This Privacy Policy explains how TIAKI AB ("TIAKI", "we") processes personal data when you visit our websites, request information, evaluate our Platform, or engage with us as an institutional counterparty. We act as a controller for the data described below, and as a processor for client data handled under a separate Data Processing Addendum.
1. Data We Process
- Identity & contact: name, business email, organisation, role, country.
- Engagement data: meeting notes, demonstration requests, NDA records, pilot scoping correspondence.
- Technical data: IP address, device, browser, log timestamps, error reports, security events.
- Cookie & analytics data: as described in our Cookie Policy.
We do not seek special-category personal data through marketing channels. Where the Platform processes sensitive identifiers as part of a client engagement (for example, athlete or beneficiary identifiers), processing is governed by the relevant DPA and the pseudonymisation-by-default architecture described in §6.
2. Lawful Bases (GDPR Art. 6)
- Legitimate interests — operating, securing, and improving the Platform; marketing to professional counterparties; protecting against fraud and abuse.
- Contract — performing pilot, NDA, evaluation, or commercial agreements.
- Legal obligation — tax, accounting, sanctions screening, regulatory retention.
- Consent — non-essential cookies and certain communications.
3. Recipients
We share personal data with vetted sub-processors providing cloud hosting, AI inference, email, identity, support and analytics, and with professional advisers, auditors, and regulators where required. A current sub-processor list is available on request.
4. International Transfers
TIAKI's primary infrastructure operates in EU regions. Where a sub-processor processes personal data outside the EEA, transfers are protected by EU Standard Contractual Clauses and supplementary measures consistent with the EDPB Recommendations.
5. Retention
We retain personal data only as long as necessary for the purposes listed above and to meet legal retention obligations (typically 7 years for accounting records, 12 months for security logs, and the duration of the relationship plus 24 months for engagement data).
6. Security & Pseudonymisation
TIAKI applies data-protection-by-design: SHA-256 pseudonymisation at ingress for sensitive identifiers, separation of identity and risk data into isolated tables, row-level security on every public table, role-segregated access via a has_role() security-definer pattern, and immutable audit logging. Architectural controls map to GDPR Art. 25 & 32, ISO 27001:2022 Annex A, and the SOC 2 Trust Services Criteria.
7. Your Rights (GDPR Art. 15–22)
- Access, rectification, erasure, restriction, portability, and objection.
- Withdraw consent at any time without affecting prior lawful processing.
- Lodge a complaint with your local supervisory authority. Our lead authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
To exercise any right, email investors@tiaki.ai. We respond within one month.
8. Automated Decision-Making
Marketing-side processing does not involve automated decisions producing legal or similarly significant effects. AI-assisted outputs surfaced through the Platform are subject to human-in-the-loop adjudication and the disclosures in our AI Output Disclaimer.
9. Contact
Controller: TIAKI AB, Stockholm, Sweden. Privacy contact: investors@tiaki.ai.