Tadlace
Legal Document

Security & Data

Updated in: October 3, 2026

This page explains, in plain terms, what data Tadlace handles, where it lives, who processes it, and how long we keep it.

It is written for the security, compliance and procurement teams who review Tadlace before it is used inside their organization. The full legal terms are in our Privacy Policy. If your team has a security questionnaire, send it to support@tadlace.com and we will complete it.

1. What We Collect

From account holders

The people at your organization who create and host experiences:

  • Name, email address and company name
  • Login credentials
  • Billing details (handled by our payment processors)
  • Quizzes, questions and files you upload

From participants

The people who join your experiences. You decide which of these fields to ask for:

  • Name or nickname
  • Email address, if you ask for it
  • Answers, scores and rankings
  • Any extra fields you add to the experience

Automatically

  • Usage analytics and log data
  • Cookies needed to keep sessions signed in

2. Who Controls the Data

For participant data, your organization is the data controller: you decide what to collect and what it is used for. Tadlace is the data processor: we store and process it on your behalf to run the experience and produce your reports.

We do not sell participant data, and we do not use one customer’s participant data for another customer.

3. Where Data Is Hosted

The Tadlace application runs on Fly.io in the US East region. Our database and cache run on Heroku, which stores them on Amazon Web Services infrastructure, also in US East.

This means data from participants is transferred to and stored in the United States. See section 9 for how that transfer is handled.

4. Subprocessors

These are the third parties that process data on our behalf. Each receives only what it needs for its purpose.

ProviderPurpose
Fly.ioApplication servers
Heroku (Salesforce), on Amazon Web ServicesDatabase and cache
OpenAIAI question generation, insights and summaries
PaystackPayment processing
FlutterwavePayment processing
BrevoTransactional email, such as reward and account emails

If you connect Tadlace to Zapier, participant data you choose to send is passed to Zapier and on to the apps you connect. That connection is set up and controlled by you.

5. AI Processing

AI features (question generation, participant insights and report summaries) send the relevant content to OpenAI through its API.

Under OpenAI’s API terms, data sent through the API is not used to train OpenAI’s models.

6. Payments

Payments are processed by Paystack and Flutterwave. Card details are entered on their checkout and held by them. Tadlace does not store full card numbers.

7. How We Protect Data

  • All traffic to Tadlace is encrypted in transit over HTTPS (TLS).
  • Access to production systems is limited to the Tadlace team members who need it to run the service.
  • Integration API keys are shown once, can be regenerated at any time, and stop working the moment they are regenerated.
  • Each organization’s data is separated by account, and team access is managed by the account owner.

8. Retention and Deletion

We keep account and participant data for as long as your account exists, so your past experiences and reports stay available. We do not delete it on a fixed schedule.

You can ask us to delete data at any time:

  • Your whole account and everything in it
  • Specific participants’ data, for example when one of them asks you to remove it

Email support@tadlace.com from the account owner’s address. If a participant contacts us directly, we will work with the organization that ran the experience, since it is the controller of that data.

9. NDPA and GDPR

We handle personal data in line with the NDPA and, for people in the European Union and United Kingdom, the General Data Protection Regulation (GDPR).

Under both, the people whose data we hold can ask to access, correct, delete or export it, and can object to or restrict how it is used. Requests go to support@tadlace.com.

Because our hosting is in the United States, personal data is transferred outside the EU and UK. If your organization needs a data processing agreement covering this, contact us.

10. Contact

For security questions, questionnaires, data requests or to report a vulnerability:

Tadlace

Email: support@tadlace.com

Give people something
worth joining

Build one in minutes. Share it by link, PIN or QR code, and see who took part and what they told you.