Security & Privacy

Your data, handled carefully

How we store, protect and handle your team’s data.

At a glance

Hosted in the EU

All customer data is hosted and stored on infrastructure in the European Union, with logical separation between customers.

Encrypted in transit and at rest

Data is encrypted in transit with TLS and encrypted at rest. Backups are encrypted too, kept within the EU, on a defined rotation and restoration schedule.

Access you control

Role-based access inside Teamistry mirrors the permission structure your admins configure.

01 — AI Agents

Your data is never used to train AI

The AI is useful because it sees your team’s context. We limit what leaves our servers, and our provider is bound by contract on the rest.

Bound by our provider’s contract

No model training

Our AI provider is engaged on terms that do not permit using your data to train AI models. We don’t use platform data for our own marketing and we don’t sell personal data.

Zero retention

The provider retains neither prompts nor responses. Inference runs exclusively on EU infrastructure, with no third-country transfer.

Done by Teamistry

Minimised before it leaves

Direct identifiers like names and emails are removed or pseudonymised before anything is sent, so the model receives only what it needs to answer.

02 — Isolation

Your organisation, sealed off

Keeping your data separate is built into how the system works.

Your organisation is on its own

Every record is tagged to your company, and every lookup is filtered by that tag. You get your own address, like yourcompany.teamistry.ai. A login for one company is refused on another.

Permissions follow your org chart

People see their own data, and team leads see the teams they lead. Our checks run on the server for security and in the browser for a good user experience.

Secure sign-ins

Use your Google account, or a password checked against length rules and known breached passwords. Sessions time out on their own.

03 — Reliability

How we build and run it

Protecting data also means not losing it. This is how changes ship and how we recover if something goes wrong.

Daily backups

Encrypted, kept in the EU, and taken every day. If data is lost or overwritten, we can restore to any moment in the past four weeks.

Separate test environment

Every change runs in a separate environment first, with its own servers and data. Nothing is deployed to your team untested.

Review before deploy

Each change is read by a real person and has to pass automated tests before it ships.

Error monitoring

Errors are reported to us as they happen, so we can diagnose faster and support you with more context.

04 — GDPR

GDPR, in practice

Teamistry is built and operated in the EU, under EU law.

You control the data

In GDPR terms you are the controller and we are the processor. We only handle it the way you tell us to.

Every company we rely on is listed

We publish the full list of services we rely on. Before we add or swap one, you get 30 days’ notice and 14 days to object.

Breaches reported within 48 hours

If your data is ever caught up in a breach, we tell your administrators within 48 hours of finding out.

We help when an employee asks

Your people can ask to see, correct, export or delete their data. Most of that can be done in Teamistry, and we step in when it cannot.

Sensitive data stays your call

Sick leave records and uploaded documents can contain health information. We treat it as especially sensitive, and you decide the grounds for collecting it.

Leaving is clean and finite

You can export everything for 30 days after leaving, and we delete all of it within 90. We will confirm in writing.

05 — FAQ

Frequently asked questions

In the European Union, all of it, including backups. A few services we rely on are run by companies based outside the EU; each is named on our subprocessors page, with a formal legal safeguard covering the transfer.

No, and neither does anyone we work with. Questions and answers are deleted once handled, and our AI provider is contractually barred from training on your data. Even our monitoring tools are EU-hosted, and record timings and errors, not conversation content.

Largely, yes, because they entered most of it. Workload, priorities, challenges and locations are all self-reported through Sync-In, and everyone can review their own history, goals, leave and documents at any time. Anonymous Spark Zone ideas stay anonymous, even from super users.

Only authorised staff, on a need-to-know basis. Our internal console shows reference numbers instead of employee names and strips out email addresses, so routine support work does not involve reading identifiable data at all.

Chat connections only post Teamistry notifications into a channel. For calendars we keep the shape of your week, meaning when meetings start and end and whether anyone else is invited. Titles, descriptions, locations and attendees are never stored.

You can export everything for 30 days after your agreement ends, and we delete it within 90, backups included. We will confirm in writing on request.

Yes. Ours meets Article 28 of the GDPR and is published in full, including our security measures and the services we rely on. Email us for a countersigned copy.

Questions from your security team?

We answer security questionnaires, walk through our architecture and sign DPAs.