1In short
The essentials, before the details:
- In the bot we identify you only by your numeric Telegram ID and your username — never first and last name, phone number, email or profile photo
- Your content stays inside your organization: no data selling, no advertising, no commercial profiling
- The AI assistants only see the organization they work in, and the model provider does not train its systems on your data
- When something is "anonymous", we tell you exactly what that means — before you send, not after (see 5.6 and 5.7)
- Database on servers in the European Union, encrypted backups, digitally signed exports
- Many deletions you can do yourself from the bot; for everything else, one email is enough (section 13)
2What this notice covers
This notice covers two things:
- The Tavora bot on Telegram — the platform where you create an organization, connect your groups and use proposals, votes, tasks, shifts, events, forms, the Library, the Service desk, your personal space and the AI assistants
- The tavora.net website — the landing pages, the guides and the support form (section 15)
Tavora runs inside Telegram, but it is not Telegram: it is an independent project, not affiliated with Telegram. Whatever you send through Telegram is also processed by Telegram under its own privacy policy.
Reading this page does not commit you to anything: it is a notice, not a contract. The legal bases we rely on are listed in section 7.
3Data controller
Tavora is an independent project in beta, developed and run by its developer, who acts as the data controller within the meaning of Art. 4(7) GDPR. There is no company yet: for any question about your data, the point of contact is this address:
No Data Protection Officer (DPO) has been appointed: for the nature and scale of this processing, Art. 37 GDPR does not require one. We answer data requests within the deadlines of Art. 12 GDPR (as a rule, within one month).
4Tavora and the organizations: who is responsible for what
Tavora is a platform: the organizations running on it are created and managed by other people. To understand who answers for what, the distinction is this:
- Tavora is the controller for the processing needed to run the platform: accounts, infrastructure, security, backups, anti-abuse limits, the technical operation of the AI assistants
- The managers of each organization (founder, admins, staff) decide how to use the tools on their own members: whom to admit, which roles and permissions to grant, what to write in a member's record (notes, warnings, recognitions, labels), which rules to give the AIs. For those choices they act as independent data controllers of their organization, and Tavora processes the data on their behalf as the platform provider
What this means for you as a member: for content that your organization's staff writes about you, your first point of contact is the organization's managers. You can always write to us too (section 17): we will help you exercise your rights in any case.
Managers are required to use Tavora's tools in compliance with data-protection law. If you believe an organization is abusing them, report it to us.
5Data we process
5.1 Telegram data
When you interact with the bot, Telegram automatically provides us with:
- Telegram User ID — your unique numeric identifier
- Telegram username — your public username (it updates by itself if you change it)
- Language code — used to offer you the interface in your language (changeable in the settings)
- Date and time of your first and last interaction
On top of these come the preferences you set yourself: time zone (for reminders), per-organization notification settings. If you block the bot on Telegram, we record the event so we stop contacting you; the flag clears by itself if you come back.
5.2 Organizations and membership
- Role in each organization (member, admin, founder) and custom permissions
- Departments and duties you belong to, and their managers
- Join requests, invites and their approvals
- Organization-level bans — with User ID, ban author and date
- Ownership transfer requests for an organization (the two User IDs involved and the status)
- Presence in connected Telegram groups — group ID, group name, and who is present there (ID and username only), to verify membership
- Publishing language chosen by the founder for messages in the groups (an organization setting, not a personal one)
5.3 Content you create
- Proposals and agenda items: title, text, type, attachments, comments
- Votes: your vote linked to your User ID (who can see it: section 8)
- Tasks: title, description, checklists, assignments, notes (public or private), reminders, change history
- Shifts: slots, assignments, swap requests
- Events and calendar: events, sign-ups/RSVPs, reminders
- Forms: your answers (for anonymity: 5.7)
- Library: uploaded materials (documents, chapters, pages) and who uploaded them
- Service desk: proposals, requests and reports sent to the managers (for anonymity: 5.6)
To preserve the formatting you enter (bold, italic, links, animated Telegram Premium emoji) we also keep a "rich" HTML version of the content. Premium emoji are stored as a numeric identifier, not as an image. Attachments (photos, videos, documents) are not stored on our servers: we only keep the reference (file_id) provided by Telegram — the files stay on Telegram's servers.
5.4 Member record — data the staff enters about you
Your organization's staff can keep a record on each member. It may contain:
- Internal staff notes (not visible to you or to other members)
- Warnings and sanctions, with author and date
- Recognitions and assigned labels
- History: joins/leaves, groups you have been seen in, activity statistics (proposals, tasks, events)
- Audit of staff actions on your profile (who did what and when)
This content is decided and written by the organization's managers, who answer for it as independent controllers (section 4). The staff can clean up the record; deleting your account erases it (section 13).
