Skip to main content
TurnellaEarly access

Privacy Policy

Last updated: 27 June 2026

This policy explains what personal data Turnella collects, why, how it is stored and protected, and the rights you have over it under the EU General Data Protection Regulation (GDPR) and the UK GDPR. We have written it to be plain and honest: Turnella does not sell your data, does not use advertising trackers, and gives you direct, self-service control to export or delete your data from your account page.

1. Who is responsible for your data

Turnella is the “data controller” for the purposes of the GDPR in relation to your account data and the planning data you enter about your own operations. Turnella is operated by Gonçalo Gomes, established in the European Union; see our Legal Notice for operator details. If you have any question about this policy or want to exercise your rights, contact us at privacy@turnella.com.

Rostering and employee data. If you use the roster features, you enter personal data about your own employees (names, roles, schedules, time off). For that employee data, youare the data controller and Turnella acts as a data processor on your behalf. You are responsible for having a valid lawful basis under applicable data-protection law to enter and process that employee data in Turnella, and for providing any required notice to your employees. See Section 2 for a full list of what rostering data is stored.

2. What data we collect

We keep data collection to the minimum needed to run the service:

  • Account data — if you create an account, your email address and a securely hashed password (handled by our authentication provider; we never see or store your password in plain text).
  • Planning data you enter — the operational information you choose to put into the app: workstreams, historical volumes, forecasts, requirements, shift schedules, cost assumptions and scenarios. This is business planning data, and you control what you enter.
  • Roster & staffing data — if you use the roster and scheduling features, the team information you enter: employee names, roles, contracted hours, days available, skill tags, time off (as date ranges with a category — vacation, sick, training or other — and optional notes), and the named shift assignments built from these. This data is also what the per-agent schedule exports (Excel and calendar) contain. You are the controller of this employee data; enter only what you need for planning.
    Turnella is a planning tool, not an HR system of record. Do not enter medical details, health information, disciplinary records, or other special-category or sensitive personal data in notes or anywhere else.
  • Technical data — standard server logs (such as IP address and request time, used for security and reliability) and privacy-friendly, aggregated usage analytics that do not use cookies and do not track you across other websites.

The free calculators do not require an account and do not save your inputs to our servers — they run in your browser.

3. Cookies and local storage

Turnella uses browser storage in two ways depending on whether you are signed in:

  • Signed-in accounts — your planning data is stored in our cloud database (Supabase). The browser retains only a tiny session marker (~30 bytes) that keeps you signed in, and a record of your cookie choice. Clearing your browser data does not lose your plans.
  • Guest (not signed in) — your planning data is saved locally in your browser via localStorage. It never leaves your device unless you create an account. Clearing browser data or switching devices will lose it. If you later create an account your local data is uploaded and then stored in the cloud only.

All of the above storage is strictly necessary to operate the service and is exempt from consent under ePrivacy rules.

For usage analytics we use Vercel Web Analytics. It is designed to be cookieless and does not build advertising profiles or track you across other sites. Even so, we ask first: it loads only after you acceptin our consent banner, and you can change or withdraw that choice at any time via the “Cookie preferences” link in the footer. Full details are in our Cookie Notice.

4. How and why we use your data (legal bases)

  • To provide the service you asked for (GDPR Art. 6(1)(b), performance of a contract) — storing your plans, syncing them across your devices, and keeping you signed in.
  • To keep the service secure and working (Art. 6(1)(f), legitimate interests) — server logs, abuse prevention, and aggregated analytics to understand and improve how the product is used.
  • To comply with the law (Art. 6(1)(c)) — where we are legally required to retain or disclose information.

5. Who processes data on our behalf

We use a small number of trusted sub-processors, each bound by data-processing terms. We do not sell your data and we do not share it with advertisers.

  • Supabase — database and authentication (stores your account and the plans you save). See Supabase’s privacy policy.
  • Vercel — application hosting and cookieless Web Analytics (consent-gated page-view counts on public pages only; no personal data, no cross-site tracking). See Vercel’s privacy policy.
  • Anthropic — powers the optional AI-assisted insights and the in-app help chatbot. Only aggregated, model-level metrics and your help questions are sent (see section 9); no raw personal or contact data. See Anthropic’s privacy policy.
  • Voyage AI — generates the search embeddings that let the help chatbot find relevant Turnella documentation. It processes our own documentation and your help questions, not your planning data. See Voyage AI’s privacy policy.
  • Resend — sends transactional email such as account confirmation and password-reset messages. It processes your email address for that purpose only. See Resend’s privacy policy.

6. Where your data is processed

Our database is hosted in the European Economic Area (Frankfurt, Germany). Our application is served via Vercel’s global edge network, which may route requests through servers in other countries. Where data is processed outside the EEA, it is protected by appropriate safeguards recognised under the GDPR, such as Standard Contractual Clauses.

7. How long we keep your data

We keep your account and planning data for as long as your account is active, so the service works for you across devices. You can erase your data or your entire account at any time (see below); once deleted, it is removed from our live systems immediately and is overwritten as our hosting provider’s standard backup-retention cycle elapses.

8. Your rights

Under the GDPR you have the right to:

  • Access and portability — get a full copy of your data. Use Export my data (JSON) in your Account page.
  • Erasure (“right to be forgotten”) — delete your planning data, or permanently delete your whole account and email, from the same Account page. Account deletion is immediate and irreversible: your cloud data is erased and your session is invalidated on all devices. Deletions propagate to your other signed-in devices the next time they sync, so deleted data is not restored from another device.
  • Rectification — correct your data by editing it directly in the app.
  • Restriction and objection — ask us to limit or stop certain processing based on legitimate interests.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any right that is not self-service, email privacy@turnella.com. You also have the right to lodge a complaint with your local data-protection authority (for example, the CNPD in Portugal, or the supervisory authority in your country).

9. AI features

AI insights. Where you generate an optional AI insights narrative, only aggregated, model-level planning metrics are sent to the AI provider (Anthropic). We do not send raw personal data, individual employee names, or contact records.

In-app chatbot (Turnello). When you ask the help assistant a question, the text of your question and the last few messages of the conversation are sent to Anthropic to generate an answer, and your question is also sent to Voyage AI to create a search embedding that finds relevant Turnella documentation. These are processed only to answer your question.

Please don’t paste confidential or personal data into the chatbot — for example real employee names, customer details, or health information. Keep your questions about how to use Turnella.

10. Children

Turnella is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.

11. Changes to this policy

We may update this policy as the product evolves. When we do, we will revise the “last updated” date above, and for material changes we will make the update clear within the app.