# Tale: The Orchestrator for AI Agents Source: https://tale.dev/ # Orchestrate every AI agent on your stack Connect Claude Code, Codex, Hermes, OpenClaw, and the rest of your team's agents. Pool their knowledge, delegate real work — on infrastructure you run. ISO 27001 · SOC 2 Type II · GDPR · MIT Licensed · Open Source > Animated product demo: a task is typed into Tale, Auto routes it to the Support Agent, and a reply streams in grounded in two cited sources. ## How Tale orchestrates your AI agents Connect what you use, pool what you know, delegate the work, govern the result — then compare models and scope by project. 01 Agents & connectors ### Bring the agents you already trust Claude Code, Codex, Hermes, OpenClaw — plus Slack, GitHub, Outlook, and the rest of your stack. Nothing gets replaced; everything gets coordinated. > Animated demo: the Agents list shows Claude Code, Codex, Hermes, Support Agent, and OpenClaw as installed rows with model chips. 02 Knowledge ### One knowledge base, every answer grounded Documents, websites, product and contact data flow into a shared knowledge base. Agents answer from what your company actually knows — with citations you can check. > Animated demo: the Knowledge documents table indexes a PDF, a website, a product catalog, and a runbook, then shows indexed status badges. 03 Automations ### Delegate the work, not the control Automations chain LLM steps, conditions, and actions into workflows that run on triggers — inbox triage, escalations, weekly reports. Every run leaves a log. > Animated demo: a workflow canvas runs Trigger → LLM → Condition → Action, then the Executions table records the run. 04 Approvals & audit ### Approve before it ships. Audit after. Human-in-the-loop approvals gate the actions that matter. Audit logs, budgets, guardrails, and SSO keep every agent inside your rules. > Animated demo: an in-chat approval card asks to send 42 refund emails; Approve is confirmed and the run continues. 05 Chat Arena ### Compare models on the same prompt Arena runs one question through two models side by side. Pick the reply that fits — without leaving the thread or retyping the ask. > Animated demo: Chat Arena splits one prompt across two models so you can compare Claude Sonnet and GPT-5.5 side by side. 06 Projects ### Scope agents and knowledge by team Projects keep agents, documents, and members in the right workspace. Support stays on support; engineering keeps its own stack. > Animated demo: the Projects list shows scoped workspaces with agent counts and members. ## Your Infrastructure. Your Data. Your Rules. Run AI on your terms — from where it's hosted to how every action is governed. ### Self-hosted by default Runs entirely on your infrastructure — no cloud required. Pair it with local models and no data leaves your network; either way, nothing locks you to a vendor. ### Security built in Single sign-on, sensitive data detection, content safety guardrails, full activity logging, and budget controls — all built in, not bolted on. ### Fully open source The entire codebase is public under the MIT license. Read it, audit it, change what you need — without asking anyone. ## Works with the agents you run Dock Claude Code, Codex, Hermes, OpenClaw, Pi, and OpenCode under one orchestrator you host. - Claude - Codex - Gemini - Cursor - Hermes - OpenClaw - Pi - OpenCode ## Plugged into the tools you already run Connect Gmail, Slack, GitHub, Shopify, and your model providers once per organization — every agent and automation shares the same governed credentials. SECURITY ## Compliance you can verify ### Independent & Transparent Swiss-based and vendor-neutral — no ties to a cloud or model provider, so your deployment answers only to you. ### Certified & Compliant Certified to ISO 27001 and SOC 2 Type II, and GDPR-compliant — audit logs and data controls mean you always know where your data is stored. ## Frequently Asked Questions Still have questions?[Contact the team](/contact) ### What is Tale? ### Is Tale open source? ### Can Tale run fully on-premises or air-gapped? ### How does Enterprise pricing work? ### Are there additional features in the Enterprise plan? ### Do I have to bring my own AI models? ### Can I use my preferred AI provider? ### Do you also provide hardware? ### Can I use my own hardware and AI models? ### Do you offer custom AI model training? ## Deploy Tale on your infrastructure. Orchestrate your AI agents on a sovereign stack you run yourself — get in touch, or spin one up in four commands. Self-host in four commands # Who is behind Tale? — About Ruler GmbH Source: https://tale.dev/about About us # Who is behind Tale? Tale is built by Ruler GmbH, a Swiss company based in Spiez — independent, vendor-neutral, and certified ISO 27001 & SOC 2 Type II. We build the orchestrator for AI agents in the open, MIT-licensed, for organizations that keep their data close. ## Our story Ruler GmbH was founded in Spiez, in the Canton of Bern, in 2020 by Yannick Monney. From day one the company has been Swiss-based and vendor-neutral — no ties to a cloud or model provider. We build Tale for data-sensitive organizations — teams that want AI agents working across their stack without handing their data to someone else's platform. That conviction has a name. Your Infrastructure. Your Data. Your Rules. Today Tale connects the agents and CLIs teams already use — Claude Code, Codex, Hermes, OpenClaw, and more — pools what they learn into one governed knowledge base, and runs automations with a human in the approval loop. ## What we build Tale is the orchestrator for AI agents — one self-hosted platform that puts every agent, and everything it does, under your control. - One orchestrator for every agentTale connects the agents and CLIs your teams already use — Claude Code, Codex, Hermes, and OpenClaw — and delegates work across them from one place. - Open source, no asterisksThe entire codebase is public on GitHub under the MIT license. The free Community edition ships identical features; Enterprise adds support and services at CHF 12 (EUR 14) per user/month. - Your infrastructure or oursSelf-host on your own hardware, or use a managed cloud in Switzerland or the EU. Wherever Tale runs, no customer data is used to train models. - Beyond softwareWe also supply AI hardware to rent, lease, or buy, and run AI trainings for teams adopting agents. ## How we work with companies Tale is the platform — but adopting AI inside a regulated business is more than software. We work alongside teams on the data, the controls, and the goals that decide whether it delivers. - Data worth pointing agents atAgents inherit the quality of what they read. We start at the foundation — structure, ownership, provenance — so retrieval cites your reality instead of approximating it. - At home in regulated environmentsWhere audits, residency, and accountability set the limits, the deployment is the design: self-hosted or hosted in Switzerland or the EU, every action logged, human approval where it counts — GDPR-compliant and certified ISO 27001 & SOC 2 Type II. - An edge that stays yoursAdvantage compounds where the data and the workflows live. Running AI on your own stack keeps it inside your company instead of handing it to a competitor's platform or to an AI lab. - Solutions shaped to your goalsNo two organizations adopt AI the same way. We build the agents, automations, knowledge, and hardware around what you are trying to achieve — and leave out what you don't need. ## What we stand for - 01Data stays yoursBuilt for data-sensitive organizations — self-hosted by default, residency in Switzerland or the EU, GDPR-compliant, and no customer data used for model training. - 02Independent & vendor-neutralSwiss-based and vendor-neutral — no ties to a cloud or model provider, so your deployment answers only to you. - 03Transparent by defaultAn MIT-licensed public codebase and a company you can look up in the Swiss commercial register. What we ship is what you can read. - 04Humans stay in chargeAutomations run with human approval, and every action stays governed — ISO 27001 & SOC 2 Type II certified. ## Talk to the team Questions about Tale, deployment, or working with Ruler GmbH? Book a demo or reach us through the contact form. # How much does Tale cost? — Community & Enterprise Source: https://tale.dev/pricing # How much does Tale cost? Tale Enterprise is CHF 12 (EUR 14) per user/month, with two months free on yearly billing. The MIT-licensed Community edition is free to self-host. ## CommunitySelf-hosted only Every product feature, free to self-host — support happens on GitHub. Plan includes: - Self-hosted - MIT licensed - Community-maintained (GitHub) - Community support (GitHub) ## EnterpriseCloud or self-hosted Everything in Community, professionally run — installation, maintenance, and support, in the cloud or on your hardware. Plan includes: - Self-hosted or cloud - Professionally maintained (ISO 27001 & SOC 2 Type II certified) - GDPR compliant - Email, phone & remote support - Installation & ongoing maintenance - Influence on product roadmap 25 users × CHF 12/user/month 1 TB + CHF 10/TB/month additional storage All product features are included in both Community and Enterprise. Additional cloud AI model usage is billed at your provider's rates. ## Compare Plans Breakdown of each plan | | Community[Get started](/contact) | Enterprise[Contact us](/contact) | | --- | --- | --- | | Deployment | | | | Self-hosted | | | | Cloud | | | | Local data centers (CH & EU) | | | | Compliance | | | | GDPR compliant | | | | ISO 27001 & SOC 2 Type II certified | | | | PII redaction | | | | Custom DPA | | | | Support | | | | Email support | | | | Phone support | | | | Remote support | | | | Professional services | | | | Standard installation | CHF 1'990 | | | Maintenance | CHF 180 / h | | | Custom development | CHF 180 / h | | | Consulting | CHF 180 / h | | | Other | | | | Influence on product roadmap | | | | AI trainings | Courses that teach your team to build and run AI in production — explore our [AI training courses](https://app1.edoobox.com/en/Alltron/Network%20and%20server/K%C3%BCnstliche%20Intelligenz). | | | Hardware | For self-hosting, we offer [flexible hardware options](/hardware-pricing) — renting, buying, or financing. | | | Cloud AI providers | We support OpenAI, Anthropic, Gemini, and other major cloud AI providers in CH & EU — no markup; usage is billed at the provider's rates. | | | Terms | All configurations are subject to our [service agreement](/files/Service_Agreement_Template.pdf). | | ## Pricing FAQ ### How much does Tale Enterprise cost? ### Is Community free? ### Can I buy hardware with software? ## Related - [What does Tale AI hardware cost?Silent inference hardware from single nodes to racks — rent, lease, or buy. Deploy on-site with remote maintenance, or host in secure data centers.](/hardware-pricing) - [How does the Tale platform work?Tale connects agents, pools knowledge, runs automations, and governs every action — self-hosted for data-sensitive teams in Switzerland and the EU.](/platform) - [Contact the Tale team — sales, support, demosTalk to the Tale team about self-hosted AI for your organization — platform, pricing, hardware, or a guided demo. Replies land within one business day.](/contact) ## Put a number on your setup Request a demo or talk to the team about Enterprise seats, storage, and hardware. # What does Tale AI hardware cost? Source: https://tale.dev/hardware-pricing # What does Tale AI hardware cost? Silent inference hardware from single nodes to racks — rent, lease, or buy. Deploy on-site with remote maintenance, or host in secure data centers. ## Quality node Made for accuracy and consistent output. ## Application node Combines local data control with high-speed inference. ## Speed node Made for low-latency replies. All hardware configurations are silent (noise-free) and can be deployed at your site and maintained remotely by our team, or hosted in our secure data centers. ## Compare Configurations Breakdown of each configuration | | Quality node[Contact us](/request-demo) | Application node[Contact us](/request-demo) | Speed node[Contact us](/request-demo) | | --- | --- | --- | --- | | Product version | 26.04 (NQ) | 26.04 (NA) | 26.04 (NS) | | Product number | P0005 | P0006 | P0007 | | Specifications | | | | | AI RAM | 96GB (UMA) | 96GB (GDDR7) | 96GB (GDDR7) | | RAM | | 96GB (DDR5 ECC) | 64GB (DDR5 ECC) | | Chip (GPU) | 1× Apple Silicon | 1× NVIDIA RTX PRO 6000 | 1× NVIDIA RTX PRO 6000 | | Chip (CPU) | 1× AMD EPYC 4545P (Zen 5) | 1× AMD EPYC 4545P (Zen 5) | | | SSD | 1TB (m.2 NVMe) | 4TB (m.2 NVMe) | 1TB (m.2 NVMe) | | HDD | | | | | Size | 197mm × 197mm × 95mm | 192mm × 366mm × 270mm | 192mm × 366mm × 270mm | | Other | | | | | Recommended AI model | Kimi K2.6 (INT4) | DeepSeek V4 Pro (INT4) | Qwen3-235B-A22B (INT4) | | Cables & network equipment | | | | | Confidential computing | Available on request | | | | Warranty | 24 months manufacturer warranty (extensible to 36 months on request) | | | | Software & services | For installation, support, and professional services, we offer [flexible options](/pricing). | | | | Terms | All configurations are subject to our [hardware agreement](/files/Hardware_Agreement_Template.pdf). | | | ## Related - [How much does Tale cost? — Community & EnterpriseTale Enterprise is CHF 12 (EUR 14) per user/month, two months free on yearly billing. Community is free to self-host under MIT.](/pricing) - [How does the Tale platform work?Tale connects agents, pools knowledge, runs automations, and governs every action — self-hosted for data-sensitive teams in Switzerland and the EU.](/platform) - [Contact the Tale team — sales, support, demosTalk to the Tale team about self-hosted AI for your organization — platform, pricing, hardware, or a guided demo. Replies land within one business day.](/contact) ## Put a number on your setup Request a demo or talk to the team about Enterprise seats, storage, and hardware. # Contact the Tale team — sales, support, demos Source: https://tale.dev/contact Contact # Contact us Questions about self-hosting, Enterprise, hardware, or a deployment you're planning? Write to the team — replies land within one business day. # Request a Tale demo — a guided walkthrough Source: https://tale.dev/request-demo Demo # See Tale in action A guided demo is the product live, not a slide deck: agents docked, replies grounded in your kind of knowledge, and an automation pausing for approval — on a self-hosted instance. Tell us what your team runs today and what must never leave your network. You'll hear back within one business day with a time and a plan that fits. # How does the Tale platform work? Source: https://tale.dev/platform # How does the Tale platform work? Tale is the orchestrator for AI agents: one place where your agents share knowledge, run automations, and answer to the same approvals — self-hosted, on your terms. > Animated product demo: a platform overview question is typed into Tale, Auto routes it to the Orchestrator Agent, and the reply names the modules that answer it with two cited sources. ## How the platform fits together Every window below is one module telling its own story — ground it in Knowledge, run it through Automations, hold it at Governance, compare it in Arena. Open any module for the full tour. 01 Agents ### Every agent, one roster Claude Code, Codex, Hermes, OpenClaw — docked beside in-product agents so work routes to the tool your team already runs. > Animated demo: the hub Agents sampler — Orchestrator Agent, Support Agent, Docs Agent, Invoice Agent, and Policy Agent, each with its model. 02 Knowledge ### One library, cited everywhere The product manual, the docs crawl, the price list, an FAQ entry — one indexed library every agent cites. > Animated demo: the hub Knowledge sampler indexes the platform overview, the module map, the trust center crawl, and an onboarding FAQ. 03 Automations ### Delegate multi-step work An invoice pipeline extracts line items, holds anything over CHF 5,000, and files the rest to the ERP — every run logged. > Animated demo: a hub sampler workflow digests overnight module activity, checks for open approvals, and posts a morning brief to Slack. 04 Governance ### Held until someone decides Even a knowledge write waits for a person. Approve, and the decision lands in the audit log with the budget in view. > Animated demo: the hub sampler holds a cross-module publish until a person approves; the journal records the decision. 05 Arena ### Two drafts, one brief One announcement brief, two models side by side — the stronger draft ships. > Animated demo: the hub Arena sampler compares two module-overview drafts so the stronger intro ships on the platform page. 06 Projects ### Scope by team Every window above ran inside one workspace. Projects decide which agents, libraries, and members sit together — and who sees the runs. > Animated demo: hub Projects sampler — Platform core, Customer pilots, Partner enablement, and Internal ops, each with its own roster. ## Platform modules Chat, Projects, Knowledge, Agents, Automations, and Governance — each is useful alone; together they make one governed system. Open a module for its own tour. - [ChatsEveryday AI with citations, tools, and Arena.](/platform/chat) - [ProjectsShared workspaces where agents pick up tasks.](/platform/projects) - [KnowledgeDocuments, websites, and records agents cite.](/platform/knowledge) - [AgentsOrchestrate Claude Code, Codex, Hermes, and OpenClaw.](/platform/agents) - [AutomationsTyped workflows with triggers and approvals.](/platform/automations) - [GovernanceApprovals, audit trail, and spend controls.](/platform/governance) ## Platform FAQ ### What is the platform in Tale? ### Which modules does Tale include? ### Is Tale open source? ### Where should I start? ## See Tale on your stack Book a guided demo or talk to the team about self-hosted deployment, pricing, and hardware. # What are agents in Tale? — instructions, tools, models Source: https://tale.dev/platform/agents Agents # What are agents in Tale? A Tale agent is the four-knob combination of instructions, knowledge, tools, and a model. Editors build them once; the team runs them in chat, automations, and projects — on harnesses like Claude Code, Codex, Hermes, and OpenClaw when the work needs a coding CLI in a sandbox. > Animated demo: the Agents list for this page — Support Agent, Docs Agent, Release Agent, Research Agent, and Pilot Agent, each with its model. ## How agents show up in Tale Dock the agents you trust, ground them in knowledge, run them in workflows, and scope them by project. 01 Projects ### Scope agents by team Each project keeps its agents, members, and knowledge in one workspace — support never sees engineering’s stack. > Animated demo: Projects scoped so Support and Platform each keep their own agent stack and members. 02 Knowledge ### Ground every agent in what you know The Support Agent gets macros, brand voice, and the help-center crawl — and nothing else. Each agent searches only the slices you grant. > Animated demo: the knowledge slices granted to one agent — support macros, a brand-voice entry, the agent playbook crawl, and the returns playbook. 03 Automations ### Run agents in multi-step work Workflows call agents as LLM steps with conditions and actions — every run leaves an execution log. > Animated demo: a nightly workflow calls the Release Agent as its LLM step, checks whether anything shipped, and posts a digest to Slack; the Executions table records each run. 04 Sandbox ### Watch the agent in Files and Live Agents that run on a harness work in a sandbox — browse the workspace tree, open the file they just wrote, and watch the live browser as they click through the result. > Animated demo: Hermes edits install_offline.py in the Files pane, then the Live browser shows the air-gapped install checklist. ## What can agents do? What one agent definition gives the whole team — and what it adds beyond a bare model. - 01Four knobs, one unitInstructions, knowledge, tools, and model define how an agent behaves. Change one knob without re-training anything.[Agent concepts](https://docs.tale.dev/platform/agents/concepts) - 02Harnesses dock inBind Claude Code, Codex, Hermes, and OpenClaw as the harness a project agent or automation agent node runs on.[Harnesses](https://docs.tale.dev/platform/agents/harnesses) - 03Delegation between agentsSpecialist agents hand work to each other when a thread leaves one domain — without losing the transcript. - 04Skills as reusable bundlesPackage a writing voice or multi-step pattern once and bind it to up to ten agents. - 05Knowledge scoped per agentEach agent searches only the library slices you grant — team docs stay invisible outside the team. ## Agents FAQ ### What is an agent in Tale? ### Can Tale orchestrate Claude Code and Hermes? ### When should I use an agent instead of a workflow? ### Can each agent use a different model? ## Related modules - [ChatsEveryday AI with citations, tools, and Arena.](/platform/chat) - [KnowledgeDocuments, websites, and records agents cite.](/platform/knowledge) - [AutomationsTyped workflows with triggers and approvals.](/platform/automations) - [GovernanceApprovals, audit trail, and spend controls.](/platform/governance) ## Read the docs - [Agent concepts](https://docs.tale.dev/platform/agents/concepts) - [Project agents](https://docs.tale.dev/platform/projects/project-agents) - [Harnesses](https://docs.tale.dev/platform/agents/harnesses) - [Task automation](https://docs.tale.dev/platform/projects/task-automation) - [Knowledge](https://docs.tale.dev/platform/knowledge/overview) ## See Tale on your stack Book a guided demo or talk to the team about self-hosted deployment, pricing, and hardware. # What is Chat in Tale? — agents, citations, approvals Source: https://tale.dev/platform/chat Chats # Chats in Tale Chat is the everyday entry point: pick an agent (or none), type, and a reply streams back with citations, tool calls, and optional Arena comparisons — the surface every other platform module feeds. > Animated demo: Chat Arena runs one announcement prompt through Claude Sonnet and GPT-5.5 side by side so the writer picks the stronger draft. ## How Chat works in Tale From a grounded reply to Arena, approvals, knowledge, and scoped projects — the same surfaces you use every day. 01 Approvals ### Approvals live in the thread When a reply would post to Slack, send mail, or change a system, an approval card lands in the thread before anything ships. > Animated demo: an in-chat approval card asks to post the release announcement to the #customers Slack channel; approval is granted and journaled. 02 Projects ### Threads stay with their team A thread belongs to its workspace. The Comms Agent's drafts stay with comms — engineering never has to scroll past them. > Animated demo: Projects that keep chat threads in the right workspace — Comms drafts stay out of engineering chat. 03 Agents ### Pick the agent that owns the ask Switch specialists mid-thread or let Auto route — every agent carries its own instructions, knowledge, and tools. > Animated demo: Chat’s specialist roster — Comms Agent, Support Agent, Research Agent, Docs Agent, and Release Agent. 