Skip to content
Menu

Privacy Policy

Last updated: 3 August 2026

This Privacy Policy explains how TideWater collects, uses, shares, and retains personal data in connection with the TideWater intelligence platform and its Sonar and Atlas modules.

TideWater is an invitation-only service for organizations. It processes two very different kinds of personal data: data about the people who hold accounts, and data about the people whose public posts our customers choose to monitor. This policy addresses both.

1. Who We Are and How to Contact Us

The controller for the personal data described in this policy is:

We have not appointed a data protection officer, because the appointment criteria in Article 37 of the GDPR do not currently apply to us. Privacy enquiries are handled at the address above.

Our lead supervisory authority is Datatilsynet, the Danish Data Protection Agency. See section 19 for how to complain.

2. Scope and Our Role

This policy covers:

  • The TideWater platform, including the Sonar monitoring module and the Atlas graph module.
  • The public TideWater website and its contact form.

2.1 Controller and processor roles

TideWater is sold to organizations, not to individual consumers. Our role depends on the data:

  • We are the controller for account records, authentication data, security events, audit logs, billing contact details, website enquiries, and the operation and security of the platform itself.
  • We act as a processor for the monitoring data an organization configures and collects: the channels, profiles, and feeds it selects, the keywords it defines, the messages that are collected as a result, and the investigations and reports it produces. The organization decides why and how that content is monitored and is the controller for it.

Organizations can request a data processing agreement covering the processor role by writing to contact@tidewater-intelligence.com.

3. Personal Data We Collect

3.1 Account data

  • Email address, display name, and profile image, as released by your identity provider.
  • Organization membership and role (audit, member, admin, or owner).
  • Multi-factor authentication material: encrypted time-based one-time password secrets, encrypted backup codes, and registered passkey credentials.
  • Public key material for end-to-end encryption. Private keys are generated in your browser and never leave your device.

3.2 Technical and usage data

  • IP address and user agent, recorded for security purposes. IP addresses are masked before they are written to the database.
  • Sign-in timestamps, session records, and session identifiers.
  • Activity logs of actions taken in the product, and security events such as failed sign-ins, lockouts, and session revocations.
  • Feature usage counters, including AI token consumption.

3.3 Monitoring configuration

  • The Telegram channels, Bluesky profiles, and RSS or Atom feeds you add.
  • Keywords, keyword groups, exclusions, and matching rules.
  • Dashboards, saved searches, and report schedules.
  • Telegram session credentials, stored encrypted, where you connect a personal Telegram account.

3.4 Content collected from monitored sources

When a source is monitored, we collect and store the content it publishes and the metadata around it. That content is written by third parties and can contain personal data about them and about anyone they mention. See section 6.

  • Message text, timestamps, message identifiers, and the channel, profile, or feed it came from.
  • Author handle, display name, and public profile identifiers.
  • Attached media, subject to size and file-type limits, and links contained in the content.
  • Machine translations, integrity hashes of saved messages, and, where enabled, AI-generated labels and summaries.

3.5 Notification delivery data

  • Mobile number, where SMS notifications are enabled. Stored masked outside the delivery path.
  • Webhook endpoint URLs and their signing secrets, stored encrypted.
  • Telegram and Signal delivery identifiers for the destinations you select.

3.6 Website enquiries

  • Name, email address, organization name if provided, and the content of your message.
  • Basic anti-abuse signals, including a masked IP address and the time the form took to complete.

3.7 Commercial records

TideWater has no self-service checkout and takes no card details. Commercial terms are agreed with the customer organization and invoiced outside the product. We keep the contract and invoicing records required for that relationship.

5. Special Category Data

TideWater does not ask for special category data and does not target it. However, the platform collects content published on public channels, profiles, and feeds, and that content can reveal political opinions, religious or philosophical beliefs, ethnic origin, trade union membership, health, or sexual orientation, whether about the author or about people they write about. Article 9 of the GDPR treats that as special category data.

We do not consider that content to be provided to us for our own purposes. Our customers decide what to monitor, and they are responsible for having a valid Article 9 condition, where one is required, for the purpose they are pursuing. The terms of service require that.

