Legal

Privacy Policy

How Tamanor processes personal data under the GDPR — what we collect, why, the legal bases, and the rights you have.

Last updated: 14 July 2026

This is early-product wording provided for transparency. It is not legal advice and will be finalized before general availability.

1. Who we are

Tamanor is a Social Account Firewall: a multi-tenant SaaS that helps brands monitor comments, reviews and audience feedback across connected social platforms, detect reputational risk, and apply moderation with human oversight and a complete audit trail. "Tamanor", "we", "us" and "our" refer to the company operating the Tamanor service.

Data controller: Infotech Solutions, s. r. o., Konopná 194/23, 027 44 Tvrdošín, Slovakia. Company ID (IČO): 56 660 308, Tax ID (DIČ): 2122380810, VAT ID (IČ DPH): SK2122380810. For any privacy question or to exercise your rights, contact us at info@tamanor.com or +421 901 724 290.

Note on naming: our public brand is Tamanor, operated by Infotech Solutions, s. r. o. Some internal package names, database tables and technical identifiers still use the earlier name "guardora". This is a transitional artefact and does not affect how your data is handled.

2. Scope of this policy

This policy explains how we handle personal data in connection with our public website, our SaaS dashboard, and the background processing that keeps connected accounts in sync. It applies to visitors of our site, to the people at customer organisations who use Tamanor, and to individuals whose public content (for example, a comment or review) is processed through the platforms our customers connect.

3. Our two roles: controller and processor

We act as a data controller for the personal data of our own users and prospects — for example account details, billing information, and how the product is used. For this data, we decide the purposes and means of processing and this policy governs it.

We act as a data processor for the platform content our customers choose to bring into Tamanor (for example public comments and reviews, and the authorship metadata the platforms provide). Here our customer is the controller, we process on their documented instructions, and a Data Processing Agreement governs that relationship. If your content was processed because a brand connected its own account, that brand is your first point of contact; we will support any request they pass to us.

4. Personal data we process

Depending on how you interact with Tamanor, we process the following categories of personal data:

  • Account & identity data — name, work email, password hash, workspace/tenant and role, and language and interface preferences.
  • Customer & billing data — organisation name, plan, trial status, usage counters, and billing contact details (payment card data is handled by our payment provider, not stored by us).
  • Connected-platform content — public comments, reviews, posts and mentions retrieved via official platform APIs from accounts our customers connect, together with the authorship metadata the platform provides (for example a display name, public profile identifier and timestamps).
  • Moderation & decision data — the risk classification, sentiment/topic signals, proposed actions, approvals, and the moderation state your team creates inside Tamanor.
  • Audit & security data — an append-only record of automated and manual actions, plus sign-in events and session information needed to secure the service.
  • Technical data — IP address, device/browser information, and server logs generated when you use the site or dashboard.
  • Communications — messages you send us via contact forms, demo requests or email, and their contents.

We do not ask for or store your social-platform passwords, we do not scrape any platform, and access tokens obtained through OAuth are encrypted and are never displayed or written to logs. We do not seek to collect special categories of personal data; where such data appears incidentally inside public content, it is processed only as part of the moderation the customer has asked us to perform.

5. Where the data comes from

  • Directly from you — when you create an account, request a demo, contact us, or use the product.
  • From connected platforms — through official OAuth/API integrations that a customer authorises for accounts they are entitled to manage (for example Facebook Pages, Instagram Business, YouTube, Google Business Profile).
  • Automatically — technical and usage data generated as you interact with the site and dashboard.

6. Why we process data and our legal bases

We rely on the following legal bases under Article 6(1) GDPR:

PurposeLegal basis
Providing the service, managing your account, and syncing connected platformsPerformance of a contract (Art. 6(1)(b))
Detecting reputational risk, preparing proposed actions for review, and keeping an audit trailLegitimate interests in operating and securing the service and helping customers protect their brand (Art. 6(1)(f)); for platform content, on the customer's instructions as processor
Securing the service, preventing abuse, and troubleshootingLegitimate interests (Art. 6(1)(f))
Billing, tax and accounting recordsLegal obligation (Art. 6(1)(c)) and performance of a contract (Art. 6(1)(b))
Product-related communications and responding to your enquiriesLegitimate interests / performance of a contract (Art. 6(1)(b) and (f))
Optional analytics or marketing where offeredConsent (Art. 6(1)(a)), which you may withdraw at any time

Where we rely on legitimate interests, we balance those interests against your rights and freedoms and only proceed where they are not overridden. You can ask us for more detail about this balancing at any time.

