Privacy Policy

Privacy Policy — Tortoise Hosted Service

This policy describes how personal data is processed in connection with the hosted Tortoise service operated by Premise Labs at tortoise.premiselabs.co.

Last updated 2026-08-08
Effective date Effective date: 2026-08-08
Version 1.0

Scope of this policy

This Privacy Policy describes how personal data is processed in connection with the hosted Tortoise service operated by Premise Labs at tortoise.premiselabs.co (and its API at api.premiselabs.co).

This policy does not apply to self-hosted deployments of the Tortoise software. In a self-hosted deployment, the operator of that deployment is the data controller for any personal data processed there, and that operator's own policies apply.

This policy is written in plain English. It describes current practices truthfully and, where the service may introduce tools in the future (such as analytics instrumentation), it describes those tools now in conditional terms so this document stays accurate when they are activated ("disclose now, instrument later").

1. Controller identity and contact

Data controller: Daniel Ospina, an individual operating the hosted Tortoise service under the name "Premise Labs" (d/b/a "Premise Labs").

Premise Labs is not a registered legal entity. The data controller is the natural person named above, acting in their personal capacity.

Jurisdiction of residence: Mexico.

Contact for privacy matters: email hello@premiselabs.co. This is the controller's designated contact channel for all privacy inquiries and requests.

EU/EEA representative (GDPR Art. 27): "We are not currently established in the EU/EEA. If we become subject to GDPR Art. 27, we will designate and disclose an EU representative here."

LFPDPPP (Mexico): The Mexican Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) applies to personal data of individuals in Mexico. ARCO rights (Access, Rectification, Cancellation, Opposition) are exercised via email hello@premiselabs.co. A standalone privacy notice (Aviso de Privacidad) in Spanish is available at Aviso de Privacidad (Español).

2. Data processed by the service

The service processes the following categories of personal data:

Sensitive data — expectation. "we expect users not to place sensitive data in the service" — do not place health data, biometric data, government identifiers, or other sensitive personal data in the service. See §13.

Eligibility. The service is intended for use by adults: you must be at least 18 years old to create an account or use the service. The service is not directed to children.

3. Analytics and cookies

Deployed analytics tools. The following analytics tools are deployed on the tortoise funnel pages (product, signup, sign-in, and welcome pages), and they capture data only after you give consent via the consent banner:

Planned tools, disclosed now. The following analytics tools are not deployed yet and may be activated with your consent; consent is managed via the consent banner:

Cookies and similar technologies are used by these tools when activated. You can give or withdraw consent at any time via the consent banner.

Until consent is given, PostHog captures no data, the planned tools are not loaded, and no data is sent to them. Google Tag Manager itself is loaded only after consent, so GA4 and any other tags it contains cannot fire before consent is given.

4. Purposes of processing and legal bases

Purposes of processing: "your email address and account information are used to deliver the service, respond to requests, and manage billing; usage data is used to improve the product"

Legal bases under the GDPR. Processing is based on the following grounds, as applicable:

Consent, where given, may be withdrawn at any time with effect for the future. Under ePrivacy rules, non-essential cookies and pixels are subject to the same consent: you can give or withdraw consent at any time via the consent banner.

5. California — CCPA/CPRA disclosures

We do not sell your personal information. Consistent with the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA): we do not sell your personal information, and no personal information has been sold in the preceding 12 months. We share limited data with advertising/analytics providers as disclosed in this policy.

"Sharing" disclosure for the Meta Pixel (conditional). If the Meta Pixel is activated, data processed through the Pixel is shared with Meta as an advertising provider, and that may constitute "sharing" for cross-context behavioral advertising under the CPRA. When the Pixel is activated, Meta is a joint controller of personal data processed through the Pixel, and shared data may be used by Meta for its own purposes. Data is shared with Meta only after consent is obtained, as described in §3.

Opt-out rights. No dedicated California opt-out link is offered at this time, because no sale occurs and no sharing occurs until analytics tools are activated with consent. Consent is managed via the consent banner; a dedicated opt-out control will be added if the Meta Pixel is activated. Until then, opt-out and all other California privacy requests may be submitted through the contact channel in §1.

