Privacy Policy
This Privacy Policy explains how TideWater collects, uses, shares, and retains personal data in connection with the TideWater intelligence platform and its Sonar and Atlas modules.
TideWater is an invitation-only service for organizations. It processes two very different kinds of personal data: data about the people who hold accounts, and data about the people whose public posts our customers choose to monitor. This policy addresses both.
1. Who We Are and How to Contact Us
The controller for the personal data described in this policy is:
- TideWater
- Contact for privacy matters: contact@tidewater-intelligence.com
We have not appointed a data protection officer, because the appointment criteria in Article 37 of the GDPR do not currently apply to us. Privacy enquiries are handled at the address above.
Our lead supervisory authority is Datatilsynet, the Danish Data Protection Agency. See section 19 for how to complain.
2. Scope and Our Role
This policy covers:
- The TideWater platform, including the Sonar monitoring module and the Atlas graph module.
- The public TideWater website and its contact form.
2.1 Controller and processor roles
TideWater is sold to organizations, not to individual consumers. Our role depends on the data:
- We are the controller for account records, authentication data, security events, audit logs, billing contact details, website enquiries, and the operation and security of the platform itself.
- We act as a processor for the monitoring data an organization configures and collects: the channels, profiles, and feeds it selects, the keywords it defines, the messages that are collected as a result, and the investigations and reports it produces. The organization decides why and how that content is monitored and is the controller for it.
Organizations can request a data processing agreement covering the processor role by writing to contact@tidewater-intelligence.com.
3. Personal Data We Collect
3.1 Account data
- Email address, display name, and profile image, as released by your identity provider.
- Organization membership and role (audit, member, admin, or owner).
- Multi-factor authentication material: encrypted time-based one-time password secrets, encrypted backup codes, and registered passkey credentials.
- Public key material for end-to-end encryption. Private keys are generated in your browser and never leave your device.
3.2 Technical and usage data
- IP address and user agent, recorded for security purposes. IP addresses are masked before they are written to the database.
- Sign-in timestamps, session records, and session identifiers.
- Activity logs of actions taken in the product, and security events such as failed sign-ins, lockouts, and session revocations.
- Feature usage counters, including AI token consumption.
3.3 Monitoring configuration
- The Telegram channels, Bluesky profiles, and RSS or Atom feeds you add.
- Keywords, keyword groups, exclusions, and matching rules.
- Dashboards, saved searches, and report schedules.
- Telegram session credentials, stored encrypted, where you connect a personal Telegram account.
3.4 Content collected from monitored sources
When a source is monitored, we collect and store the content it publishes and the metadata around it. That content is written by third parties and can contain personal data about them and about anyone they mention. See section 6.
- Message text, timestamps, message identifiers, and the channel, profile, or feed it came from.
- Author handle, display name, and public profile identifiers.
- Attached media, subject to size and file-type limits, and links contained in the content.
- Machine translations, integrity hashes of saved messages, and, where enabled, AI-generated labels and summaries.
3.5 Notification delivery data
- Mobile number, where SMS notifications are enabled. Stored masked outside the delivery path.
- Webhook endpoint URLs and their signing secrets, stored encrypted.
- Telegram and Signal delivery identifiers for the destinations you select.
3.6 Website enquiries
- Name, email address, organization name if provided, and the content of your message.
- Basic anti-abuse signals, including a masked IP address and the time the form took to complete.
3.7 Commercial records
TideWater has no self-service checkout and takes no card details. Commercial terms are agreed with the customer organization and invoiced outside the product. We keep the contract and invoicing records required for that relationship.
