SECURITY
Data Handling and Subprocessors
Effective: 5 August 2026 · v1.0 · Owner: Talonic Security
This disclosure describes how Talonic handles data belonging to customers who purchase Talonic through AWS Marketplace. It covers what we collect, where it is stored, how it is used, who it is shared with, how long we keep it, and how it is backed up.
Scope: Subscriptions purchased through AWS Marketplace run on a dedicated environment hosted entirely on Amazon Web Services, in an AWS Region located in the European Union. This environment is separate from Talonic's other infrastructure, and data from AWS Marketplace subscriptions is not processed outside it.
Roles: For the documents and data you submit to the platform, you are the data controller and Talonic is the processor. Talonic acts as controller only for its own account, billing and website records.
1. Data collection
We collect two categories of data:
- Content data: the documents you submit for extraction, the structured data extracted from them, and the field registry entries derived from that extraction. This data is yours. We process it to provide the service.
- Operational data: account information, usage logs, access logs, and the security audit trail needed to run and audit the service. We collect what is necessary to operate the platform, investigate security events, and meet our legal obligations.
We do not collect payment card or bank details — billing for AWS Marketplace subscriptions runs entirely through AWS Marketplace. We do not ask for government identifiers or authentication secrets, and you should not submit them.
2. Data storage
- Location: all data is stored on Amazon Web Services in an AWS Region located in the European Union. It does not leave the EU.
- Encryption: data is encrypted at rest — including database storage and all file storage — and encrypted in transit using TLS, including connections between internal services and queues.
- Isolation: every data lookup in the platform is scoped to the organisation that owns the data. This is enforced by a single rule applied at the data-access layer rather than implemented separately per feature, so isolation does not depend on individual features being written correctly.
- Access control: all access is authenticated by email, Google or Microsoft single sign-on, with optional two-factor authentication. Access within the platform is governed by role-based permissions. Internal access to production systems is restricted to authorised personnel and logged.
3. How we use your data
We use your data to run the service, investigate security events, and meet our legal obligations.
We do not use your data to train machine learning models. We do not aggregate, anonymise or derive from your data beyond what is necessary to provide the service to you. We do not use your data for advertising, profiling or any form of behavioural analysis.
4. Data sharing and subprocessors
For AWS Marketplace subscriptions, Talonic uses one subprocessor:
- Amazon Web Services — infrastructure hosting, compute, storage and model inference, in an AWS Region located in the European Union.
No other third party transmits, stores or processes data belonging to AWS Marketplace subscriptions. The full subprocessor list for Talonic's other environments is set out in our Data Processing Agreement and in our Privacy Policy at talonic.com/privacy.
We will inform you before adding a subprocessor to this environment, so that you have the opportunity to object.
5. Data retention and deletion
We retain your data for as long as your subscription is active and you have not asked us to delete it, and only for as long as is reasonably required to provide the service.
You may delete your data at any time or ask us to delete it; we action deletion requests within 30 days. For 45 days after your subscription ends, your data remains available so you can retrieve or delete it; after that window we permanently delete it within 30 days. On request we confirm deletion in writing.
Security audit records are handled differently: they are append-only and retained for 24 months, then expire. They are not removed by a routine deletion request. Where you exercise your right to erasure, we delete your documents and extracted data and retain audit records for the remainder of the 24-month period as permitted by GDPR Article 17(3)(e).
Records we are required by law to keep — for example invoicing and tax records — are retained for the period the law requires and only for that purpose.
For full details see our Data Retention and Deletion Policy.
6. Backups
Encrypted backups are retained for up to 35 days after deletion from primary systems; they expire and are overwritten on a rolling basis. Backup copies remain encrypted and access-controlled, are held in the same AWS Region as the primary data, and are used only to restore the service.
Your rights and how to reach us
You can request access to, correction of, or deletion of your data, a copy of it in machine-readable form, or written certification of deletion. Email security@talonic.ai. We acknowledge requests within 24 business hours and respond within 30 days.
A GDPR-compliant Data Processing Agreement is available on request from the same address.
Talonic GmbH · Luisenstr. 53, 10117 Berlin, Germany · security@talonic.ai