04 Knowledge ### Ground every reply in indexed sources Chat retrieves from the libraries you grant — citation cards land in the thread so readers can open the file or page the answer used. > Animated demo: the sources Chat retrieves for a grounded reply — the release notes PDF, the changelog crawl, the announcement template, and the brand-voice entry. ## What does Chat include? Everyday AI that cites its sources, calls your tools, and compares models side by side. - 01Composer with Auto routingThe composer carries the agent picker and model picker. Auto lets Tale pick the model for the thread.[Chat basics](https://docs.tale.dev/platform/chat/basics) - 02Citations on every grounded replyRetrieved passages carry their source so readers can open the file, entry, or page the answer used.[Chat basics](https://docs.tale.dev/platform/chat/basics) - 03Arena modeCompare models or agents side by side when you need a second opinion before you commit.[Arena Mode](https://docs.tale.dev/platform/chat/arena-mode) - 04Attachments and CanvasUpload supported files; open Canvas when the reply needs a long document or diagram beside the thread.[Attachments](https://docs.tale.dev/platform/chat/attachments) - 05Agents in the threadSwitch agents mid-thread, run one-shot specialists, or keep a sticky agent for the conversation.[Agents in chat](https://docs.tale.dev/platform/chat/agents-in-chat) ## Chat FAQ ### What is Chat in Tale? ### Does Chat work without an agent? ### What is Arena mode? ### Can Chat take actions, or only answer? ## Related modules - [ProjectsShared workspaces where agents pick up tasks.](/platform/projects) - [KnowledgeDocuments, websites, and records agents cite.](/platform/knowledge) - [AgentsOrchestrate Claude Code, Codex, Hermes, and OpenClaw.](/platform/agents) - [GovernanceApprovals, audit trail, and spend controls.](/platform/governance) ## Read the docs - [Chat overview](https://docs.tale.dev/platform/chat/overview) - [Chat basics](https://docs.tale.dev/platform/chat/basics) - [Arena Mode](https://docs.tale.dev/platform/chat/arena-mode) - [Agents in chat](https://docs.tale.dev/platform/chat/agents-in-chat) - [Attachments](https://docs.tale.dev/platform/chat/attachments) ## See Tale on your stack Book a guided demo or talk to the team about self-hosted deployment, pricing, and hardware. # What are Projects in Tale? — shared agent workspaces Source: https://tale.dev/platform/projects Projects # What are Projects in Tale? Projects are shared workspaces that bundle the chats, files, instructions, and task board for one piece of work — so context follows the work and agents pick tasks up where your team leaves them. > Animated demo: the Projects list — each shared workspace with its agents and members. ## How projects run work Assign a task to an agent, resume the project chat with its context, ground replies in project files, and keep outbound steps behind review. 01 Tasks ### Assign a card, an agent takes it Assigning a board task to an agent starts the task-ops loop — execution, checks, and escalation run on workflows your organization owns and can tune. > Animated demo: the Website relaunch board — Relaunch Agent works WEB-12 (migration guide) in In progress while WEB-11 waits in In review. 02 Chats ### Every chat starts with the context Project instructions and files ride along in every thread, so a new chat picks up the relaunch where the last one stopped. > Animated demo: a project chat resumes the website relaunch with the project's instructions and files as context; the agent answers with citations. 03 Knowledge ### Files that stay inside the project The Knowledge tab keeps the project's folder tree indexed for retrieval — cited in project chats, invisible outside the project. > Animated demo: the project's Knowledge tab — brand guidelines, the current site crawl, the redirect map, and the launch checklist. 04 Review ### Nothing ships without a decision When a task would publish or send, the approval card lands with the project's owner — and the decision stays in the audit trail. > Animated demo: publishing the relaunched pricing page pauses on an approval card until the project owner decides. ## One workspace per piece of work A project keeps everything a contact, a launch, or an investigation needs in one place — and puts agents to work inside it. - 01Context that follows the workChats, files, instructions, and tasks live on the project's tabs, so nobody re-pastes background into a fresh composer.[Projects overview](https://docs.tale.dev/platform/projects/overview) - 02A board agents work fromAssign a task card to an agent and the task-ops pack runs it — triage, execution, review, and escalation included.[Task automation](https://docs.tale.dev/platform/projects/task-automation) - 03A backlog with human triageAutomations propose work; a teammate starts what is worth doing and closes what is not. Nothing runs unvetted.[Project backlog](https://docs.tale.dev/platform/projects/backlog) - 04Files scoped to the projectThe Knowledge tab holds the project's folder tree — indexed for retrieval inside the project, invisible outside it.[Manage files](https://docs.tale.dev/platform/projects/manage-files) - 05The right agents on callCurate which agents and models members see in the project, so the recommended specialist is one click away.[Agents and models](https://docs.tale.dev/platform/projects/project-agents) ## Projects FAQ ### What is a project in Tale? ### How do agents work on project tasks? ### Who sees a project's chats and files? ### How is a project different from a chat? ## Related modules - [ChatsEveryday AI with citations, tools, and Arena.](/platform/chat) - [AgentsOrchestrate Claude Code, Codex, Hermes, and OpenClaw.](/platform/agents) - [AutomationsTyped workflows with triggers and approvals.](/platform/automations) - [KnowledgeDocuments, websites, and records agents cite.](/platform/knowledge) ## Read the docs - [Projects overview](https://docs.tale.dev/platform/projects/overview) - [Project concepts](https://docs.tale.dev/platform/projects/concepts) - [Task automation](https://docs.tale.dev/platform/projects/task-automation) - [Project backlog](https://docs.tale.dev/platform/projects/backlog) - [Manage files](https://docs.tale.dev/platform/projects/manage-files) - [Agents and models](https://docs.tale.dev/platform/projects/project-agents) ## See Tale on your stack Book a guided demo or talk to the team about self-hosted deployment, pricing, and hardware. # What are Automations in Tale? — triggers to approvals Source: https://tale.dev/platform/automations Automations # What are Automations in Tale? An automation bundles connectors, agents, a workflow, and the views it ships — an Inbox, for example — into one installable unit. The workflow inside is a graph of typed steps — LLM, Action, Condition, Loop, Sandbox — with schedules, webhooks, events, and human approvals. > Animated demo: an invoice pipeline extracts line items, holds amounts over CHF 5,000 for approval, and files the rest to the ERP; the Executions table records each run. ## How automations run in Tale Chain triggers, LLM steps, and actions — then approve what ships and ground every step in knowledge. 01 Approvals ### Human-in-the-loop before it ships The run pauses where you told it to. Approve releases the held step with a journal entry; reject stops the run cold. > Animated demo: the invoice batch held by the workflow asks for approval in chat; approving files the invoices and writes the run journal. 02 Agents ### Call the right agent as an LLM step Workflows pick specialists the same way Chat does — instructions, knowledge, and tools travel with the step. > Animated demo: specialists workflows call as LLM steps — Invoice Agent, Vendor Agent, ERP Agent, Matching Agent, and Exceptions Agent. 03 Knowledge ### Ground every step in indexed sources The pipeline's LLM steps read from vendor contracts, the ERP field map, and the supplier crawl — every classification cites the source it used. > Animated demo: the sources the pipeline's LLM steps retrieve from — vendor contracts, an ERP field-map entry, the supplier portal crawl, and vendor records. 04 Projects ### Scope workflows by workspace Projects keep automations, agents, and members together so ops runs stay out of engineering. > Animated demo: Projects that scope automations by workspace — ops pipelines stay out of engineering. ## What ships in an automation? Compose multi-step work as a typed graph — LLM, action, condition, loop, and sandbox steps — with approvals and versioned runs. - 01Installable bundlesOwners and Admins install from the catalog; Members use the Inbox, agents, or views it registers without assembling pieces by hand.[Automation concepts](https://docs.tale.dev/platform/automations/concepts) - 02Typed workflow stepsLLM, Action, Condition, Loop, and Sandbox steps compose the graph. Every save snapshots a version you can restore.[Workflow editor](https://docs.tale.dev/platform/automations/editor) - 03Triggers that fit the jobSchedules (cron), webhooks, platform events, or a manual test run from the editor.[Triggers](https://docs.tale.dev/platform/automations/triggers) - 04Execution logsEvery run records status, timing, inputs, and a per-step journal — audit trail and debugger in one place.[Execution logs](https://docs.tale.dev/platform/automations/execution-logs) - 05Approvals in the loopProposed workflow edits, agent-started runs, and waiting-for-input pauses land as approval cards before work continues. ## Automations FAQ ### What is an automation in Tale? ### Is there a standalone workflow product? ### When should I use an automation instead of an agent? ### Can I test a workflow before it runs on a schedule? ## Related modules - [AgentsOrchestrate Claude Code, Codex, Hermes, and OpenClaw.](/platform/agents) - [KnowledgeDocuments, websites, and records agents cite.](/platform/knowledge) - [GovernanceApprovals, audit trail, and spend controls.](/platform/governance) - [ChatsEveryday AI with citations, tools, and Arena.](/platform/chat) ## Read the docs - [Automation concepts](https://docs.tale.dev/platform/automations/concepts) - [Workflow editor](https://docs.tale.dev/platform/automations/editor) - [Triggers](https://docs.tale.dev/platform/automations/triggers) - [Execution logs](https://docs.tale.dev/platform/automations/execution-logs) - [Built-in automations](https://docs.tale.dev/platform/automations/builtin) ## See Tale on your stack Book a guided demo or talk to the team about self-hosted deployment, pricing, and hardware. # What is Knowledge in Tale? — indexed and cited sources Source: https://tale.dev/platform/knowledge Knowledge # What is Knowledge in Tale? Knowledge is the org's shared library — documents, knowledge entries, crawled websites, and typed records — that agents retrieve and cite so replies reflect your reality, not only model training data. > Animated demo: the org library indexes the product manual, the docs site crawl, the 2026 price list, and an onboarding FAQ entry. ## How knowledge grounds Tale Index what your company knows, cite it in chat, bind it to agents, and keep comparisons honest. 01 Chat ### Every grounded reply carries its sources Retrieved passages land as citation cards so readers can open the file or page the answer used. > Animated demo: a battery-care question is answered from the indexed product manual, with the manual and the FAQ entry cited beneath the reply. 02 Agents ### Grant libraries per agent An agent sees its grants and nothing more — what legal indexed never surfaces in a support thread. > Animated demo: agents granted library slices — Product Agent, Docs Agent, Support Agent, Research Agent, and Policy Agent. 03 Arena ### Compare answers on the same sources Arena runs one prompt through two models so you can see which reply uses the knowledge better. > Animated demo: two models answer the same warranty question from the same indexed sources, so the better-grounded reply wins. 04 Projects ### Libraries live with their teams Projects scope which documents sit next to which agents and members. > Animated demo: Projects that keep libraries next to the agents and members who use them. ## What lives in Knowledge? Give agents the documents, records, and crawls they need — and every answer cites where it came from. - 01Documents with an indexing pipelineUpload files; Tale extracts, chunks, embeds, and stores them for retrieval with citations.[Documents](https://docs.tale.dev/platform/knowledge/documents) - 02Knowledge entriesSmall topic-keyed facts — captured from chat with approval or added by hand.[Knowledge entries](https://docs.tale.dev/platform/knowledge/knowledge-entries) - 03Website crawlsIndex pages your agents should cite without pasting them into prompts.[Crawling](https://docs.tale.dev/platform/knowledge/crawling) - 04Typed recordsProducts, Contacts, and Vendors are exact field rows agents read as data, not prose.[Structured data](https://docs.tale.dev/platform/knowledge/structured-data) - 05Per-agent retrieval scopeAn agent's Knowledge tab decides which slices it can search; team items stay team-scoped. ## Knowledge FAQ ### What is Knowledge in Tale? ### Do agents see the whole library by default? ### What is the difference between documents and typed records? ### Can agents write to Knowledge, or only read? ## Related modules - [ChatsEveryday AI with citations, tools, and Arena.](/platform/chat) - [AgentsOrchestrate Claude Code, Codex, Hermes, and OpenClaw.](/platform/agents) - [AutomationsTyped workflows with triggers and approvals.](/platform/automations) - [GovernanceApprovals, audit trail, and spend controls.](/platform/governance) ## Read the docs - [Knowledge overview](https://docs.tale.dev/platform/knowledge/overview) - [Documents](https://docs.tale.dev/platform/knowledge/documents) - [Knowledge entries](https://docs.tale.dev/platform/knowledge/knowledge-entries) - [Crawling](https://docs.tale.dev/platform/knowledge/crawling) - [Structured data](https://docs.tale.dev/platform/knowledge/structured-data) ## See Tale on your stack Book a guided demo or talk to the team about self-hosted deployment, pricing, and hardware. # What is Governance in Tale? — approvals and audit trail Source: https://tale.dev/platform/governance Governance # What is Governance in Tale? Governance is the seam between agent initiative and human judgement: approval cards hold actions until someone decides, every decision lands in the audit log, and spend stays visible — without a separate approver inbox. > Animated demo: an agent asks to publish three knowledge entries captured from a thread; a person approves, and the decision lands in the audit log. ## How governance holds the line Approve before actions ship, audit every run, compare models honestly, and keep agents inside your rules. 01 Automations ### Every gated run leaves a log A nightly access review runs on schedule and alerts #security on new admin grants — every execution numbered in the same journal approvals write to. > Animated demo: a scheduled access review checks permission changes each night and alerts the #security channel when new admin grants appear. 02 Arena ### Compare before you commit Policy-sensitive wording is exactly where models disagree. Arena drafts the same reply twice so the safer version ships. > Animated demo: two models draft the same access-exception reply side by side, so the safer wording ships. 03 Agents ### Agents stay inside budgets and tools Spend controls and tool grants travel with each agent — governance is not a separate bolt-on. > Animated demo: agents carrying spend controls and tool grants — Policy Agent, Audit Agent, Budget Agent, Access Agent, and Exceptions Agent. 04 Knowledge ### Cite what policy allowed the reply Grounded answers show the policy and runbook sources so auditors can follow the same trail. > Animated demo: the policy corpus auditors can open — the AI-usage policy, the trust page crawl, a data-handling entry, and the model risk register. ## What does governance cover? Put a human in the loop where it matters — with an audit trail, budget controls, and filters that keep sensitive data out of prompts and replies. - 01In-chat approval cardsPlans, document writes, knowledge writes, connector calls, MCP tools, and workflow runs pause until approve or reject.[Approval concepts](https://docs.tale.dev/platform/approvals/concepts) - 02Suggest changes on connectorsDescribe what is wrong; the agent revises the call instead of abandoning the work.[Approval concepts](https://docs.tale.dev/platform/approvals/concepts) - 03Audit trailEach decision records actor, action, and timestamp. Resolved cards stay in the transcript.[Audit logs](https://docs.tale.dev/platform/admin/governance/audit-logs) - 04Guardrails and policiesOrg-level guardrails and policies set the limits on what agents may attempt — before a card ever appears.[Guardrails](https://docs.tale.dev/platform/admin/governance/guardrails) - 05PII filtered in both directionsEvery chat message passes content safety, PII detection, and an optional moderation provider — on the way in and the way out. Matches block, mask, or flag; the matched text itself is never stored.[Guardrails](https://docs.tale.dev/platform/admin/governance/guardrails) - 06Usage visibilityUsage analytics and budgets keep model spend visible to Admins. ## Governance FAQ ### What is Governance in Tale? ### Is there a separate approval inbox? ### Can I choose which actions require approval? ### Can agents send email without approval? ### How does Tale help with GDPR and PII? ## Related modules - [AutomationsTyped workflows with triggers and approvals.](/platform/automations) - [ProjectsShared workspaces where agents pick up tasks.](/platform/projects) - [AgentsOrchestrate Claude Code, Codex, Hermes, and OpenClaw.](/platform/agents) - [ChatsEveryday AI with citations, tools, and Arena.](/platform/chat) ## Read the docs - [Approval concepts](https://docs.tale.dev/platform/approvals/concepts) - [Configure approvals](https://docs.tale.dev/platform/approvals/configure) - [Approvals in workflows](https://docs.tale.dev/platform/automations/approvals-in-workflows) - [Audit logs](https://docs.tale.dev/platform/admin/governance/audit-logs) - [Guardrails](https://docs.tale.dev/platform/admin/governance/guardrails) ## See Tale on your stack Book a guided demo or talk to the team about self-hosted deployment, pricing, and hardware. # What's new in Tale? — Changelog Source: https://tale.dev/changelog Changelog # What's new in Tale? Release notes for Tale, newest first — published from GitHub Releases. Sourced from [GitHub Releases](https://github.com/tale-project/tale/releases). ## v0.5.62September 29, 2026 ### API contract changes The contract moved from 2.1.0 to 3.3.0 (136 → 136 operations). Read the API reference's versioning section before upgrading a pinned client. Added operations: none. Removed operations: none. #### Changelog 3.3.0 — 2026-09-28: `Task` carries its schedule and how it repeats, read only: `startDate` and `dueDate` (epoch ms, present when set), `repeat` — the new `TaskRepeat` rule (frequency, interval, anchors, `timezone`, and `createOn: "dueDate"` when the next task is also created on the due date) or null when the task does not repeat — and `repeatNextTaskId`, the task that continues its series once one exists. An approved review (`POST …/tasks/{taskId}/review`) that closes a repeating task continues its series as a close in the app does. ### What's Changed - feat: run organizations' sandboxes on devices they connect by @yannickmonney in [https://github.com/tale-project/tale/pull/3504](https://github.com/tale-project/tale/pull/3504) - fix(platform): destroy the container of a failed agent session by @yannickmonney in [https://github.com/tale-project/tale/pull/3505](https://github.com/tale-project/tale/pull/3505) - fix(platform): make embedding credential refusals terminal by @yannickmonney in [https://github.com/tale-project/tale/pull/3507](https://github.com/tale-project/tale/pull/3507) - fix(platform): answer a database restart with 503, not a crash or 500 by @yannickmonney in [https://github.com/tale-project/tale/pull/3506](https://github.com/tale-project/tale/pull/3506) - feat(platform): fold project metrics from the live task rows by @larryro in [https://github.com/tale-project/tale/pull/3508](https://github.com/tale-project/tale/pull/3508) - fix(platform): treat a cancelled request as neither failure nor outage by @yannickmonney in [https://github.com/tale-project/tale/pull/3510](https://github.com/tale-project/tale/pull/3510) - fix(platform): recover a tab that outlived a deploy by @yannickmonney in [https://github.com/tale-project/tale/pull/3509](https://github.com/tale-project/tale/pull/3509) - fix(platform): bound conversation timestamps, tolerate stored ones by @yannickmonney in [https://github.com/tale-project/tale/pull/3511](https://github.com/tale-project/tale/pull/3511) - fix(platform): merge each live transcript flush into the op row by @yannickmonney in [https://github.com/tale-project/tale/pull/3512](https://github.com/tale-project/tale/pull/3512) - fix(platform): send an email that carries only an attachment by @yannickmonney in [https://github.com/tale-project/tale/pull/3514](https://github.com/tale-project/tale/pull/3514) - fix(platform): show members the password rules they are held to by @yannickmonney in [https://github.com/tale-project/tale/pull/3515](https://github.com/tale-project/tale/pull/3515) - fix(platform): report browser defects, not extension or refusal noise by @yannickmonney in [https://github.com/tale-project/tale/pull/3513](https://github.com/tale-project/tale/pull/3513) - fix(platform): spare a session with a live turn from the expiry sweep by @yannickmonney in [https://github.com/tale-project/tale/pull/3516](https://github.com/tale-project/tale/pull/3516) - fix(platform): re-target the pending review when the reviewer changes by @yannickmonney in [https://github.com/tale-project/tale/pull/3517](https://github.com/tale-project/tale/pull/3517) - feat(platform): audit each retention run and what it destroyed by @yannickmonney in [https://github.com/tale-project/tale/pull/3518](https://github.com/tale-project/tale/pull/3518) - fix(platform): name the title limit when task_create refuses by @yannickmonney in [https://github.com/tale-project/tale/pull/3529](https://github.com/tale-project/tale/pull/3529) - feat(platform): fan out @mentions in task descriptions by @yannickmonney in [https://github.com/tale-project/tale/pull/3519](https://github.com/tale-project/tale/pull/3519) - fix(platform): show the server's refusal reasons in the app by @yannickmonney in [https://github.com/tale-project/tale/pull/3520](https://github.com/tale-project/tale/pull/3520) - fix(platform): give synced files no extractor