Privacy Policy
Tringel S.R.L.
1. Who we are and what this policy covers
Tringel S.R.L. (“Tringel”, “we”, “us”) runs a web app that a sales team uses as its CRM for accounts that signed up to the customer’s product on their own. The customer’s product sends usage events to our HTTPS intake, or PostHog sends them through a webhook destination. We match each event to an account, evaluate the rules the customer has written, which we call plays, and put a signal on a sales rep’s list when a play fires. The rep records an outcome, and a booked call opens a deal. A model proposes account matches, writes a three-sentence brief for the rep and proposes candidate plays. It puts nothing on a list and decides nothing. We don’t capture mail, calendar or calls, we sell no contact data, and we send no messages to the customer’s users.
Registered at Boulevard San Juan 540, Piso 3, X5000ATT Córdoba, Argentina.
We handle personal data in two different situations, and different rules apply to each:
| Whose data | Our role | What applies | |
|---|---|---|---|
| Part A | People who visit this website, ask about the service or write to us | Controller: we decide why and how the data is used | This policy |
| Part B | The product events a customer sends: event name, time, workspace id, properties, and the name and email of the user who did it. The account state built from them: seats used, active users, plan, seat limit and trial end. Billing state read from Stripe: customer id, plan, subscription status, amounts and invoice status, never card data. Account traits read from Snowflake if the customer connects it. The signals, the Why now briefs, the outcomes and notes reps record, the deals, the plays and their edit history, and the confirmed workspace-to-account matches. And the account data of the customer’s own staff: name, work email, role, Slack user id, sign-in records and invoices. | Set out in B.1, because it depends on the data | This policy and the data processing agreement we sign with each customer |
If the data processing agreement (“DPA”) and this policy ever disagree about Part B, the DPA wins.
2. Part A: this website and our contact with you
This part covers the personal data we collect for our own purposes: running this website, answering requests, and staying in touch with people who are or might become customers.
A.1 What we collect
What you give us. When you send the form on this site, we collect what you type into it, such as your name, email address, phone number or company, and the fact that you agreed to be contacted. If you email or talk to us, we keep that correspondence and any contact details in it.
What is collected automatically. Our web server records the IP address a request came from, the browser used, the pages requested, the page you came from and the time. These logs exist to keep the site running and secure.
We don’t ask for sensitive data (the “special categories” in Article 9 GDPR) through this website, so please don’t send any through the form.
A.2 Why we use it, and what allows us to
| Why | What | Legal basis (GDPR Art. 6) |
|---|---|---|
| Answering your request and working out whether the service fits | What you sent in the form, our correspondence | Art. 6(1)(b): steps you asked for before a contract |
| Looking after customers, billing and support | Contact details, correspondence | Art. 6(1)(b): carrying out a contract |
| Keeping the site running, secure and free of abuse | Server logs | Art. 6(1)(f): our legitimate interest in running a secure service |
| Contacting you about the service | Email address, company | Art. 6(1)(f): our legitimate interest in business-to-business marketing. You can object at any time |
| Meeting tax, accounting and legal duties | Billing and contract records | Art. 6(1)(c): a legal obligation |
Where we rely on legitimate interest, we have weighed that interest against your rights, and you can ask to see the assessment.
A.3 How long we keep it
- Requests from people who don’t become customers: 12 months from our last contact, then deleted.
- Customer contact and contract records: for the length of the agreement plus ten years, because Argentina’s Civil and Commercial Code has a company keep its accounting records that long.
- Server logs: 30 days.
- A record that you objected or opted out: kept indefinitely, so we can keep respecting it.
A.4 Your rights
If you are in the EEA or the UK, you can ask to see your data, correct it, have it deleted, limit or object to how we use it, get a copy you can take elsewhere, and withdraw consent where we rely on it. Write to [email protected] and we will answer within one month.
You can also complain to a data protection authority. If you are in the EEA, that can be the authority where you live or work.
3. Part B: data inside the service
Two kinds of data are in Tringel. The first is the customer’s: product events about its own users, the billing state of its own customers, and the sales record its reps build on top. It contains personal data about people who use the customer’s product, and we hold it only to run the service for that customer. The second is ours and small: the names, work emails and sign-in records of the customer’s staff, and the invoices we send. This part covers both, in that order.
B.1 What we handle, and in what role
For product events, billing state, traits, signals, briefs, outcomes and deals we are the customer’s processor and act only on its instructions, which are the sources it connects and the plays it writes. For the account data of its staff and for invoices we are the controller. Nothing a customer sends is used for anything other than running that customer’s workspace.
- Product events. Every event the customer posts to the intake or routes through its PostHog webhook destination. We read the event name, the time, the workspace id, the properties, and the name and email of the user. We read what is sent and nothing else: we hold no login to the customer’s product or database.
- Billing state from Stripe. Through a restricted, read-only key the customer creates: customers, subscriptions, plans, seat quantities, trial end dates and invoice status. We never read card numbers or bank details, and the key cannot create, change or refund anything.
- Account traits from Snowflake. If connected, one view the customer names, read hourly with a read-only role. Traits fill in the account page. A trait never raises a signal, because a source read on a schedule cannot say when something happened.
- Slack. We post a direct message to the owning rep for each signal and read the button press that claims it. We read no channels and no other messages.
- HubSpot or Salesforce. We read company records only to find the one to write to, by domain or by an id the customer maps. We then write a task and a note for each signal, outcome and deal. The mirror runs one way, from Tringel to the CRM.
We never pull events from the customer’s product. If the customer stops sending, we stop receiving.
We buy and sell no contact data. The only people in a workspace are the ones the customer’s own product told us about.
We send nothing to the customer’s users. A signal goes to the customer’s rep, and what the rep does next happens outside Tringel.
