Tawsik sealTAWSIK
Guidance, not legal advice. Tawsik helps you understand and work toward EU AI Act compliance, but it isn't legal advice and doesn't replace a qualified lawyer for your specific situation.

Privacy Policy

Last updated: 27 June 2026

1. Who we are

Tawsik ("Tawsik", "we") is operated by Anthony Zakkour, an individual (sole trader) based in France (postal code 95380), who is the data controller for personal data processed through the Service. Contact: legal@tawsik.com.

2. What we collect

  • Account data — your name, email address, and profile photo (from your sign-in provider, e.g. Google), your company name, and an optional company email.
  • Compliance data — the answers you give about your AI system, the resulting risk classification and obligations, and the documents and Trust Passports you generate.
  • Usage data — privacy-friendly, cookieless analytics and server logs used to operate and secure the Service. We do not build advertising profiles.
  • Billing data — handled by Stripe. We store your plan status and Stripe customer/subscription identifiers, never your full card details.

3. Why we use it (legal bases)

  • To provide the Service and your results — performance of a contract.
  • To secure and improve the Service — legitimate interests.
  • For optional marketing — consent.
  • To meet legal obligations — legal obligation.

4. Sub-processors

We share data only with the processors that run the Service, under data-processing agreements. We never sell your data.

  • Supabase — database & authentication.
  • Stripe — subscription payments.
  • Anthropic — AI document drafting (your profile and any optional system description are sent to draft a document).
  • Plausible Analytics — cookieless, privacy-friendly usage statistics (no personal data).
  • Railway — application hosting.
  • Resend — transactional email, where enabled.

5. International transfers

Where data is processed outside your region, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.

6. Retention

We keep personal data only as long as needed for the purposes above or as required by law. When you delete your account, your organisation's data is erased and any subscription is cancelled.

7. Your rights

Subject to applicable law (including the GDPR), you may request access, correction, deletion, restriction, portability, and may object to certain processing. You can export or permanently delete your data yourself from Profile → Privacy & your data in the app. Questions: legal@tawsik.com — you may also complain to your local supervisory authority.

8. Cookies

We use only essential cookies needed to run the Service (e.g. to keep you signed in). Our analytics (Plausible) is cookieless and stores no personal data, so it requires no tracking cookie.

9. Security

We protect your data with row-level access isolation between organisations, encryption in transit, rate limiting, and least-privilege access controls. No system is perfectly secure.

10. Children

The Service is not directed to children under 16, and we don't knowingly collect their data.

11. Changes

We may update this policy and will notify you of material changes.

12. Contact

Privacy questions: legal@tawsik.com.