reads a terminal status by @yannickmonney in [https://github.com/tale-project/tale/pull/3540](https://github.com/tale-project/tale/pull/3540) - feat(platform): index inbound email bodies for chat retrieval by @yannickmonney in [https://github.com/tale-project/tale/pull/3530](https://github.com/tale-project/tale/pull/3530) - fix(platform): let task runs call connectors for the run's starter by @yannickmonney in [https://github.com/tale-project/tale/pull/3528](https://github.com/tale-project/tale/pull/3528) - fix(platform): log pg-boss's failed polls once per database outage by @yannickmonney in [https://github.com/tale-project/tale/pull/3548](https://github.com/tale-project/tale/pull/3548) - fix(platform): read the flat error envelope's code in backendFetch by @yannickmonney in [https://github.com/tale-project/tale/pull/3539](https://github.com/tale-project/tale/pull/3539) - chore(platform): label the dev toolchain step as external toolchains by @yannickmonney in [https://github.com/tale-project/tale/pull/3521](https://github.com/tale-project/tale/pull/3521) - fix(platform): stop reporting client aborts and unparseable bodies by @yannickmonney in [https://github.com/tale-project/tale/pull/3536](https://github.com/tale-project/tale/pull/3536) - fix(ui): answer 404 for a site path carrying a NUL byte by @yannickmonney in [https://github.com/tale-project/tale/pull/3537](https://github.com/tale-project/tale/pull/3537) - fix(platform): hold every stored date to the epoch bound by @yannickmonney in [https://github.com/tale-project/tale/pull/3549](https://github.com/tale-project/tale/pull/3549) - fix(platform): keep the ElevenLabs key out of the root .env.example by @yannickmonney in [https://github.com/tale-project/tale/pull/3543](https://github.com/tale-project/tale/pull/3543) - fix(platform): frame project sharing as settings field rows by @yannickmonney in [https://github.com/tale-project/tale/pull/3522](https://github.com/tale-project/tale/pull/3522) - test(platform): port the chat conversation search privacy suite by @yannickmonney in [https://github.com/tale-project/tale/pull/3541](https://github.com/tale-project/tale/pull/3541) - feat(platform): reap expired auth sessions once a day by @yannickmonney in [https://github.com/tale-project/tale/pull/3545](https://github.com/tale-project/tale/pull/3545) - fix(platform): sweep chat filter events under their retention policy by @yannickmonney in [https://github.com/tale-project/tale/pull/3544](https://github.com/tale-project/tale/pull/3544) - fix(platform): collect the render lane's failed sessions by @yannickmonney in [https://github.com/tale-project/tale/pull/3547](https://github.com/tale-project/tale/pull/3547) - fix(platform): disable filters over empty, unfiltered lists by @yannickmonney in [https://github.com/tale-project/tale/pull/3525](https://github.com/tale-project/tale/pull/3525) - feat(platform): make the contact-support URL configurable by @yannickmonney in [https://github.com/tale-project/tale/pull/3523](https://github.com/tale-project/tale/pull/3523) - fix(platform): give uploaded files no extractor reads a terminal status by @yannickmonney in [https://github.com/tale-project/tale/pull/3556](https://github.com/tale-project/tale/pull/3556) - fix(platform): retire the schedules and rows of deleted organizations by @yannickmonney in [https://github.com/tale-project/tale/pull/3550](https://github.com/tale-project/tale/pull/3550) - fix(platform): keep the org accent legible on every mark it paints by @yannickmonney in [https://github.com/tale-project/tale/pull/3534](https://github.com/tale-project/tale/pull/3534) - fix(docs): hash the docs tree in every task that reads it by @yannickmonney in [https://github.com/tale-project/tale/pull/3553](https://github.com/tale-project/tale/pull/3553) - feat(platform): refuse an embedding provider that cannot embed by @yannickmonney in [https://github.com/tale-project/tale/pull/3527](https://github.com/tale-project/tale/pull/3527) - fix(sandbox): give every harness the built-in visual-aspect-analyzer by @yannickmonney in [https://github.com/tale-project/tale/pull/3535](https://github.com/tale-project/tale/pull/3535) - fix(platform): give code and text previews an editor's line rhythm by @yannickmonney in [https://github.com/tale-project/tale/pull/3524](https://github.com/tale-project/tale/pull/3524) - fix(platform): name every refused limit in task tools and doors by @yannickmonney in [https://github.com/tale-project/tale/pull/3546](https://github.com/tale-project/tale/pull/3546) - feat(platform): add floating mobile navigation that compacts on scroll by @Israeltheminer in [https://github.com/tale-project/tale/pull/3573](https://github.com/tale-project/tale/pull/3573) - feat(platform): pause a schedule after five permanent failures in a row by @yannickmonney in [https://github.com/tale-project/tale/pull/3533](https://github.com/tale-project/tale/pull/3533) - refactor(platform): drop the retired sandbox tables by @yannickmonney in [https://github.com/tale-project/tale/pull/3532](https://github.com/tale-project/tale/pull/3532) - test(platform): keep shutdown clients alive through close by @yannickmonney in [https://github.com/tale-project/tale/pull/3570](https://github.com/tale-project/tale/pull/3570) - build(platform): hash the config tree and other files the tests read by @yannickmonney in [https://github.com/tale-project/tale/pull/3560](https://github.com/tale-project/tale/pull/3560) - fix(platform): page every settings list alike and create via addAction by @yannickmonney in [https://github.com/tale-project/tale/pull/3531](https://github.com/tale-project/tale/pull/3531) - fix(platform): restore reply files on undo and name their remove button by @yannickmonney in [https://github.com/tale-project/tale/pull/3552](https://github.com/tale-project/tale/pull/3552) - fix(platform): focus task dialogs when they open by @yannickmonney in [https://github.com/tale-project/tale/pull/3562](https://github.com/tale-project/tale/pull/3562) - fix(platform): name the refused field at the app doors and in forms by @yannickmonney in [https://github.com/tale-project/tale/pull/3538](https://github.com/tale-project/tale/pull/3538) - fix(platform): treat emailed attachments as mail in retrieval by @yannickmonney in [https://github.com/tale-project/tale/pull/3555](https://github.com/tale-project/tale/pull/3555) - fix(platform): make task list titles keyboard accessible by @yannickmonney in [https://github.com/tale-project/tale/pull/3564](https://github.com/tale-project/tale/pull/3564) - fix(platform): pin object-store to linux/amd64 by @Israeltheminer in [https://github.com/tale-project/tale/pull/3571](https://github.com/tale-project/tale/pull/3571) - fix(platform): list the caller's slugs on every org slug refusal by @yannickmonney in [https://github.com/tale-project/tale/pull/3526](https://github.com/tale-project/tale/pull/3526) - fix(docs): hash the ui i18n files the docs tests read by @yannickmonney in [https://github.com/tale-project/tale/pull/3563](https://github.com/tale-project/tale/pull/3563) - fix(platform): keep pinned sandboxes pinned through the drift reconcile by @yannickmonney in [https://github.com/tale-project/tale/pull/3542](https://github.com/tale-project/tale/pull/3542) - fix(platform): close the reviewer edge cases after re-targeting by @yannickmonney in [https://github.com/tale-project/tale/pull/3554](https://github.com/tale-project/tale/pull/3554) - fix(platform): preserve Inbox drafts after upload failures by @yannickmonney in [https://github.com/tale-project/tale/pull/3566](https://github.com/tale-project/tale/pull/3566) - fix(ui): stop a multi-button toast action from squeezing beside copy by @Israeltheminer in [https://github.com/tale-project/tale/pull/3574](https://github.com/tale-project/tale/pull/3574) - fix(platform): name task limits alike on every door and cut long imports by @yannickmonney in [https://github.com/tale-project/tale/pull/3577](https://github.com/tale-project/tale/pull/3577) - fix(platform): name a harness turn by the harness it ran on by @larryro in [https://github.com/tale-project/tale/pull/3575](https://github.com/tale-project/tale/pull/3575) - fix(platform): cancel pending Inbox editor work on teardown by @yannickmonney in [https://github.com/tale-project/tale/pull/3578](https://github.com/tale-project/tale/pull/3578) - fix(platform): extend 'Not supported' to thread attachments and old rows by @yannickmonney in [https://github.com/tale-project/tale/pull/3579](https://github.com/tale-project/tale/pull/3579) - fix(platform): send the live inbox editor document by @yannickmonney in [https://github.com/tale-project/tale/pull/3568](https://github.com/tale-project/tale/pull/3568) - fix(platform): take the audit chain before removing a trigger's run by @yannickmonney in [https://github.com/tale-project/tale/pull/3594](https://github.com/tale-project/tale/pull/3594) - fix(platform): never preload admin-only policies for a member by @yannickmonney in [https://github.com/tale-project/tale/pull/3551](https://github.com/tale-project/tale/pull/3551) - fix(platform): close the trigger doors of deleted organizations by @yannickmonney in [https://github.com/tale-project/tale/pull/3576](https://github.com/tale-project/tale/pull/3576) - fix(ui): answer 404 for a site path too long to name a file by @yannickmonney in [https://github.com/tale-project/tale/pull/3648](https://github.com/tale-project/tale/pull/3648) - test(platform): make the chat search fake parse the leg's SQL by @yannickmonney in [https://github.com/tale-project/tale/pull/3649](https://github.com/tale-project/tale/pull/3649) - test(platform): verify SOPS timeout termination directly by @yannickmonney in [https://github.com/tale-project/tale/pull/3638](https://github.com/tale-project/tale/pull/3638) - fix(platform): preserve drafts during session recovery by @yannickmonney in [https://github.com/tale-project/tale/pull/3569](https://github.com/tale-project/tale/pull/3569) - fix(platform): clear stale mail stamps in the nightly stamp pass by @yannickmonney in [https://github.com/tale-project/tale/pull/3668](https://github.com/tale-project/tale/pull/3668) - fix(platform): harden the configurable contact-support URL by @yannickmonney in [https://github.com/tale-project/tale/pull/3650](https://github.com/tale-project/tale/pull/3650) - fix(platform): keep source previews still and legible while they load by @yannickmonney in [https://github.com/tale-project/tale/pull/3683](https://github.com/tale-project/tale/pull/3683) - fix(sandbox): answer CPU usage on the first capacity poll by @larryro in [https://github.com/tale-project/tale/pull/3690](https://github.com/tale-project/tale/pull/3690) - test(platform): guard the inherited turbo inputs of the test task by @yannickmonney in [https://github.com/tale-project/tale/pull/3686](https://github.com/tale-project/tale/pull/3686) - fix(platform): close the schedule pause streak's review follow-ups by @yannickmonney in [https://github.com/tale-project/tale/pull/3688](https://github.com/tale-project/tale/pull/3688) - fix(platform): harden data migrations and scope RAG status hints by @yannickmonney in [https://github.com/tale-project/tale/pull/3687](https://github.com/tale-project/tale/pull/3687) - feat(platform): move automation versions into the workbench by @Israeltheminer in [https://github.com/tale-project/tale/pull/3692](https://github.com/tale-project/tale/pull/3692) - fix(ui): refine update toast action styling by @Israeltheminer in [https://github.com/tale-project/tale/pull/3693](https://github.com/tale-project/tale/pull/3693) - fix(platform): restore Safari viewport and lower mobile navigation by @Israeltheminer in [https://github.com/tale-project/tale/pull/3694](https://github.com/tale-project/tale/pull/3694) - fix(platform): name tasks, not ids, when dragging by keyboard by @yannickmonney in [https://github.com/tale-project/tale/pull/3684](https://github.com/tale-project/tale/pull/3684) - fix(platform): say a lapsed session in words on every surface by @yannickmonney in [https://github.com/tale-project/tale/pull/3685](https://github.com/tale-project/tale/pull/3685) - fix(platform): close the app-door refusal review follow-ups by @yannickmonney in [https://github.com/tale-project/tale/pull/3696](https://github.com/tale-project/tale/pull/3696) - test(platform): pin the chat search's empty term and cap edges by @yannickmonney in [https://github.com/tale-project/tale/pull/3697](https://github.com/tale-project/tale/pull/3697) - fix(platform): drain chat filter events past one batch per run by @yannickmonney in [https://github.com/tale-project/tale/pull/3702](https://github.com/tale-project/tale/pull/3702) - fix(ui): keep an open filter panel and a failed read's filter usable by @yannickmonney in [https://github.com/tale-project/tale/pull/3703](https://github.com/tale-project/tale/pull/3703) - fix(platform): describe project fields by their settings row's help by @yannickmonney in [https://github.com/tale-project/tale/pull/3699](https://github.com/tale-project/tale/pull/3699) - fix(platform): follow up task limits and imports after #3577 by @yannickmonney in [https://github.com/tale-project/tale/pull/3689](https://github.com/tale-project/tale/pull/3689) - fix(platform): prevent focus zoom in Safari browser tabs by @Israeltheminer in [https://github.com/tale-project/tale/pull/3695](https://github.com/tale-project/tale/pull/3695) - fix(platform): close the accent audit's remaining gaps by @yannickmonney in [https://github.com/tale-project/tale/pull/3698](https://github.com/tale-project/tale/pull/3698) - fix(platform): finish the settings-list page sizes and API key focus by @yannickmonney in [https://github.com/tale-project/tale/pull/3700](https://github.com/tale-project/tale/pull/3700) - fix(platform): close the fail-open embedding provider refusal by @yannickmonney in [https://github.com/tale-project/tale/pull/3701](https://github.com/tale-project/tale/pull/3701) - fix(platform): refresh watchdog ownership after settlement by @yannickmonney in [https://github.com/tale-project/tale/pull/3727](https://github.com/tale-project/tale/pull/3727) - fix(platform): keep chat sharing truthful, prefixed and keyboard-usable by @yannickmonney in [https://github.com/tale-project/tale/pull/3728](https://github.com/tale-project/tale/pull/3728) - fix(platform): close the #3686-#3688 review leftovers by @yannickmonney in [https://github.com/tale-project/tale/pull/3740](https://github.com/tale-project/tale/pull/3740) - fix(platform): release orphaned mail bytes and guard the stamp clear by @yannickmonney in [https://github.com/tale-project/tale/pull/3739](https://github.com/tale-project/tale/pull/3739) - fix(platform): strip HTML before truncating an inbox row's preview by @Israeltheminer in [https://github.com/tale-project/tale/pull/3730](https://github.com/tale-project/tale/pull/3730) - feat(platform): let tasks repeat, with a reusable recurrence picker by @yannickmonney in [https://github.com/tale-project/tale/pull/3731](https://github.com/tale-project/tale/pull/3731) - fix(platform): let the docs seeder settle on the project files list by @yannickmonney in [https://github.com/tale-project/tale/pull/3760](https://github.com/tale-project/tale/pull/3760) - test(platform): pin the embedding recommendations route's wire body by @yannickmonney in [https://github.com/tale-project/tale/pull/3757](https://github.com/tale-project/tale/pull/3757) - test(platform): pin the chat search's scan order and contact grouping by @yannickmonney in [https://github.com/tale-project/tale/pull/3758](https://github.com/tale-project/tale/pull/3758) - fix(platform): word lapsed-session failures and guard the rule by @yannickmonney in [https://github.com/tale-project/tale/pull/3763](https://github.com/tale-project/tale/pull/3763) - fix(platform): add or reconnect exactly the OAuth credential chosen by @yannickmonney in [https://github.com/tale-project/tale/pull/3729](https://github.com/tale-project/tale/pull/3729) - fix(platform): close the app-door refusal round-two review findings by @yannickmonney in [https://github.com/tale-project/tale/pull/3765](https://github.com/tale-project/tale/pull/3765) - fix(ui): keep the reader's focus when a filter bar turns disabled by @yannickmonney in [https://github.com/tale-project/tale/pull/3764](https://github.com/tale-project/tale/pull/3764) - fix: stop PR image cleanup failing on retired services by @yannickmonney in [https://github.com/tale-project/tale/pull/3741](https://github.com/tale-project/tale/pull/3741) - fix(platform): queue pinned sandbox recreates and unpin before destroy by @yannickmonney in [https://github.com/tale-project/tale/pull/3762](https://github.com/tale-project/tale/pull/3762) - fix(platform): close the accent audit's last review findings by @yannickmonney in [https://github.com/tale-project/tale/pull/3748](https://github.com/tale-project/tale/pull/3748) - fix(platform): close the task-limits review round after #3689 by @yannickmonney in [https://github.com/tale-project/tale/pull/3749](https://github.com/tale-project/tale/pull/3749) - fix(manual): judge NAV-B14's support-URL warning only in a deployment by @yannickmonney in [https://github.com/tale-project/tale/pull/3761](https://github.com/tale-project/tale/pull/3761) - fix(platform): preserve recurring task work and series by @yannickmonney in [https://github.com/tale-project/tale/pull/3771](https://github.com/tale-project/tale/pull/3771) - fix(ai): stagger gateway token refreshes and resume runs they cut by @yannickmonney in [https://github.com/tale-project/tale/pull/3742](https://github.com/tale-project/tale/pull/3742) - feat(platform): make the desktop Home panel resizable by @Israeltheminer in [https://github.com/tale-project/tale/pull/3768](https://github.com/tale-project/tale/pull/3768) - fix(ui): localize the date picker and let the keyboard clear it by @yannickmonney in [https://github.com/tale-project/tale/pull/3759](https://github.com/tale-project/tale/pull/3759) - feat(platform): tell agents what each equipped skill is for by @yannickmonney in [https://github.com/tale-project/tale/pull/3775](https://github.com/tale-project/tale/pull/3775) - fix(docs): send guessed section and /en addresses to a real page by @yannickmonney in [https://github.com/tale-project/tale/pull/3769](https://github.com/tale-project/tale/pull/3769) - fix(platform): stop promising skills and images the product does not have by @yannickmonney in [https://github.com/tale-project/tale/pull/3770](https://github.com/tale-project/tale/pull/3770) - fix(platform): re-queue renamed synced files and isolate watchdog faults by @yannickmonney in [https://github.com/tale-project/tale/pull/3782](https://github.com/tale-project/tale/pull/3782) - fix(platform): close the #3739 mail stamp pass review findings by @yannickmonney in [https://github.com/tale-project/tale/pull/3785](https://github.com/tale-project/tale/pull/3785) - test: read browser-test layouts once their eases end, not on a timer by @yannickmonney in [https://github.com/tale-project/tale/pull/3783](https://github.com/tale-project/tale/pull/3783) - fix(platform): scope automation runs to the projects the viewer can see by @yannickmonney in [https://github.com/tale-project/tale/pull/3772](https://github.com/tale-project/tale/pull/3772) - docs(docs): add a guide to using Tale from an editor or a script by @yannickmonney in [https://github.com/tale-project/tale/pull/3800](https://github.com/tale-project/tale/pull/3800) - fix(platform): let admins cap any member's API key in the budget editor by @yannickmonney in [https://github.com/tale-project/tale/pull/3780](https://github.com/tale-project/tale/pull/3780) - feat(platform): start new project agents with the document skills ticked by @yannickmonney in [https://github.com/tale-project/tale/pull/3781](https://github.com/tale-project/tale/pull/3781) - fix(platform): close the session-lapse review round after #3763 by @yannickmonney in [https://github.com/tale-project/tale/pull/3795](https://github.com/tale-project/tale/pull/3795) - feat(platform): ground chat answers about Tale in its documentation by @yannickmonney in [https://github.com/tale-project/tale/pull/3773](https://github.com/tale-project/tale/pull/3773) - feat(platform): show readers live automation navigation by @yannickmonney in [https://github.com/tale-project/tale/pull/3779](https://github.com/tale-project/tale/pull/3779) - fix(platform): apply the organization's custom instructions to agent runs by @yannickmonney in [https://github.com/tale-project/tale/pull/3774](https://github.com/tale-project/tale/pull/3774) - fix(ai): let a small broker pool serve while an account cools down by @yannickmonney in [https://github.com/tale-project/tale/pull/3794](https://github.com/tale-project/tale/pull/3794) - fix(platform): hold skill uploads to the owner and team-audience rules by @yannickmonney in [https://github.com/tale-project/tale/pull/3776](https://github.com/tale-project/tale/pull/3776) [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.62) ## v0.5.61September 27, 2026 One merged pull request (#3503) and nineteen direct commits since v0.5.60. No migrations, no API contract change (2.1.0), and no proxy or sandbox-runtime image change: run `tale update` and then `tale deploy` as usual. ### Chat - A project member opening a chat someone else shared with the project now reads its messages under the read-only pill, and sees the version the owner has selected rather than the root's replaced branch; Copy, message info and Export stay, nothing that writes. (#3503) ### Phones and narrow columns - Sign-in, sign-up, 2FA enrolment, the forced password change, onboarding and the root 404 scroll on a phone held sideways or at 200% zoom; a source guard keeps `min-h-dvh` out of the app. (9887f7223) - Settings field rows stack at full width until their own surface is 36rem wide, and a toggle's label and description wrap on a phone instead of truncating. (d65cfeb65, d94268887) - Metric strips, breakdown lists, chart pairs and card grids pick their columns from their own width; the branding preview joins the form only once the settings surface is 48rem wide. (855d66dc7, e9f6ce5af) - A list toolbar moves its primary action to a line of its own when search, Filter and the action do not fit; the task board shares the same toolbar. (48801017d) - A tab strip's actions yield and wrap before a tab slides under the buttons, so the automation editor's Runs tab stays in view at 768px. (838e8d7cb) - Automation version and run rows wrap the date instead of the message; chat health's recent errors read on two lines on a phone. (3c33b705b, 651bdb8e3) - On a phone the project chats' repeated "Share with project" label is hidden (the switch keeps its accessible name), OAuth app rows wrap their status and buttons, the retention drawer stacks its buttons, and a vendor's name stays readable in the credential picker. (6e0f63e97, d1a0d648a, c1b74da8a, 34f55770c) ### Docs and marketing sites - The docs breadcrumb shows only the immediate parent below 1024px and truncates a deep trail inside its header strip. (26105b7f8, 0712bd971) - The marketing site's footer links wrap inside their column, and the pricing and hardware comparison tables scroll sideways on a phone instead of clipping. (8a7e3af29, 31b88a71f) - The UI docs describe field rows, grids and toolbars by their column; the platform's manual responsive suite adds the narrow page column and short viewports, and the app design contract states the rule: viewport breakpoints decide the shell, a page's layout answers to its own column. (67e863e02, 7242c9b0a) ### API contract changes None in this range. The contract stays at 2.1.0: 136 operations. [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.61) ## v0.5.60September 27, 2026 One merged pull request (#3498, the S3 fixes from the 2026-09-26 platform evaluation) and fourteen direct commits since v0.5.59. Migrations `0119`–`0121` (backfills, applied at boot); API contract 2.0.0 → 2.1.0; the proxy image changes, so run `tale update` and then `tale deploy --stop` (recreates db, object-store and proxy with a brief downtime). ### Behaviour changes - Mounting the WebDAV root `/dav//` now lists two folders, `documents/` and `.trash/`; dot-segment paths (`..