Shine the Light (Cal. Civ. Code § 1798.83). California residents may request, once per calendar year, information about personal information disclosed to third parties for their own direct marketing purposes in the preceding calendar year. Requests may be submitted through the contact channel in §1.

Non-discrimination. You will not be denied goods or services, charged different prices, or provided a different quality of service for exercising your California privacy rights.

6. Retention

Personal data is retained only for as long as needed to deliver the service and to fulfill the purposes described in this policy. When data is no longer needed, it is deleted or de-identified.

Retention carve-outs, stated honestly:

7. Security

Reasonable technical and organizational measures are applied to protect personal data:

No security measures are absolute, and the security of the internet cannot be guaranteed. You are responsible for keeping your account credentials confidential.

8. Your rights

GDPR rights. If you are located in the EU/EEA, the UK, or Switzerland, you have the right to:

CCPA/CPRA rights. If you are a California resident, you have the right to:

Where rights under different laws overlap or conflict, the applicable law governs. All requests are subject to identity verification as described in §16.

9. Data Processing Agreement

A copy of the Data Processing Agreement (DPA) is available at https://tortoise.premiselabs.co/dpa.

Under GDPR Art. 28(3), a DPA is required whenever a processor relationship exists — regardless of deal size, including for free-tier users. The DPA applies to the processor relationships described in §10 and takes effect when personal data is submitted to the service.

10. Processors and third-party sharing

Personal data is shared only with the processors and providers listed below, and only to the extent necessary to operate the service. Each processor is engaged under a data processing agreement that complies with GDPR Art. 28, and processors act only on documented instructions.

No other sharing of personal data occurs, except as required by law or with your consent.

11. AI training

we do not use your content or usage data to train AI models — at any tier, free or paid, now or in the future under this policy. This is a commitment of the product, not a limitation of a plan.

12. International data transfers

Personal data may be transferred to, and processed in, countries other than the country where you reside, including the United States, where the service's infrastructure and processors are located.

Where personal data is transferred from the EU/EEA, the UK, or Switzerland, appropriate safeguards are provided:

PostHog US residency. PostHog is a data processor; data is stored in the United States. EU-origin analytics data captured with consent is stored in the United States.

13. Sensitive data

we do not intentionally collect sensitive personal information. Sensitive personal data — such as health data, biometric data, government identifiers, racial or ethnic origin, or other special-category data — is not requested, and is not needed for any feature of the service.

As stated in §2, "we expect users not to place sensitive data in the service." If you place sensitive data in the service despite this expectation, that data is processed at your direction in the same way as other content you submit, and you are responsible for ensuring you are entitled to process it.

14. (Reserved)

Reserved — see §12.

15. Version, effective date, and document history

Current version: 1.0

This policy is versioned. When this policy changes, the version number and effective date are updated, and a new entry is added to the document history below. Material changes are posted before they take effect.

16. Exercising your rights — deletion and other requests

Primary mechanism: email. To request deletion of your account and associated data, or to make any other privacy request (access, correction, export, restriction, objection), email your request to hello@premiselabs.co.

Response commitment. Requests are answered within one month of receipt, as required by GDPR Art. 12(3). If a request is complex or numerous, the response period may be extended by up to two additional months; you will be informed of any extension within one month of receipt, together with the reasons for the delay.

Identity verification. we may request identity verification before acting on any request (GDPR Art. 12(6)). Where a request cannot be verified or is manifestly unfounded or excessive, the request may be refused or a reasonable fee may be charged, as permitted by law.

What this channel covers. The email channel covers: (a) account data, (b) non-account data, (c) users who cannot log in to their account, and (d) access, export, and objection requests. It is the general-purpose rights channel for this release.

Deletion scope. When a deletion request is fulfilled, account and associated data is deleted or de-identified, subject to the retention carve-outs in §6 (billing/transactional records retained as required by law; analytics data handled per the analytics section). Deletion does not extend to content you have already shared publicly or to data that others have lawfully obtained.

Self-service deletion (future). An in-product self-service account deletion feature does not exist at the time of this publication, so this policy does not promise one. If a self-service deletion feature is added to the product, this policy will be updated to describe it.