Privacy Policy
1. Who we are
Tunga Lead Intelligence is a product of Tunga BV, a private limited company incorporated in the Netherlands.
- Registered name: Tunga BV
- Registered office: Jan van Ghestellaan 40, 3054 CJ Rotterdam, The Netherlands
- Chamber of Commerce (KVK) number: 67015697
- VAT (BTW) number: NL856794636B01
- Privacy contact: Bart Leijssenaar — [email protected]
Tunga BV is the data controller for personal data processed via the Tunga Lead Intelligence website (leadintelligence.tunga.io) and the services described below. As a small company, Bart Leijssenaar currently serves as our privacy contact and acts in a Data Protection Officer capacity. If our scale or processing activities change in a way that requires a formally appointed external DPO, we will update this policy and notify users accordingly.
If you have a question about this policy or wish to exercise any of your rights, contact us at [email protected].
2. Scope of this policy
This policy explains how Tunga BV collects, uses, shares, and protects personal data of:
- Visitors to
leadintelligence.tunga.io - People who interact with the Signal Finder chat
- People who submit their email through the lead-capture form
- People who book a call via the Calendly integration
- People who contact us directly via email or other channels
3. Data we collect
3.1 Information you provide directly
- Signal Finder conversation data — the messages you type, the options you select, and any custom signals you describe.
- Business context — the business type you indicate at the start of the chat (e.g. "agency", "dev shop").
- Email address — when you submit your email at the end of the Signal Finder to receive your report.
- Calendar booking details — when you book a call via Calendly: name, email, time slot, and any free-text notes you provide.
- Other communications — when you email us or contact us through other channels.
3.2 Information collected automatically
- Technical data — IP address, browser type, operating system, device type, referring URL, pages visited, and time spent.
- Cookies and similar technologies — see Section 8.
- Server logs — kept by our hosting provider (Cloudflare) for security and performance.
3.3 We do not knowingly collect
- Special categories of personal data (health, religion, political views, etc.)
- Data from children under 16
- Payment or financial data (we do not process payments through this site)
4. How we use your data, and why
We process personal data for the purposes and on the legal bases listed below (GDPR Article 6).
| Purpose | Data used | Legal basis |
|---|---|---|
| Run the Signal Finder chat and generate a tailored result | Conversation messages, business type | Consent (you initiate the chat) and legitimate interest (operating the service) |
| Send you the requested report and follow-up emails | Email address, conversation context | Consent (you explicitly submit your email to receive the report) |
| Schedule and run sales calls booked via Calendly | Name, email, scheduling data | Contract / pre-contractual measures at your request |
| Improve our service (aggregate analysis of which signals matter to which segments) | Anonymised conversation patterns | Legitimate interest in improving the product |
| Site security, fraud detection, and abuse prevention | Technical data, IP address | Legitimate interest in keeping the site safe |
| Comply with legal obligations | Whatever is required | Legal obligation |
We do not sell personal data. We do not engage in automated decision-making with legal effects on you.
5. Who we share data with
We use a small number of trusted third parties ("sub-processors") to deliver this service. Each is bound by appropriate contractual safeguards.
| Sub-processor | Purpose | Location |
|---|---|---|
| Anthropic, PBC | LLM that powers the Signal Finder chat | United States |
| Cloudflare, Inc. | Website hosting, CDN, serverless backend (Workers) | Global, primary in EU/US |
| Twilio SendGrid | Lead-capture email delivery | United States |
| Calendly LLC | Call scheduling | United States |
We do not currently use third-party analytics, marketing, or CRM providers. If we add any in the future, we will update this policy before doing so.
We may also disclose personal data if required by law, court order, or to protect our rights or those of others.
We do not share personal data with third parties for their own marketing purposes.
6. International data transfers
Some of our sub-processors are based outside the European Economic Area (EEA), notably in the United States. When we transfer personal data outside the EEA, we rely on one or more of the following safeguards:
- EU Standard Contractual Clauses (SCCs) with the sub-processor.
- The EU-US Data Privacy Framework where the sub-processor is certified (Anthropic, Calendly, Cloudflare, and SendGrid are currently certified or operate under SCCs).
- Supplementary technical and organisational measures where appropriate.
A copy of the safeguards is available on request via [email protected].
7. How long we keep your data
We keep personal data only as long as necessary for the purposes described above.
| Data | Retention period |
|---|---|
| Signal Finder conversation transcripts (with identifiable info) | 24 months from your last interaction, then anonymised |
| Email address and lead-capture data | Until you unsubscribe, or 36 months of inactivity |
| Calendly booking records | 36 months from the booked meeting |
| Server logs | 30 days (Cloudflare default) |
| Anonymised, aggregated data | Indefinitely |
You can request earlier deletion at any time — see Section 9.
8. Cookies and similar technologies
We use only the minimum cookies necessary to run the site.
- Strictly necessary cookies — required for the site to function. Set by Cloudflare for security and performance (e.g. bot detection, load balancing). These cannot be disabled.
- Functional cookies — set by Calendly when you open the booking widget to schedule a call. These are only loaded if you interact with the booking flow.
We do not currently use analytics, marketing, or advertising cookies. If we add any in the future, we will update this policy and our cookie banner first.
A short cookie notice is shown on your first visit so you can accept or reject non-essential cookies. You can also adjust your browser settings to block cookies at any time.
9. Your rights under GDPR
If you are in the EEA, UK, or Switzerland, you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your data ("right to be forgotten") where one of the conditions in Article 17 GDPR applies.
- Restriction — request that we limit how we use your data while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format and transmit it to another controller.
- Objection — object to processing based on legitimate interest, including direct marketing.
- Withdraw consent — at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us at [email protected]. We will respond within one month (extendable by two further months for complex requests, with notice).
If you believe we have not handled your data properly, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority in your country of residence.
- Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl
10. Security
We take appropriate technical and organisational measures to protect personal data, including:
- Transport encryption — TLS 1.2+ on all connections to our site and APIs.
- Access controls — personal data is accessible only to staff and contractors with a legitimate need, under confidentiality obligations.
- Sub-processor due diligence — we choose providers with strong security postures (SOC 2, ISO 27001, equivalent).
- API key management — credentials for third-party APIs (including the LLM) are stored as encrypted secrets, never in code repositories.
- Logging and monitoring — we keep audit logs of access to personal data and review them periodically.
- Incident response — if a personal data breach occurs, we will notify the supervisory authority within 72 hours and affected individuals where required, in accordance with Articles 33 and 34 GDPR.
No system is fully immune to attack. Despite our safeguards, we cannot guarantee absolute security.
11. Children
This service is intended for business audiences and is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have collected such data, please contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top.
- Post a notice on the site for at least 30 days.
- For significant changes, notify you by email if we have your address.
We encourage you to review the policy periodically.
13. Contact
For questions about this policy or to exercise your rights:
Tunga BV — PrivacyJan van Ghestellaan 40
3054 CJ Rotterdam
The Netherlands
Email: [email protected]
KVK: 67015697
VAT: NL856794636B01