5.5 Personal space
Outside the organizations you have a space of your own: agenda, to-dos, notes, reminders (recurring too) and personal forms. This data is visible only to you: it appears in no organization, ends up in no Library, and no manager can see it. Your personal AI assistant accesses it only when you ask it to (section 6.4).
5.6 Service desk and anonymity — told honestly
From the Service desk a member can send the managers a report anonymously. Here is exactly what that means:
- To the managers it is truly anonymous: they see no name, username or ID — not even by searching. In the CSV export the sender column is empty
- To the system it is not: the database still records who sent the report. This prevents abuse and lets you follow your own case
- The bot tells you this clearly at the moment of sending, before you choose
The identity of the sender of an anonymous report is never revealed to the managers in any screen of the bot. It could be disclosed only if a legal obligation required us to (section 7).
5.7 Forms and anonymity
Whoever creates a form chooses whether it is named or anonymous, and the choice can no longer be changed after publication. In an anonymous form:
- While you fill it in, the system keeps a temporary link between you and the draft (so you can resume filling it in); on submission that link is deleted: the submitted answers can no longer be traced back to you in the database
- It remains recorded that you answered (to prevent duplicate responses), but not what you answered
- That is why an anonymous form does not allow editing your answers after submission
5.8 Donations (Telegram Stars)
If you support the project with a donation in Telegram Stars we record: User ID and username, the amount, the transaction ID (charge_id, useful for refunds), date and time, and — only here — your Telegram first name, used exclusively to thank you publicly if you accept, or for the donor badge. We neither receive nor store any payment details (cards, accounts): the transaction happens entirely inside Telegram.
5.9 Technical data
- Audit trail: for tasks and management actions we record who did what and when
- Temporary wizard sessions (proposal/task creation…): deleted automatically after 24 hours of inactivity
- Attachments of bug reports/feedback sent from the bot: kept as Telegram references and deleted after about 30 days
- Digital signature of exports: exported PDFs are signed with an RSA-2048 key; the signature proves the document is authentic and unaltered, and contains no additional personal data
- Technical logs: the bot's logs contain no tokens and no sensitive content
- Internal product statistics (beta phase): aggregated activation events (e.g. creating your first organization) and usage counters for some screens, tied to User ID and timestamp. They stay internal, feed no profiling or advertising, and will be removed or anonymized at the end of the beta. You can request early deletion
5.10 Data we do NOT collect
The bot does not collect:
- First and last name (except donors' first name, 5.8), email, phone number
- Profile photos or biographical data
- Location or GPS data
- Private messages outside the conversation with the bot
- Data from other apps or services, browsing history, cookies, device data
- Payment details (cards, accounts, IBAN)
6AI assistants
Tavora includes several AI assistants. The same ground rules apply to all of them: answers are generated by the Claude model from Anthropic (section 10), the data sent to the provider is not used to train its models, each assistant sees only the organization (or the personal space) it works in, and none of them acts on its own: they read and answer when someone asks them to.
6.1 Tavora AI (for members)
It answers questions based on the Library materials marked "AI = Yes" by the staff and on Tavora's base knowledge. We keep:
- Conversation memory in private chat, until you delete it or after 30 days of inactivity; in groups (
/ask) the memory is separate, per user, and expires after 7 days - Automatic summary of older turns when the conversation gets long (the 10 most recent turns stay intact)
- Synthetic profile of your interaction style (max 200 characters), regenerated weekly, only to calibrate the tone
- Usage counters to enforce the limits (they contain no question text)
- Answer cache for public questions to the global Tavora AI, to answer similar questions instantly
What is sent to the AI provider: the question, the previous turns of the conversation, the relevant Library excerpts and the staff's AI Instructions. Your User ID and username are not sent: to the provider, Tavora AI users are not identifiable.
6.2 Member Management AI (for the staff)
An assistant reserved for founders and admins. When the staff uses it, the member data needed for the request is processed — and partly sent to the AI provider: usernames, roles, labels, activity statistics, sanctions, limited to that one organization. The staff's conversation memory lasts at most 16 exchanges / 14 days, isolated per organization and per admin. Periodic rules saved by the staff execute only reversible actions automatically: expulsions and bans are never automatic. Every action requires explicit confirmation and lands in the audit.
