Privacy Policy

What personal data Treica processes, why, where it is stored, and the rights available to individuals.

Last updated 2026-07-28

Draft - pending review by a qualified lawyer.

This document is not legal advice. Text in square brackets must be completed by the operating company. Statements about how the product behaves are drawn from the implementation and are accurate; the legal framing around them is not yet settled.

Who is responsible

Treica is operated by [COMPANY LEGAL NAME], [COMPANY FORM], registered at [REGISTERED ADDRESS], company number [COMPANY NUMBER] (the "Provider", "we").

For personal data that a customer loads into their own workspace, the customer is the controller and we act as processor on their documented instructions. For data we collect to run the service itself (account records, sign-in events, billing correspondence), we are the controller.

Data protection contact: [DPO OR PRIVACY CONTACT EMAIL]. Values in square brackets must be completed by the operating company before publication.

What we process, and why

CategoryExamplesPurposeLawful basis
Account dataName, work email, role, home entityProvide access, enforce roles, attribute actions in the audit trailContract performance
Authentication dataSign-in link tokens, two-factor secret, session recordsVerify identity, protect the accountContract performance; legitimate interest in security
Customer register contentThird-party records, contracts, evidence documents, assessment answers, findingsDeliver the service the customer configuredProcessor acting on the customer's instructions
Contact data of third-party representativesNames and business contact details recorded against a provider or evidence requestOperate the customer's third-party governance programmeProcessor; the customer's legitimate interest as controller
Usage and audit recordsActions taken, records viewed, IP address, user agent, timestampsProduce the immutable audit trail the regulation expects, and detect abuseLegal obligation of the customer; our legitimate interest in security
Support correspondenceMessages you send usAnswer you and improve the serviceLegitimate interest

Where data is stored

The application database is hosted in the European Union (Frankfurt, Germany). Uploaded evidence files are held in EU-hosted object storage with private access only.

Application hosting and content delivery are provided by Vercel Inc.; transactional email is sent through Resend. Where these providers process personal data outside the EEA, transfers rely on the European Commission's standard contractual clauses together with the safeguards in the relevant provider's data processing agreement. Current sub-processors are listed at [SUB-PROCESSOR LIST URL].

AI processing

AI-assisted features are part of the Premium plan and are switched OFF by default. No content is sent to a model provider unless the workspace is on Premium AND an owner has explicitly enabled AI. Either condition being absent means no model call is made at all.

When enabled, only the material submitted for that specific action is transmitted: the contract document or text you supply, the questions and answers of the assessment you are reviewing, or the code and message of a single validation result. Your register is never transmitted.

Model access is provided through Vercel's AI Gateway to Anthropic models. Submitted content is not used to train models. Full detail, including the human-in-the-loop guarantee, is in the AI Use and Compliance notice.

Retention

Register content and evidence are retained for as long as the customer's workspace is active, and afterwards for the period the customer specifies in their agreement. Audit records are retained for [AUDIT RETENTION PERIOD] because their value depends on being complete and immutable.

Sign-in tokens expire shortly after issue and are single-use. Sessions expire after a period of inactivity.

Security

  • Passwordless sign-in; no password is stored. Optional time-based two-factor authentication.
  • Every workspace's data is isolated at the database level by row-level security enforced under an application role that cannot bypass it, in addition to application-level scoping.
  • Evidence files are hashed on upload so any later alteration is detectable, and are served only to authenticated, authorised users.
  • Transport is encrypted and strict transport security is enforced. Administrative surfaces are separated from the customer application.
  • Every create, update, delete, privileged action and record view is written to an append-only audit log.

Your rights

Individuals in the EEA and the UK may request access, rectification, erasure, restriction, portability, and may object to processing based on legitimate interest. Where we act as processor, we will forward your request to the relevant customer, who is the controller, and assist them in answering it.

Requests: [PRIVACY CONTACT EMAIL]. You may also complain to your national supervisory authority; ours is [LEAD SUPERVISORY AUTHORITY].

Cookies

Treica sets only the cookies required to operate: a session cookie, a cross-site request forgery token, and a cookie remembering which entity you are working in. There is no advertising or cross-site tracking, and no third-party analytics cookie is set without consent.

Changes

We will post any material change here and, where the change affects how personal data is processed, notify workspace owners by email before it takes effect.