`, `%2e%2e`) are refused with 404 at the edge and in the app. (#3498) - OIDC ID tokens carry `acr: "0"` (better-auth hard-codes it); relying parties pinned to the bronze URN have not matched since v0.5.45, and the docs now say so. (#3498) - The `llm-gateway` network alias and its `NO_PROXY` entries, kept since the June rename to `sandbox-llm-gateway`, are gone. (4f6b3100a) - Deleting a project agent clears its task assignments; removing a member revokes every competence grant; feedback is attributed by the rated message. The three migrations backfill the rows written before. (#3498) ### Chat - A stopped reply settles to its saved text without a reload; "B is better" switches the composer to model B; the losing Arena column goes to Trash at settle. (#3498) - The chat assistant finds a task by its `KEY-n` id; dictation reports a denied microphone; a new chat focuses the message box. (#3498) - A ⌘K chat hit shows plain prose cut around the match instead of raw markdown from the start of the message. (d94390c04) ### Knowledge - Knowledge entries render as Markdown; the copyable id is labelled **Version ID**; Owners and Admins can pick any team for a document, synced teams included. (#3498) - Server refusal reasons reach the user for websites, products and contacts; folder duplicates show the right toast; product forms refuse negative or oversized prices and stock; bulk import names the refused rows instead of rejecting the file. (#3498) - Deleting the credential the embedding model uses is refused (`CREDENTIAL_IN_USE`); deleting a product or replacing its image releases the managed image, legal holds honoured. (#3498) ### Projects and tasks - Board drops land in the lane under the pointer; opening a task pushes history; a subtask links to its parent; a deep link to a missing task says so. (#3498) - Projects pick an icon and colour; an archived project is read-only (`PROJECT_ARCHIVED`); a mixed upload ends in one summary toast; project rows open from the keyboard. (#3498) ### Automations - Run lists name who started a run and why it waits; `startedVia` on run reads. (#3498) - One cron validator serves client and server; the Blank wizard previews the schedule and hands over the one-time webhook URL; revoking or rotating a webhook URL asks first. (#3498) - Paused and undeployed schedules say so; new trigger bindings start disabled; stopped runs show where they stopped and who stopped them; a deleted automation's runs stay reachable. (#3498) - Validation warns about a model the organization does not serve (`LLM_MODEL_UNAVAILABLE`); a connector node without a usable credential fails before an approval is requested. (#3498) ### Governance and settings - Team names are unique per organization (`TEAM_NAME_TAKEN`, also on SCIM); deleting an organization requires typing its name; Branding Reset commits everything in its confirm. (#3498) - Lists say "Showing the first N — scroll for more"; a Member's admin deep link is refused once; blocked erasure receipts say when a hold was released; Trash names chats. (#3498) - Chat-health merges provider-less rows; harness-turn metrics add up and name the harness. (#3498) - Password policy rules are switches like every other toggle; the account's change-password section is titled **Password**; an unconfigured OAuth app is explained once, not under every row. (8fe16bf8b, b66ed24de, 858a7aa9e) ### Developer surfaces and shell - Docs search indexes whole pages and keeps inline code, so error codes, headers and env vars are findable. (#3498) - Cold-load JavaScript drops from 2604 to 1928 KB gzipped, and the build guards the budget. (#3498) - The offline overlay fires on `offline` and while the backend is unreachable; light-theme muted text and sidebar ages meet AA contrast. (#3498) - The environment reference drops the `RAG_RERANKING_*` variables nothing reads; the image no longer sets `SANDBOX_STORAGE_INTERNAL_BASE_URL`. (bd2c51806, 6d04ce701) - Dead code and 23 unused platform dependencies are removed: unrendered UI, the Slack notification renderer, the Convex upload lane, app doors nothing called. (94145ddb5, acc87b91d, 271a8df5b, f1c5d4255, 5c89086b2, fe56bd8f9) ### API contract changes The contract moved from 2.0.0 to 2.1.0 (136 → 136 operations). Read the API reference's versioning section before upgrading a pinned client. Added operations: none. Removed operations: none. #### Changelog 2.1.0 — 2026-09-27: `startedVia` (`schedule` | `webhook` | `event`) on `RunSummary` and `Run` — which kind of trigger started a `trigger:` run, read off the run's own input so it stays true after the binding changes kind; absent on a run a person or an API key started. A listing could not tell a scheduled run from a webhook delivery before. `DELETE /api/v1/products/{id}` answers 409 `LEGAL_HOLD_ACTIVE` under an organization-wide legal hold or a custodian hold on the uploader of the product's image, the way document and contact deletes do — the response is now documented on the operation. [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.60) ## v0.5.59September 27, 2026 ### What's Changed - fix(platform): send no credential with a backend error event by @yannickmonney in [https://github.com/tale-project/tale/pull/3499](https://github.com/tale-project/tale/pull/3499) - feat(platform): run agents on Claude Opus 5.5 and offer Fable 5.1 by @yannickmonney in [https://github.com/tale-project/tale/pull/3500](https://github.com/tale-project/tale/pull/3500) [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.59) ## v0.5.58September 27, 2026 ### What's Changed - feat(platform): put chats, tasks and the inbox in one Home panel by @yannickmonney in [https://github.com/tale-project/tale/pull/3492](https://github.com/tale-project/tale/pull/3492) - fix(ai): balance subscription accounts and enable OpenAI brokers by @yannickmonney in [https://github.com/tale-project/tale/pull/3495](https://github.com/tale-project/tale/pull/3495) - fix(platform): polish the UI details across every section by @yannickmonney in [https://github.com/tale-project/tale/pull/3493](https://github.com/tale-project/tale/pull/3493) - feat(platform)!: synchronize source issues and harden agent tasks by @yannickmonney in [https://github.com/tale-project/tale/pull/3496](https://github.com/tale-project/tale/pull/3496) - feat(ai-gateway): grey out an account whose session or week is spent by @yannickmonney in [https://github.com/tale-project/tale/pull/3497](https://github.com/tale-project/tale/pull/3497) [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.58) ## v0.5.57September 26, 2026 ### What's Changed - perf(platform): name a foreign-model agent exec for replica cache affinity by @yannickmonney in [https://github.com/tale-project/tale/pull/3490](https://github.com/tale-project/tale/pull/3490) [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.57) ## v0.5.56September 26, 2026 One merged pull request since v0.5.55 (#3491): the S2 fixes from the 2026-09-26 platform evaluation. Migration `0114` (one nullable column, applied at boot); new sandbox-runtime image; `tale deploy` as usual. ### Chat - Retry then Edit no longer loses a branch: forks attach to the fork point and the switcher counts every sibling. (#3491) - A share publishes the branch on screen, and **Include newer messages** re-takes that branch. (#3491) - Knowledge search hits carry the whole chunk instead of 500 characters; product and contact rows carry every user-facing field. (#3491) ### Guardrails - Order numbers, dates and build numbers are no longer masked as `[PASSPORT]` / `[NZ_IRD]`: digits-only national-ID patterns need a context keyword or a valid check digit. (#3491) - Docs say the stored message is the masked text. (#3491) ### Agents - Managed Codex runs start again: the runtime creates `CODEX_HOME`, the session key no longer lists a model twice, and Codex on a custom DeepSeek connector goes through its Anthropic endpoint. (#3491) - A failed run shows the provider's error message and status, not the assistant's last reply. (#3491) - Deleting a skill removes it from every agent that has it; an agent that still references a missing skill stops with `equipment_missing`. (#3491) ### Automations - Two editor tabs no longer overwrite each other: saving from a stale version gets 409 `AUTOMATION_VERSION_STALE`, and the editor offers reload or save anyway. (#3491) ### Governance and usage - Audit log covers team writes (app, Better Auth, SSO sync), API keys, WebDAV app passwords, connector credentials, branding and WebDAV document writes. (#3491) - **Top models** counts chat spend again (a zero audio-seconds field was classifying it as transcription). (#3491) - Legacy `user:` / `api-key:` / `trigger:` ledger rows count toward the person they belong to, including the personal cap. (#3491) - Typing a partial hex value into the accent colour field no longer freezes the page. (#3491) ### Inbox and API - A `deleted` source snapshot closes the mirrored conversation and keeps its messages. (#3491) ### App shell - A list whose load failed shows an error with **Retry** instead of the first-run empty state. (#3491) - The service worker caches the app shell again (offline page, no **Update available** prompt on a first visit); the prompt has **Later**. (#3491) [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.56) ## v0.5.55September 25, 2026 ### What's Changed - fix(ai-gateway): keep the account list when a re-read fails by @yannickmonney in [https://github.com/tale-project/tale/pull/3487](https://github.com/tale-project/tale/pull/3487) - fix(platform): put the email and profile claims back into Tale's ID tokens by @yannickmonney in [https://github.com/tale-project/tale/pull/3488](https://github.com/tale-project/tale/pull/3488) [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.55) ## v0.5.54September 24, 2026 ### What's Changed - fix(platform): name the mailbox a thread arrived on by @Israeltheminer in [https://github.com/tale-project/tale/pull/3478](https://github.com/tale-project/tale/pull/3478) - fix(platform): show an API-thread reply before its app acknowledges it by @Israeltheminer in [https://github.com/tale-project/tale/pull/3480](https://github.com/tale-project/tale/pull/3480) - fix(platform): send a composed email from the mailbox you pick by @Israeltheminer in [https://github.com/tale-project/tale/pull/3481](https://github.com/tale-project/tale/pull/3481) - feat(platform): filter the Inbox by mailbox when a connector has several by @Israeltheminer in [https://github.com/tale-project/tale/pull/3482](https://github.com/tale-project/tale/pull/3482) - feat(platform): route conversations by the mailbox or API app they arrive on by @Israeltheminer in [https://github.com/tale-project/tale/pull/3483](https://github.com/tale-project/tale/pull/3483) - feat(platform): let an integration queue its conversation to a team by @Israeltheminer in [https://github.com/tale-project/tale/pull/3484](https://github.com/tale-project/tale/pull/3484) - refactor(ui): move the list-page hook into the design system by @yannickmonney in [https://github.com/tale-project/tale/pull/3485](https://github.com/tale-project/tale/pull/3485) - feat(ai-gateway): connect accounts on their own and name each plan by @yannickmonney in [https://github.com/tale-project/tale/pull/3486](https://github.com/tale-project/tale/pull/3486) [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.54) ## v0.5.53September 24, 2026 ### What's Changed - fix(platform): pull the object store image from the fleet's GHCR mirror by @larryro in [https://github.com/tale-project/tale/pull/3479](https://github.com/tale-project/tale/pull/3479) [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.53) ## v0.5.52September 24, 2026 Two merged pull requests since v0.5.51 (#3476–#3477). No migration; `tale deploy` as usual. ### Settings and governance - New **Settings › Governance › Competences** page: the register of grants (member, competence, status with its until/since date, granted by, evidence), an Active filter by default, a **Grant competence** dialog (platform capability or named qualification, expiry Never / 30 / 90 / 365 days, evidence) and a per-row **Revoke** with confirmation; revoked and expired grants stay as history. (#3476) - Competence listings return every live grant plus the newest revoked ones; a long history no longer hides an old grant that still vouches. (#3476) - Register refusals (already granted, reserved `tale:` name, not a member, already revoked) show inline in the grant form, in the admin's language. (#3476) - New docs guide `platform/admin/governance/competences` (EN/DE/FR); the API keys guide and the API reference point to it. (#3476) ### SSO and members - Role-mapping rules can be reordered (drag handle, up/down); the first matching rule decides the role at sign-in, and the help text and the Enterprise SSO guide now say so. (#3477) - Settings › Account shows **Your role** with the translated role badge and a **Manage members** link for admins; the profile-menu tooltip shows the translated role. (#3477) - Teams table: long synced group names show in full on hover, and the Name column gets most of the width. (#3477) - Trash table: long owner names stay in their column and no longer paint over the **Trashed** badge. (#3477) [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.52) ## v0.5.51September 24, 2026 Ten merged pull requests since v0.5.50 (#3466–#3475). One migration (0113, additive, applied on start); `tale deploy` as usual. ### Inbox - A reply leaves from the mailbox that received the thread; an org with two mailboxes on one email connector no longer answers from the default one. (#3468) - Rows show the channel a conversation arrived on; the header names the connector or API source; the composer says where the reply goes; the Channel filter works again. (#3470) - Picking the current assignee again unassigns them; the assigned row is announced as selected. (#3469) - Composing without an email connector shows a warning with a link to connector settings (admins) or an ask-your-admin hint; Send says why it is off. (#3472) ### Chat - Arena Mode shows the prompt at once and snaps each send to the top of both columns. (#3473) ### Contacts and records - Phone fields accept digits and `+ ( ) . -` only; the API rejects a phone with letters. (#3467) - Record view dialogs drop the empty space and lead with identity facts (website name and ID, contact email); website pages have one search field. (#3472) ### Automations - A trivial template expression no longer times out when the run carries large node outputs ("evaluation timed out after 100ms"). (#3475) - A finished automation run keeps its Run row and Details on the task. (#3475) ### Settings and knowledge - Opening Settings › Sandboxes no longer removes idle project workspaces; they stay listed while the agent is idle. (#3474) - Reindexing from the status badge shows one "Indexing started" toast. (#3466) ### AI Gateway - ChatGPT accounts show their usage instead of "No usage read yet". (#3471) - A **Resets in** column with a countdown bar beside each usage window; the product name is no longer translated. (#3471) [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.51) ## v0.5.50September 22, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.50) ## v0.5.49September 22, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.49) ## v0.5.48September 22, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.48) ## v0.5.47September 22, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.47) ## v0.5.46September 21, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.46) ## v0.5.45September 21, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.45) ## v0.5.44September 21, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.44) ## v0.5.43September 20, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.43) ## v0.5.41September 20, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.41) ## v0.5.39September 20, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.39) ## v0.5.38September 20, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.38) ## v0.5.37September 19, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.37) ## v0.5.36September 19, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.36) ## v0.5.35September 18, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.35) ## v0.5.34September 18, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.34) ## v0.5.33September 18, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.33) ## v0.5.32September 17, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.32) ## v0.5.31September 17, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.31) ## v0.5.30September 16, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.30) ## v0.5.29September 16, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.29) ## v0.5.28September 15, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.28) ## v0.5.27September 15, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.27) ## v0.5.26September 14, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.26) ## v0.5.25September 14, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.25) ## v0.5.24September 14, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.24) ## v0.5.23September 13, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.23) ## v0.5.22September 12, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.22) ## v0.5.21September 12, 2026 [View on GitHub](https://github.com/tale-project/tale/releases/tag/v0.5.21) Last updated September 29, 2026. ## See Tale on your stack Book a guided demo or talk to the team about self-hosted deployment, pricing, and hardware. # Terms of service Source: https://tale.dev/legal/terms-of-service **Last updated:** 18.05.2026 ## 1. Introduction These Terms of Service ("Terms") govern your access to and use of the website [https://tale.dev](https://tale.dev) ("Website") operated by Ruler GmbH ("we", "us", "our"). By accessing or using our Website, you agree to be bound by these Terms. If you do not agree with any part of these Terms, please do not use our Website. These Terms apply to the use of the Website only. The use of Tale products and services is governed separately by our [Service Agreement](/files/Service_Agreement_Template.pdf) and [Hardware Agreement](/files/Hardware_Agreement_Template.pdf), as applicable. ## 2. Operator **Ruler GmbH** Seestrasse 4 3700 Spiez Switzerland Company registration: CHE-186.532.610 ## 3. Use of the Website ### 3.1 Permitted Use You may use this Website for lawful purposes and in accordance with these Terms. The Website is intended to provide information about Tale, our products and services, and to facilitate communication with us. ### 3.2 Prohibited Conduct You agree not to: - Use the Website in any way that violates applicable local, national, or international laws or regulations. - Attempt to gain unauthorized access to the Website, its servers, or any connected systems or networks. - Interfere with or disrupt the integrity or performance of the Website or its underlying infrastructure. - Use automated systems, bots, or scrapers to access the Website without our prior written consent, except for standard search engine indexing. - Transmit any material that is unlawful, threatening, abusive, defamatory, or otherwise objectionable through our contact forms. - Impersonate any person or entity, or misrepresent your affiliation with any person or entity. - Attempt to reverse-engineer, decompile, or disassemble any part of the Website that is not covered by an open-source license. ## 4. Intellectual Property ### 4.1 Website Content The content on this Website — including but not limited to text, graphics, logos, images, and the overall design — is the property of Ruler GmbH and is protected by Swiss and international copyright, trademark, and other intellectual property laws, unless otherwise stated. ### 4.2 Open-Source Software Tale is MIT licensed and free to use, modify, and distribute under the terms of the MIT License. The open-source components of Tale are governed by their respective licenses. The MIT License applies solely to the Tale software and does not extend to the Website content, branding, or trademarks. ### 4.3 Trademarks "Tale", the Tale logo, and "Ruler GmbH" are trademarks of Ruler GmbH. You may not use these trademarks without our prior written permission, except as reasonably necessary to refer to our products or company. ## 5. Contact Forms and Submissions When you submit information through our contact or demo request forms, you represent that the information you provide is accurate and that you have the authority to share it. We process all personal data submitted through these forms in accordance with our [Privacy Policy](/legal/privacy-policy). Submitting a form does not create a contractual relationship between you and Ruler GmbH. A contractual relationship is only established upon execution of a separate agreement. ## 6. Third-Party Links, User-Submitted URLs, and Video Analysis ### 6.1 Links from the Website Our Website may contain links to third-party websites, services, or resources that are not owned or controlled by us, including but not limited to our documentation site, training courses, and service agreements. We have no control over, and assume no responsibility for, the content, privacy practices, or availability of any third-party websites or services. The inclusion of a link does not imply endorsement. We encourage you to review the terms and privacy policies of any third-party sites you visit. ### 6.2 URLs You Submit to the Service When you submit a URL to the Service for retrieval, transcription, or analysis (including video links), you represent and warrant that: - you hold the rights, licences, or applicable statutory exceptions under your jurisdiction's copyright and