These safeguards apply to reduce the risk:

  • Purpose limitation. Content is collected only from sources a customer has explicitly configured, and is used only to operate monitoring, search, and reporting for that customer.
  • Scoped access. Content is segregated by organization and by user, with role-based access control and enforced multi-factor authentication available to organizations.
  • Encryption. Organizations can enable end-to-end encryption for alerts, investigations, and generated reports, so that stored records are opaque to the server. Keyword matching over encrypted records uses blind indexing rather than decryption.
  • Retention limits and deletion. Retention is set out in section 12, and any monitored source and its collected content can be deleted by the customer at any time.
  • No profiling of the wider public. We do not build or sell profiles of monitored individuals, and we do not use monitored content to train models for other customers.

6. People Whose Public Content We Process

If you post publicly on Telegram, Bluesky, or a website that publishes an RSS or Atom feed, your content may be collected by TideWater because one of our customers has chosen to monitor that source. You do not have an account with us, but you are still a data subject and this section is your notice under Articles 13 and 14 of the GDPR.

6.1 What is processed

  • The public content itself, its timestamp, and the source it was published on.
  • Your public handle, display name, and public profile identifiers.
  • Links you published, and the relationships between your posts and other posts, which may be stored as nodes and edges in a graph database where the monitoring user has consented to graph storage. For shared graph records, one consenting monitoring user is enough for the record to be written.
  • Derived data: machine translations, and, where a customer has enabled it, AI-generated summaries or classification labels.

6.2 Where it comes from

Only from the source platform itself: the Telegram API, the Bluesky AT Protocol, or the published feed. We do not buy data sets, we do not scrape private or access-restricted content, and we do not attempt to bypass access controls.

6.3 Why it is processed

The legal basis is the legitimate interest of our customers in conducting lawful monitoring of publicly published information, and our legitimate interest in providing the tooling for it, under Article 6(1)(f). The customer organization is the controller for that monitoring and decides its purpose. We do not use this content for our own commercial purposes, we do not sell it, and we do not use it to advertise to you.

6.4 Your rights

You have the rights set out in section 15, including the right to object to this processing under Article 21 and the right to ask for your data to be erased. Write to contact@tidewater-intelligence.com with enough detail to identify the content, for example the handle or profile URL. We will act on the request in the records we control and, where we act as a processor, pass it to the relevant customer organization and support them in responding. We will tell you the outcome within one month, or explain why we need longer.

Where a request would defeat a lawful and proportionate monitoring activity, for example an ongoing security investigation, the customer may rely on an exemption. In that case we will say so rather than silently decline.

7. How We Use Personal Data

We use personal data to:

  • Provide, operate, and maintain the platform.
  • Collect content from the sources a customer configures, match it against keywords, and generate alerts.
  • Deliver notifications through the channels a user selects, and produce reports, briefings, exports, and investigations.
  • Authenticate users and enforce organization access policies.
  • Protect the service: rate limiting, abuse detection, account lockout, audit logging, and incident response.
  • Support customers, including consent-gated support access described in section 14.
  • Maintain the service: diagnose faults, monitor capacity, and improve reliability.
  • Comply with legal obligations and respond to lawful requests.

We do not sell personal data, we do not share it with advertising networks, and we do not use it for automated decisions that produce legal or similarly significant effects on an individual.

8. AI and Automated Processing

The platform uses two kinds of models, and the distinction matters for where your data goes:

  • Self-hosted models. Machine translation, and message classification where an organization has enabled it, run on models hosted on our own infrastructure in the EU. Content submitted for translation or classification is not sent to a third-party model provider.
  • Third-party models. AI reports, catch-up briefings, keyword suggestions, and natural-language channel discovery use an external AI model provider. Content submitted for those features is transferred to that provider in the United States under the safeguards described in section 11. The provider is named in the sub-processor register available under section 10.

Third-party AI features are consent-gated and are off unless an organization enables them and the required consent is recorded. AI output is labelled as machine-generated in the product, and reports cite the specific alert or source message behind each statement so that a human can verify it. AI output is advisory: it does not by itself trigger any decision about a person.