6.3 Task AI and Shifts AI (for managers)
Same principles as 6.2, applied to tasks and shifts: they read the boards, workloads and rosters of only the area the manager has permissions on, they propose, and sensitive actions require confirmation. The AI provider receives the task/shift data relevant to the request (titles, assignees, deadlines), never the whole database.
6.4 Personal assistant (personal space)
It works only on your personal data: to-dos, agenda, notes, reminders. It has a memory separate from everything else and does not talk to the organizations' AIs.
6.5 Automatic moderation of AI Instructions
When the staff saves an AI Instruction (a behavior rule for the assistant), its text is sent to the provider for an automatic safety check. If it violates the usage rules (insults, prompt injection, illegal activities) it is marked as "ignored" and the AI does not apply it. Only the instruction text is sent, no other data.
Embeddings (the numeric representation of texts used for search in the Library and in the cache) are computed locally on our server with an open-source model: for this operation no data leaves our infrastructure.
7Legal bases and purposes
We do not process data "because you use the bot and therefore agree": every processing activity has a legal basis under Art. 6 GDPR.
- Performance of the service you request (Art. 6(1)(b)) — everything Tavora does: organizations, proposals, votes, tasks, shifts, events, forms, Library, Service desk, personal space, AI assistants, notifications and reminders
- Legitimate interest (Art. 6(1)(f)) — security and abuse prevention (rate limits, bans, audit trail), backups and service continuity, aggregated internal statistics to improve the product, defense of our rights. You can object to these activities (section 13)
- Consent (Art. 6(1)(a)) — the public thank-you for donors and the support form on the website. Revocable at any time
- Legal obligation (Art. 6(1)(c)) — responding to legitimate requests from the authorities, where applicable
No fully automated decision produces legal or similarly significant effects on you (Art. 22 GDPR): the AI assistants propose, people decide. Expulsions and bans are never executed automatically by an AI.
Your data is not used for commercial or advertising profiling, is not sold, and feeds no marketing of any kind.
8Who sees your data
Other members of your organization see
- Your username as the author of proposals and in comments published in the groups
- Your assignments on tasks and shifts, and public notes
- Your event sign-ups, where the attendee list is visible
- Who the organization's founder and admins are (visible to every member)
Only the managers see
- Individual votes (e.g. via
/votes), where the organization allows it - The member record (internal notes, warnings, recognitions, labels, history — section 5.4)
- The Service desk cases — with the sender visible only if not anonymous (5.6)
- The respondents of named forms (never the answer↔person link in anonymous ones, 5.7)
Nobody sees
- Your private conversations with the bot and the AI assistants
- Your personal space (agenda, to-dos, notes, reminders)
- Proposals you have hidden from your own view
Beyond this, technical access to the database is limited to the developer (section 12). No data is shared with third parties other than the providers listed in section 10.
9Retention
General rule: we keep data for as long as you use Tavora and the organization it belongs to exists. In detail:
- Deleting an organization: members are disconnected immediately; the data (proposals, votes, tasks…) stays recoverable for 10 days (on request by email), then it is deleted permanently and automatically
- Wizard sessions: 24 hours of inactivity
- Bug report and feedback attachments: ~30 days
- AI memories: Tavora AI 30 days of inactivity (7 in groups), management AIs 14 days — on top of the manual resets (section 13)
- Synthetic AI profile: replaced weekly; deleted with the memory reset or with the account
- AI answer cache: invalidates itself when the underlying materials change
- Pending proposals: finalized automatically after 7 days
- Bans: User ID and username stay on the ban list for as long as the ban is active
- Blocking the bot: the data remains but we no longer contact you; you can request its deletion
- Beta statistics: removed or anonymized at the end of the beta
- Backups: encrypted copies, rotated periodically. Deleted data may survive in a backup for a limited period before rotation overwrites it
10External providers
Tavora relies on a small number of providers, each for one precise job. There are no third-party analytics services, pixels, advertising SDKs or data brokers.
For the bot
- Telegram — the platform the bot lives on: messages, files and interactions pass through its servers under its own privacy policy. Telegram is an independent controller of its own processing
- Anthropic (USA) — the provider of the Claude model behind the AI assistants. It receives only the data described in section 6, does not use it for training (it keeps it for a limited period for safety purposes, then deletes it) and processes it under its privacy policy and its Data Processing Addendum
- Hosting — the bot and the PostgreSQL database run on a virtual private server in the European Union, managed by us. No third-party cloud service stores the bot's data
For the website
- Vercel — hosting of tavora.net and the support form
- Resend — delivery of the support form emails
- Cloudflare Turnstile — anti-bot verification of the form, with no persistent cookies and no cross-site tracking
11Transfers outside the EU
The bot's database resides in the European Union. Some providers, however, operate from the United States:
- Anthropic — for the requests to the AI assistants (section 6)
- Vercel, Resend and Cloudflare — for the website and the support form (section 15)
These transfers rely on the safeguards of Chapter V GDPR: certification under the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs), depending on the provider. Telegram processes data under its own policy, as an independent controller.
