Data & Security.
Last updated: 27 August 2026
At Tuleva, we understand that the information organisations collect and manage through their circular activities is valuable.
Our platform is designed with security, privacy, and responsible data management in mind. This page explains the measures and principles we use to protect information processed through Tuleva.
This document provides a general overview of our approach to data and security. It does not replace our Privacy Policy, Terms of Use, or any applicable Data Processing Agreement (DPA).
1. Our Approach to Security
Security is an ongoing responsibility.
We work to protect information within Tuleva against unauthorised access, accidental loss, alteration, disclosure, destruction, and other forms of unauthorised processing.
Our approach includes appropriate technical and organisational measures proportionate to the nature of the information we process and the risks associated with processing it.
2. Data Ownership
Your organisation retains ownership of the information and content that you submit to Tuleva.
Using Tuleva does not transfer ownership of your organisation’s data to Tuleva.
We process customer data only to the extent necessary to provide, maintain, secure, and improve the Services, or as otherwise permitted or required by applicable agreements and law.
Where Tuleva acts as a data processor on behalf of an organisation, the organisation remains responsible for determining the purposes and lawful basis of processing personal data, while Tuleva processes that data according to the applicable instructions and agreement.
3. Data Protection
Where applicable, Tuleva processes personal data in accordance with relevant data protection laws, including the General Data Protection Regulation (EU) 2016/679 (GDPR).
Our privacy practices are described in greater detail in our Privacy Policy.
Where an organisation uses Tuleva as a processor of personal data, we may enter into a Data Processing Agreement establishing the respective responsibilities and obligations of Tuleva and the organisation.
4. Access Controls
Access to Tuleva information is designed around user accounts and permissions.
Depending on the functionality available, access may be controlled through:
- User authentication;
- Account roles;
- Organisation-level permissions;
- Administrative controls;
- Access restrictions;
- Session management.
We aim to ensure that users have access only to the information and functionality necessary for their role.
Organisations are responsible for managing their own users and permissions and for removing access when a person no longer requires it.
5. Authentication and Account Security
Users are responsible for keeping their account credentials secure.
We encourage users to:
- Use strong and unique passwords;
- Never share account credentials;
- Avoid using the same password across multiple services;
- Sign out of shared or public devices;
- Report suspected unauthorised access promptly.
Where additional authentication or security features are available, users should enable them where appropriate.
Tuleva may apply technical controls designed to detect and prevent suspicious authentication activity.
6. Encryption and Secure Transmission
We use appropriate security measures to protect information while it is transmitted between users and Tuleva systems.
Where supported by our infrastructure, communications with Tuleva are protected using industry-standard secure transport technologies such as HTTPS/TLS.
Data stored within Tuleva may also be protected using appropriate security controls provided by our infrastructure and service providers.
Specific encryption technologies, configurations, and security architecture may change over time as our platform evolves.
7. Infrastructure and Hosting
Tuleva relies on third-party infrastructure and technology providers to operate parts of the platform.
These providers may provide services such as:
- Cloud hosting;
- Data storage;
- Databases;
- Authentication;
- Application infrastructure;
- Monitoring;
- Security services;
- Backups and recovery infrastructure.
We assess service providers based on factors relevant to the services they provide, including security, reliability, privacy, and data protection requirements.
Current infrastructure and hosting providers: Vercel and Github.
Where third-party providers process personal data on our behalf, appropriate contractual and data protection arrangements are maintained where required.
8. Data Storage
Information submitted to Tuleva may be stored within systems operated by Tuleva or our authorised service providers.
We take reasonable measures to protect stored information against unauthorised access, modification, loss, or destruction.
The location in which data is stored may depend on the infrastructure and service providers used by Tuleva.
Primary data hosting region(s): EU
9. Backups and Recovery
Where appropriate, Tuleva maintains backup and recovery mechanisms designed to reduce the risk of permanent data loss resulting from technical failures, operational incidents, or other disruptions.
Backup practices may include:
- Automated backups;
- Redundant infrastructure;
- Recovery procedures;
- Monitoring of critical systems.
Backup retention periods may vary depending on the system and operational requirements.
Backups are subject to appropriate access controls.
10. Monitoring and Security
We may monitor relevant systems and technical events to help:
- Detect security threats;
- Identify unusual activity;
- Investigate incidents;
- Maintain system reliability;
- Diagnose technical problems;
- Protect the availability and integrity of the Services.