4. Legal Bases for Processing
We process personal data only where Article 6 of the GDPR provides a basis for it. The basis depends on the activity:
| Processing activity | Legal basis |
|---|---|
| Creating and administering accounts and organizations, and providing the platform to the customer. | Performance of a contract, or steps taken at your request before entering into one (Art. 6(1)(b)). Where the contract is with your employer, our basis is the legitimate interest in performing that contract (Art. 6(1)(f)). |
| Collecting, indexing, translating, and searching content from the Telegram channels, Bluesky profiles, and RSS feeds a customer has chosen to monitor. | Legitimate interests of the customer and of the platform in operating a lawful monitoring service, balanced against the rights of the people concerned (Art. 6(1)(f)). |
| Generating alerts and delivering notifications through the dashboard, Telegram, email, webhooks, SMS, and Signal. | Performance of the contract (Art. 6(1)(b)) for in-product delivery. Consent (Art. 6(1)(a)) for SMS, webhook, and AI-assisted delivery paths, which are individually consent-gated. |
| Machine translation, AI report generation, AI briefings, and AI keyword suggestions. | Consent (Art. 6(1)(a)), recorded per feature and withdrawable. |
| Storing message, sender, and link data in the graph database used by Atlas. | Consent (Art. 6(1)(a)) of the monitoring user, and separate organization consent where the graph is routed to infrastructure the organization controls. |
| Authentication, multi-factor authentication, rate limiting, abuse prevention, audit logging, and security event recording. | Legitimate interests in keeping the service and its customers secure (Art. 6(1)(f)), and compliance with legal obligations where they apply (Art. 6(1)(c)). |
| Responding to enquiries submitted through the contact form. | Steps taken at your request prior to entering into a contract, and our legitimate interest in responding to enquiries (Art. 6(1)(b) and (f)). |
| Product and service marketing communications. | Consent (Art. 6(1)(a)), withdrawable at any time. |
Where we rely on legitimate interests, we have weighed those interests against the rights and freedoms of the people concerned. You can ask us for the reasoning behind any of these assessments, and you can object to the processing under Article 21.
5. Special Category Data
TideWater does not ask for special category data and does not target it. However, the platform collects content published on public channels, profiles, and feeds, and that content can reveal political opinions, religious or philosophical beliefs, ethnic origin, trade union membership, health, or sexual orientation, whether about the author or about people they write about. Article 9 of the GDPR treats that as special category data.
We do not consider that content to be provided to us for our own purposes. Our customers decide what to monitor, and they are responsible for having a valid Article 9 condition, where one is required, for the purpose they are pursuing. The terms of service require that.
These safeguards apply to reduce the risk:
- Purpose limitation. Content is collected only from sources a customer has explicitly configured, and is used only to operate monitoring, search, and reporting for that customer.
- Scoped access. Content is segregated by organization and by user, with role-based access control and enforced multi-factor authentication available to organizations.
- Encryption. Organizations can enable end-to-end encryption for alerts, investigations, and generated reports, so that stored records are opaque to the server. Keyword matching over encrypted records uses blind indexing rather than decryption.
- Retention limits and deletion. Retention is set out in section 12, and any monitored source and its collected content can be deleted by the customer at any time.
- No profiling of the wider public. We do not build or sell profiles of monitored individuals, and we do not use monitored content to train models for other customers.
6. People Whose Public Content We Process
If you post publicly on Telegram, Bluesky, or a website that publishes an RSS or Atom feed, your content may be collected by TideWater because one of our customers has chosen to monitor that source. You do not have an account with us, but you are still a data subject and this section is your notice under Articles 13 and 14 of the GDPR.
6.1 What is processed
- The public content itself, its timestamp, and the source it was published on.
- Your public handle, display name, and public profile identifiers.
- Links you published, and the relationships between your posts and other posts, which may be stored as nodes and edges in a graph database where the monitoring user has consented to graph storage. For shared graph records, one consenting monitoring user is enough for the record to be written.
- Derived data: machine translations, and, where a customer has enabled it, AI-generated summaries or classification labels.
6.2 Where it comes from
Only from the source platform itself: the Telegram API, the Bluesky AT Protocol, or the published feed. We do not buy data sets, we do not scrape private or access-restricted content, and we do not attempt to bypass access controls.
6.3 Why it is processed
The legal basis is the legitimate interest of our customers in conducting lawful monitoring of publicly published information, and our legitimate interest in providing the tooling for it, under Article 6(1)(f). The customer organization is the controller for that monitoring and decides its purpose. We do not use this content for our own commercial purposes, we do not sell it, and we do not use it to advertise to you.
6.4 Your rights
You have the rights set out in section 15, including the right to object to this processing under Article 21 and the right to ask for your data to be erased. Write to contact@tidewater-intelligence.com with enough detail to identify the content, for example the handle or profile URL. We will act on the request in the records we control and, where we act as a processor, pass it to the relevant customer organization and support them in responding. We will tell you the outcome within one month, or explain why we need longer.
Where a request would defeat a lawful and proportionate monitoring activity, for example an ongoing security investigation, the customer may rely on an exemption. In that case we will say so rather than silently decline.