In line with the transparency obligations of the EU AI Act (Regulation (EU) 2024/1689, Article 50): AI-generated text such as briefings, reports, and summaries is visibly labelled in the product and carries a machine-readable AI marker in downloads and delivery payloads; machine-translated message text is identified as such wherever it is shown or delivered; and automated interfaces such as the Sonar Telegram bot identify themselves as automated systems. The platform does not generate or manipulate image, audio, or video content and produces no deepfakes, and it operates no emotion recognition or biometric categorisation systems.

10. Sharing and Sub-processors

We share personal data only with the categories of recipients below, with the organization you belong to, where the law requires it, or where you direct us to (for example by configuring a webhook endpoint). A named register of our sub-processors, including the specific vendors behind each category, is available to organization customers on request under our data processing terms via contact@tidewater-intelligence.com.

Recipient categoryPurposeLocationData categoriesTransfer basis
AI model providerGeneration of catch-up briefings, recurring reports, and natural-language discovery, only where the organization has enabled AI features and the required consent is on record.United StatesMessage content and metadata submitted for analysis, prompts entered by the user, and the generated output.Standard Contractual Clauses (GDPR Art. 46(2)(c)).
SMS delivery providerSMS alert delivery, where enabled and consented to.EU processing regionRecipient mobile number and the notification text, which may contain an extract of a matched message.Processing in the EEA. Onward carrier routing to a recipient outside the EEA relies on Art. 49(1)(b).
Email delivery providerOutbound platform email: alert digests, notifications, invitations, and contact form forwarding.SwitzerlandRecipient email address, sender address, subject line, and message body.European Commission adequacy decision for Switzerland (GDPR Art. 45).
Sign-in identity providerOAuth sign-in for accounts not using enterprise SSO.SwitzerlandEmail address or alias, account identifier, and display name returned by the provider.European Commission adequacy decision for Switzerland (GDPR Art. 45).
Network infrastructure providerCarries outbound connections from the platform to source platforms.Germany (EU)Connection metadata only: timestamps, source IP address, destination port. Connection payloads are encrypted between the platform and the source platform and are not readable in transit.Processing within the EEA. No transfer to a third country. Data processing agreement on file.
Telegram (source platform)Independent controller for its own service. The platform connects to Telegram to read channels the customer has chosen to monitor and to deliver Telegram notifications.Outside the EEA (as determined by Telegram)Account identifiers and session credentials of the connecting user, requested channel identifiers, and any message the user sends through the platform.GDPR Art. 49(1)(b): transfer necessary to perform the connection the user has requested.
Bluesky (source platform)Independent controller for its own service. The platform polls public profiles and threads the customer has chosen to monitor.United States and distributed hosting operatorsRequested handles and post identifiers, plus the network metadata of the platform request. Content retrieved is public content published by the account holder.GDPR Art. 49(1)(b) for outbound requests. Content retrieval is of data the publisher has made public.
RSS and Atom feed origins (source)Independent publishers whose feed URLs are chosen by the customer. The platform fetches the feed on a schedule.Determined by the feed URL the customer configuresHTTP request metadata of the platform fetcher. No customer account data is transmitted.Customer-controlled. The customer selects the origin and therefore the destination of the request.
Graph data storeStorage of the message, sender, and link graph used by the Atlas module. Written only for users who have granted graph data consent.Platform-operated in the EU, or a customer-connected instance in a location the customer determines.Message records and text, sender handles and display names, channel and feed records, extracted links, and the relationships between them.Processing within the EEA for the platform-operated instance. For a customer-connected instance the customer is responsible for location and safeguards.
Enterprise SSO identity providersAuthentication, where an organization has configured its own OIDC or SAML identity provider.Determined by the customer organizationAuthentication assertions: email address, display name, and any group or role claims the identity provider is configured to release.Customer-controlled. The customer selects the identity provider, its location, and the applicable safeguards.
Signal (notification delivery)Delivery of alert and report notifications to an organization Signal group, where provisioned and opted into.United States (service operator)Recipient group identifier and the notification content, end-to-end encrypted in transit and not readable by the service operator.GDPR Art. 49(1)(b): transfer necessary to perform the requested delivery.
Self-hosted translation and classification modelsMachine translation of monitored messages and, where enabled, message classification.Platform infrastructure in the EUMessage content submitted for translation or classification, and the generated output.Not a sub-processor transfer. The models run on platform infrastructure and no data is sent to a third-party model provider.
VK (source platform)Independent controller for its own service. Where an organization has been provisioned with a VK API credential and the user has granted VK API consent, Atlas searches VK for profiles and, where the user explicitly triggers it, retrieves the friend, family, follower, and community network of a profile.Russian FederationThe search term the user enters, which is typically a person's name, the organization API credential, and the network metadata of the platform request. Profile data returned by VK is stored in the graph database.GDPR Art. 49(1)(b): transfer necessary to perform the lookup the user has requested. The Russian Federation is not covered by an adequacy decision and no Standard Contractual Clauses are in place with VK, so this transfer carries a higher risk than the others listed here. The feature is off by default and requires both organization provisioning and individual consent.

