations with the platform's agents, backlog items, source code, and the artifacts a factory run produces. Any personal data inside that content is there because the customer put it there, and we process it only to deliver the service.
  • Operational records: audit entries, job and deployment history, and the technical logs needed to run and secure the service.

Identity and single sign-on

Amazon Cognito is the platform's identity provider. Where an organization federates its own Microsoft Entra ID directory, three claims pass through Taiga's federation broker on each sign-in:

  • Email address, used to identify the user and route the sign-in to the right organization.
  • Display name, used to show who did what in the platform's audit trail.
  • The OpenID Connect subject identifier issued by Entra, used as the stable key linking the directory account to the platform account.

These claims transit the broker application; they are not stored in Taiga's own Microsoft Entra tenant. The user record they create is stored in Amazon Cognito and in the platform database, both in AWS eu-central-1 (Frankfurt).

The broker requests three scopes: openid, email, and profile. It requests no directory permissions. Taiga cannot read your directory, enumerate your users, or see anyone who has not signed in.

Customer content

Uploaded documents are stored in Amazon S3 in eu-central-1 and indexed into a per-tenant Amazon Bedrock knowledge base so the platform's agents can retrieve them. Conversations, specifications, and backlog items are held in the platform database. Source code stays in the customer's own version control, reached through a GitHub App the customer installs and can revoke; the platform does not keep a copy of the repository.

We do not inspect customer content except as needed to deliver the service, to investigate a security incident, or where the customer instructs us to. Content is scoped to the tenant that owns it, and within a tenant to the team or project it was uploaded to.

Where data is processed

Customer data at rest is held in AWS eu-central-1 (Frankfurt). Model inference runs through Amazon Bedrock inside EU regions; for capacity and resilience it may run in more than one EU region, and nothing persists there. EU-only operation is enforced at the infrastructure boundary by AWS Control Tower guardrails that deny non-EU regions, not by policy alone.

Models and training

The platform uses Anthropic Claude models through Amazon Bedrock. Amazon Bedrock does not use prompts or outputs to train foundation models, and an organization-wide policy opts Taiga out of AWS AI services using its content. Customer data is not used to train models, ours or anyone else's.

Tenant isolation

Each customer organization is a separate tenant. Isolation is enforced at the database layer with PostgreSQL row-level security, deny by default, in addition to authorization checks in the API. Enforcing it at the data layer means an application-level mistake does not by itself expose another tenant's data.

Audit trail

The platform records who did what and when: the actions people take, the work the agents perform, and the deployments that result. That record exists so a customer can account for how its software was built, which is a core part of what the platform is for. It necessarily identifies the people who acted.

Retention and erasure

Customer data is retained for as long as the tenant exists, because the platform is a working system rather than an archive. Retention terms are set in the services agreement.

A tenant owner can instruct erasure of the tenant. A grace period of 30 days follows, during which the tenant stays fully usable and the instruction can be cancelled. Once it elapses, a worker purges tenant data across the database, S3, Amazon Cognito, and the Bedrock knowledge base, tombstones the tenant record, and issues a signed deletion certificate recording what was deleted.

Production data is erased immediately on purge. Residual encrypted backups age out within 35 days, which is the maximum point-in-time recovery window of the underlying database, so the commitment is one the infrastructure can actually keep. A legal hold blocks the entire pipeline.

Export and portability

A tenant owner can export the tenant's data as an archive, downloaded through a short-lived signed link. This is the mechanism behind a controller's portability obligations, and it does not depend on Taiga's assistance case by case.

Sub-processors

The platform relies on sub-processors, principally Amazon Web Services for infrastructure, storage, identity, and model inference. The current list is published on our sub-processors page. We inform customers of any intended addition or replacement before it takes effect, and a customer may object on reasonable grounds within the notice period its data processing agreement sets.

Subprocessors

Your right to audit us

A customer, or a representative it authorises, may audit our compliance with the data processing agreement, on the cadence and notice that agreement sets. Where an audit report or our system description answers the question, we offer that first, because it is usually faster for both sides.

Data subject rights

Because we act as processor here, requests from individuals go to the customer organization that controls the data, not to us. If you contact us directly about data held in a customer's tenant, we will refer you to that organization. We assist our customers in responding to such requests as set out in the data processing agreement, and the export and erasure tooling above exists so that assistance is a mechanism rather than a promise.

Personal data breaches

Where we become aware of a personal data breach affecting customer data, we notify the affected customer without undue delay, on the timetable the data processing agreement sets. The notification describes the nature of the breach, the categories and approximate numbers affected, the likely consequences, and the measures taken. The customer, as controller, decides on notification to the supervisory authority and to affected individuals.

Certification status

Taiga runs an information security management system built to ISO/IEC 27001:2022. Certification is in progress and SOC 2 is planned. We hold neither certificate today and will not imply otherwise. AWS, as our infrastructure sub-processor, holds ISO 27001, SOC 1, SOC 2, SOC 3, and C5 reports, available through AWS Artifact.

Changes

We update this statement as the platform changes. The date at the top shows when it last changed. Where a change affects the data processing agreement, it is handled under that agreement's own change process.

Contact

Questions about platform data handling go to hello@tai.ga

The full security posture lives in the Trust center