7. How We Use Personal Data
We use personal data to:
- Provide, operate, and maintain the platform.
- Collect content from the sources a customer configures, match it against keywords, and generate alerts.
- Deliver notifications through the channels a user selects, and produce reports, briefings, exports, and investigations.
- Authenticate users and enforce organization access policies.
- Protect the service: rate limiting, abuse detection, account lockout, audit logging, and incident response.
- Support customers, including consent-gated support access described in section 14.
- Maintain the service: diagnose faults, monitor capacity, and improve reliability.
- Comply with legal obligations and respond to lawful requests.
We do not sell personal data, we do not share it with advertising networks, and we do not use it for automated decisions that produce legal or similarly significant effects on an individual.
8. AI and Automated Processing
The platform uses two kinds of models, and the distinction matters for where your data goes:
- Self-hosted models. Machine translation, and message classification where an organization has enabled it, run on models hosted on our own infrastructure in the EU. Content submitted for translation or classification is not sent to a third-party model provider.
- Third-party models. AI reports, catch-up briefings, keyword suggestions, and natural-language channel discovery use an external AI model provider. Content submitted for those features is transferred to that provider in the United States under the safeguards described in section 11. The provider is named in the sub-processor register available under section 10.
Third-party AI features are consent-gated and are off unless an organization enables them and the required consent is recorded. AI output is labelled as machine-generated in the product, and reports cite the specific alert or source message behind each statement so that a human can verify it. AI output is advisory: it does not by itself trigger any decision about a person.
In line with the transparency obligations of the EU AI Act (Regulation (EU) 2024/1689, Article 50): AI-generated text such as briefings, reports, and summaries is visibly labelled in the product and carries a machine-readable AI marker in downloads and delivery payloads; machine-translated message text is identified as such wherever it is shown or delivered; and automated interfaces such as the Sonar Telegram bot identify themselves as automated systems. The platform does not generate or manipulate image, audio, or video content and produces no deepfakes, and it operates no emotion recognition or biometric categorisation systems.
9. Consent and Consent Tracking
Features that send data to a third party, or that carry a meaningful privacy choice, are individually consent-gated. Consent is recorded with a timestamp and the policy version in force at the time, and each grant or withdrawal is written to an immutable consent history.
The full set of consents tracked in the product:
| Consent | Covers |
|---|---|
| Privacy policy | Acceptance of this policy. |
| Terms of service | Acceptance of the terms of service. |
| Translation | Machine translation of monitored messages using the self-hosted translation model. |
| Webhook notifications | Sending alert data to an external endpoint that you configure. |
| Data export | Producing a downloadable export of your personal data. |
| Marketing | Receiving product and service communications. |
| AI synonym suggestions | Submitting keyword text to an AI model to suggest related terms. |
| AI research analysis | Submitting monitored content to an AI model to generate reports and briefings. |
| SMS notifications | Sending alert notifications to your mobile number. |
| Graph data | Storing message, sender, and link data in the graph database used by Atlas. |
| External graph infrastructure (read) | Organization consent to query and display graph data held in an instance the organization controls. |
| External graph infrastructure (write) | Organization consent to route graph data to an instance the organization controls. |
| External graph infrastructure (legacy) | A superseded combined consent, retained only for historical records. It is no longer requested. |
| VK API | Searching VK for profiles from Atlas and, where you explicitly trigger it, retrieving the friend, family, follower, and community network of a VK profile into the graph. Available only where your organization has been provisioned with a VK credential. |
| Bluesky monitoring | Monitoring Bluesky profiles and indexing the reply networks around them. |
| RSS monitoring | Monitoring RSS and Atom feeds and indexing their items. |
You can review and change every consent in your account settings. Under Article 7(3) of the GDPR you may withdraw consent at any time, and withdrawal is as easy as granting it. Withdrawal stops the feature going forward and does not affect the lawfulness of processing carried out before it. Consent history is retained for the period set out in section 12, in anonymized form after that, so that we can evidence what was agreed and when.
11. International Transfers
The platform is operated from infrastructure in the European Union. The following transfers outside the EEA take place:
- AI model provider, United States. Content submitted to AI report, briefing, keyword suggestion, and discovery features. Transferred under Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c)), together with the vendor data processing addendum.
- Email delivery and sign-in identity providers, Switzerland. Outbound email and OAuth authentication. Switzerland is covered by a European Commission adequacy decision (Art. 45), so no additional safeguard is required.
