Tandem

Tandem Privacy Policy

Draft prepared 2026-09-06 for review by a solicitor; not yet in force.

This policy explains what personal data we collect when you use Tandem at https://app.numux.tech, why we collect it, who processes it for us, and what your rights are. We collect only what we need to run the service. We do not sell personal data, and we do not use it for advertising.

1. Who is responsible

1.1. The controller of your personal data is Numux Tech Ltd, a company registered in England and Wales (number 15596572), registered office 71-75 Shelton Street, London, England, WC2H 9JQ. ICO registration number: [ICO_REGISTRATION].

1.2. Contact us about privacy at hello@numux.tech. We do not have a data protection officer; the law does not require one for a company of our size and activity.

1.3. [Note for the solicitor: as a UK company offering services to people in the EU, we may need a representative in the EU under EU GDPR Article 27, unless the "occasional processing" exemption applies. Please advise. If one is needed, its name and address go here.]

2. What we collect, why, and on what basis

The table lists each kind of data, where it comes from, why we use it, and the lawful basis under UK GDPR and EU GDPR Article 6.

DataSourceWhy we use itLawful basis
Account data: email address, name, the identifier your sign-in provider gives us, the sign-in method you chose, time of last loginYou, via Auth0 (and Google or GitHub if you sign in with them)To create your account, sign you in, and email you about your workspace and paymentsPerformance of our contract with you
Billing data: billing name and address, country, VAT number if you give one, payment method (held by Stripe; we see only the last four digits and the card brand), invoices, payment historyYou, at checkout; StripeTo charge you, work out VAT, issue invoices and handle refundsPerformance of the contract; legal obligation (tax and accounting law)
Workspace data: the name of your workspace, its plan, its settings, and everything you and your agents put in it (tasks, documents, messages, API keys you add, agent logs and output); on Workspace Plus, a count of model usage against your allowanceYou and your agentsTo host and run your workspace; on Workspace Plus, to meter the allowancePerformance of the contract. For personal data about other people that you put in your workspace, you are the controller and we are your processor (see section 8)
Technical logs: IP address, browser, pages requested, timestamps, errors, and security events such as failed loginsYour browser and our serversTo keep the service secure, diagnose faults, and stop abuseOur legitimate interest in running a secure and reliable service
Support correspondence: emails you send us, and our repliesYouTo answer you and keep a record of what was agreedPerformance of the contract; our legitimate interest in keeping records

2.1. We do not collect special category data on purpose. Please do not put health, biometric or similar data about yourself into your account details. What you put in your workspace is up to you (section 8).

2.2. We do not make automated decisions about you that have legal or similarly significant effects, and we do not profile you.

2.3. You do not have to give us any data, but without an email address we cannot open an account, and without billing details we cannot start a workspace.

3. Who processes data for us

We use a small number of service providers ("processors"). Each acts on our instructions under a written contract, and each holds only what it needs.

ProcessorWhat it holdsWhere
Auth0 (Okta, Inc.)Sign-in: email, name, password hash (for email/password accounts), sign-in provider identifiers, login eventsOur Auth0 tenant is in the EU. Okta is a US company; support and some operational access may come from the US, under Okta's data processing agreement and the safeguards in section 4
Stripe (Stripe Payments Europe Ltd and Stripe, Inc.)Payment and billing: name, billing address, payment method, VAT number, invoices, receipts, payment emailsStripe processes data in the EU, the UK and the US, under its data processing agreement and the safeguards in section 4. [Note for the solicitor: please confirm which Stripe entity contracts with a UK merchant.]
DigitalOcean (DigitalOcean, LLC)Hosting: your workspace, its database, files and backups; server logsServers in Frankfurt, Germany. DigitalOcean is a US company; operational access may come from the US, under its data processing agreement and the safeguards in section 4
Google (Google Ireland Ltd)Only if you choose "Sign in with Google": Google tells us your email and name, and knows that you signed in to TandemEU and US, under Google's own privacy policy for your Google account
GitHub (GitHub, Inc.)Only if you choose "Sign in with GitHub": GitHub tells us your email and name, and knows that you signed in to TandemUS, under GitHub's own privacy policy for your GitHub account

3.1. AI model providers. On a plan where you bring your own keys, your agents call model providers (for example OpenAI, Anthropic or OpenRouter) using the API keys you add. What they send is decided by you and your agents, and it goes under your agreement with that provider; we do not see or store your provider account. On Workspace Plus, calls covered by the monthly allowance go through our own account with [MODEL_PROVIDER], which then processes what your agents send as our processor, under its data processing terms, in the locations it states. [Note for the solicitor: name the provider (the design mentions OpenRouter), its entity and location, and the transfer safeguard, once the Plus plan's provider is fixed; add it to the processor table above.]