Security and system logs may contain technical information such as account identifiers, IP addresses, timestamps, device information, and system events.
Such information is handled in accordance with applicable data protection requirements.
11. Vulnerability Management
We aim to identify and address security vulnerabilities affecting the Tuleva platform and its supporting infrastructure.
This may include:
- Applying security updates;
- Monitoring dependencies;
- Reviewing system configurations;
- Addressing identified vulnerabilities;
- Maintaining appropriate access controls;
- Testing and reviewing security measures.
Security practices evolve as new threats, technologies, and vulnerabilities emerge.
12. Security Incidents
Despite reasonable security measures, no digital service can guarantee absolute security.
If Tuleva becomes aware of a security incident affecting personal data, we will assess the incident and take appropriate action in accordance with applicable law and our contractual obligations.
Where required, we will notify affected customers, individuals, regulators, or other relevant parties within the applicable legal or contractual timeframe.
Where Tuleva acts as a data processor, we will follow the applicable incident-notification requirements established in the relevant Data Processing Agreement.
13. Customer Responsibilities
Security is a shared responsibility.
Customers and users are responsible for:
- Protecting their account credentials;
- Using appropriate access permissions;
- Keeping user information accurate;
- Removing access for users who no longer require it;
- Not sharing accounts;
- Ensuring that uploaded information is lawful and appropriate;
- Avoiding unnecessary submission of sensitive personal data;
- Reporting suspected security incidents or unauthorised access.
Customers should also maintain appropriate internal security practices when using Tuleva.
14. Data Minimisation
Tuleva follows a principle of collecting and processing information that is reasonably necessary for the purposes for which the Services are provided.
Users should avoid uploading personal information that is unnecessary for their intended use of the platform.
Where organisations use Tuleva to process personal data, those organisations remain responsible for determining what information is necessary for their particular processing activities.
15. Data Retention and Deletion
We retain information only for as long as reasonably necessary for the purposes for which it is processed, subject to applicable legal, contractual, security, and operational requirements.
When information is no longer required, it may be deleted, anonymised, or otherwise securely disposed of.
Customer-specific retention and deletion requirements may be established through applicable agreements.
For more information about personal-data retention, please see our Privacy Policy.
16. International Data Processing
Some Tuleva infrastructure or service providers may process information outside the European Economic Area.
Where personal data is transferred internationally, we apply appropriate safeguards required by applicable data protection law.
These safeguards may include:
- Adequacy decisions;
- Standard Contractual Clauses;
- Appropriate contractual protections;
- Additional technical or organisational safeguards where required.
For more information, please refer to our Privacy Policy and, where applicable, the relevant Data Processing Agreement.
17. Third-Party Services
Tuleva may use carefully selected third-party services to operate and improve the platform.
These services may support:
- Infrastructure;
- Authentication;
- Communications;
- Analytics;
- Monitoring;
- Security;
- Customer support;
- Other essential platform functionality.
Third-party providers may process information according to their contractual relationship with Tuleva and applicable data protection requirements.
A current list of relevant subprocessors may be made available to customers where applicable.
Subprocessor information: [Insert subprocessor list / process for obtaining the current list]
18. Security Assessments and Certifications
Tuleva may adopt recognised security frameworks, standards, certifications, or independent assessments as the platform develops.
We will only represent Tuleva as holding a certification or compliance status where that certification or status has actually been obtained and remains valid.
Current certifications: None currently
19. Responsible Disclosure
If you discover a potential security vulnerability affecting Tuleva, please report it responsibly rather than attempting to exploit or publicly disclose it.
Security reports should include enough information for our team to understand and reproduce the issue where possible.
Security contact: hello@mytuleva.com
Please do not include unnecessary personal or confidential information in a security report.
20. Changes to Our Security Practices
As Tuleva grows, our security architecture, infrastructure, providers, and operational practices may change.
We may update this page to reflect significant changes to our approach.
However, we will not use this page to make unsupported claims about security certifications, technical controls, or compliance standards.
21. Contact Us
If you have questions about Tuleva’s security or data practices, please contact us:
Tuleva
Lisbon, Portugal
Privacy, Security and General Enquiries: hello@mytuleva.com