- Telegram. Requests and account credentials necessary to connect to the Telegram network on your instruction, under Art. 49(1)(b). Telegram acts as an independent controller for its own service.
- Bluesky and AT Protocol hosts, United States and elsewhere. Requests for public content on the profiles a customer monitors, under Art. 49(1)(b).
- VK, Russian Federation. Search terms and lookup requests sent when your organization has been provisioned for the VK integration and you have granted VK API consent, under Art. 49(1)(b). The Russian Federation is not covered by a European Commission adequacy decision and there are no Standard Contractual Clauses in place with VK, so this transfer carries a higher risk than the others listed here. The feature is off unless an organization is explicitly provisioned for it.
- Signal Messenger LLC, United States. Delivery of notifications to an organization Signal group, under Art. 49(1)(b). The content is end-to-end encrypted in transit and is not readable by the service operator.
- Customer-directed destinations. Webhook endpoints, enterprise identity providers, and customer-hosted graph databases are chosen by the customer, who determines the destination country and is responsible for the safeguards applying to it.
Our network infrastructure provider, through which outbound connections to source platforms transit, is located in Germany, so that is not a transfer outside the EEA. SMS is processed in our SMS provider's EU region; delivery to a recipient outside the EEA depends on the mobile carrier and relies on Art. 49(1)(b).
A copy of the relevant transfer safeguards is available on request from contact@tidewater-intelligence.com.
12. Data Retention
Automated cleanup jobs run daily and enforce the periods below. Where a period is described as a default, an organization deployment may configure a different value within the limits the platform allows.
| Data | Retention |
|---|---|
| Account and organization records | Until the account or organization is deleted. On deletion, records that must be preserved for audit integrity are anonymized rather than removed. |
| Alerts (matched messages) | No age-based deletion. Alerts are pruned by count: when a user exceeds the applicable alert cap, the oldest alerts are deleted first. An alert can therefore persist indefinitely while the cap is not exceeded. |
| Collected source messages | No automated age-based deletion. Retained while the channel, profile, or feed remains configured, and removed when the source, the account, or the organization is deleted. |
| Saved messages | Until deleted by the user. Capped at 5,000 saved messages per user. |
| Activity logs | 90 days by default. |
| Security events | 14 days for organization-scoped events and 30 days for platform-wide events once exported to the organization SIEM, with a 90-day fallback for events that were never exported. Security events are never deleted on account closure; they are anonymized. |
| Health and service events | 7 days by default. |
| Consent history | 5 years, then anonymized rather than deleted, so the record that consent was given or withdrawn survives for audit purposes. |
| Translation usage records | 365 days by default. |
| Telegram connection metrics | 90 days by default. |
| Generated AI reports | 180 days, and at most the 50 newest reports per report schedule. |
| Saved dashboard briefings | 180 days, and at most the 100 newest briefings per user. |
| Crawl job records | 30 days once completed, 90 days if the job failed. |
| Account deletion requests | 24 hours. The confirmation link expires after 24 hours and the pending request is removed by the daily cleanup job. |
| Sessions, invitations, and verification tokens | Removed after expiry by the daily cleanup job. |
| Contact form submissions | Retained until the enquiry is handled, and in any case no longer than 24 months. |
Two categories are deliberately never deleted outright: security events and consent history. When an account is closed, those records are anonymized instead, with the user identifier removed and the email replaced by a placeholder, so that the audit trail stays intact while ceasing to identify anyone.
You can request deletion of your data at any time, subject to the exceptions above. See section 15.
13. How We Protect Data
The platform applies the following technical measures:
- In transit. TLS for all traffic between browsers, the platform, and its integrations.
- At rest. AES-256-GCM encryption for multi-factor secrets, backup codes, API keys, proxy credentials, webhook secrets, and Telegram session data.
- End-to-end encryption. Optional hybrid RSA-4096 and AES-256-GCM encryption for alerts, investigations, and generated reports. Keys are generated in the browser and the private key remains in browser storage on your device. Records are dual encrypted to the user key and an organization master key so that an organization can recover its own data.
- Blind indexing. Keyword matching over encrypted records uses HMAC-SHA256 index values with a per-user salt, so matching does not require decrypting the content.
- Authentication. OAuth and enterprise single sign-on, time-based one-time password or passkey multi-factor authentication, organization-enforced multi-factor policies, account lockout, session revocation, and a platform-wide forced re-authentication control.
