How we store, protect and process your team's data · Last updated: 15 August 2026
This page is written for the person asked to review us before a purchase. Everything below is current practice, not aspiration. If you need something that isn't here — a completed security questionnaire, a signed DPA, or a specific contractual term — email hello@tailabs.ai and we'll turn it around rather than route you through a sales cycle.
| Legal entity | SnapDrum Ltd (trading as The AI Internship), 124 City Road, London EC1V 2NX, United Kingdom |
|---|---|
| Governing regime | UK GDPR and the Data Protection Act 2018 |
| Encryption in transit | TLS on every connection to the platform and between us and our sub-processors |
| Database access control | Row-level security, enforced in the database rather than in application code |
| Authentication | Supabase Auth — email, magic link and Google OAuth. Admin access additionally requires 2FA |
| International transfers | UK GDPR Art 46 Standard Contractual Clauses, including the UK Addendum |
| DPA | Available on request before signature — hello@tailabs.ai |
| Data deletion | Self-serve from dashboard settings, or on verified request |
We are not currently SOC 2 or ISO 27001 certified, and we would rather say so here than let you discover it late in a procurement cycle. We operate under UK GDPR and the Data Protection Act 2018, we will complete your security questionnaire, and we will sign a DPA before you send us any data.
If a formal attestation is a hard requirement for your organisation, tell us at the start of the conversation — it changes what we can commit to and when, and that is a better discussion to have on day one than at contract stage.
On team plans, an employer sponsors access but does not get a window into the employee. This boundary is built into the product, not left to policy.
Every third party that may process customer data, and what it does. Where data leaves the UK/EU we rely on UK GDPR Art 46 Standard Contractual Clauses, including the UK Addendum.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database and authentication hosting | EU |
| Netlify | Website and application hosting | US / global edge |
| Cloudflare | Edge workers and page rendering for enrichment features | Global edge |
| Stripe, Inc. | Payment processing. Card numbers never reach our servers | US |
| Anthropic | AI model processing for platform features | US |
| AI model processing, and Google OAuth sign-in | US | |
| Resend | Transactional email (receipts, verification, notifications) | US |
| Maven Learning, Inc. | Only where you purchase a Maven-hosted programme. Maven is an independent controller of the data you give it | US |
| PostHog | Product analytics | EU |
Analytics and advertising partners used on our marketing pages are listed in the privacy policy.
| Account and learning data | For the life of the account. Deleted on verified account-deletion request. |
|---|---|
| Payment and accounting records | 7 years, as required for tax and audit. |
| Marketing data | Until you unsubscribe or object. |
| Anonymous usage logs for free-tool limits | Rolling 30-day window, plus aggregate statistics. |
An individual can delete their account and its data from dashboard settings. An administrator can request deletion for a departing employee, and seats can be reassigned without carrying the previous holder's private data across.
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk). Full detail is in the privacy policy.
If you believe you have found a security issue, email security@tailabs.ai with enough detail to reproduce it. We will acknowledge within two working days and keep you updated until it is resolved. Please give us a reasonable window to fix an issue before disclosing it publicly — we will not pursue anyone who reports in good faith and does not access or alter data belonging to other people.
Security questionnaires, DPAs, and architecture questions: hello@tailabs.ai. For a rollout conversation that includes your security team, book a call.