Privacy Policy
Last updated: 2026-09-10
Taiga AI Oy (“Taiga”, “we”, “us”) is the data controller for personal data processed through tai.ga. This policy explains what data we collect, why, how we use it, and your rights under the EU General Data Protection Regulation (GDPR).
Data controller
Taiga AI Oy Business ID: 3607851-2 Lapinlahdenkatu 16 00180 Helsinki, Finland Email: hello@tai.ga
What we collect
The information we process depends on how you use the site:
- Analytics, with your consent: page paths, selected interaction types, device and browser information, performance measurements and technical error diagnostics. PostHog's automatic click capture and session recording are disabled, and captured URLs exclude query strings and fragments. Analytics events exclude assessment answers, scores, and inquiry names, email addresses, organizations and messages. Inquiry events include the selected conversation type and whether submission succeeded or failed. PostHog uses a pseudonymous browser identifier. With the same consent, selected calls to action, self-assessment actions and form submission attempts generate internal notifications. These contain only an action type, fixed page category, position on the page, random request reference and timestamp. They exclude browser identifiers, URLs, assessment answers, scores and form contents. Network services receive connection information needed to handle requests.
- Product updates: your email address, the signup surface and any optional company, role, industry or contact-frequency information you submit. This subscription is separate from an inquiry.
- Job applications: If you write to us about working at Taiga, we process what you choose to send — your name, contact details, any links or materials you include, and what you tell us about your work. Applications arrive by email at hello@tai.ga and are read by Taiga’s founders. We only process what is relevant to assessing your suitability for the work. Please do not send health information; we will not ask for it, and if an application contains special categories of data (health, religion, political opinions, trade union membership) we remove it rather than keep it on file.
Website inquiries and bookings
The inquiry form collects your name, email address, optional organization, selected conversation type and message, plus the product count, plan and Scale units if you attach a pricing configuration. The stored record also includes the resulting estimate and rate-card version. We add a request reference and timestamps to acknowledge receipt and handle retries. We use these details to answer you; sending an inquiry does not subscribe you to product updates. Please do not include credentials, confidential code or personal customer data. If you email us, we receive the details you include in that email. If you use the Google Calendar scheduler, Google processes the booking details you enter there; clicking the link alone does not book a meeting.
Legal basis for processing
Under GDPR Article 6, we process data on the following bases:
- Consent (Article 6(1)(a)). Analytics data is only collected after you actively accept cookies via the consent banner. You can withdraw consent at any time using the “Cookie Settings” link in the footer.
- Steps before a contract (Article 6(1)(b)), where you ask us to take those steps for a contract with you personally. Business inquiries made on behalf of an organization are handled under our legitimate interest in answering that organization's request.
- Legitimate interest (Article 6(1)(f)): responding to business inquiries and protecting the website from abuse. We consider your rights when doing so. This basis does not authorize analytics without consent or subscribe an inquirer to marketing.
- Consent (Article 6(1)(a)): product updates you choose to subscribe to. You can withdraw by emailing hello@tai.ga. Withdrawing does not affect the processing that occurred before withdrawal.
- Steps prior to a contract (Article 6(1)(b)) and legitimate interest (Article 6(1)(f)). We read and assess an application you send us in order to decide whether to talk to you about working here.
- Legitimate interest (Article 6(1)(f)). We keep an application on file so we can return to it when a role opens. You can object to this at any time under Article 21, and we will delete it.
Purpose of processing
We process personal data for these specific purposes:
- Site improvement: understanding which pages visitors use, where they come from, and how the site performs technically.
- Early-access communication: sending you updates about Taiga at the frequency you chose.
- Inquiries and bookings: responding to the conversation you choose, arranging a meeting if requested, and preventing duplicate inquiry records after a network retry.
- Recruitment: assessing whether to talk to you about working at Taiga, and returning to your application when a role opens.
We do not build individual profiles, serve targeted advertising, or sell data to third parties.
Third-party recipients
The following services are involved in website processing:
- PostHog (analytics processor): EU instance hosted in Frankfurt, Germany. PostHog processes pseudonymized usage data on our behalf. PostHog’s DPA and sub-processors: posthog.com/dpa.