related laws to retrieve and process the content at that URL; - your use of the Service complies with the source platform's terms of service and with all applicable law; and - the content is not infringing, defamatory, unlawful, or otherwise restricted from third-party processing. Transcripts, captions, summaries, and any other artifacts the Service derives from the submitted URL are derivative works of the underlying source content. All intellectual-property rights in the original content remain with the original rightsholder; the Service grants you no new rights in the derived artifacts beyond your existing licence to use the source. As between you and the Service, you own the derived artifacts subject always to the rightsholder's underlying rights — the Service does not claim ownership over transcripts or summaries you generate from your own submitted URLs. Tale acts as your processor under your instructions in respect of the content you submit (URL fetching, transcription, storage). Tale acts as controller for operational metadata generated by the Service (rate-limit counters, error classification, telemetry needed to deliver the Service). We do not curate, review, or endorse user-submitted URLs. ### 6.3 Service Discretion We may refuse, throttle, suspend, or remove any submitted URL or stored output at our sole discretion, including where we receive a complaint, where processing would exceed platform limits, or where the source platform is blocking our requests. We may also reject categories of URLs (for example, livestreams, age-restricted content, or playlist endpoints) on technical or policy grounds. ### 6.4 Notice and Action If you believe that content stored by the Service infringes your rights or violates applicable law, please contact us at the address in Section 14 with: (i) identification of the protected work or right; (ii) the URL of the stored content; (iii) your contact details; and (iv) a good-faith statement of the basis of your claim. We will review reports promptly and may, at our discretion, remove or restrict access to the content within a reasonable period. This procedure is offered in addition to, and does not replace, any rights or procedures available to you under applicable copyright or content-moderation law (including, where applicable, Article 16 of EU Regulation 2022/2065 — the Digital Services Act). ### 6.5 No Service Guarantee URL retrieval and transcription are provided on a best-effort basis. We do not guarantee that any given URL will be processable, that transcripts will be accurate or complete, or that processing will be available at any particular time. Accuracy of automated transcription varies with audio quality, language, and source platform behaviour. ## 7. Disclaimer of Warranties The Website is provided on an "as is" and "as available" basis without any warranties of any kind, whether express or implied, including but not limited to implied warranties of merchantability, fitness for a particular purpose, or non-infringement. We do not warrant that the Website will be uninterrupted, error-free, or free of viruses or other harmful components. While we strive to ensure that the information on the Website is accurate and up to date, we make no guarantees regarding the completeness, accuracy, or reliability of any content. Information provided on this Website is for general informational purposes only and does not constitute professional, legal, financial, or technical advice. ## 8. Limitation of Liability To the maximum extent permitted by applicable law, Ruler GmbH, its directors, employees, and agents shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, goodwill, or business opportunity, arising out of or in connection with your use of or inability to use the Website. Our total aggregate liability for any claims arising from or relating to the use of the Website shall not exceed CHF 100. This limitation of liability does not apply to damages caused by intent or gross negligence, or where such limitation is not permitted under applicable law. ## 9. Indemnification You agree to indemnify, defend, and hold harmless Ruler GmbH and its directors, employees, and agents from and against any claims, liabilities, damages, losses, or expenses (including reasonable legal fees) arising out of or in connection with your breach of these Terms or your use of the Website in violation of applicable law. ## 10. Modifications to the Terms We reserve the right to modify these Terms at any time. The updated version will be posted on this page with a revised "Last updated" date. Your continued use of the Website after such changes constitutes your acceptance of the revised Terms. We encourage you to review these Terms periodically. ## 11. Severability If any provision of these Terms is found to be invalid or unenforceable by a court of competent jurisdiction, the remaining provisions shall continue in full force and effect. The invalid or unenforceable provision shall be replaced by a valid and enforceable provision that most closely reflects the original intent. ## 12. Waiver The failure of Ruler GmbH to enforce any right or provision of these Terms shall not constitute a waiver of such right or provision. Any waiver must be in writing and signed by Ruler GmbH to be effective. ## 13. Governing Law and Jurisdiction These Terms are governed by and construed in accordance with the substantive laws of Switzerland, excluding its conflict of law provisions and excluding the United Nations Convention on Contracts for the International Sale of Goods (CISG). Any disputes arising out of or in connection with these Terms shall be subject to the exclusive jurisdiction of the competent courts of the Canton of Bern, Switzerland, unless otherwise required by mandatory law. ## 14. Contact If you have any questions about these Terms, please contact us: **Ruler GmbH** Seestrasse 4 3700 Spiez Switzerland # Privacy policy Source: https://tale.dev/legal/privacy-policy **Last updated:** 01.04.2026 ## 1. Introduction Ruler GmbH ("we", "us", "our") operates the website [https://tale.dev](https://tale.dev) and the Tale platform. We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you visit our website or interact with us. This Privacy Policy complies with the Swiss Federal Act on Data Protection (FADP/nDSG) and, where applicable, the European Union General Data Protection Regulation (GDPR). ## 2. Data Controller The data controller responsible for the processing of your personal data is: **Ruler GmbH** Seestrasse 4 3700 Spiez Switzerland Company registration: CHE-186.532.610 For any questions or requests regarding data protection, please contact us through our [contact form](https://tale.dev/contact). ## 3. Data We Collect ### 3.1 Contact and Demo Request Forms When you submit our contact form or request a demo, we collect the following personal data: - Name - Email address - Company name (optional on contact form, required on demo request form) - Phone number (optional, demo request form only) - Area of interest (demo request form only) - Message content or additional comments ### 3.2 Automatically Collected Data Our website measures aggregate traffic with Umami, an open-source analytics tool we host ourselves on our own server in Frankfurt, Germany. It is served from our own domain, sets no cookies, stores no identifier in your browser, and sends nothing to any third party — no analytics data ever leaves our infrastructure, and we do not track you across other websites. For each page view we record the page address, the referring page, your approximate location (country, region, city), your screen size, and your browser, operating system and device type. Your IP address is used only to derive that approximate location and — combined with a secret that rotates regularly — a one-way hash that groups the requests belonging to a single visit; the IP address itself is never stored. We build no visitor profiles and cannot identify you from this data. To deliver the website we also temporarily process minimal technical data (see Server Logs below), and the site stores one functional language cookie plus a theme preference in your browser (see Cookies below). Only the page path and the referring origin are collected; URL search parameters, fragments and page titles are omitted. Browser language is included. Completed contact and demo requests are counted without form contents. Do Not Track and Global Privacy Control disable collection. ### 3.3 Server Logs When you visit our website, our self-operated web server and hosting infrastructure ([hosting provider — to be confirmed before publication]) may temporarily process technical data such as your IP address, browser type, and access timestamps for the purpose of delivering the website and maintaining security (for example, rate limiting). This data is processed as part of standard web-server operations, retained only briefly, and is not used by us for any other purpose. ## 4. Purpose and Legal Basis for Processing We process your personal data for the following purposes: | Purpose | Data involved | Legal basis (FADP) | Legal basis (GDPR) | | ---------------------------------------------- | --------------------------------------------------------------------- | ------------------- | -------------------------------------------- | | Responding to your inquiry | Name, email, company, message | Legitimate interest | Art. 6(1)(f) GDPR — Legitimate interest | | Scheduling and conducting a product demo | Name, email, phone, company, area of interest | Legitimate interest | Art. 6(1)(b) GDPR — Pre-contractual measures | | Maintaining and securing our website | Technical data (IP address, browser) | Legitimate interest | Art. 6(1)(f) GDPR — Legitimate interest | | Measuring website usage | Page address, referrer, approximate location, device and browser data | Legitimate interest | Art. 6(1)(f) GDPR — Legitimate interest | | Establishing a potential business relationship | Contact form data | Legitimate interest | Art. 6(1)(f) GDPR — Legitimate interest | Under the Swiss FADP, processing of personal data is generally permitted unless it violates the personality rights of the data subject. We process your data in good faith, proportionally, and only for the purposes stated above. ## 5. Data Sharing We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes. Your personal data may be accessible to the following categories of service providers who process data on our behalf and under our instructions: - **Hosting infrastructure:** The website is operated by Ruler GmbH on self-hosted infrastructure provided by [hosting provider — to be confirmed before publication], located in [data center location — to be confirmed before publication]. - **CRM provider:** We store contact form submissions in a customer relationship management system hosted in Switzerland. These providers act as data processors and are bound by data processing agreements in accordance with Art. 9 FADP and Art. 28 GDPR. ## 6. International Data Transfers Your personal data is primarily stored and processed in Switzerland. [To be confirmed before publication: state where the website's servers are located — Switzerland or the EU/EEA — and adjust this section accordingly.] All EU/EEA member states are recognized by the Swiss Federal Council as providing an adequate level of data protection under Art. 16 FADP. The European Commission has likewise recognized Switzerland as providing adequate protection under the GDPR. No personal data is transferred to countries without an adequate level of data protection. ## 7. Data Retention We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected: - **Contact form submissions:** If no business relationship is established, your data will be deleted within 12 months after your last interaction with us. - **Demo request submissions:** If no business relationship is established, your data will be deleted within 12 months after your last interaction with us. - **Ongoing business relationships:** If a business relationship is established, your data will be retained for the duration of the relationship and for the period required by applicable statutory retention obligations (typically 10 years under Swiss commercial law). - **Server logs:** Technical data is processed on our own infrastructure for short-term operational and security purposes only and is deleted automatically thereafter. ## 8. Your Rights Under the Swiss FADP and, where applicable, the GDPR, you have the following rights: - **Right of access:** You may request information about whether and what personal data we process about you. - **Right to rectification:** You may request that inaccurate personal data be corrected. - **Right to deletion:** You may request the deletion of your personal data, subject to any legal retention obligations. - **Right to data portability:** You may request that your personal data be provided to you or to a third party in a commonly used, machine-readable format. - **Right to object:** You may object to the processing of your personal data at any time. - **Right to withdraw consent:** Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing prior to withdrawal. To exercise any of these rights, please contact us through our [contact form](https://tale.dev/contact). We will respond to your request within 30 days. If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland or, if applicable, with a supervisory authority in your EU/EEA member state. ## 9. Cookies Our website does not use cookies for analytics or tracking purposes — the self-hosted analytics described above sets no cookie and stores no identifier in your browser. The site stores exactly one functional cookie: `tale_locale`, which remembers your language choice for one year so pages load in your language on your next visit. It contains no personal data and no identifier. Your light/dark theme preference is kept in your browser's local storage and never leaves your device. If we introduce any cookies or third-party services in the future that require consent, we will update this Privacy Policy and implement an appropriate consent mechanism. ## 10. Data Security We take appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, misuse, or destruction. These measures include encryption of data in transit (TLS/SSL), access controls, and hardened, self-operated hosting infrastructure. Ruler GmbH is ISO 27001 and SOC 2 certified. ## 11. Children's Privacy Our website and services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child under 16, we will take steps to delete it promptly. ## 12. Changes to This Privacy Policy We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. The updated version will be published on this page with a revised "Last updated" date. We encourage you to review this page periodically. ## 13. Contact If you have any questions or concerns about this Privacy Policy or our data processing practices, please contact us: **Ruler GmbH** Seestrasse 4 3700 Spiez Switzerland # Data processing agreement Source: https://tale.dev/legal/data-processing-agreement **Last updated:** 11.06.2026 This Data Processing Agreement ("DPA") is an addendum to the Service Agreement ("Agreement") between Ruler GmbH ("Tale", "we", "us", "our") and the entity or person accepting the Agreement ("Customer", "you", "your"). It applies whenever Tale processes Personal Data on behalf of the Customer in providing the services. By executing the Agreement, the Customer enters into this DPA on its own behalf and, where Applicable Data Protection Law requires, on behalf of its authorized users and affiliates. This DPA takes effect on the date of the Agreement. ## 1. Definitions Capitalized terms not defined here have the meanings set out in the Agreement. **"Applicable Data Protection Law"** — the Swiss Federal Act on Data Protection (FADP/nDSG) and its ordinances, the EU General Data Protection Regulation (GDPR), and any other data protection or privacy legislation that applies, as amended or replaced from time to time. **"Controller"** — the entity that determines the purposes and means of processing Personal Data. For this DPA, the Customer is the Controller. **"Data Breach"** — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data that Tale processes on behalf of the Customer. **"Data Subject"** — an identified or identifiable natural person to whom the Personal Data relates. **"Personal Data"** — any information relating to an identified or identifiable natural person that Tale processes on behalf of the Customer in connection with the services. **"Processing"** — any operation performed on Personal Data, whether or not by automated means. **"Processor"** — the entity that processes Personal Data on behalf of the Controller. For this DPA, Tale is the Processor. **"Sub-processor"** — any third party Tale engages to process Personal Data on behalf of the Customer. The current list is in **Appendix A**. ## 2. Scope and details of processing ### 2.1 Roles The Customer is the Controller. Tale is the Processor. Tale processes Personal Data only to provide and maintain the services under the Agreement, and only on the Customer's documented instructions. ### 2.2 Processing details | Element | Description | | ------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Purpose** | Provision of the Tale platform and related services under the Agreement, including AI-powered workflow automation, conversation management, and related operational features. Endpoints and data flows are described in the public [API documentation](https://platform.tale.dev/docs). | | **Nature** | Storage, retrieval, organization, structuring, computation, transmission, and display of data as needed to deliver the services. | | **Categories of Data Subjects** | Determined by the Customer; may include employees, end users, clients, contractors, business contacts, and any other individuals whose data the Customer submits to the services. | | **Categories of Personal Data** | Determined by the Customer; may include names, email addresses, phone numbers, company information, message content, conversation data, workflow data, documents, and any other data the Customer submits. | | **Duration** | The term of the Agreement, plus any period required for return or deletion under Section 13. | ### 2.3 Customer responsibilities The Customer: a) has a valid legal basis under Applicable Data Protection Law for the processing of Personal Data and for instructing Tale; b) has provided all required notices to, and obtained all required consents or authorizations from, Data Subjects; c) ensures its instructions to Tale comply with Applicable Data Protection Law; d) is solely responsible for the accuracy, quality, and legality of the Personal Data it submits. ## 3. Customer instructions The Customer instructs Tale to process Personal Data to the extent necessary to provide the services under the Agreement. Additional or alternative instructions must be agreed in writing. If Tale concludes that an instruction infringes Applicable Data Protection Law, Tale notifies the Customer promptly and may suspend the affected processing until a lawful instruction is given. ## 4. Tale's obligations as Processor Tale: a) processes Personal Data only on the Customer's documented instructions, including this DPA and the Agreement, unless applicable law requires otherwise (in which case Tale informs the Customer before processing, unless prohibited from doing so); b) ensures that persons authorized to process Personal Data are bound by confidentiality; c) implements and maintains the technical and organizational measures set out in Section 7; d) does not engage any Sub-processor except in line with Section 6; e) assists the Customer — taking into account the nature of the processing and the information available to Tale — with Data Subject requests (Section 9), data security, breach notification, data protection impact assessments, and prior consultations with supervisory authorities; f) at the Customer's choice, returns or deletes all Personal Data at the end of the services (Section 13); g) makes available all information reasonably necessary to demonstrate compliance with this DPA, and contributes to audits (Section 10). ## 5. AI processing — no use for training or improvement ### 5.1 No training, fine-tuning, or model improvement Tale does not use Personal Data — including prompts, inputs, outputs, embeddings, audio payloads, images, or any derived artifacts — to train, fine-tune, evaluate, benchmark, or otherwise improve any AI or machine-learning model, whether Tale's own or any third party's. Personal Data is processed only to deliver the requested output for the specific call. ### 5.2 Sub-processor obligations regarding training Each AI Sub-processor listed in **Appendix A** is contractually bound — via the enterprise or API terms in effect between Tale and that provider — not to use Customer-submitted payloads to train, fine-tune, or improve its models or services. Tale provides evidence of these terms on reasonable written request under Section 10. ### 5.3 Opt-in — separate written agreement required Sections 5.1 and 5.2 may only be varied by a separate written agreement signed by both Parties that identifies (a) the scope of Personal Data involved, (b) the permitted training or improvement purpose, (c) the duration, and (d) the safeguards that apply. Continued use of the services, acceptance of updated terms, in-product toggles, or any form of implicit consent do **not** constitute opt-in. ## 6. Sub-processors ### 6.1 General authorization The Customer grants Tale a general written authorization to engage Sub-processors to process Personal Data. The current list of Sub-processors is set out in **Appendix A** and mirrored at [/legal/subprocessors](/legal/subprocessors). ### 6.2 Notification of changes Tale notifies the Customer at least 30 days before engaging a new Sub-processor or replacing an existing one, by updating Appendix A and the public list, and — where the Customer subscribes to such notifications — by email. ### 6.3 Right to object The Customer may object to a new or replacement Sub-processor in writing within 30 days of notification, on reasonable data protection grounds. Tale then uses commercially reasonable efforts to offer an alternative. If no resolution is reached within 30 days of the objection, either Party may terminate the affected services under the Agreement. ### 6.4 Pass-through obligations and liability Tale imposes on each Sub-processor, by written agreement, data protection obligations no less protective than those set out in this DPA — including the no-training commitment in Section 5. Tale remains fully liable to the Customer for the performance of each Sub-processor's obligations. ## 7. Technical and organizational measures ### 7.1 Security measures Tale implements and maintains appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, or disclosure, including: a) encryption of Personal Data in transit and at