Last updated: 10 July 2026
This Privacy Policy explains how Talivio Technology OÜ (registry code 16991406, Ahtri tn 12, Kesklinna linnaosa, Tallinn, Harju maakond, 15551, Estonia — "Talivio", "we") processes personal data in connection with the TCSR (Talivio Cyber Security Report) service. We are the data controller for the data described below, except where this policy says we act as a processor (section 4). For privacy questions, contact [email protected].
We process personal data on the following legal bases under Article 6(1) GDPR: to perform our contract with you — providing your account, scans, reports and billing (Article 6(1)(b)); to comply with legal obligations, including accounting and tax law (Article 6(1)(c)); and for our legitimate interests in keeping the service secure, preventing abuse of the scanner, and improving the service (Article 6(1)(f)).
Scan results, collector submissions and forensic evidence describe your systems and may incidentally contain personal data of people other than you — most notably IP addresses of visitors or attackers appearing in your server logs. You decide to collect and submit this data; for it, you are the data controller and we act as your processor, handling it only to produce your reports. We will, on request, enter into a GDPR Article 28 data processing agreement with business customers covering this processing; our standard DPA is available from [email protected]. Passive scans of domains you have not verified use only publicly available information about the domain itself.
To author report narratives we may send structured scan findings, page excerpts and aggregated log statistics to our AI provider, Google (Gemini API). We do not send your account credentials, test-account credentials or payment data for this purpose. We use the paid Gemini API tier; under Google's terms and the Google Cloud Data Processing Addendum, prompts and outputs are not used to train or improve Google's models. Google acts as our processor for this purpose.
We do not sell personal data. We share it only with the recipients needed to deliver the service.
Processors (act on our behalf, under our instructions):
Independent controllers (act on their own account):
We host within the EU and we do not transfer your personal data outside the European Economic Area. Some of our sub-processors may process data in the United States: transfers to Google rely on Google's certification under the EU-US Data Privacy Framework, backed by the European Commission's Standard Contractual Clauses in the Google Cloud Data Processing Addendum as an additional safeguard. Where Stripe processes data outside the EEA as an independent controller, it relies on its own transfer safeguards.
Under the GDPR you may request access to your data, rectification, erasure, portability, restriction of processing, and object to processing. You may lodge a complaint with a supervisory authority — for us that is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), but you may also contact the authority in your own country. To exercise a right, email [email protected]. Where we process data as your processor (section 4), we will refer requests from third parties to you as the controller.
We apply technical and organizational measures appropriate to the risk: passwords are hashed, test-account credentials and raw forensic evidence are encrypted at rest, traffic is served over TLS, access is restricted, and active or intrusive scan modules run only against domains whose ownership you have verified. No system is perfectly secure, but we take reasonable measures to protect your data.
We use only essential first-party cookies: a session cookie that keeps you signed in, a CSRF cookie that protects forms against abuse and — if you choose "remember me" — a persistent sign-in cookie. We do not use analytics or advertising cookies.
We may update this policy; the date at the top shows when it last changed, and material changes will be communicated where appropriate.