GDPR Compliance

How TyneBase ensures GDPR compliance for EU data protection.

Read time:6 minUpdated:2026-01-10

GDPR Compliance

TyneBase is designed for GDPR compliance from the ground up.

Our Commitment

  • All data processing within EU/UK data centers
  • Privacy by design and default
  • Complete data portability
  • Right to erasure support
  • Transparent data handling

Data Processing

Where Data is Stored

Data Type Location Provider
Database EU (Frankfurt) Supabase
File Storage EU (Frankfurt) Supabase
AI Processing EU endpoints OpenAI EU, Vertex AI
Embeddings EU (Frankfurt) Supabase pgvector

Data We Collect

Category Data Purpose Lawful Basis
Account Email, name Service provision Contract
Content Documents Core functionality Contract
Usage Page views, actions Analytics Legitimate interest
AI Prompts, generations AI features Consent

User Rights

Right of Access (Art. 15)

Export all your data:

  1. Go to SettingsPrivacy
  2. Click Export My Data
  3. Download JSON/ZIP archive

Export includes:

  • Profile information
  • All documents you created
  • Comments and discussions
  • Activity history

Right to Erasure (Art. 17)

Delete your account and data:

  1. Go to SettingsPrivacy
  2. Click Delete Account
  3. 30-day grace period begins
  4. Permanent deletion after 30 days

During grace period:

  • Account is deactivated
  • Data preserved but inaccessible
  • Can cancel deletion

Right to Portability (Art. 20)

Data export in machine-readable format:

  • JSON for structured data
  • Markdown for documents
  • CSV for activity logs

Control what data processing you allow:

Purpose Default Can Withdraw
Essential services Required No
Analytics Off Yes
AI processing Off Yes
Knowledge indexing Off Yes
  1. Go to SettingsPrivacyConsent
  2. Toggle each purpose on/off
  3. Changes take effect immediately

Data Protection Officer

Contact our DPO for privacy inquiries:

Breach Notification

In case of data breach:

  1. Detection and containment
  2. Assessment of risk
  3. Notification within 72 hours (if required)
  4. User communication
  5. Post-incident review