rest; b) measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; c) measures to restore the availability of and access to Personal Data in a timely manner after a physical or technical incident; d) access controls that limit access to Personal Data to authorized personnel on a need-to-know basis; e) regular testing, assessment, and evaluation of the effectiveness of the measures; f) physical security measures for data centers and infrastructure; g) security awareness training for personnel. ### 7.2 Certifications Tale maintains ISO 27001 and SOC 2 Type II certifications (or equivalent standards) and provides evidence of current certification on reasonable request. ### 7.3 Updates Tale may update its security measures from time to time, provided the overall level of protection afforded to Personal Data does not materially decrease. ## 8. Data breach notification ### 8.1 Notification to the Customer Tale notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Data Breach affecting Personal Data processed on behalf of the Customer. ### 8.2 Content of notification The notification includes, to the extent then reasonably available: a) the nature of the Data Breach, including — where possible — the categories and approximate number of Data Subjects and records concerned; b) the contact details of Tale's point of contact for further information; c) the likely consequences of the Data Breach; d) the measures taken or proposed to address it, including measures to mitigate possible adverse effects. ### 8.3 Cooperation Tale cooperates with the Customer and takes commercially reasonable steps to assist in investigating, mitigating, and remediating the Data Breach. ### 8.4 No admission A notification under this Section is not an admission of fault or liability. The Customer is solely responsible for determining whether the Data Breach triggers notification obligations under Applicable Data Protection Law and for fulfilling them. ## 9. Data subject rights ### 9.1 Assistance Tale assists the Customer — taking into account the nature of the processing — with appropriate technical and organizational measures to respond to Data Subject requests under Applicable Data Protection Law (access, rectification, erasure, restriction, portability, objection). ### 9.2 Forwarding requests If Tale receives a request directly from a Data Subject regarding Personal Data processed on behalf of the Customer, Tale forwards the request to the Customer promptly and does not respond directly unless the Customer instructs Tale to do so or applicable law requires it. ### 9.3 Costs Where assistance with Data Subject requests requires significant effort beyond what is reasonably expected, Tale may charge the Customer a reasonable fee based on its administrative costs. ## 10. Audits and inspections ### 10.1 Audit reports Tale makes available, on reasonable request and no more than once per year, copies of relevant third-party audit reports or certifications (such as SOC 2 Type II reports and ISO 27001 certificates) to demonstrate compliance with this DPA. ### 10.2 Additional audits If the Customer reasonably determines that the information provided under Section 10.1 is insufficient to verify compliance, the Customer may request an additional audit. Such audits are: a) at the Customer's expense, unless the audit reveals a material breach by Tale; b) preceded by at least 30 days' written notice; c) carried out during normal business hours and in a way that minimizes disruption to Tale's operations; d) conducted by the Customer or by an independent third-party auditor that is not a competitor of Tale and that is bound by appropriate confidentiality obligations; e) limited in scope to the processing of the Customer's Personal Data. ### 10.3 Confidentiality of findings Audit reports, findings, and information obtained through audits are confidential information of Tale and subject to the confidentiality provisions of the Agreement. ## 11. International data transfers ### 11.1 Processing locations Tale hosts the platform and stores Personal Data in Switzerland for Swiss customers and in the European Union for all other customers. AI calls (LLM inference, audio, and image processing) are processed in the European Union/EEA for all customers — no AI Sub-processor Tale engages operates a Swiss processing region. For Swiss customers, that processing relies on the adequacy of EU/EEA countries under Art. 16 FADP (the Federal Council's country list). The place of processing for each Sub-processor is listed in **Appendix A**. Where the Customer deploys Tale on its own infrastructure (on-premises or private cloud), the Customer determines the processing locations. ### 11.2 Adequate countries Tale may process Personal Data in countries recognized by the Swiss Federal Council under Art. 16 FADP, or by the European Commission under Art. 45 GDPR, as providing an adequate level of data protection. ### 11.3 Safeguards for other transfers Tale does not transfer Personal Data to countries without an adequate level of data protection unless appropriate safeguards are in place — such as Standard Contractual Clauses approved by the European Commission or recognized by the Swiss Federal Data Protection and Information Commissioner (FDPIC), or another legally recognized transfer mechanism. ### 11.4 Transparency The current processing locations and any relevant transfer mechanisms are listed in **Appendix A**. ## 12. Confidentiality Tale treats all Personal Data processed under this DPA as confidential. This obligation survives termination of this DPA and the Agreement. Tale ensures that all personnel with access to Personal Data are bound by appropriate confidentiality obligations. ## 13. Data retention and deletion ### 13.1 During the Agreement Tale retains Personal Data for the term of the Agreement and in accordance with the Customer's documented instructions. ### 13.2 On termination On termination or expiration of the Agreement, Tale — at the Customer's written request — either: a) returns all Personal Data to the Customer in a commonly used, machine-readable format; or b) securely deletes all Personal Data and provides written confirmation of deletion. If the Customer does not make a written request within 30 days of termination, Tale deletes all Personal Data within 90 days of termination. ### 13.3 Legal retention Where applicable law requires Tale to retain certain Personal Data beyond termination, Tale informs the Customer, limits further processing to what the law requires, and continues to protect the data in accordance with this DPA. ## 14. Liability Liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, to the extent permitted by Applicable Data Protection Law. Nothing in this DPA or the Agreement limits or excludes either Party's liability for damages arising from a willful or grossly negligent breach of Applicable Data Protection Law. ## 15. Relationship with the Agreement ### 15.1 Precedence In the event of any conflict between this DPA and the Agreement, this DPA prevails with respect to the processing of Personal Data. ### 15.2 Incorporation This DPA is incorporated into and forms part of the Agreement. All other provisions of the Agreement remain in full force. ### 15.3 Severability If any provision of this DPA is found invalid or unenforceable, the remaining provisions remain in full force. ### 15.4 Amendments Tale may update this DPA from time to time to reflect changes in its processing practices or in Applicable Data Protection Law. Material changes are communicated to the Customer in advance. The Customer's continued use of the services after the changes take effect constitutes acceptance of the updated DPA. Changes that vary Section 5 (AI processing — no use for training or improvement) require a separate written agreement under Section 5.3 and never take effect by continued use. ## 16. Governing law and jurisdiction This DPA is governed by the substantive laws of Switzerland, excluding its conflict-of-law provisions and the United Nations Convention on Contracts for the International Sale of Goods (CISG). Any disputes arising out of or in connection with this DPA are subject to the exclusive jurisdiction of the competent courts of the Canton of Bern, Switzerland, unless mandatory law requires otherwise. ## 17. Contact For any questions regarding this DPA or Tale's processing activities, contact us via our [contact form](https://tale.dev/contact). **Ruler GmbH** Seestrasse 4 3700 Spiez Switzerland --- ## Appendix A — Sub-processors This appendix lists the third parties Tale engages to process Personal Data on behalf of the Customer for Tale Cloud — each with its legal entity, registered address, type of service, and place of processing. Self-hosted deployments are operated by the Customer; for those, the Sub-processor list is whichever providers the Customer assembles. ### Current Sub-processors Each name links to that provider's publicly available DPA (or equivalent terms); certifications and trust pages are listed below the tables. Platform hosting follows the Customer's data-residency choice: table A.1 applies to customers in the EU/EEA, table A.2 to Swiss customers. AI calls (LLM inference, audio, and image processing) are processed in the EU/EEA for all customers; they do not leave the EU/EEA and are at no point processed in third countries such as the USA. #### A.1 — Customers in the EU/EEA | Sub-processor (legal entity) | Registered address | Type of service | Place of processing | | ----------------------------------------------------- | --------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- | | [Akenes SA (Exoscale)](https://www.exoscale.com/dpa/) | Boulevard de Grancy 19A, 1006 Lausanne, Switzerland | Cloud infrastructure (datacenter): hosting of the Tale Cloud platform — VMs, container runtime, database, and storage. | Germany (Frankfurt region). | | [OpenRouter, Inc.](https://openrouter.ai/privacy) | 169 Madison Avenue, New York, NY 10016, USA | LLM inference (chat, vision, embeddings), audio (speech-to-text and text-to-speech), plus image processing and generation. | European Union (in-region routing via `eu.openrouter.ai`: prompts and responses are processed exclusively within the EU). | #### A.2 — Swiss customers | Sub-processor (legal entity) | Registered address | Type of service | Place of processing | | ----------------------------------------------------- | --------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------- | | [Akenes SA (Exoscale)](https://www.exoscale.com/dpa/) | Boulevard de Grancy 19A, 1006 Lausanne, Switzerland | Cloud infrastructure (datacenter): hosting of the Tale Cloud platform — VMs, container runtime, database, and storage. | Switzerland (Zurich; disaster-recovery replica in Geneva). | | [OpenRouter, Inc.](https://openrouter.ai/privacy) | 169 Madison Avenue, New York, NY 10016, USA | LLM inference (chat, vision, embeddings), audio (speech-to-text and text-to-speech), plus image processing and generation. | European Union (in-region routing via `eu.openrouter.ai`). | For Swiss customers, platform hosting stays entirely in Switzerland. The AI Sub-processor does not offer a Swiss processing region; those calls are processed in the EU/EEA. All EU/EEA countries are on the Swiss Federal Council's adequacy list under Art. 16 FADP — the transfer requires no additional safeguards. ### Data categories and training prohibition | Sub-processor | Categories of data | Training on Customer data | | -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------- | | Akenes SA (Exoscale) | Application data in transit and at rest on the hosted runtime and storage. | No (infrastructure only; no AI training). | | OpenRouter, Inc. | Prompts and responses for the specific inference call; audio payloads and transcribed or synthesized text; image prompts and generated images. | No — contractually prohibited (enterprise terms). | ### Certifications and trust pages Each Sub-processor maintains its own security certifications and publishes them on a trust page: - **Akenes SA (Exoscale)** — ISO/IEC 27001:2022, ISO/IEC 27017, ISO/IEC 27018, SOC 2 Type II, PCI DSS v4.0, HDS, BSI C5, TISAX. Trust page: [exoscale.com/compliance](https://www.exoscale.com/compliance/). - **OpenRouter, Inc.** — SOC 2; evidence available through the access-gated trust portal [trust.openrouter.ai](https://trust.openrouter.ai). EU Standard Contractual Clauses apply to transfers outside the EU/EEA. ### Notes - The AI Sub-processor is engaged only when an AI feature routes a call to it. An organization that uses no LLM inference, audio, or image features sends no data to OpenRouter, Inc. - Model providers reachable through OpenRouter (such as Anthropic, Google, Meta, Mistral, OpenAI) are upstream providers of OpenRouter and are not Tale's direct Sub-processors. The default audio models — Whisper for speech-to-text and gpt-4o-mini-tts for text-to-speech — are OpenAI models reached this way. They operate under OpenRouter's own contractual terms, which forbid training on routed payloads; in-region routing restricts every call to provider endpoints inside the EU. - Each Sub-processor engages its own sub-processors (cloud hosting, CDN, secret stores). Those lists are public on the providers' trust pages above; Tale tracks material changes through the same 30-day notice mechanism in Section 6.2. - Tale Cloud's middleware, application state, and supporting infrastructure run on Exoscale in the Customer's selected region. Each AI call is routed to the provider's EU/EEA region. # Technical and organizational measures Source: https://tale.dev/legal/technical-organizational-measures **Last updated:** 01.05.2026 This document describes the technical and organizational measures ("TOMs") that Ruler GmbH ("Tale") implements to protect Personal Data processed on behalf of its customers, as referenced in Section 7 of the [Data Processing Agreement](/legal/data-processing-agreement). It applies to Tale Cloud. Self-hosted deployments are operated by the Customer; for those, the Customer determines and applies its own measures, while Tale provides hardened defaults and documented controls. Tale reviews these measures at least annually and may update them, provided the overall level of protection afforded to Personal Data does not materially decrease. ## 1. Confidentiality ### 1.1 Access control — physical Tale does not operate its own data centers. Physical infrastructure is provided by sub-processors listed in Appendix A of the [Data Processing Agreement](/legal/data-processing-agreement). Each provider is certified to ISO/IEC 27001 (or equivalent) and operates access controls including 24/7 staffing, video surveillance, badge or biometric entry, mantraps, and visitor logging. Evidence is available on request via the sub-processor trust pages. ### 1.2 Access control — systems a) Multi-factor authentication is mandatory for every Tale employee with production access. b) Access to production systems is granted on a least-privilege, need-to-know basis and reviewed at least quarterly. c) Personnel access is provisioned through a central identity provider and revoked within one business day of role change or departure. d) Privileged operations require an approved change ticket and are logged with the actor, action, and timestamp. e) Customer access to the platform is authenticated by email and password (with optional WebAuthn or TOTP second factor) or by SSO (OIDC) where the Customer has configured it. ### 1.3 Access control — data a) Personal Data is tenant-isolated at the application layer; every database query is scoped to the requesting organisation. b) Production data is never copied to non-production environments. Synthetic or anonymized data is used for development and testing. c) Customer-issued API keys are hashed at rest and revocable from the admin surface. ### 1.4 Separation control a) Each customer organisation is a separate logical tenant; tenant identifiers are present on every row in the database and enforced at the query layer. b) Backups are encrypted per tenant key; restoration into another tenant is prevented at the key-management layer. c) Workloads run in isolated containers; network policies prevent cross-tenant traffic. ### 1.5 Pseudonymization and encryption a) Personal Data is encrypted in transit using TLS 1.2 or higher, with HSTS enforced on every public endpoint. b) Personal Data is encrypted at rest using AES-256 (or equivalent) at the storage layer. c) Encryption keys are managed by the cloud sub-processor's key management service; key rotation occurs at least annually. d) Where pseudonymization is feasible without breaking functionality, Tale prefers pseudonymous identifiers over plaintext personal identifiers in logs and analytics. ## 2. Integrity ### 2.1 Transfer control a) All ingress and egress traffic crossing public networks is encrypted in transit. b) Internal service-to-service traffic uses authenticated mTLS or signed tokens. c) AI sub-processor calls are routed to a region matching the Customer's data-residency selection (Switzerland or EU); routing is enforced server-side. ### 2.2 Input control a) Every administrative action in the platform is recorded in an immutable audit log, including the actor, the affected resource, and the timestamp. b) Audit logs are retained for the period configured by the Customer (default 365 days, no upper bound) and are not modified by snapshot restores. c) System logs from infrastructure components are retained for 90 days and are accessible only to authorized Tale personnel. ## 3. Availability and resilience ### 3.1 Availability control a) Application services run in redundant configurations behind load balancers, with automatic failover between availability zones within the chosen region. b) Monitoring covers system uptime, error rates, latency, and queue depth; on-call engineers are paged on threshold breaches. c) Tale's status page publishes incident notifications and historical uptime data. ### 3.2 Recoverability a) Tale snapshots application databases daily and object storage hourly. Snapshots are encrypted at rest with keys held by Tale's cloud sub-processor. b) A disaster-recovery replica is maintained within the customer's selected region (Geneva for Switzerland, Dublin for the European Union). c) Restores from snapshot are initiated by the Customer via support and meet the recovery time objective stated in the Service Agreement. d) Backup integrity is verified at least quarterly by restoring a representative snapshot to an isolated environment. ### 3.3 Capacity and performance a) Production environments are sized for expected peak load and scaled horizontally as utilization grows. b) Rate limits and back-pressure mechanisms prevent any single tenant from degrading service for others. ## 4. Procedures for regular testing, assessment, and evaluation ### 4.1 Vulnerability management a) Tale runs automated dependency scanning on every commit and tracks vulnerability disclosures for all production dependencies. b) Security patches are applied within the timeframes mandated by Tale's vulnerability management policy: critical within 7 days, high within 30 days, medium within 90 days. c) Container images are rebuilt at least monthly to pick up upstream security updates. ### 4.2 Penetration testing a) Tale commissions an external penetration test at least annually. Findings are remediated according to severity, and an attestation letter is available to customers under NDA via support. ### 4.3 Audits and certifications a) Tale maintains ISO/IEC 27001 and SOC 2 Type II certifications (or equivalent standards) for Tale Cloud. b) Customers may request copies of the current SOC 2 Type II report and ISO 27001 certificate by contacting support; both are provided under NDA. ### 4.4 Internal review a) The security team reviews access logs, configuration drift, and incident patterns on a rolling weekly basis. b) The privacy team reviews data-subject request handling and retention behaviour at least quarterly. c) Material findings from any review feed back into a tracked remediation backlog with owners and deadlines. ## 5. Incident response ### 5.1 Incident detection a) Production systems emit telemetry to a centralized logging and monitoring platform. b) Automated alerts page the on-call engineer on anomalies including elevated error rates, unauthorized access attempts, and unusual data egress patterns. ### 5.2 Incident response procedure a) Tale maintains a documented incident response procedure covering detection, containment, eradication, recovery, and post-incident review. b) The procedure is tested at least annually through a tabletop exercise or live drill. c) Severity classifications and escalation paths are defined in advance; the on-call engineer is empowered to escalate to leadership without delay. ### 5.3 Customer notification a) Tale notifies affected Customers without undue delay and in any event within 72 hours of becoming aware of a Data Breach affecting their Personal Data, as set out in Section 8 of the [Data Processing Agreement](/legal/data-processing-agreement). b) Notifications include the information required by Applicable Data Protection Law: nature of the breach, categories and approximate numbers affected, likely consequences, and remediation steps. ## 6. Personnel ### 6.1 Confidentiality a) Every Tale employee, contractor, and consultant signs a written confidentiality agreement covering Personal Data, source code, and customer information. The obligation survives termination of the engagement. ### 6.2 Background checks a) Background checks are performed on Tale employees with production access, to the extent permitted by local law. ### 6.3 Training a) New hires complete security and privacy training within their first 30 days. b) All personnel complete refresher training at least annually, including topics such as phishing awareness, secure development, and data handling. ### 6.4 Offboarding a) Access is revoked within one business day of departure or role change. b) Equipment is wiped and recovered; physical credentials are returned and deactivated. ## 7. Sub-processor management ### 7.1 Selection a) Sub-processors are selected after a security and privacy review covering their certifications, data protection commitments, and processing locations. ### 7.2 Contractual obligations a) Each sub-processor is contractually bound — by written agreement — to data protection obligations no less protective than those set out in the [Data Processing Agreement](/legal/data-processing-agreement), including the no-training commitment in Section 5. ### 7.3 Ongoing review a) Sub-processor certifications and audit reports are reviewed at least annually. b) Material changes to a sub-processor's posture trigger notification to Customers under the 30-day mechanism in Section 6.2 of the DPA. ## 8. Data minimization, retention, and deletion ### 8.1 Data minimization a) The platform collects only the Personal Data required to deliver the requested functionality. b) Customers control what data they submit; Tale does not enrich Customer-submitted data with third-party sources without an explicit opt-in. ### 8.2 Retention a) Retention periods for each data category are documented in Tale's [Privacy policy](https://tale.dev/legal/privacy-policy) and in the in-product retention configuration. b) Audit-log retention floors are configured by the Customer; the platform default is 365 days with no upper bound. ### 8.3 Deletion a) On termination of the Agreement, Personal Data is returned or deleted according to Section 13 of the [Data Processing Agreement](/legal/data-processing-agreement). b) Deletion crosses every store that holds the data, including object storage and backups (the latter via key destruction within the backup retention window). c) Customers may initiate erasure for individual Data Subjects through the in-product data-subject request workflow. ## 9. Governance ### 9.1 Policies a) Tale maintains written information security and data protection policies, reviewed at least annually. b) Policy changes are communicated to all personnel; material changes are accompanied by mandatory training. ### 9.2 Roles and responsibilities a) Tale designates a person responsible for information security and a person responsible for data protection. Both report into senior leadership. b) Their contact addresses are `security@tale.dev` and `privacy@tale.dev` respectively. ### 9.3 Risk management a) Tale maintains a risk register covering technical, organizational, and legal risks. b) Risks are reviewed at least quarterly and after any material incident, with mitigations tracked through completion. ## 10. Contact For any questions regarding these TOMs or to request audit evidence, contact us via our [contact form](https://tale.dev/contact). **Ruler GmbH** Seestrasse 4 3700 Spiez Switzerland # Personalization — Privacy notice Source: https://tale.dev/legal/personalization **Last updated:** 27.09.2026 ## 1. The contract Tale's personalization layer — your custom instructions — is built around a single contract: > **Within Tale, no other user — including your organization's admins — can read your custom instructions via any UI or API. Custom instructions are OFF by default: they apply only once you turn them on under Settings › Preferences, or once an admin makes them your organization's default and you have not turned them off yourself.