Privacy
Effective from 15 September 2026
Tanduva at tanduva.com offers custom AI development, public guides and a separate catalogue of AI agents with a personal workspace. For questions about the service and personal data, contact us at mail@victoreliot.com.
Operator and data controller
Tanduva is operated and managed by vinireto s.r.o., company ID 23101717, registered at Školská 660/3, Nové Město, 110 00 Prague 1, entered in the Commercial Register at the Municipal Court in Prague, Section C, File 421409. The company also develops Tanduva software and is the controller of personal data processed to operate the service.
Contact: mail@victoreliot.com, +420 777 666 651. Czech data mailbox: yczu4tp. Full company details and contact.
Agency website and enquiries
You can read the public service pages and guides without registering. Email links open your email application with a draft; no enquiry is transmitted this way until you send it yourself. The contact form sends your email, request, optional company name and page context to Tanduva’s server. We store these details encrypted to respond and discuss the requested service; the administrator can access the overview. The operator is notified by email through the connected mail service. Form confirmation means the message was stored, not that an order was placed. You can request deletion using the contact above. To protect the form, we temporarily limit messages from a single connection. Interactive demos and the potential-benefit calculation run in your browser; their values are transmitted only with a submitted enquiry if you choose to include them.
Account and application use
We store your name, email, a secure password hash, login sessions and agents added to your library. These support sign-in, account protection and the selected features. The server may process IP addresses and technical request data for security and abuse prevention.
Web Assistant and enquiries
For each Web Assistant, we separately store encrypted company settings, supplied text and retrieved public pages. The owner determines active sources and permitted websites. For a confirmed question, OpenAI receives the question, part of that chat’s history and selected active material for that assistant. Google statistics and other companies’ knowledge are not added. Test chat is available only after the owner signs in. Chat access and history expire after two hours and are removed during server maintenance. Changes to settings or sources may end the session earlier.
After an enquiry is reviewed and confirmed, we store the name, contact email, optional phone number and request content. If outgoing mail and a recipient are configured, we email these details to the address chosen by the business owner. Enquiries and sources can be deleted in the assistant settings, or all records by deleting the assistant. Recording interest does not confirm an order or payment. Email delivery uses the connected SMTP provider configured by the operator. Unsent enquiries remain available in Tanduva.
Hosting connections and website changes
We store server credentials, connected websites, proposed changes and task history encrypted and separately for each account. Passwords and SSH keys are not sent to the model. When a coding proposal is run, OpenAI processes the request and the selected source files. Installing a prepared widget follows a fixed procedure without sending source code to AI. You initiate server writes for a specific proposed change. With SSH, original files are backed up outside the website directory on your server. With FTP, FTPS and SFTP, backups of changed files are stored encrypted in Tanduva. Disconnecting removes access, history and FTP/SFTP backups in Tanduva; it does not remove the installed widget or server backups. Chat visitors cannot use server connections or the coding tool. This feature is currently available only in the operator’s private test.
Photos and listings
We process photos uploaded to the Listings Agent, remove their metadata and store them encrypted with your account and project. They remain available until you delete them from the gallery or with the project. Deleting a photo may also make its preview unavailable in an older result. Selected images are sent to OpenAI only when you confirm a task run. Prepared listings and your edits are saved in your account’s results. Listing portals are not yet connected; we do not automatically send them listings or photos.
Google Analytics and Search Console connections
Connecting is optional. Google asks for your consent. Tanduva receives the connected account’s identifier and email, and read-only access to the services you authorise.
- From Google Analytics, we retrieve available GA4 properties and summaries of organic traffic, users, engagement and views.
- From Search Console, we retrieve available websites and summaries of clicks, impressions, CTR, positions, queries and pages.
- The data is used only to display your SEO overview and prepare a task if you select “Use data in task”. We do not change Google settings or your website content.
Authorisation tokens and your selected sources are stored encrypted on the server. Statistical reports are retrieved on request. If you run an AI agent with Google data, its inputs and result are stored encrypted within your account; you can delete the result in its detail view. The project profile remains for other agents. Connections and source selections are separate for each user.
AI tools and data sharing
In the operator’s private testing, built-in agents use server-side Codex signed into the operator’s ChatGPT account. Runs are restricted to that account. For future public operation, the application supports a separate OpenAI API connection. Before each run, you explicitly confirm sharing the request, project profile, supplied material, any previous result and selected Google statistics for that task. The Listings Agent sends selected photos and listing details, not Google statistics or an unrelated business profile. Google access tokens and passwords are not sent to the model. Server-side Codex follows the connected ChatGPT account’s rules and settings. Temporary files on the AI server are removed after the run. API mode uses store:false; this alone does not rule out the provider’s operational data retention. Details: Codex with a ChatGPT plan and OpenAI API data handling. Analysis and content runs do not publish content. The Web Assistant forwards confirmed enquiries as described above.
Tanduva does not sell Google data or use it for its own ad targeting or training general-purpose AI models. During private testing, OpenAI processing is also governed by the connected account’s data settings, rather than API settings. Use and any transfer of Google data follow the Google API Services User Data Policy, including its Limited Use requirements.
Technical operation and cookies
The application runs on a Hostinger server; Cloudflare manages the domain and DNS. Google provides access to authorised sources. We use necessary cookies for sign-in and security. The tanduva_language cookie remembers your chosen language for one year. The session cookie tanduva_seen prevents repeated automatic redirects based on browser language after the first visit. These cookies contain no advertising identifier. The website has no advertising cookies or Google Analytics visitor tracking. The Analytics connection in the SEO agent reads statistics for your website.
Retention and deletion
We retain the account and library while you use the service. You can disconnect Google at any time using “Disconnect” in Google data settings; the application removes credentials and asks Google to revoke access. You can also revoke access in your Google account settings. Older backups may contain previously stored data for a limited period and are used only to restore the service.
To request a copy or correction of your data, deletion of your account and library, or to raise an objection, contact mail@victoreliot.com. We may need to verify that the account belongs to you before acting on the request.
Changes to this information
We update this page when our processing changes. Before using Google data for a new purpose, we will request the appropriate consent.