- Amazon Web Services: the website infrastructure and signup, inquiry and action-notification records use AWS. These databases are in eu-central-1 (Frankfurt). Notifications use AWS SNS and Amazon Q Developer in chat applications.
- Slack: accepted inquiry, signup and subscription-preference requests generate notifications in an internal team channel so the team can reply; these do not require analytics consent. An inquiry notification contains your name, email address, organization, the conversation type, the first 300 characters of your message and a request reference. A signup notification contains your email address, any company, role, industry or frequency you gave, the page and a request reference. With analytics consent, selected website actions are also recorded for 30 days; those records do not generate notifications and contain no contact details.
- Google Calendar: the optional scheduler opens on Google's site and processes the booking information you choose to enter. Google's privacy notice explains its processing. Your email provider also processes messages you send us.
We do not sell website data to advertisers or data brokers.
International data transfers
The website's AWS databases and PostHog EU service are hosted in Frankfurt. This is not a claim that every website-related service processes data only in the EEA: Slack and Google describe international processing in their privacy notices. Their applicable terms describe transfer safeguards. Contact hello@tai.ga for the processor and transfer information relevant to your interaction.
Cookies and local storage
Your consent choice is stored in local storage. With analytics consent, PostHog also stores a pseudonymous browser identifier. Cookie Settings resets that consent and removes the PostHog identifier; it does not erase data already received by a service. The self-assessment stores its answers locally when that feature is used and provides its own reset control. Inquiry text stays in the form until submission and is not saved to browser storage by the website.
Data retention
We retain personal data only as long as necessary for its purpose:
- PostHog analytics data: retained for 12 months, then automatically deleted. AWS records for website action and signup notifications expire after 30 days; deletion can take a few additional days, and recovery backups can retain deleted records for up to 35 days. Copies in Slack follow the workspace's retention settings.
- Signup email addresses: retained for 24 months from the date of signup. After this period, we delete your email unless you have become an active customer or explicitly asked us to keep it.
- Inquiry form records expire after 730 days; DynamoDB deletion can take a few additional days. Recovery backups can retain a deleted record for up to 35 days. Technical notification-failure records contain request references and expire after 30 days. Ask hello@tai.ga to delete an inquiry sooner. A subsequent customer relationship has separate recordkeeping requirements.
- Job applications: retained for 12 months from the date we receive them, then deleted. Ask us to delete yours sooner and we will. If we hire you, your application becomes part of your employment records, which are kept under separate retention rules.
- Consent records: stored locally in your browser. Cleared when you reset consent or clear browser data.
Data security
The website uses encrypted connections and encrypted AWS storage. Inquiry records are accessible to authorized roles; there is no public inquiry lookup endpoint. Public form requests go through server-side validation and API Gateway throttling. Technical logs omit inquiry payloads, and team notifications use references rather than inquiry text. CloudFront applies HSTS, Content Security Policy, X-Frame-Options, X-Content-Type-Options and Referrer-Policy headers.
Your rights under GDPR
You have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: ask us to correct inaccurate data.
- Right to erasure: ask us to delete your personal data.
- Right to restriction: ask us to limit how we process your data.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interest.
- Right to withdraw consent: withdraw analytics consent at any time via the “Cookie Settings” link. This does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, email us at hello@tai.ga. We will respond within 30 days.
Right to lodge a complaint
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Finnish Data Protection Ombudsman:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) Visiting address: Lintulahdenkuja 4, 00530 Helsinki Postal address: PO Box 800, 00531 Helsinki Email: tietosuoja@om.fi Website: tietosuoja.fi
Personal data breaches
A personal data breach affecting website data is handled under our incident response policy. Where required, we notify the Office of the Data Protection Ombudsman within 72 hours of becoming aware of it (GDPR Article 33). Where a breach is likely to result in a high risk to your rights and freedoms, we notify you without undue delay (GDPR Article 34): by email if you are an early-access signup contact, or by a notice on tai.ga if a broader group of visitors is affected.
Automated decision-making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you.
Changes to this policy
If we materially change how we process personal data, we will update this page, change the “last updated” date, and reset your consent choice so you can review and decide again.
Contact
For any questions about this privacy policy or how we handle your data, contact us at hello@tai.ga
Security specifics live in the Trust center
Using the Taiga platform? Platform data is covered separately