10.1 Within your organization

Administrators and owners of your organization can see membership, role, activity logs, security events, consent status, and usage for their organization. Where an organization has enabled end-to-end encryption, an organization master key allows administrators to recover encrypted records belonging to the organization.

10.2 Legal requirements

We may disclose data where we are legally required to, for example in response to a binding court order. We assess each request, disclose only what is required, and notify the affected customer unless we are prohibited from doing so.

10.3 Business transfers

If the business is merged, acquired, or sold, personal data may transfer to the acquirer as part of that transaction. We will notify affected customers before any such transfer takes effect and the acquirer remains bound by this policy until it is lawfully changed.

10.4 Changes to this list

We maintain a named internal register behind this table. Where we add a sub-processor that materially affects customer data, we will update this page and inform organization administrators.

11. International Transfers

The platform is operated from infrastructure in the European Union. The following transfers outside the EEA take place:

  • AI model provider, United States. Content submitted to AI report, briefing, keyword suggestion, and discovery features. Transferred under Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c)), together with the vendor data processing addendum.
  • Email delivery and sign-in identity providers, Switzerland. Outbound email and OAuth authentication. Switzerland is covered by a European Commission adequacy decision (Art. 45), so no additional safeguard is required.
  • Telegram. Requests and account credentials necessary to connect to the Telegram network on your instruction, under Art. 49(1)(b). Telegram acts as an independent controller for its own service.
  • Bluesky and AT Protocol hosts, United States and elsewhere. Requests for public content on the profiles a customer monitors, under Art. 49(1)(b).
  • VK, Russian Federation. Search terms and lookup requests sent when your organization has been provisioned for the VK integration and you have granted VK API consent, under Art. 49(1)(b). The Russian Federation is not covered by a European Commission adequacy decision and there are no Standard Contractual Clauses in place with VK, so this transfer carries a higher risk than the others listed here. The feature is off unless an organization is explicitly provisioned for it.
  • Signal Messenger LLC, United States. Delivery of notifications to an organization Signal group, under Art. 49(1)(b). The content is end-to-end encrypted in transit and is not readable by the service operator.
  • Customer-directed destinations. Webhook endpoints, enterprise identity providers, and customer-hosted graph databases are chosen by the customer, who determines the destination country and is responsible for the safeguards applying to it.

Our network infrastructure provider, through which outbound connections to source platforms transit, is located in Germany, so that is not a transfer outside the EEA. SMS is processed in our SMS provider's EU region; delivery to a recipient outside the EEA depends on the mobile carrier and relies on Art. 49(1)(b).

A copy of the relevant transfer safeguards is available on request from contact@tidewater-intelligence.com.

12. Data Retention

Automated cleanup jobs run daily and enforce the periods below. Where a period is described as a default, an organization deployment may configure a different value within the limits the platform allows.

