Privacy Policy
Version 1.0Effective 21 September 2026
This Privacy Policy explains what personal information Tarka collects when you use the platform (the "Service"), how we use and share it, and the choices you have. It applies to account holders and to visitors of our public pages. It does not cover the research datasets you upload to the Service ("Customer Data"), which we process on your organization's instructions as described in our Terms of Service and any data-processing agreement.
1. Information we collect
Account information. Name, email address, profile details you choose to add (such as job title or time zone), your organization and team memberships, and your role.
Sign-in and security information. Password hashes, passkeys, two-factor settings, a verified phone number if you enable text-message codes, identifiers for the browsers you sign in from, and session records. If you sign in through Google, Microsoft, or your organization's identity provider, we receive the profile fields that provider shares (typically your name, email address, and a provider identifier).
Usage and device information. IP address, approximate location derived from it, browser and operating system, pages and features used, and the timing and outcome of actions you take. This is recorded in our audit log, which exists to secure the Service and to satisfy the compliance obligations of research organizations.
Communications. Messages you send through contact or feedback forms, survey responses, and support correspondence.
Assistant interactions. If you use the in-app assistant, the prompts you send and the responses you receive are stored with your account so you can return to them.
We do not knowingly collect information from children under 16.
2. How we use information
- To provide, operate, and secure the Service, including authenticating you, enforcing your organization's policies, and detecting unusual sign-ins.
- To send service messages: verification codes, security alerts, invitations, and notices about changes to our terms or policies.
- To respond to your requests and support enquiries.
- To understand how the Service is used so that we can maintain and improve it.
- To comply with legal obligations and to establish, exercise, or defend legal claims.
We do not sell personal information and we do not use it for third-party advertising.
3. Legal bases
Where data-protection law requires a legal basis, we rely on: performance of our contract with you or your organization; our legitimate interests in securing and improving the Service; compliance with legal obligations; and, for optional features such as text-message codes, your consent, which you may withdraw at any time.
4. How we share information
- Your organization. Workspace owners and administrators can see your name, email address, role, activity within the workspace, and security status (for example, whether two-factor authentication is enabled).
- Service providers. Hosting, storage, email and SMS delivery, and similar providers that process information on our behalf under contractual confidentiality and security obligations.
- Identity providers. When you sign in through a third-party provider, that provider receives your sign-in request.
- Legal and safety. When required by law, legal process, or to protect the rights, safety, or property of users, the public, or Tarka.
- Business transfers. In connection with a merger, acquisition, or sale of assets, subject to this Policy.
5. Retention
We keep account information for as long as your account exists. Audit records are retained according to the retention period configured for the platform and for your organization. Records of your acceptance of our terms and policies are kept for as long as needed to demonstrate that acceptance. When you delete your account, we delete or anonymize your personal information within a reasonable period, except where we must keep it to meet legal obligations or resolve disputes.
6. Security
We protect personal information with encryption in transit and at rest, access controls, secret management, and an immutable audit trail. We offer two-factor authentication, passkeys, trusted-device controls, and session management so that you can protect your own account.
7. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. You can update your profile, manage security settings, review your activity, and delete your account from your account settings. For anything else, contact us using the form in the Service. You may also lodge a complaint with your local data-protection authority.
8. International transfers
We may process personal information in countries other than your own. Where we do, we rely on appropriate safeguards such as standard contractual clauses.
9. Cookies
We use strictly necessary cookies to keep you signed in, protect against cross-site request forgery, remember the device you sign in from, and store interface preferences. We do not use third-party advertising cookies.
10. Changes to this Policy
We may update this Policy from time to time. We will notify you of changes by email and in the Service. Material changes require your acceptance before you continue using the Service; for other changes, continued use after the effective date constitutes acceptance. The current and previous versions are always available in the Service.
11. Contact
Privacy questions and requests can be sent through the contact form in the Service.