- Access control. Role-based permissions, per-request authorization checks, CSRF protection, and rate limiting on every API route.
- Auditability. Immutable security events and activity logs, with optional export to an organization SIEM.
We operate controls aligned to the SOC 2 trust services criteria. We do not hold a SOC 2 attestation and do not claim certification under any scheme. If that changes, this section will be updated.
Two honest limits: end-to-end encryption protects records only for users who have registered encryption keys, and the server necessarily holds content in plain text for the short period during which it is collected, matched, translated, and encrypted. Users without keys registered have their records stored in plain text on the server.
If you believe you have found a vulnerability, write to contact@tidewater-intelligence.com.
14. Support Access and Platform Controls
14.1 Consent-gated support sessions
Our support staff can, in defined circumstances, open a session that shows them the product as you see it, in order to diagnose a problem. The rules are:
- Consent first. By default, a request is sent to you and the session cannot start until you approve it.
- Read-only by default. The session cannot make changes on your behalf unless write access is separately enabled; emergency sessions can never write.
- Organization pre-approval. An organization can choose to pre-approve support sessions for its members, in which case requests are auto-approved without a separate prompt to the individual. This is an organization decision, visible to its administrators.
- Emergency access. A read-only emergency path exists for incidents where waiting for approval would cause harm. It is hard-limited to read access, is logged as an emergency session, and triggers a notification.
- Full audit trail. Every request, approval, denial, session start, write, and session end is recorded in an immutable audit log that is never deleted, and is available to your organization administrators.
- Identity. The consent prompt identifies the request as coming from support rather than naming the individual staff member. The individual is recorded in the audit trail and named in the notification sent after the session.
- End-to-end encrypted records stay encrypted during a support session. Support staff cannot read them without your keys.
14.2 SIEM export
An organization can configure export of its own security events to its security information and event management system. Where that is enabled, events relating to members of that organization, including masked IP addresses and event metadata, are sent to the destination the organization controls.
14.3 Platform controls
We retain a small number of operational controls that can affect your session: a platform-wide broadcast banner, a switch that pauses AI features, a switch that pauses outbound email, and a control that forces all users to sign in again. Each use is recorded in the audit log.
15. Your Rights
Under the GDPR you have the following rights in relation to your personal data:
Obtain confirmation of whether we process your personal data and receive a copy of it.
Have inaccurate or incomplete personal data corrected.
Request deletion of your personal data where one of the grounds in the GDPR applies.
Require us to limit processing while accuracy or the basis for processing is being verified.
Receive the data you provided in a structured, commonly used, machine-readable format.
Object at any time to processing based on legitimate interests, on grounds relating to your particular situation.
Withdraw any consent you have given, at any time, without affecting the lawfulness of processing before withdrawal.
Lodge a complaint with a supervisory authority in the country where you live, work, or where the alleged infringement occurred.
Account holders can exercise most of these rights directly in account settings: consents can be reviewed and withdrawn, a full data export can be generated, and account deletion can be requested. For anything else, or if you do not have an account, write to contact@tidewater-intelligence.com.
We respond within one month. If a request is complex we may extend that by up to two further months and will tell you why. We do not charge for responding unless a request is manifestly unfounded or excessive. We may ask for information to verify your identity before acting.
Where we act as a processor for a customer organization, we will pass your request to that organization and assist it in responding.
17. Children
TideWater is a professional tool provided to organizations and is not directed at children. Accounts are issued by invitation to members of a customer organization and we do not knowingly create accounts for anyone under 16. If you believe a child holds an account, contact us and we will remove it.
18. Changes to This Policy
We update this policy when the platform changes or when the law requires. The current version is always published here with the date it took effect. Where a change materially affects how we process personal data, we will notify organization administrators and, where consent is involved, ask for it again before relying on it.
19. Complaints and Supervisory Authority
If you are unhappy with how we handle your personal data, tell us first at contact@tidewater-intelligence.com. We would rather fix it directly.
You also have the right under Article 77 of the GDPR to lodge a complaint with a supervisory authority. Our lead authority is:
- Datatilsynet (the Danish Data Protection Agency), https://www.datatilsynet.dk
You may also complain to the supervisory authority in the EU or EEA country where you live or work.
20. Contact
For any question about this policy or about your personal data:
- Email: contact@tidewater-intelligence.com
- Account holders can also raise a request from within the application.