DataRetention
Account and organization recordsUntil the account or organization is deleted. On deletion, records that must be preserved for audit integrity are anonymized rather than removed.
Alerts (matched messages)No age-based deletion. Alerts are pruned by count: when a user exceeds the applicable alert cap, the oldest alerts are deleted first. An alert can therefore persist indefinitely while the cap is not exceeded.
Collected source messagesNo automated age-based deletion. Retained while the channel, profile, or feed remains configured, and removed when the source, the account, or the organization is deleted.
Saved messagesUntil deleted by the user. Capped at 5,000 saved messages per user.
Activity logs90 days by default.
Security events14 days for organization-scoped events and 30 days for platform-wide events once exported to the organization SIEM, with a 90-day fallback for events that were never exported. Security events are never deleted on account closure; they are anonymized.
Health and service events7 days by default.
Consent history5 years, then anonymized rather than deleted, so the record that consent was given or withdrawn survives for audit purposes.
Translation usage records365 days by default.
Telegram connection metrics90 days by default.
Generated AI reports180 days, and at most the 50 newest reports per report schedule.
Saved dashboard briefings180 days, and at most the 100 newest briefings per user.
Crawl job records30 days once completed, 90 days if the job failed.
Account deletion requests24 hours. The confirmation link expires after 24 hours and the pending request is removed by the daily cleanup job.
Sessions, invitations, and verification tokensRemoved after expiry by the daily cleanup job.
Contact form submissionsRetained until the enquiry is handled, and in any case no longer than 24 months.

Two categories are deliberately never deleted outright: security events and consent history. When an account is closed, those records are anonymized instead, with the user identifier removed and the email replaced by a placeholder, so that the audit trail stays intact while ceasing to identify anyone.

You can request deletion of your data at any time, subject to the exceptions above. See section 15.

13. How We Protect Data

The platform applies the following technical measures:

  • In transit. TLS for all traffic between browsers, the platform, and its integrations.
  • At rest. AES-256-GCM encryption for multi-factor secrets, backup codes, API keys, proxy credentials, webhook secrets, and Telegram session data.
  • End-to-end encryption. Optional hybrid RSA-4096 and AES-256-GCM encryption for alerts, investigations, and generated reports. Keys are generated in the browser and the private key remains in browser storage on your device. Records are dual encrypted to the user key and an organization master key so that an organization can recover its own data.
  • Blind indexing. Keyword matching over encrypted records uses HMAC-SHA256 index values with a per-user salt, so matching does not require decrypting the content.
  • Authentication. OAuth and enterprise single sign-on, time-based one-time password or passkey multi-factor authentication, organization-enforced multi-factor policies, account lockout, session revocation, and a platform-wide forced re-authentication control.
  • Access control. Role-based permissions, per-request authorization checks, CSRF protection, and rate limiting on every API route.
  • Auditability. Immutable security events and activity logs, with optional export to an organization SIEM.

We operate controls aligned to the SOC 2 trust services criteria. We do not hold a SOC 2 attestation and do not claim certification under any scheme. If that changes, this section will be updated.

Two honest limits: end-to-end encryption protects records only for users who have registered encryption keys, and the server necessarily holds content in plain text for the short period during which it is collected, matched, translated, and encrypted. Users without keys registered have their records stored in plain text on the server.

If you believe you have found a vulnerability, write to contact@tidewater-intelligence.com.

14. Support Access and Platform Controls

14.1 Consent-gated support sessions

Our support staff can, in defined circumstances, open a session that shows them the product as you see it, in order to diagnose a problem. The rules are:

  • Consent first. By default, a request is sent to you and the session cannot start until you approve it.
  • Read-only by default. The session cannot make changes on your behalf unless write access is separately enabled; emergency sessions can never write.
  • Organization pre-approval. An organization can choose to pre-approve support sessions for its members, in which case requests are auto-approved without a separate prompt to the individual. This is an organization decision, visible to its administrators.
  • Emergency access. A read-only emergency path exists for incidents where waiting for approval would cause harm. It is hard-limited to read access, is logged as an emergency session, and triggers a notification.
  • Full audit trail. Every request, approval, denial, session start, write, and session end is recorded in an immutable audit log that is never deleted, and is available to your organization administrators.
  • Identity. The consent prompt identifies the request as coming from support rather than naming the individual staff member. The individual is recorded in the audit trail and named in the notification sent after the session.
  • End-to-end encrypted records stay encrypted during a support session. Support staff cannot read them without your keys.