** This page documents what that contract does and does not cover. Five caveats are inherent to running an AI service on a third-party model and on a database someone operates, and cannot be eliminated by Tale's code alone. ## 2. Caveats inherent to the LLM stack ### 2.1 Your custom instructions are sent to your configured LLM provider on every chat turn When you send a chat message and custom instructions apply to you, they are included in the system prompt that goes to your organization's configured upstream LLM (OpenAI, Anthropic, Google, Azure, your self-hosted model, etc.). They are then subject to that provider's data-retention and abuse-monitoring terms. Most major hosted providers retain inputs and outputs for abuse monitoring for a bounded window (typically 7–30 days as of mid-2026) and offer Zero Data Retention or equivalent programs to qualifying enterprise customers. Durations and eligibility change frequently — refer to the contract your organization holds with the provider, and to each provider's published policy: - Anthropic — [Privacy policy](https://www.anthropic.com/legal/privacy) · [Data retention FAQ](https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data) - OpenAI — [API data usage policies](https://openai.com/policies/api-data-usage-policies/) - Google Vertex AI / Gemini — [Generative AI data governance](https://cloud.google.com/vertex-ai/generative-ai/docs/data-governance) - Azure OpenAI / Microsoft Foundry — [Data, privacy & security](https://learn.microsoft.com/en-us/azure/ai-foundry/responsible-ai/openai/data-privacy) · [Abuse monitoring](https://learn.microsoft.com/en-us/azure/ai-foundry/openai/concepts/abuse-monitoring) For self-hosted models or custom OpenAI-compatible endpoints (Ollama, vLLM, internal gateways, etc.), no third-party retention applies — retention is governed entirely by the operator of that endpoint. Once your instructions are sent, **Tale cannot recall them**. If you change or clear them, future requests carry the new text, but copies already sent to the provider follow the provider's retention schedule. ### 2.2 Self-hosted deployments: the deployment operator can read raw rows Tale stores your custom instructions in your deployment's Postgres database, in the `app.user_preferences` table. Whoever has database access at your deployment, or access to its backups, can read those rows directly — Tale's role-based admin restriction ("admin can't read content") **does not extend to the database layer**. If you self-host, treat your database operators as having access to all personalization content. SOC 2 / ISO controls covering DB-level access are your responsibility. ### 2.3 Assistant replies may quote or paraphrase your custom instructions The model's reply can repeat your custom instructions verbatim or paraphrased. That reply is then stored in your chat under the **chat's visibility rules**, not the rules that protect your instructions: if you share the chat, the shared copy includes the reply. Changing or clearing your instructions does not retroactively redact past replies. ### 2.4 Database and server logs Tale's application code keeps your custom instructions out of its own logs and error reports. The database server and the infrastructure around it keep logs of their own: if your operator turns on statement logging in Postgres, the text you save can land in those logs, and Tale cannot redact them. ### 2.5 Provider abuse-monitoring review Major LLM providers run automated abuse-detection over inputs they receive. Content flagged as suspect may be reviewed by the provider's abuse team. Zero-data-retention (ZDR) endpoints, where available, can opt out. Personalization-bearing requests are no different from any other request in this regard. ## 3. What Tale enforces - **Off by default.** With no organization default and no choice of your own, custom instructions are never sent to the model. Blank instructions count as none, even while the feature is on. - **Two-signal gating.** Whether your custom instructions apply is decided by two signals: - **Organization default** — admin-controlled, under Settings › Governance › Policies & Limits. When on, members inherit on; when off or absent, members inherit off. - **Your preference** — your explicit on/off under Settings › Preferences beats the organization default in either direction. The page tells you whether you follow the organization default or override it. - **No admin override.** The admin role grants no access to another user's row. Every read and write reaches only the signed-in user's own row and re-checks organization membership on every request, so a removed user whose session is still valid cannot read that row. - **Off keeps the text.** Turning custom instructions off stops sending them but keeps the text, so it is still there when you turn them back on. To remove it, clear the field and save; Tale keeps no earlier versions. - **Cascade hard-delete.** Removing a user from an organization, deleting the organization, or processing an erasure request for that user (filed by an admin under Settings › Governance › Data subject requests) hard-deletes the user's preferences in that organization, custom instructions included, in the same operation. An active legal hold on the user or on the whole organization blocks all three until it is released. The audit log records each of these events, but never the text of the instructions. Account-level self-deletion is not yet a product feature; when it ships, it will delete these rows too. ## 4. DPA addendum (draft) Customers requiring a Data Processing Addendum addition for personalization content should request the **Personalization Processor Annex**, which covers: - Categories of personal data: free-form user-authored instructions; audit metadata without instruction content. - Purposes: per-user personalization of chat responses only. - Sub-processors: the LLM provider configured per organization (see "Your custom instructions are sent…" above). - Retention: indefinite while the user is a member of the organization, including while the feature is off; deleted immediately when the user clears the field, on member removal, on organization deletion, or when an erasure request is processed. - Cross-border transfers: governed by the LLM provider's residency and the customer's choice of provider region. - Subject rights: erasure of content (Art. 17 via cascade on member removal and organization deletion, and via erasure requests). Audit-log metadata (no content) is retained for compliance. Operator-invokable export query (Art. 15/20) is available against the underlying tables; in-product self-service export is planned for v2. # Nutzungsbedingungen Source: https://tale.dev/de/legal/terms-of-service **Letzte Aktualisierung:** 18.05.2026 ## 1. Einleitung Diese Nutzungsbedingungen ("Bedingungen") regeln deinen Zugriff auf und deine Nutzung der Website [https://tale.dev](https://tale.dev) ("Website"), die von der Ruler GmbH ("wir", "uns", "unsere") betrieben wird. Mit dem Zugriff auf oder der Nutzung unserer Website erklärst du dich an diese Bedingungen gebunden. Wenn du mit einem Teil dieser Bedingungen nicht einverstanden bist, nutze die Website bitte nicht. Diese Bedingungen gelten ausschließlich für die Nutzung der Website. Die Nutzung von Tale-Produkten und -Diensten wird separat durch unseren [Service Agreement](/files/Service_Agreement_Template.pdf) und den [Hardware Agreement](/files/Hardware_Agreement_Template.pdf) geregelt, jeweils wo anwendbar. ## 2. Betreiber **Ruler GmbH** Seestrasse 4 3700 Spiez Schweiz Handelsregister: CHE-186.532.610 ## 3. Nutzung der Website ### 3.1 Zulässige Nutzung Du darfst diese Website für rechtmäßige Zwecke und im Einklang mit diesen Bedingungen nutzen. Die Website informiert über Tale, unsere Produkte und Dienste und erleichtert die Kommunikation mit uns. ### 3.2 Verbotenes Verhalten Du verpflichtest dich, nicht: - die Website in einer Weise zu nutzen, die geltendes lokales, nationales oder internationales Recht verletzt; - unbefugt auf die Website, ihre Server oder angeschlossene Systeme oder Netze zuzugreifen; - die Integrität oder Performance der Website oder der zugrunde liegenden Infrastruktur zu stören oder zu beeinträchtigen; - automatisierte Systeme, Bots oder Scraper ohne unsere vorherige schriftliche Zustimmung zu nutzen, außer für das übliche Suchmaschinen-Indexing; - über unsere Kontaktformulare rechtswidrige, bedrohliche, beleidigende, ehrverletzende oder anderweitig zu beanstandende Inhalte zu übermitteln; - dich als eine andere Person oder Organisation auszugeben oder deine Verbindung zu einer Person oder Organisation falsch darzustellen; - Teile der Website, die nicht unter eine Open-Source-Lizenz fallen, zu reverse-engineeren, zu dekompilieren oder zu disassemblieren. ## 4. Geistiges Eigentum ### 4.1 Website-Inhalte Die Inhalte dieser Website — darunter Texte, Grafiken, Logos, Bilder und das Gesamt-Design — sind Eigentum der Ruler GmbH und, soweit nicht anders angegeben, durch schweizerisches und internationales Urheber-, Marken- und sonstiges geistiges Eigentumsrecht geschützt. ### 4.2 Open-Source-Software Tale steht unter MIT-Lizenz und darf nach den Bedingungen der MIT-Lizenz frei genutzt, verändert und weitergegeben werden. Die Open-Source-Komponenten von Tale unterliegen ihren jeweiligen Lizenzen. Die MIT-Lizenz gilt ausschließlich für die Tale-Software und erstreckt sich nicht auf die Website-Inhalte, das Branding oder die Marken. ### 4.3 Marken "Tale", das Tale-Logo und "Ruler GmbH" sind Marken der Ruler GmbH. Du darfst diese Marken ohne unsere vorherige schriftliche Genehmigung nicht verwenden, außer in angemessenem Umfang zur Bezeichnung unserer Produkte oder unseres Unternehmens. ## 5. Kontaktformulare und Einsendungen Mit der Einsendung von Informationen über unsere Kontakt- oder Demo-Anfrageformulare sicherst du zu, dass die bereitgestellten Informationen zutreffend sind und dass du befugt bist, sie weiterzugeben. Wir verarbeiten alle über diese Formulare eingesandten personenbezogenen Daten gemäß unserer [Datenschutzerklärung](/de/legal/privacy-policy). Das Absenden eines Formulars begründet kein Vertragsverhältnis zwischen dir und der Ruler GmbH. Ein Vertragsverhältnis kommt erst mit Abschluss eines gesonderten Vertrags zustande. ## 6. Drittanbieter-Links, von dir übermittelte URLs und Video-Analyse ### 6.1 Links von der Website Unsere Website kann Links zu Drittanbieter-Websites, -Diensten oder -Ressourcen enthalten, die nicht von uns betrieben oder kontrolliert werden, einschließlich unserer Dokumentations-Site, Schulungsangebote und Service-Vereinbarungen. Wir haben keine Kontrolle über und übernehmen keine Verantwortung für Inhalte, Datenschutzpraktiken oder Verfügbarkeit solcher Drittanbieter-Websites oder -Dienste. Die Aufnahme eines Links stellt keine Empfehlung dar. Wir empfehlen dir, die Bedingungen und Datenschutzerklärungen aller besuchten Drittanbieter-Seiten zu lesen. ### 6.2 An den Dienst übermittelte URLs Wenn du dem Dienst eine URL zum Abruf, zur Transkription oder Analyse übermittelst (einschließlich Video-Links), sicherst du zu und gewährleistest, dass: - du die Rechte, Lizenzen oder die nach dem Urheberrecht und verwandten Rechten deiner Rechtsordnung anwendbaren gesetzlichen Schranken besitzt, um den Inhalt unter dieser URL abzurufen und zu verarbeiten; - deine Nutzung des Dienstes mit den Nutzungsbedingungen der Quellplattform und mit allen anwendbaren Gesetzen vereinbar ist; und - der Inhalt nicht rechtsverletzend, ehrverletzend, rechtswidrig oder anderweitig von einer Drittverarbeitung ausgeschlossen ist. Transkripte, Untertitel, Zusammenfassungen und sonstige Artefakte, die der Dienst aus der übermittelten URL ableitet, sind Bearbeitungen des zugrunde liegenden Ausgangsinhalts. Sämtliche Urheber- und Schutzrechte am Originalinhalt verbleiben beim ursprünglichen Rechteinhaber; der Dienst gewährt dir an den abgeleiteten Artefakten keine über deine bestehende Nutzungslizenz am Ausgangsmaterial hinausgehenden Rechte. Im Verhältnis zwischen dir und dem Dienst stehen die abgeleiteten Artefakte dir zu — stets vorbehaltlich der zugrunde liegenden Rechte des Rechteinhabers — und der Dienst erhebt keinen Eigentumsanspruch auf Transkripte oder Zusammenfassungen, die du aus deinen eigenen übermittelten URLs erzeugst. Tale handelt in Bezug auf die von dir übermittelten Inhalte (URL-Abruf, Transkription, Speicherung) als Auftragsverarbeiter auf deine Weisung. In Bezug auf die zur Bereitstellung des Dienstes generierten Betriebsmetadaten (Rate-Limit-Zähler, Fehlerklassifikation, Telemetrie) handelt Tale als Verantwortlicher. Wir kuratieren, prüfen oder befürworten von Nutzenden übermittelte URLs nicht. ### 6.3 Ermessensvorbehalt Wir können jede übermittelte URL oder gespeicherte Ausgabe nach eigenem Ermessen ablehnen, drosseln, aussetzen oder entfernen, insbesondere bei Beschwerden, bei Überschreitung von Plattformlimits oder wenn die Quellplattform unsere Anfragen blockiert. Wir können auch Kategorien von URLs (zum Beispiel Live-Streams, altersbeschränkte Inhalte oder Playlist-Endpunkte) aus technischen oder grundsätzlichen Gründen ablehnen. ### 6.4 Bekanntmachungs- und Maßnahmenverfahren Wenn du der Meinung bist, dass vom Dienst gespeicherte Inhalte deine Rechte verletzen oder gegen geltendes Recht verstoßen, kontaktiere uns über die in Abschnitt 14 angegebene Adresse mit: (i) Angabe des geschützten Werks oder Rechts; (ii) der URL des gespeicherten Inhalts; (iii) deinen Kontaktdaten; und (iv) einer Erklärung in gutem Glauben über die Grundlage deines Anspruchs. Wir prüfen Meldungen zeitnah und können den Inhalt nach eigenem Ermessen innerhalb einer angemessenen Frist entfernen oder den Zugang dazu einschränken. Dieses Verfahren wird zusätzlich zu allen Rechten und Verfahren angeboten, die dir nach geltendem Urheber- oder Inhaltemoderationsrecht zur Verfügung stehen (insbesondere Artikel 16 der EU-Verordnung 2022/2065 — Digital Services Act, soweit anwendbar). ### 6.5 Keine Dienstleistungsgarantie Der URL-Abruf und die Transkription werden nach bestem Bemühen erbracht. Wir gewährleisten nicht, dass eine bestimmte URL verarbeitbar ist, dass Transkripte richtig oder vollständig sind oder dass die Verarbeitung zu einem bestimmten Zeitpunkt verfügbar ist. Die Genauigkeit der automatisierten Transkription hängt von Audioqualität, Sprache und Verhalten der Quellplattform ab. ## 7. Haftungsausschluss Die Website wird ohne jegliche ausdrückliche oder stillschweigende Gewährleistung bereitgestellt — insbesondere ohne Gewährleistung der Marktgängigkeit, Eignung für einen bestimmten Zweck oder Nichtverletzung von Rechten Dritter. Die Bereitstellung erfolgt "wie besehen" und "wie verfügbar". Wir sichern nicht zu, dass die Website unterbrechungs- und fehlerfrei oder frei von Viren oder sonstigen schädlichen Komponenten ist. Obwohl wir uns bemühen, die Informationen der Website aktuell und korrekt zu halten, übernehmen wir keine Garantie für Vollständigkeit, Richtigkeit oder Zuverlässigkeit der Inhalte. Informationen auf dieser Website dienen ausschließlich allgemeinen Informationszwecken und stellen keine professionelle, rechtliche, finanzielle oder technische Beratung dar. ## 8. Haftungsbeschränkung Soweit nach geltendem Recht zulässig, haften die Ruler GmbH, ihre Organe, Angestellten und Beauftragten nicht für mittelbare, zufällige, besondere, Folge- oder Strafschäden — einschließlich, aber nicht beschränkt auf entgangenen Gewinn, Datenverlust, entgangene Reputationswerte oder entgangene Geschäftschancen — die sich aus oder im Zusammenhang mit der Nutzung oder Nichtnutzbarkeit der Website ergeben. Unsere Gesamthaftung für sämtliche Ansprüche im Zusammenhang mit der Nutzung der Website ist auf CHF 100 begrenzt. Diese Haftungsbegrenzung gilt nicht für Schäden, die durch Vorsatz oder grobe Fahrlässigkeit verursacht werden, oder soweit sie nach geltendem Recht unzulässig ist. ## 9. Freistellung Du verpflichtest dich, die Ruler GmbH sowie deren Organe, Angestellte und Beauftragte von allen Ansprüchen, Haftungen, Schäden, Verlusten oder Kosten (einschließlich angemessener Anwaltskosten) freizustellen, die sich aus einer Verletzung dieser Bedingungen oder aus einer rechtswidrigen Nutzung der Website durch dich ergeben. ## 10. Änderungen der Bedingungen Wir behalten uns das Recht vor, diese Bedingungen jederzeit zu ändern. Die aktualisierte Version wird auf dieser Seite mit angepasstem "Letzte Aktualisierung"-Datum veröffentlicht. Deine fortgesetzte Nutzung der Website nach solchen Änderungen gilt als Annahme der geänderten Bedingungen. Wir empfehlen, diese Bedingungen regelmäßig zu prüfen. ## 11. Salvatorische Klausel Sollte eine Bestimmung dieser Bedingungen von einem zuständigen Gericht für unwirksam oder nicht durchsetzbar erklärt werden, bleiben die übrigen Bestimmungen in vollem Umfang wirksam. Die unwirksame oder nicht durchsetzbare Bestimmung ist durch eine wirksame und durchsetzbare Bestimmung zu ersetzen, die der ursprünglichen Absicht am nächsten kommt. ## 12. Verzicht Ein Verzicht der Ruler GmbH auf die Durchsetzung eines Rechts oder einer Bestimmung dieser Bedingungen gilt nur, wenn er schriftlich erklärt und von der Ruler GmbH unterzeichnet ist. ## 13. Anwendbares Recht und Gerichtsstand Diese Bedingungen unterliegen dem materiellen Recht der Schweiz und sind nach diesem auszulegen, unter Ausschluss der Kollisionsnormen und unter Ausschluss des UN-Übereinkommens über Verträge über den internationalen Warenkauf (CISG). Streitigkeiten aus oder im Zusammenhang mit diesen Bedingungen unterliegen der ausschließlichen Zuständigkeit der zuständigen Gerichte des Kantons Bern, Schweiz, soweit nicht zwingendes Recht entgegensteht. ## 14. Kontakt Bei Fragen zu diesen Bedingungen erreichst du uns: **Ruler GmbH** Seestrasse 4 3700 Spiez Schweiz # Datenschutzerklärung Source: https://tale.dev/de/legal/privacy-policy **Letzte Aktualisierung:** 01.04.2026 ## 1. Einleitung Die Ruler GmbH ("wir", "uns", "unsere") betreibt die Website [https://tale.dev](https://tale.dev) und die Tale-Plattform. Wir setzen uns für den Schutz deiner personenbezogenen Daten ein und respektieren deine Privatsphäre. Diese Datenschutzerklärung erläutert, wie wir personenbezogene Daten erheben, nutzen, speichern und schützen, wenn du unsere Website besuchst oder mit uns interagierst. Diese Datenschutzerklärung entspricht dem Schweizer Bundesgesetz über den Datenschutz (FADP/nDSG) und, soweit anwendbar, der Datenschutz-Grundverordnung der Europäischen Union (DSGVO). ## 2. Verantwortlicher Verantwortlich für die Verarbeitung deiner personenbezogenen Daten ist: **Ruler GmbH** Seestrasse 4 3700 Spiez Schweiz Handelsregister: CHE-186.532.610 Für Fragen oder Anliegen rund um den Datenschutz erreichst du uns über unser [Kontaktformular](https://tale.dev/contact). ## 3. Welche Daten wir erheben ### 3.1 Kontakt- und Demo-Anfrageformulare Wenn du unser Kontaktformular oder unser Demo-Anfrageformular abschickst, erheben wir folgende personenbezogene Daten: - Name - Email-Adresse - Firmenname (optional beim Kontaktformular, Pflicht beim Demo-Anfrageformular) - Telefonnummer (optional, nur Demo-Anfrageformular) - Interessensbereich (nur Demo-Anfrageformular) - Nachrichteninhalt oder zusätzliche Kommentare ### 3.2 Automatisch erhobene Daten Unsere Website misst aggregierte Zugriffszahlen mit Umami, einem quelloffenen Analytics-Werkzeug, das wir selbst auf unserem eigenen Server in Frankfurt (Deutschland) betreiben. Es wird von unserer eigenen Domain ausgeliefert, setzt keine Cookies, speichert keinen Identifikator in deinem Browser und sendet nichts an Dritte — keine Analysedaten verlassen jemals unsere Infrastruktur, und wir verfolgen dich nicht über andere Websites hinweg. Pro Seitenaufruf erfassen wir die aufgerufene Adresse, die verweisende Seite, deinen ungefähren Standort (Land, Region, Stadt), deine Bildschirmgröße sowie Browser, Betriebssystem und Gerätetyp. Deine IP-Adresse dient ausschließlich dazu, diesen ungefähren Standort abzuleiten und — zusammen mit einem regelmäßig wechselnden Geheimnis — einen Einweg-Hash zu bilden, der die Anfragen eines einzelnen Besuchs gruppiert; die IP-Adresse selbst wird nie gespeichert. Wir erstellen keine Besucherprofile und können dich anhand dieser Daten nicht identifizieren. Zur Auslieferung der Website verarbeiten wir zudem vorübergehend minimale technische Daten (siehe Server-Logs unten); außerdem speichert die Website ein funktionales Sprach-Cookie sowie eine Theme-Einstellung in deinem Browser (siehe Cookies unten). Erfasst werden nur der Seitenpfad und der Ursprung des Verweises; Suchparameter, Fragmente und Seitentitel bleiben außen vor. Die Browsersprache