3.2. We share personal data with no one else, except: an authority, when the law requires it; a professional adviser, in confidence; or a buyer of our business, who would be bound by this policy. We will tell you before a buyer takes over, so you can delete your account if you prefer.

4. International transfers

4.1. Our servers are in Frankfurt, Germany (EU). We are a UK company and manage the service from the UK. Data flows both ways between the UK and the EU. Both sides recognise the other as providing adequate protection: the European Commission's adequacy decision for the UK, adopted in 2021 and renewed in December 2025, and the UK's adequacy regulations for the EEA. No further safeguard is needed for those flows.

4.2. Auth0 (Okta), Stripe, DigitalOcean and GitHub are US companies, and Google is a US group. Where personal data is accessed from or transferred to the United States, we rely on one of these safeguards:

  • the provider's certification under the EU-US Data Privacy Framework and its UK Extension (the "UK-US data bridge"), where the provider is certified; or
  • the European Commission's Standard Contractual Clauses (Decision 2021/914) for EU data, and the ICO's International Data Transfer Agreement or the UK Addendum to those clauses for UK data, which are built into each provider's data processing agreement.

4.3. You can ask us at hello@numux.tech for a copy of the safeguards we rely on.

5. How long we keep data

DataKept for
Account dataUntil you delete your account, or until we delete it after two years without a login or a workspace
Workspace dataWhile your account exists. After a subscription ends the workspace is suspended and its data kept; it is deleted within 7 days of your request by email, or when your account is closed
Billing data and invoices6 years after the end of the financial year they relate to, because UK tax law (HMRC) requires it. Stripe keeps its own records under its own obligations
Technical logs30 days
Support correspondence2 years after the last message, or as long as needed for a dispute

5.1. When you delete your account we delete your Auth0 user, your workspace records and your Stripe customer, in that order, within 30 days, except for invoices and records we must keep by law.

6. Your rights

6.1. Under UK GDPR and EU GDPR you can ask us to:

  • access the personal data we hold about you, and get a copy;
  • correct it if it is wrong;
  • delete it, where we no longer need it or where you withdraw consent;
  • restrict how we use it, in some cases;
  • give it to you in a portable format, where we process it under the contract with you;
  • stop using it, where we rely on legitimate interests, unless we have compelling grounds to continue.

6.2. To use any of these rights, email hello@numux.tech. We may ask you to confirm your identity. We reply within one month; if a request is complex we may take up to two more months, and we will tell you. There is no charge, unless a request is clearly unfounded or excessive.

6.3. Most of your data is also in your hands: you can change your name and email in your account, export your data from your workspace, ask us by email to delete your workspace (we do so within 7 days), and manage billing details in the Stripe portal.

6.4. Where we rely on consent, you can withdraw it at any time. At present we do not rely on consent for anything.

7. Cookies

7.1. Tandem sets three cookies, all strictly necessary for the service to work:

CookieWhat it doesLifetime
SessionKeeps you signed in across app.numux.tech and your workspace address7 days
CSRF tokenProtects forms against cross-site request forgerySession
Login stateCarries the state of a sign-in in progress between our site and Auth0A few minutes

7.2. Strictly necessary cookies do not need consent under the UK Privacy and Electronic Communications Regulations or the EU ePrivacy Directive, so there is no cookie banner. We use no analytics, tracking or advertising cookies, and no third-party scripts on our pages. Stripe Checkout, the Stripe billing portal and Auth0's login pages are hosted by those companies and set their own cookies, described in their policies.

7.3. Your workspace sets its own session cookie for the same purpose.

8. Data in your workspace

8.1. You decide what goes into your workspace and what your agents do with it. If that includes personal data about other people, you are the controller of that data and we are your processor. We process it only to host your workspace, keep backups, and support you when you ask. We do not read it except to fix a fault you report or to investigate abuse, and then as little as possible.

8.2. Your agents may send workspace data to the AI model providers and other services you connect. That is your choice and happens under your agreements with them.

8.3. Business customers who need a data processing agreement can ask for one at hello@numux.tech. [Note for the solicitor: see the note at clause 11.2 of the Terms.]

9. Security

9.1. All traffic is encrypted in transit (TLS). Each workspace runs in its own isolated environment with its own database, and workspaces cannot reach each other. Secrets are encrypted at rest. Access to production is limited to the people who run it. Passwords are handled by Auth0 and never reach us.

9.2. If a breach affects your personal data and is likely to put you at high risk, we will tell you without undue delay, and we report to the ICO within 72 hours where the law requires.