14.2 SIEM export

An organization can configure export of its own security events to its security information and event management system. Where that is enabled, events relating to members of that organization, including masked IP addresses and event metadata, are sent to the destination the organization controls.

14.3 Platform controls

We retain a small number of operational controls that can affect your session: a platform-wide broadcast banner, a switch that pauses AI features, a switch that pauses outbound email, and a control that forces all users to sign in again. Each use is recorded in the audit log.

15. Your Rights

Under the GDPR you have the following rights in relation to your personal data:

Art. 15
Access

Obtain confirmation of whether we process your personal data and receive a copy of it.

Art. 16
Rectification

Have inaccurate or incomplete personal data corrected.

Art. 17
Erasure

Request deletion of your personal data where one of the grounds in the GDPR applies.

Art. 18
Restriction

Require us to limit processing while accuracy or the basis for processing is being verified.

Art. 20
Portability

Receive the data you provided in a structured, commonly used, machine-readable format.

Art. 21
Objection

Object at any time to processing based on legitimate interests, on grounds relating to your particular situation.

Art. 7(3)
Withdraw consent

Withdraw any consent you have given, at any time, without affecting the lawfulness of processing before withdrawal.

Art. 77
Complain

Lodge a complaint with a supervisory authority in the country where you live, work, or where the alleged infringement occurred.

Account holders can exercise most of these rights directly in account settings: consents can be reviewed and withdrawn, a full data export can be generated, and account deletion can be requested. For anything else, or if you do not have an account, write to contact@tidewater-intelligence.com.

We respond within one month. If a request is complex we may extend that by up to two further months and will tell you why. We do not charge for responding unless a request is manifestly unfounded or excessive. We may ask for information to verify your identity before acting.

Where we act as a processor for a customer organization, we will pass your request to that organization and assist it in responding.

16. Cookies and Local Storage

We use only first-party cookies that are strictly necessary to operate the service. There are no analytics, no advertising pixels, no third-party trackers, no session recording, and no cross-site tracking of any kind. Because every cookie we set is strictly necessary, no consent banner is required and none is shown.

NamePurposeTypeDuration
Session tokenKeeps you signed in. Set only after you authenticate. Named __Host-authjs.session-token in production.First-party, strictly necessarySession lifetime
CSRF tokenProtects form and API submissions against cross-site request forgery. Named __Host-csrf-token in production.First-party, strictly necessarySession lifetime
Sign-in flow cookiesShort-lived cookies that carry an invitation token or an enterprise single sign-on state value through the sign-in redirect.First-party, strictly necessaryMinutes, cleared once the flow completes
Theme preferenceStores your light or dark theme choice. This is browser local storage, not a cookie, and is never sent to the server.First-party, preference (local storage)Until you clear browser storage

The application also uses browser local storage and IndexedDB to hold interface preferences and, where end-to-end encryption is enabled, your private key. That data stays in your browser and is not transmitted to us. Clearing browser storage removes it, and clearing an encryption key without a backup makes encrypted records unrecoverable for that user.

17. Children

TideWater is a professional tool provided to organizations and is not directed at children. Accounts are issued by invitation to members of a customer organization and we do not knowingly create accounts for anyone under 16. If you believe a child holds an account, contact us and we will remove it.

18. Changes to This Policy

We update this policy when the platform changes or when the law requires. The current version is always published here with the date it took effect. Where a change materially affects how we process personal data, we will notify organization administrators and, where consent is involved, ask for it again before relying on it.

19. Complaints and Supervisory Authority

If you are unhappy with how we handle your personal data, tell us first at contact@tidewater-intelligence.com. We would rather fix it directly.

You also have the right under Article 77 of the GDPR to lodge a complaint with a supervisory authority. Our lead authority is:

You may also complain to the supervisory authority in the EU or EEA country where you live or work.

20. Contact

For any question about this policy or about your personal data: