Who has access to your data, how it's encrypted, what we retain, and how to reach us when something's wrong.
Last updated: March 19, 2026TLS 1.2+ in transit · AES-256 at rest
Deleted within 30 days of request
Readiness in progress — Q4 2026 target
Here's the explicit commitment, with no asterisks:
The following third-party providers may process customer data as part of the annotation service. All are under contractual obligations consistent with applicable data protection law.
| Provider | Role | Data Access | Trains on Data? |
|---|---|---|---|
|
Render
🇺🇸 United States
|
Application hosting and compute. Runs the Tagmatic web server and background annotation workers. | Infrastructure-level only (no direct data access). Storage encrypted at rest. | No |
|
Neon
🇺🇸 United States
|
PostgreSQL database. Stores annotation records, project metadata, audit logs, and user account data. | Full database access. Encrypted at rest (AES-256). Private networking only — no public endpoint. | No |
|
Google
🇺🇸 United States
(Gemini API) |
Tier 1 annotation model. Processes text inputs to produce annotation labels and confidence scores. | Text inputs per API request only. No persistent storage by Google under commercial API terms. | No — API only |
|
Anthropic
🇺🇸 United States
(Claude API) |
Tier 2 annotation model. Re-processes low-confidence Tier 1 results for higher-quality annotation output. | Text inputs per API request only. Anthropic does not retain or train on API inputs per commercial terms. | No — API only |
We maintain this list and will notify customers via email at least 14 days in advance before adding a new sub-processor. Email help@tagmatic.app to opt in to sub-processor change notifications.
We keep data only as long as necessary to run the service and meet legal obligations.
To request deletion: email help@tagmatic.app with subject "Delete my account."
Honest status on where we are:
Data processing practices are GDPR-aligned. DPA available on request and downloadable below.
California Consumer Privacy Act rights honored for California residents. Covered in our DPA.
Readiness assessment underway. Not yet certified. Target certification: Q4 2026.
Standard Data Processing Addendum available below. Mutual NDA available on request.
If you discover a security vulnerability, please report it to us before public disclosure. We take all reports seriously.
Email: help@tagmatic.app
Subject: "Security Vulnerability Report"
Include: description of the issue, steps to reproduce, and potential impact.
We will acknowledge within 2 business days and keep you updated as we investigate.
Standard DPA based on the Bonterms open-source template, pre-filled for Tagmatic. Covers GDPR Article 28, CCPA obligations, sub-processor commitments, and data deletion terms.