7. Automated processing and the AI Risk Engine

Tamanor uses an AI Risk Engine to classify content and suggest actions such as flagging or hiding a public comment. These are decision-support signals: sensitive actions are gated behind human approval, and the product is read-only by default. We do not make decisions producing legal or similarly significant effects about you solely by automated means without human involvement. Every automated and manual action is recorded in the audit log so it can be reviewed.

8. Who we share data with

We do not sell your personal data. We share it only with the recipients needed to run the service:

  • Social platform providers — Meta (Facebook/Instagram), Google (YouTube, Google Business Profile) and similar, via their official APIs, strictly to read the content and perform the moderation you enable.
  • Infrastructure & hosting providers — who host the application and database under contract and on our instructions.
  • AI processing providers — used by the Risk Engine to classify content, under contract and without using your data to train third-party models where avoidable.
  • Professional advisers and authorities — where we are legally required to disclose, or to establish, exercise or defend legal claims.
  • Successors — in the event of a merger, acquisition or reorganisation, subject to this policy.

All processors act under a written agreement (Art. 28 GDPR) that limits them to processing on our instructions. A current list of sub-processors is available on request at info@tamanor.com.

9. International transfers

Some recipients may process data outside the European Economic Area. Where they do, we rely on an adequacy decision or on appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with supplementary measures where needed. You can request a copy of the relevant safeguards using the contact details below.

10. How long we keep data

  • Account and workspace data — for as long as your account is active, then deleted or anonymised within a reasonable period after closure.
  • Connected-platform content and moderation state — retained per the customer's configuration and instructions; disconnecting a platform stops further syncing for that account.
  • Audit records — retained for a period appropriate to their security and accountability purpose.
  • Billing and tax records — retained for the period required by applicable law.
  • Technical logs — retained for a short operational period, then rotated.

Data export, deletion and retention controls are being finalised and will be fully documented before general availability. You can already request deletion using the contact details below.

11. How we protect data

We apply technical and organisational measures appropriate to the risk, including encryption of OAuth tokens at rest, strict tenant isolation so each workspace only sees its own data, least-privilege access, fail-closed defaults for sensitive actions, and an append-only audit log. Access tokens and secrets are never logged or shown in the interface.

12. Your rights

Subject to conditions in the GDPR, you have the right to:

  • Access — obtain confirmation of, and a copy of, the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — ask us to delete your data (the "right to be forgotten").
  • Restriction — ask us to limit processing in certain circumstances.
  • Portability — receive certain data in a structured, commonly used, machine-readable format.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
  • Not be subject to solely-automated decisions with legal or similarly significant effect.

To exercise any right, email info@tamanor.com. Where your content was processed because a brand connected its account, we may direct your request to that customer as the controller. You also have the right to lodge a complaint with a supervisory authority — in Slovakia, the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky) — or with the authority in your country of residence.

13. Cookies

We use a small number of cookies that are strictly necessary to run the service (for sign-in sessions and your language preference). We do not use advertising or cross-site tracking cookies. See our Cookie Policy for the full list and how to manage them.

14. Children

Tamanor is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 16. Public content processed on a customer's behalf may occasionally originate from minors on the connected platform; such content is processed only for the moderation the customer has configured.

15. Changes to this policy

We may update this policy as the product evolves or as the law requires. We will change the "last updated" date above and, for material changes, provide reasonable notice. The current version is always available on this page.

16. Contact us

Questions about privacy or your data? Email info@tamanor.com, call +421 901 724 290, or write to Infotech Solutions, s. r. o., Konopná 194/23, 027 44 Tvrdošín, Slovakia. We aim to respond within the timeframe required by the GDPR (normally one month).

Privacy Policy — Tamanor