12Security
Main measures in place:
- Encryption in transit — communications with Telegram and between bot and database travel over encrypted channels
- Encryption at rest — the server's disk is encrypted
- Encrypted backups — with AES-256 and robust key derivation; the passphrase does not live on the server
- Digital signature — PDF exports are signed with a publicly verifiable RSA-2048 key
- Limited access — only the developer has direct access to the database
- Parameterized queries — protection against SQL injection
- Input validation and length limits on everything you enter
- Anti-abuse rate limiting on creations and interactions
- Sober logging — no tokens and no sensitive content in the logs
No system is 100% secure. Should a breach occur that puts your rights at risk, we will notify the authority and — in the cases set out by Art. 34 GDPR — you as well.
13Your rights
The GDPR grants you these rights (Arts. 15–21), all free of charge:
- Access — knowing what data we hold about you and getting a copy
- Rectification — correcting inaccurate data (your username updates by itself from Telegram)
- Erasure — the complete deletion of your account (details below)
- Restriction — asking us to "freeze" a processing activity while we check a dispute you raised
- Portability — receiving your data in a structured, commonly used format; from the bot you can already export to PDF/CSV/ZIP
- Objection — objecting to the processing based on legitimate interest (section 7)
- Withdrawal of consent — at any time, without affecting what happened before
Complaint to the authority: you always have the right to turn to the Italian Data Protection Authority (Garante) (Art. 77 GDPR) or to the supervisory authority of your country, without having to notify us first.
What you can do yourself, right now, from the bot
- AI memory reset — the "🧹 Reset memory" button immediately deletes conversation turns, synthetic profile and summaries (the operation is irreversible and asks for confirmation)
- Leave an organization at any time
- Delete appointments, notes, to-dos and reminders in your personal space
- Hide proposals from your own view
- Block the bot to stop all communication
- Account deletion — the bot has a built-in GDPR function
What deleting your account entails
- Deleted: account, memberships, roles, member records about you, bans, join and transfer requests, personal space, AI memories
- Deleted: the organizations you founded (with the 10-day recovery window of section 9)
- Anonymized: proposals, votes, comments, tasks and notes you created inside other people's organizations — the content remains (it is the organization's collective heritage), but with no link to you anymore. Aggregated vote counts stay unchanged, the voter's identity is removed
To exercise the rights that require our intervention, write to tavorasystems@gmail.com stating your Telegram User ID. We reply as a rule within one month (Art. 12 GDPR).
14Minors
Tavora is not intended for children under 16 and we do not knowingly collect their data. If a parent or guardian believes a minor has provided us with personal data, they can write to us for removal (section 17).
15Website and support form
The tavora.net website
The website uses no cookies, has no banner because none is needed, and embeds no trackers, third-party analytics or pixels. The hosting (Vercel) generates technical delivery logs processed under its own privacy policy.
The support form
When you send a report from the form (/support/) we collect what you write: type, title (max 120 characters), description (max 4000), your email (to reply to you), optional attachments (max 3 files; allowed types: images, videos, PDF, TXT), the page language and a hash of the IP (SHA-256 with salt) used only for rate limiting — never the IP in the clear.
Legal basis: your explicit consent (mandatory checkbox) and the performance of your request (replying to you). The emails travel via Resend and land in our inbox; the anti-bot verification is by Cloudflare Turnstile, with no persistent cookies.
- Email retention: the time needed to handle the report, at most 24 months
- Form diagnostic logs: 7 days, with no personal data in the clear
- Withdrawal: you can withdraw your consent at any time by writing to us; the withdrawal does not affect the lawfulness of what already happened
16Changes to this notice
If Tavora changes, this page changes with it. For substantial changes we notify you with a message in the bot; the date of the last update is always at the top of the page. Previous versions are available on request.
17Contact
For questions about this notice or to exercise your rights:
State your Telegram User ID in the request: it is the only way we have to identify your data with certainty (we will never ask for your name or documents, except in case of well-founded doubts about the requester's identity under Art. 12(6) GDPR).
This notice is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and applies to the Tavora bot on Telegram and to the tavora.net website. It is available in several languages as a courtesy: in case of discrepancies, the Italian version prevails.