Who we are and what this notice covers
TUNCBA LTD (Company No. 16706349), 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom, operates the TUNCBA software development platform. Contact our privacy team at privacy@tuncba.com.
For account registration, authentication, support, sales, security and business administration, TUNCBA generally determines why and how personal data is used and acts as a data controller. Where a business customer submits personal data inside project content and instructs TUNCBA to process that content solely to provide the service, TUNCBA generally acts as a processor for that customer, subject to the applicable contract or Data Processing Addendum.
Data we process
- Account information such as name, business email, password hash and account status.
- Project content, source code, transformation instructions and generated output submitted by authenticated users.
- Security and diagnostic data such as IP address, user agent, authentication events and timestamps.
- Support and sales communications that you choose to send us.
- Consent and privacy-request records required to demonstrate how preferences and rights requests were handled.
Purposes and lawful bases
We process account and project data to perform our contract and provide requested services; security and fraud-prevention data for our legitimate interests in protecting the platform and users; legal/compliance records where necessary to comply with law; and optional marketing only where consent or another valid lawful basis applies. We do not use optional marketing consent as a condition of service.
Project content
TUNCBA does not use customer project content in this release to train its own general-purpose foundation models. Customers should avoid submitting unnecessary personal data, credentials, secrets or special-category data. When TUNCBA acts as a processor, customer project content is processed on the customer's documented instructions as necessary to provide the development and transformation service, except where law requires otherwise.
Recipients and subprocessors
We may use hosting, database, security, email, support and approved software-processing providers to operate the service. Access is limited to the purpose for which each provider is engaged. Enterprise customers may request the current subprocessor information and contractual transfer mechanism before onboarding regulated workloads.
International transfers
Where personal data is transferred outside the UK or EEA, TUNCBA will use an applicable adequacy decision or appropriate contractual safeguards, such as the UK International Data Transfer Agreement/Addendum or EU Standard Contractual Clauses, where required.
Platform terms
These Terms govern use of the TUNCBA website and authenticated software-development workspace. By creating an account or using the service, you agree to these Terms and the Acceptable Use Policy.
Your account
You must provide accurate account information, keep credentials secure, use the service only for lawful business or development purposes, and promptly notify TUNCBA if you reasonably believe your account has been compromised. You are responsible for activity carried out through your account and by users you authorize.
Your content and generated output
You retain rights you hold in source code and other material you submit. Subject to third-party rights and applicable law, you may use generated output provided to you. You are responsible for determining whether output is suitable for your purpose. Generated output is probabilistic and may be inaccurate, incomplete, insecure, outdated or similar to output provided to others. Do not rely on it without appropriate independent review and testing.
No hidden guarantee
Unless an executed enterprise agreement states otherwise, the service is provided without a guaranteed uptime, response time, capacity level, certification or fitness for a particular production workload. Published demonstrations and sample metrics are not contractual performance commitments.
Suspension
TUNCBA may restrict or suspend access where reasonably necessary to address security incidents, non-payment, legal requirements, material policy violations, attempts to evade limits, compromise of credentials or risk to the platform or third parties. Where appropriate, we will provide notice and an opportunity to resolve the issue.
Third-party services
The platform may depend on third-party hosting, infrastructure and software-processing services. Their availability and permitted use may be subject to additional restrictions. Customers must not use TUNCBA to cause TUNCBA or its providers to breach applicable agreements or law.
Responsible use requirements
You and your authorized users must use TUNCBA in accordance with applicable law, these Terms, security controls and any restrictions that apply to upstream services used to provide a requested feature.
Prohibited uses
- Illegal activity, infringement of third-party rights, fraud, abuse, harassment or creation/distribution of malicious code intended to compromise systems without authorization.
- Attempting to bypass authentication, quotas, rate limits, safety mechanisms, access restrictions or technical controls.
- Reverse engineering, extracting or attempting to reconstruct underlying hosted models, service internals, model weights, hidden system instructions or proprietary infrastructure.
- Using platform output to train, fine-tune, distill or otherwise improve a competing general-purpose AI/foundation model where such activity is prohibited by the applicable upstream service terms or has not been expressly authorized in writing.
- Reselling or exposing the underlying inference/model service as a raw pass-through, model marketplace or credential-sharing service unless TUNCBA and the applicable upstream provider have expressly approved that arrangement in writing.
- Buying, selling, sharing or transferring service credentials, or enabling third parties to use an account in a way that defeats account-level controls.
- Submitting data you do not have the right or lawful basis to process, including unnecessary secrets, credentials or personal data.
- Using generated output as the sole basis for decisions that create material legal or similarly significant effects on individuals without appropriate human review, lawful basis and safeguards.
Developer responsibility
TUNCBA is intended to assist software development. You remain responsible for code review, licensing, dependency checks, testing, security assessment and deployment decisions. If you make generated output available to your own users, you should communicate that automated output can be incorrect and provide appropriate review or escalation mechanisms.
Controller and processor responsibilities
Where a customer controls the purposes and means of personal data contained in project content and TUNCBA processes that data only to provide the contracted service, the customer is normally the controller and TUNCBA is the processor. A production enterprise DPA should document subject matter, duration, nature and purpose of processing, data types, data-subject categories, confidentiality, security, subprocessors, breach assistance, data-subject requests, deletion/return and audit obligations.
For account administration, fraud prevention, service security, direct customer communications and TUNCBA's own legal obligations, TUNCBA may act as an independent controller.
If TUNCBA becomes aware of a personal-data breach affecting data it processes on a customer's behalf, the processor workflow is to notify the relevant customer without undue delay and provide information reasonably available to support the customer's own regulatory assessment. TUNCBA's controller-side incident process must assess applicable notification duties, including statutory deadlines where required.
Enterprise customers can request a DPA at privacy@tuncba.com.
How long information is kept
- Account and project data: while the account remains active and until deletion is requested or required for service/legal purposes.
- Password reset tokens: expire after one hour and are marked used after reset.
- Security/audit records: retained for a reasonable security investigation period; production deployments should configure and document a defined schedule.
- Sales/support messages: retained only as long as reasonably needed to respond, maintain business records and meet legal obligations.
- Backups: where enabled by the hosting environment, deletion follows the configured backup lifecycle and is addressed in enterprise processing terms.
Privacy requests
We aim to acknowledge and handle verified privacy requests within the period required by applicable law; under UK/EU GDPR this is generally one month, subject to permitted extensions or exceptions.
Depending on applicable law, you may have rights to access, rectify or erase personal data, restrict or object to processing, receive portable data, and withdraw consent. Authenticated users can submit requests from the Privacy Center and export core account/project data. You can also contact privacy@tuncba.com.
UK data subjects may also complain to the Information Commissioner's Office. EEA data subjects may contact their competent supervisory authority. Some rights are subject to legal exceptions and identity verification.