10. Children

Tandem is for adults. You must be 18 or older to have an account. We do not knowingly collect data from anyone under 18; if we learn that we have, we delete it.

11. Complaints

11.1. If you are unhappy with how we handle your data, write to hello@numux.tech first. We will do our best to put it right.

11.2. You also have the right to complain to a supervisory authority. In the UK that is the Information Commissioner's Office, https://ico.org.uk, telephone 0303 123 1113. If you live in the EU, you can complain to the data protection authority of your own country; the list is at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

12. Changes to this policy

We will update this policy when the service or the law changes. The date at the top shows the current version. If a change matters to you, for example a new processor or a new purpose, we will email you before it takes effect.

13. For residents of the United States

This section applies if you live in the United States. It adds to the rest of this policy, which applies to you too.

13.1. Who is responsible, and where your data is. Numux Tech Ltd, a company in England, is responsible for your personal data (section 1). Our servers are in Frankfurt, Germany, and we manage the service from the United Kingdom, so your data is processed outside the United States, under UK and EU data protection law, which gives you the rights in section 6 wherever you live. The US companies that process data for us are listed in section 3.

13.2. What we collect, and who receives it. The categories of personal information we collect are those in section 2: identifiers (your name, email address, sign-in identifier and IP address); commercial information (your plan, invoices and payment history); internet activity (the pages you request and our technical logs); and the content you and your agents put in your workspace. We collect them from you, from your sign-in provider and from Stripe, and from your browser. We share them only with the service providers in section 3, for the purposes there: Auth0 (sign-in), Stripe (payment), DigitalOcean (hosting), Google or GitHub if you sign in with them, and the model provider on Workspace Plus; and otherwise only as section 3.2 says. We do not sell personal information, and we do not share it for cross-context behavioural advertising, and we have not done so in the past twelve months.

13.3. How to review and change your information. Email hello@numux.tech and we will show you what we hold and correct or delete it (section 6). You can also change your name and email address in your account, manage your billing details in the Stripe billing portal, and export your data from your workspace (section 6.3).

13.4. Do Not Track. We do not track you across other websites. We use no analytics, advertising or tracking cookies and no third-party scripts (section 7), so our site behaves the same whether or not your browser sends a "Do Not Track" or Global Privacy Control signal, and we do not respond to those signals in any other way. No third party collects information about your online activities over time and across different websites through our service. [Note for the US attorney: should the CCPA ever apply, a Global Privacy Control signal must be honoured as an opt-out of sale or sharing; we sell and share nothing, but please confirm the wording.]

13.5. Changes to this policy. Section 12 says how we tell you about changes; the date at the top of this policy is its effective date.

13.6. California residents. Although the California Consumer Privacy Act does not apply to a business of our size, we honour its rights on request: to know what personal information we collect about you, from where, why, and with whom we share it, and to receive a copy; to delete it; to correct it; to opt out of its sale or sharing (we do neither); to limit the use of sensitive personal information (we do not collect it on purpose); and not to be treated differently for using these rights. Email hello@numux.tech; we verify you through the email address on your account, and reply within 45 days. You may use an authorised agent, and we may ask the agent for proof of your permission. Under California's "Shine the Light" law (Civil Code § 1798.83), we disclose no personal information to third parties for their own direct marketing.

13.7. Residents of other states. If your state's privacy law (for example Virginia, Colorado, Connecticut, Texas or Oregon) gives you rights to access, correct, delete or take a copy of your personal data, or to opt out of its sale, targeted advertising or profiling, we honour them on the same terms as 13.6 whether or not the law applies to us. If we refuse a request, you may appeal by replying to our answer, and we reply to the appeal within 45 days.

13.8. Breach notification. If a security breach affects your unencrypted personal information, we notify you by email without unreasonable delay, in the form and within the time your state's breach-notification law requires, and we notify your state's attorney general or other regulator where that law requires it. This is in addition to the UK notice in section 9.2. Every US state, the District of Columbia, Guam, Puerto Rico and the US Virgin Islands have such a law.

13.9. Children. Tandem is for adults (section 10). We do not knowingly collect personal information from children under 13, as the Children's Online Privacy Protection Act defines them, or from anyone under 18; if we learn that we have, we delete it.

13.10. Email and messages. The only emails we and our providers send you are about your account, your workspace and your payments: sign-in and verification from Auth0, receipts, renewal reminders, failed-payment notices and cancellation confirmations from Stripe, and our replies to you. We send no marketing email, and we do not call or text you.

14. Contact

Numux Tech Ltd 71-75 Shelton Street, London, England, WC2H 9JQ Company number 15596572 (England and Wales) ICO registration: [ICO_REGISTRATION] Email: hello@numux.tech