B.2 What we do with it
Where it runs. The intake, the stream processor, the database and the web app run on cloud infrastructure in Frankfurt. The matching model and the brief model run on cloud GPU capacity we control in Frankfurt. No customer data is sent to a third-party hosted model API.
Separation between customers. Each customer’s events, accounts, plays and labeled pairs sit in their own logical partition under their own encryption key. A model adapter tuned for one customer serves only that customer.
Keys and tokens. Source keys are shown once and stored hashed. The Stripe restricted key, the Snowflake role credential and the Slack and CRM tokens are encrypted at rest and deleted within 24 hours of a disconnect.
Who at Tringel can read it. Support staff read a customer’s workspace only after the customer grants access from Settings, for a period the customer picks, and every read is written to the customer’s audit log.
Subprocessors. The cloud infrastructure provider in Frankfurt, a transactional email provider for sign-in and invoice mail, and a payment processor for our own fees. The list is published, and a change is announced 30 days ahead so a customer can object or leave.
B.3 AI models: where they run and what they learn from
Where models run. Inference runs on cloud GPU capacity we control in Frankfurt, beside the rest of the service on cloud infrastructure in Frankfurt. That covers the embedding model that proposes account matches and the open-weight language model that writes the Why now brief. The sequence model that proposes candidate plays runs on cloud infrastructure in Frankfurt today and moves onto the same GPU capacity in March 2027. No event, brief, note or outcome is sent to a third-party hosted model API, and no model provider is on our subprocessor list.
Training. We don’t train any shared model on a customer’s events, briefs, notes, outcomes or plays. There is one narrow exception, and it stays inside the customer’s own workspace. When a person confirms or changes a proposed match, we keep the pair: the workspace’s traits and the account chosen. When a rep edits a brief, we keep the sentence before and after. When a head of sales accepts or dismisses a candidate play, we keep the rule and the decision. When a rep closes a signal, we keep the signal and the outcome chosen. Those pairs tune that customer’s matching threshold, brief adapter and candidate plays only. They are never pooled across customers and are deleted with the workspace.
Where a person decides. The model proposes and a person decides. A match below 0.92 confidence waits in the Unmatched queue for a person, and until then its signals are marked Account not confirmed and are not mirrored. A brief sentence that cites no event is dropped before anyone sees it. A candidate play is a draft until the head of sales reads the backtest and sets it live. No model places an account on a list, reorders a list or removes a signal, and the decision to contact anyone is always a rep’s. This service never takes a decision with a legal or similarly significant effect on a person automatically.
B.4 Where the data is kept
All processing and storage is on cloud infrastructure in Frankfurt, Germany. The matching model and the brief model run on cloud GPU capacity we control in Frankfurt, and every backtest runs on cloud infrastructure in the same city.
No event, brief or outcome leaves the European Economic Area through us. Where the customer mirrors to HubSpot or Salesforce, the mirrored task and note are stored wherever the customer’s own CRM account stores them.
Backups are encrypted and kept on cloud infrastructure in Frankfurt, in a second facility in the same metropolitan area, for 35 days.
The suppliers that handle data in the service are named on our subprocessor list, which comes with the data processing agreement and which we send to anyone who asks: write to [email protected].
B.5 How long we keep it, and what deleting can’t remove
Product events: 13 months from the event time, rolling, so a 12-month backtest is always possible. Then deleted.
Accounts, signals, briefs, outcomes, notes, deals, plays and confirmed matches: while the workspace is open and 90 days after it closes, so the customer can export. Then deleted.
Billing state from Stripe and traits from Snowflake: the latest value and a 13-month history, deleted within 24 hours of a disconnect.
Source keys, tokens and credentials: until revoked or disconnected, then deleted within 24 hours.
Backups: 35 days.
Staff account data: while the workspace is open and 90 days after. Invoices and the records behind them: ten years, because Argentina’s Civil and Commercial Code has a company keep its books that long.
B.6 Requests from people whose data is in the service
The account data we control is contact data for the customer’s staff acting for it. If one of them writes to us, we answer directly: access, correction, deletion and objection, within thirty days. The people inside the product events are the customer’s users, and the customer controls that data. A request from one of them goes to the customer, and we help within ten working days: we can export everything held about one email address, or delete it, from a tool in Settings. Deleting a person removes them from events, accounts, briefs and notes and keeps the counts.
For everyone
4. Moving data between countries
Tringel S.R.L. is a company in Argentina, outside the EEA, and handles personal data under Argentina’s Personal Data Protection Law 25.326 and, where it applies, the GDPR. Section B.4 says where the data in the service is kept. When personal data from the EEA or the UK reaches us, for example because someone there writes to us or a customer there uses the service, it is protected by the European Commission’s adequacy decision for Argentina, or by its Standard Contractual Clauses, and the technical measures described in our security documentation. You can ask us for a copy. In Argentina you can complain to the Agencia de Acceso a la Información Pública.
EU representative (Article 27 GDPR). Write to [email protected] with “EU representative” in the subject line and we will send you our representative’s details.
5. Security
We protect data in line with the risk. That includes encryption in transit and at rest, access limited to the people and systems that need it, each customer’s data kept separate from every other’s, and a log of every access to production systems.
If a personal data breach affects you, we tell you without undue delay, and at the latest within 36 hours of finding out, with the information you need to meet your own reporting duties.
6. Children
The service is sold to businesses and is not meant for children. We don’t knowingly collect personal data from anyone under 16.
7. Changes to this policy
We may update this policy. If a change matters, we email customers at least 30 days before it takes effect. The version number and date at the top of this page change every time.
8. Contact
Privacy questions and anything else: [email protected]
By post: Tringel S.R.L., Boulevard San Juan 540, Piso 3, X5000ATT Córdoba, Argentina