Legal
Privacy Policy
This Privacy Policy explains how turnkeeper.ai (“turnkeeper,” “we,” “us,” or “our”) collects, uses, shares, and protects personal data when you visit our website, request pilot access, or use our AI agent conversation governance platform (the “Service”). This is a starter policy and should be reviewed by counsel, and completed with your legal entity name and governing jurisdiction, before public launch.
Effective date: July 21, 2026
Scope and our two roles
turnkeeper acts as an operational control layer for AI agent conversations and workflows. Depending on the data involved, we play one of two roles:
- As a controller for information about our website visitors, pilot applicants, and the account users who administer the Service. This policy governs how we handle that data.
- As a processor (service provider) for bounded workflow metadata, policy decisions, approvals, metadata-only lifecycle events, and audit records that our business customers route through the Service (“Governed Data”). We process Governed Data only on our customers’ documented instructions under our customer agreement and any applicable data processing addendum. If you are an end user whose interaction was governed through a turnkeeper customer, that customer is the controller of your data—please direct privacy requests to them.
Information we collect
Information you provide to us. When you request pilot access, create an account, or contact us, we collect the information you submit—such as your name, work email, company, role, the workflow you want to govern, timeline, other details in your message or survey responses, and records of your correspondence with us.
Governed Data processed on behalf of customers. When a customer uses the Service, we process bounded workflow metadata, pseudonymous identifiers, policy matches, review and approval decisions, and audit-log entries that the customer routes through the control layer. The Service is currently designed not to ingest or store message text, prompts, completions, summaries, transcripts, names, email addresses, phone numbers, addresses, or raw customer or contact identifiers as Governed Data. We process Governed Data as a processor under the customer’s instructions and do not determine the purposes for which it is processed.
Information collected automatically. When you visit our site, we automatically collect certain technical data, including your IP address (which we may store in hashed form for abuse prevention), device and browser type, operating system, referring and source pages, and log data about your visits. We collect this through cookies and similar technologies described below.
Cookies and analytics
We use first-party and third-party cookies and similar technologies to operate the site, remember your preferences (such as light/dark theme), keep you signed in, and understand how the site is used. These include:
- Strictly necessary cookies that are essential to provide the site and secure areas of it.
- Functional cookies that remember your settings and preferences.
- Performance and analytics cookies that help us measure and improve how the site performs.
We do not use cookies to serve interest-based or targeted advertising. If you disable cookies in your browser, some parts of the site may not function correctly.
How we use personal data
- To provide, operate, and secure the Service, including evaluating bounded workflow metadata against policies and routing review, approval, block, and audit handoffs;
- To respond to pilot requests, evaluate fit, and administer accounts and notifications;
- To communicate with you about the Service, respond to inquiries, and—where permitted—send you relevant product updates, which you can opt out of at any time;
- To improve, develop, and troubleshoot the Service and to conduct internal research;
- To keep the Service safe—detecting and preventing spam, fraud, abuse, security incidents, and violations of our terms;
- To comply with legal obligations and enforce our agreements.
We do not use Governed Data to train or fine-tune our own or third parties’ machine-learning models, and we do not sell personal data. We may create aggregated or de-identified information (for example, usage trends) that cannot reasonably identify you, and we may use and share such information for any lawful business purpose.
How we share and disclose personal data
We do not sell your personal data. We share personal data only as described here:
- Service providers and sub-processors who perform functions on our behalf—such as hosting, database, email, and analytics providers. They may access personal data only to perform tasks for us and are contractually obligated to protect it and not use it for other purposes.
- Our customers, with respect to the Governed Data and decision records generated within their own workflows.
- Affiliates and corporate partners, subject to this policy.
- Corporate transactions—in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case personal data may be transferred to the successor entity.
- Legal and safety—when required to comply with law, respond to lawful requests from public authorities, enforce our terms, or protect the rights, safety, and security of turnkeeper, our customers, or others.
Data security
We implement technical and organizational measures designed to protect personal data from loss and from unauthorized access, use, alteration, and disclosure. Metadata-only lifecycle evidence and decision custody are core functions of the Service, and we maintain audit-ready logging of governance decisions. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. Keep your account credentials confidential and do not share your password.
Data retention
We retain personal data for as long as reasonably necessary to provide the Service, evaluate pilots, operate our business, and comply with our legal obligations. We retain and delete Governed Data in accordance with our customer agreements and our customers’ instructions. When data is no longer needed, we delete or de-identify it, except where retention is required for security, billing, or legal compliance.
International data transfers
We may process and store personal data in the United States and other countries that may have data-protection laws different from those where you live. Where required, we rely on appropriate safeguards—such as European Commission adequacy decisions or standard contractual clauses—for cross-border transfers.
Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, or to opt out of product communications, email [email protected]. You can also unsubscribe using the link in our emails. We do not sell or share personal data for targeted advertising.
If your data was processed as Governed Data through one of our customers, please contact that customer to exercise your rights; we will assist them as their processor.
Eligibility
The Service is intended for businesses and is not directed to children. It is available to users who are at least 16 years old, and we do not knowingly collect personal data directly from children.
Third-party links and services
The site and Service may link to or integrate with third-party websites and services. We are not responsible for the privacy practices of those third parties, and this policy does not apply to them.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version with a new effective date and, for material changes, provide notice where appropriate. Your continued use of the Service after an update means you accept the revised policy.
Contact us
For privacy questions or to exercise your rights, contact us at [email protected].