Security

Your data is safe with us.

We built Tenor Analytics with privacy at the core — not as an afterthought. Here is exactly how we handle your data.

Protection

Security at every layer.

GDPR Compliant

All data processing follows GDPR regulations. You retain full ownership of your data at all times.

Files Deleted Instantly

Uploaded files are permanently deleted from our servers the moment your report is generated.

Encrypted in Transit

All data is transferred over HTTPS/TLS 1.3. No data is ever sent over unencrypted connections.

EU Cloud Infrastructure

All servers and storage are hosted in EU data centres. Your data never leaves European jurisdiction.

Data Lifecycle

What happens to your file.

Every uploaded file follows a strict lifecycle. From the moment you upload to the moment it's deleted, your data is protected at every step.

1
Upload
Your file is sent over HTTPS directly to our encrypted temporary storage (Cloudflare R2, EU region). It is encrypted at rest with AES-256.
Encrypted at rest
2
Processing
Our engine reads and analyses your data in an isolated serverless environment. No human ever sees your raw data. The environment is destroyed after processing.
Isolated execution
3
Report Generated
Your PDF is created and queued for delivery. The raw file is deleted from temporary storage immediately — it exists for seconds, not minutes.
Instant deletion
4
Delivery
Report sent to your email via Resend. The PDF is stored encrypted in your report history for your plan's retention period.
Encrypted delivery
5
Retention & Deletion
Reports are kept for 30 days (Starter), 90 days (Growth), or 1 year (Pro/Agency), then permanently deleted. No backups, no archives.
Auto-deleted

Your data is never sold, shared, or used to train external models.

We use your data exclusively to generate your report. Full stop. No exceptions, no fine print.

No data selling
No third-party sharing
No model training
Full data ownership
Compliance

Your rights, plain and simple.

We believe in transparency. Here is what you can expect from us as a data processor.

Data Access
You can request a copy of all data we hold about you at any time. We will provide it within 30 days.
Right to Deletion
Request deletion of your account and all associated data. We will comply within 72 hours.
Data Portability
Export your data in standard formats (CSV, JSON) at any time. No lock-in, no barriers.
Breach Notification
In the unlikely event of a data breach, we will notify affected users within 72 hours as required by GDPR.
DPO Contact
Our Data Protection Officer is available for any privacy-related questions or concerns.
Audit Trail
Complete audit logs of all data processing activities. Available for review upon request.

Found a vulnerability?

We take security reports seriously. If you've found a vulnerability or have a privacy concern, please contact us directly. We aim to respond within 24 hours.