ist enthalten. Abgeschlossene Kontakt- und Demo-Anfragen werden ohne Formularinhalte gezählt. Do Not Track und Global Privacy Control deaktivieren die Erfassung. ### 3.3 Server-Logs Wenn du unsere Website besuchst, verarbeitet unser selbst betriebener Webserver bzw. unsere Hosting-Infrastruktur ([Hosting-Anbieter — vor Veröffentlichung zu bestätigen]) möglicherweise vorübergehend technische Daten wie deine IP-Adresse, deinen Browser-Typ und Zugriffs-Zeitstempel zur Auslieferung der Website und zur Wahrung der Sicherheit (z. B. Rate-Limiting). Diese Daten werden nur kurzzeitig im Rahmen des üblichen Webserver-Betriebs verarbeitet und von uns zu keinem anderen Zweck genutzt. ## 4. Zweck und Rechtsgrundlage der Verarbeitung Wir verarbeiten deine personenbezogenen Daten zu folgenden Zwecken: | Zweck | Betroffene Daten | Rechtsgrundlage (FADP) | Rechtsgrundlage (DSGVO) | | -------------------------------------------- | ------------------------------------------------------------------------------------- | ---------------------- | ------------------------------------------------------ | | Beantwortung deiner Anfrage | Name, Email, Firma, Nachricht | Berechtigtes Interesse | Art. 6 Abs. 1 lit. f DSGVO — Berechtigtes Interesse | | Planung und Durchführung einer Produkt-Demo | Name, Email, Telefon, Firma, Interessensbereich | Berechtigtes Interesse | Art. 6 Abs. 1 lit. b DSGVO — Vorvertragliche Maßnahmen | | Betrieb und Sicherheit unserer Website | Technische Daten (IP-Adresse, Browser) | Berechtigtes Interesse | Art. 6 Abs. 1 lit. f DSGVO — Berechtigtes Interesse | | Messung der Website-Nutzung | Aufgerufene Adresse, verweisende Seite, ungefährer Standort, Geräte- und Browserdaten | Berechtigtes Interesse | Art. 6 Abs. 1 lit. f DSGVO — Berechtigtes Interesse | | Anbahnung einer möglichen Geschäftsbeziehung | Daten aus Kontaktformularen | Berechtigtes Interesse | Art. 6 Abs. 1 lit. f DSGVO — Berechtigtes Interesse | Nach dem Schweizer FADP ist die Verarbeitung personenbezogener Daten grundsätzlich zulässig, solange sie die Persönlichkeit der betroffenen Person nicht verletzt. Wir verarbeiten deine Daten in gutem Glauben, verhältnismäßig und ausschließlich zu den oben genannten Zwecken. ## 5. Datenweitergabe Wir verkaufen, vermieten oder teilen deine personenbezogenen Daten nicht mit Dritten für Marketing- oder Werbezwecke. Folgende Kategorien von Dienstleistern können in unserem Auftrag und nach unseren Weisungen Zugriff auf deine personenbezogenen Daten haben: - **Hosting-Infrastruktur:** Die Website wird von Ruler GmbH auf selbst gehosteter Infrastruktur betrieben, bereitgestellt von [Hosting-Anbieter — vor Veröffentlichung zu bestätigen], Standort [Rechenzentrums-Standort — vor Veröffentlichung zu bestätigen]. - **CRM-Anbieter:** Einsendungen aus dem Kontaktformular speichern wir in einem in der Schweiz gehosteten CRM-System. Diese Anbieter handeln als Auftragsverarbeiter und sind durch Auftragsverarbeitungsverträge gemäß Art. 9 FADP und Art. 28 DSGVO gebunden. ## 6. Internationale Datenübermittlung Deine personenbezogenen Daten werden primär in der Schweiz gespeichert und verarbeitet. [Vor Veröffentlichung zu bestätigen: Standort der Webserver angeben — Schweiz oder EU/EWR — und diesen Abschnitt entsprechend anpassen.] Alle EU/EWR-Mitgliedstaaten werden vom Schweizer Bundesrat nach Art. 16 FADP als Staaten mit angemessenem Datenschutzniveau anerkannt. Die Europäische Kommission hat die Schweiz ebenfalls als Land mit angemessenem Schutzniveau nach der DSGVO anerkannt. Es werden keine personenbezogenen Daten in Länder ohne angemessenes Datenschutzniveau übermittelt. ## 7. Speicherdauer Wir speichern deine personenbezogenen Daten nur so lange, wie es für den Zweck ihrer Erhebung erforderlich ist: - **Einsendungen aus dem Kontaktformular:** Kommt keine Geschäftsbeziehung zustande, werden deine Daten innerhalb von 12 Monaten nach deinem letzten Kontakt gelöscht. - **Einsendungen aus dem Demo-Anfrageformular:** Kommt keine Geschäftsbeziehung zustande, werden deine Daten innerhalb von 12 Monaten nach deinem letzten Kontakt gelöscht. - **Laufende Geschäftsbeziehungen:** Kommt eine Geschäftsbeziehung zustande, werden deine Daten für die Dauer der Beziehung und für den gesetzlich vorgeschriebenen Zeitraum aufbewahrt (typischerweise 10 Jahre nach schweizerischem Handelsrecht). - **Server-Logs:** Technische Daten werden ausschließlich kurzzeitig zu Betriebs- und Sicherheitszwecken auf unserer eigenen Infrastruktur verarbeitet und danach automatisch gelöscht. ## 8. Deine Rechte Nach dem Schweizer FADP und, soweit anwendbar, der DSGVO hast du folgende Rechte: - **Auskunftsrecht:** Du kannst Auskunft darüber verlangen, ob und welche personenbezogenen Daten wir über dich verarbeiten. - **Recht auf Berichtigung:** Du kannst die Korrektur unrichtiger Daten verlangen. - **Recht auf Löschung:** Du kannst die Löschung deiner Daten verlangen, vorbehaltlich gesetzlicher Aufbewahrungspflichten. - **Recht auf Datenübertragbarkeit:** Du kannst verlangen, dass deine Daten dir oder einem Dritten in einem gängigen, maschinenlesbaren Format zur Verfügung gestellt werden. - **Widerspruchsrecht:** Du kannst der Verarbeitung deiner personenbezogenen Daten jederzeit widersprechen. - **Recht auf Widerruf der Einwilligung:** Beruht die Verarbeitung auf Einwilligung, kannst du sie jederzeit widerrufen, ohne die Rechtmäßigkeit der bisherigen Verarbeitung zu berühren. Um eines dieser Rechte auszuüben, kontaktiere uns bitte über unser [Kontaktformular](https://tale.dev/contact). Wir antworten innerhalb von 30 Tagen. Wenn du der Meinung bist, dass deine Datenschutzrechte verletzt wurden, hast du das Recht, eine Beschwerde beim Eidgenössischen Datenschutz- und Öffentlichkeitsbeauftragten (EDÖB) in der Schweiz oder gegebenenfalls bei einer Aufsichtsbehörde in deinem EU/EWR-Mitgliedstaat einzureichen. ## 9. Cookies Unsere Website nutzt keine Cookies für Analytics oder Tracking — die oben beschriebene selbst betriebene Analyse setzt kein Cookie und speichert keinen Identifikator in deinem Browser. Sie speichert genau ein funktionales Cookie: `tale_locale`, das deine Sprachwahl für ein Jahr speichert, damit Seiten beim nächsten Besuch in deiner Sprache laden. Es enthält keine personenbezogenen Daten und keinen Identifikator. Deine Hell-/Dunkel-Einstellung liegt im Local Storage deines Browsers und verlässt dein Gerät nie. Sollten wir künftig Cookies oder Drittanbieter-Dienste einführen, die eine Einwilligung erfordern, aktualisieren wir diese Datenschutzerklärung und implementieren einen passenden Einwilligungs-Mechanismus. ## 10. Datensicherheit Wir treffen angemessene technische und organisatorische Maßnahmen, um deine personenbezogenen Daten vor unbefugtem Zugriff, Verlust, Missbrauch oder Zerstörung zu schützen. Dazu gehören Verschlüsselung in der Übertragung (TLS/SSL), Zugriffssteuerungen und eine gehärtete, selbst betriebene Hosting-Infrastruktur. Ruler GmbH ist ISO-27001- und SOC-2-zertifiziert. ## 11. Datenschutz für Kinder Unsere Website und Dienste richten sich nicht an Personen unter 16 Jahren. Wir erheben wissentlich keine personenbezogenen Daten von Kindern. Erfahren wir, dass wir unbeabsichtigt Daten einer Person unter 16 Jahren erhoben haben, löschen wir diese umgehend. ## 12. Änderungen dieser Datenschutzerklärung Wir können diese Datenschutzerklärung von Zeit zu Zeit aktualisieren, um Änderungen unserer Praktiken, Dienste oder rechtlicher Anforderungen abzubilden. Die aktualisierte Version wird auf dieser Seite mit angepasstem "Letzte Aktualisierung"-Datum veröffentlicht. Wir empfehlen, diese Seite regelmäßig zu prüfen. ## 13. Kontakt Bei Fragen oder Anliegen zu dieser Datenschutzerklärung oder unseren Datenverarbeitungspraktiken erreichst du uns: **Ruler GmbH** Seestrasse 4 3700 Spiez Schweiz # Auftragsverarbeitungsvereinbarung Source: https://tale.dev/de/legal/data-processing-agreement **Letzte Aktualisierung:** 11.06.2026 Diese Auftragsverarbeitungsvereinbarung ("AVV") ist ein Zusatz zum Service Agreement ("Vereinbarung") zwischen der Ruler GmbH ("Tale", "wir", "uns", "unsere") und der Entität oder Person, die die Vereinbarung akzeptiert ("Kunde", "du", "dein"). Sie gilt, soweit Tale personenbezogene Daten im Auftrag des Kunden im Rahmen der Leistungserbringung verarbeitet. Mit Abschluss der Vereinbarung schließt der Kunde diese AVV im eigenen Namen und, soweit nach anwendbarem Datenschutzrecht erforderlich, im Namen seiner autorisierten Nutzer und verbundenen Unternehmen ab. Diese AVV tritt mit dem Datum der Vereinbarung in Kraft. ## 1. Definitionen Begriffe in Großschreibung, die hier nicht definiert sind, haben die in der Vereinbarung festgelegten Bedeutungen. **"Anwendbares Datenschutzrecht"** — das Schweizer Bundesgesetz über den Datenschutz (FADP/nDSG) samt Verordnungen, die EU-Datenschutz-Grundverordnung (DSGVO) und jede weitere anwendbare Datenschutzgesetzgebung, jeweils in der aktuellen Fassung. **"Verantwortlicher"** — die Entität, die über Zwecke und Mittel der Verarbeitung personenbezogener Daten entscheidet. Für diese AVV ist der Kunde der Verantwortliche. **"Datenschutzvorfall"** — eine Verletzung der Sicherheit, die zur zufälligen oder widerrechtlichen Zerstörung, zum Verlust, zur Veränderung, zur unbefugten Offenlegung oder zum unbefugten Zugriff auf personenbezogene Daten führt, die Tale im Auftrag des Kunden verarbeitet. **"Betroffene Person"** — die identifizierte oder identifizierbare natürliche Person, auf die sich die personenbezogenen Daten beziehen. **"Personenbezogene Daten"** — alle Informationen über eine identifizierte oder identifizierbare natürliche Person, die Tale im Auftrag des Kunden im Rahmen der Leistungen verarbeitet. **"Verarbeitung"** — jeder Vorgang im Zusammenhang mit personenbezogenen Daten, ob automatisiert oder nicht. **"Auftragsverarbeiter"** — die Entität, die personenbezogene Daten im Auftrag des Verantwortlichen verarbeitet. Für diese AVV ist Tale der Auftragsverarbeiter. **"Unterauftragsverarbeiter"** — jede Dritt-Partei, die Tale für die Verarbeitung personenbezogener Daten im Auftrag des Kunden einsetzt. Die aktuelle Liste steht in **Anhang A**. ## 2. Umfang und Details der Verarbeitung ### 2.1 Rollen Der Kunde ist Verantwortlicher. Tale ist Auftragsverarbeiter. Tale verarbeitet personenbezogene Daten ausschließlich zur Bereitstellung und Pflege der Leistungen gemäß Vereinbarung und nach den dokumentierten Weisungen des Kunden. ### 2.2 Details der Verarbeitung | Element | Beschreibung | | -------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Zweck** | Bereitstellung der Tale-Plattform und verbundener Leistungen gemäß Vereinbarung, einschließlich KI-gestützter Workflow-Automatisierung, Konversations-Verwaltung und zugehöriger Betriebsfunktionen. Endpunkte und Datenflüsse sind in der öffentlichen [API-Dokumentation](https://platform.tale.dev/docs) beschrieben. | | **Art** | Speichern, Abrufen, Organisieren, Strukturieren, Berechnen, Übermitteln und Anzeigen von Daten, soweit zur Leistungserbringung erforderlich. | | **Kategorien Betroffener** | vom Kunden bestimmt; können Mitarbeitende, Endnutzer, Kunden, Auftragnehmer, Geschäftskontakte und weitere Personen umfassen, deren Daten der Kunde in die Leistungen einspeist. | | **Kategorien personenbezogener Daten** | vom Kunden bestimmt; können Namen, E-Mail-Adressen, Telefonnummern, Firmendaten, Nachrichteninhalte, Konversationsdaten, Workflow-Daten, Dokumente und weitere vom Kunden eingespeiste Daten umfassen. | | **Dauer** | die Laufzeit der Vereinbarung, zuzüglich einer Frist zur Rückgabe oder Löschung gemäß Abschnitt 13. | ### 2.3 Pflichten des Kunden Der Kunde: a) verfügt über eine gültige Rechtsgrundlage nach anwendbarem Datenschutzrecht für die Verarbeitung und für die Beauftragung von Tale; b) hat gegenüber den Betroffenen alle notwendigen Informationen bereitgestellt und alle notwendigen Einwilligungen oder Berechtigungen eingeholt; c) stellt sicher, dass seine Weisungen an Tale dem anwendbaren Datenschutzrecht entsprechen; d) ist allein für die Genauigkeit, Qualität und Rechtmäßigkeit der übermittelten personenbezogenen Daten verantwortlich. ## 3. Weisungen des Kunden Der Kunde weist Tale an, personenbezogene Daten in dem Umfang zu verarbeiten, der zur Leistungserbringung gemäß Vereinbarung erforderlich ist. Zusätzliche oder abweichende Weisungen erfordern eine schriftliche Vereinbarung. Kommt Tale zum Schluss, dass eine Weisung gegen anwendbares Datenschutzrecht verstößt, informiert Tale den Kunden unverzüglich und kann die betroffene Verarbeitung aussetzen, bis eine rechtmäßige Weisung vorliegt. ## 4. Pflichten von Tale als Auftragsverarbeiter Tale: a) verarbeitet personenbezogene Daten nur auf Grundlage dokumentierter Weisungen des Kunden — einschließlich dieser AVV und der Vereinbarung —, soweit nicht gesetzlich anders vorgeschrieben (in letzterem Fall informiert Tale den Kunden vor der Verarbeitung, sofern gesetzlich zulässig); b) stellt sicher, dass zur Verarbeitung berechtigte Personen einer Vertraulichkeitspflicht unterliegen; c) implementiert und pflegt die technischen und organisatorischen Maßnahmen gemäß Abschnitt 7; d) setzt keinen Unterauftragsverarbeiter ein, der nicht Abschnitt 6 entspricht; e) unterstützt den Kunden — unter Berücksichtigung der Art der Verarbeitung und der Tale verfügbaren Informationen — bei Anfragen Betroffener (Abschnitt 9), bei Datensicherheit, Meldung von Vorfällen, Datenschutz-Folgenabschätzungen und vorherigen Konsultationen mit Aufsichtsbehörden; f) löscht oder gibt nach Wahl des Kunden alle personenbezogenen Daten am Ende der Leistungserbringung zurück (Abschnitt 13); g) stellt dem Kunden alle Informationen bereit, die zum Nachweis der Einhaltung dieser AVV erforderlich sind, und wirkt an Audits mit (Abschnitt 10). ## 5. KI-Verarbeitung — keine Nutzung zum Training oder zur Verbesserung ### 5.1 Kein Training, kein Fine-Tuning, keine Modell-Verbesserung Tale nutzt personenbezogene Daten — einschließlich Prompts, Eingaben, Ausgaben, Embeddings, Audio-Payloads, Bildern oder daraus abgeleiteten Artefakten — nicht, um KI- oder Machine-Learning-Modelle zu trainieren, fein zu justieren, zu evaluieren, zu benchmarken oder anderweitig zu verbessern — weder eigene Modelle noch jene von Dritten. Personenbezogene Daten werden ausschließlich zur Erbringung der angeforderten Ausgabe für den konkreten Aufruf verarbeitet. ### 5.2 Pflichten der Unterauftragsverarbeiter zum Training Jeder in **Anhang A** aufgeführte KI-Unterauftragsverarbeiter ist — über die zwischen Tale und dem jeweiligen Anbieter geltenden Enterprise- oder API-Bedingungen — vertraglich verpflichtet, eingespeiste Kunden-Payloads nicht zum Training, Fine-Tuning oder zur Verbesserung seiner Modelle oder Dienste zu nutzen. Tale weist diese Bedingungen auf zumutbare schriftliche Anfrage gemäß Abschnitt 10 nach. ### 5.3 Opt-in — gesonderte schriftliche Vereinbarung erforderlich Die Abschnitte 5.1 und 5.2 können nur durch eine **gesonderte, beidseitig schriftlich unterzeichnete Vereinbarung** geändert werden, die (a) den Umfang der betroffenen personenbezogenen Daten, (b) den zulässigen Trainings- oder Verbesserungszweck, (c) die Dauer und (d) die geltenden Schutzmaßnahmen festlegt. Die fortgesetzte Nutzung der Leistungen, die Akzeptanz aktualisierter Bedingungen, Einstellungs-Schalter im Produkt oder jede sonstige Form impliziter Zustimmung gelten **nicht** als Opt-in. ## 6. Unterauftragsverarbeiter ### 6.1 Allgemeine Genehmigung Der Kunde erteilt Tale eine allgemeine schriftliche Genehmigung zum Einsatz von Unterauftragsverarbeitern. Die aktuelle Liste steht in **Anhang A** und wird unter [/de/legal/subprocessors](/de/legal/subprocessors) gespiegelt. ### 6.2 Benachrichtigung bei Änderungen Tale informiert den Kunden mindestens 30 Tage vor dem Einsatz eines neuen oder dem Austausch eines bestehenden Unterauftragsverarbeiters, indem Anhang A und die öffentliche Liste aktualisiert werden, und — wo der Kunde entsprechende Benachrichtigungen abonniert hat — per E-Mail. ### 6.3 Widerspruchsrecht Der Kunde kann einem neuen oder ersetzenden Unterauftragsverarbeiter innerhalb von 30 Tagen nach der Benachrichtigung schriftlich aus angemessenen Datenschutzgründen widersprechen. Tale bemüht sich mit zumutbarem wirtschaftlichen Aufwand um eine Alternative. Wird innerhalb von 30 Tagen nach dem Widerspruch keine Einigung erzielt, kann jede Partei die betroffenen Leistungen gemäß Vereinbarung kündigen. ### 6.4 Weitergegebene Pflichten und Haftung Tale auferlegt jedem Unterauftragsverarbeiter durch schriftliche Vereinbarung Datenschutzpflichten, die nicht hinter denen dieser AVV zurückbleiben — einschließlich der Trainings-Verbots-Pflicht aus Abschnitt 5. Tale haftet gegenüber dem Kunden uneingeschränkt für die Leistung jedes Unterauftragsverarbeiters. ## 7. Technische und organisatorische Maßnahmen ### 7.1 Sicherheitsmaßnahmen Tale implementiert und pflegt angemessene technische und organisatorische Maßnahmen zum Schutz personenbezogener Daten gegen unbefugte oder widerrechtliche Verarbeitung und gegen zufälligen Verlust, Zerstörung, Schädigung oder Offenlegung, darunter: a) Verschlüsselung bei Übertragung und Speicherung; b) Maßnahmen zur dauerhaften Gewährleistung von Vertraulichkeit, Integrität, Verfügbarkeit und Belastbarkeit der Verarbeitungssysteme und -dienste; c) Maßnahmen zur rechtzeitigen Wiederherstellung der Verfügbarkeit und des Zugangs zu Daten nach einem physischen oder technischen Vorfall; d) Zugriffskontrollen, die personenbezogene Daten nur autorisierten Personen nach dem Need-to-Know-Prinzip zugänglich machen; e) regelmäßige Tests, Bewertungen und Überprüfungen der Wirksamkeit der Maßnahmen; f) physische Sicherheitsmaßnahmen für Rechenzentren und Infrastruktur; g) Security-Awareness-Schulungen der Mitarbeitenden. ### 7.2 Zertifizierungen Tale hält ISO-27001- und SOC-2-Type-II-Zertifizierungen (oder gleichwertige Standards) aufrecht und weist diese auf zumutbare Anfrage nach. ### 7.3 Aktualisierungen Tale kann die Sicherheitsmaßnahmen von Zeit zu Zeit aktualisieren, sofern das Gesamtschutzniveau für personenbezogene Daten nicht wesentlich sinkt. ## 8. Meldung von Datenschutzvorfällen ### 8.1 Meldung an den Kunden Tale meldet dem Kunden jeden Datenschutzvorfall, der personenbezogene Daten betrifft, die im Auftrag des Kunden verarbeitet werden, unverzüglich und in jedem Fall innerhalb von 72 Stunden nach Kenntnisnahme. ### 8.2 Inhalt der Meldung Die Meldung enthält, soweit zum Zeitpunkt vernünftigerweise verfügbar: a) eine Beschreibung der Art des Vorfalls, soweit möglich einschließlich Kategorien und ungefährer Zahl der betroffenen Personen sowie der betroffenen Datensätze; b) die Kontaktdaten der Anlaufstelle von Tale für weitere Informationen; c) die wahrscheinlichen Folgen des Vorfalls; d) die ergriffenen oder vorgeschlagenen Maßnahmen zur Behebung, einschließlich Maßnahmen zur Minderung möglicher negativer Auswirkungen. ### 8.3 Kooperation Tale kooperiert mit dem Kunden und unternimmt zumutbare wirtschaftliche Schritte bei Untersuchung, Eindämmung und Behebung des Vorfalls. ### 8.4 Kein Schuldeingeständnis Eine Meldung nach diesem Abschnitt ist kein Schuldeingeständnis. Der Kunde ist allein dafür verantwortlich, zu bestimmen, ob ein Vorfall Meldepflichten nach anwendbarem Datenschutzrecht auslöst, und diese zu erfüllen. ## 9. Rechte Betroffener ### 9.1 Unterstützung Tale unterstützt den Kunden — unter Berücksichtigung der Art der Verarbeitung — mit angemessenen technischen und organisatorischen Maßnahmen bei der Beantwortung von Anfragen Betroffener zur Wahrnehmung ihrer Rechte nach anwendbarem Datenschutzrecht (Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit, Widerspruch). ### 9.2 Weiterleitung von Anfragen Erhält Tale eine Anfrage direkt von einer betroffenen Person zu Daten, die im Auftrag des Kunden verarbeitet werden, leitet Tale die Anfrage unverzüglich an den Kunden weiter und antwortet nicht direkt — es sei denn, der Kunde weist dies an oder geltendes Recht verlangt es. ### 9.3 Kosten Erfordert die Unterstützung bei Anfragen Betroffener einen erheblichen Aufwand, der über das vernünftigerweise zu Erwartende hinausgeht, kann Tale dem Kunden eine angemessene Gebühr entsprechend den Verwaltungskosten in Rechnung stellen. ## 10. Audits und Prüfungen ### 10.1 Audit-Berichte Tale stellt dem Kunden auf zumutbare Anfrage und nicht mehr als einmal jährlich Kopien relevanter Dritt-Audit-Berichte oder Zertifizierungen (z. B. SOC-2-Type-II-Berichte, ISO-27001-Zertifikate) zur Verfügung, um die Einhaltung dieser AVV zu belegen. ### 10.2 Zusätzliche Audits Hält der Kunde die nach Abschnitt 10.1 gelieferten Informationen vernünftigerweise für unzureichend, kann er ein zusätzliches Audit verlangen. Solche Audits: a) erfolgen auf Kosten des Kunden, es sei denn, das Audit deckt einen wesentlichen Verstoß von Tale auf; b) erfordern eine schriftliche Vorankündigung von mindestens 30 Tagen; c) finden während regulärer Geschäftszeiten und unter Minimierung der Beeinträchtigung des Tale-Betriebs statt; d) werden vom Kunden oder einem unabhängigen Dritt-Auditor durchgeführt, der kein Wettbewerber von Tale ist und angemessenen Vertraulichkeitspflichten unterliegt; e) sind im Umfang auf die Verarbeitung der personenbezogenen Daten des Kunden beschränkt. ### 10.3 Vertraulichkeit der Ergebnisse Audit-Berichte, Feststellungen und Informationen aus Audits gelten als vertrauliche Informationen von Tale und unterliegen den Vertraulichkeitsbestimmungen der Vereinbarung. ## 11. Internationale Datenübermittlung ### 11.1 Verarbeitungs-Standorte Tale hostet die Plattform und speichert personenbezogene Daten in der Schweiz für Schweizer Kunden und in der Europäischen Union für alle übrigen Kunden. KI-Aufrufe (LLM-Inferenz, Audio- und Bild-Verarbeitung) werden für alle Kunden in der Europäischen Union bzw. im EWR verarbeitet — kein eingesetzter KI-Unterauftragsverarbeiter betreibt eine Schweizer Verarbeitungs-Region. Für Schweizer Kunden stützt sich diese Verarbeitung auf die Angemessenheit der EU-/EWR-Staaten nach Art. 16 FADP (Staatenliste des Bundesrats). Der Ort der Verarbeitung pro Unterauftragsverarbeiter steht in **Anhang A**. Deployt der Kunde Tale auf eigener Infrastruktur (on-premises oder Private Cloud), bestimmt der Kunde die Verarbeitungs-Standorte. ### 11.2 Übermittlung in angemessene Länder Tale kann personenbezogene Daten in Länder übermitteln, die der Schweizer Bundesrat nach Art. 16 FADP oder die Europäische Kommission nach Art. 45 DSGVO als Länder mit angemessenem Schutzniveau anerkannt hat. ### 11.3 Schutz bei sonstigen Übermittlungen Tale übermittelt personenbezogene Daten nicht in Länder ohne angemessenes Schutzniveau, es sei denn, es bestehen geeignete Schutzmaßnahmen — wie von der Europäischen Kommission genehmigte Standardvertragsklauseln oder vom EDÖB anerkannte Mechanismen. ### 11.4 Transparenz Die aktuellen Verarbeitungs-Standorte und etwaigen Transfer-Mechanismen sind in **Anhang A** aufgeführt. ## 12. Vertraulichkeit Tale behandelt alle unter dieser AVV verarbeiteten personenbezogenen Daten als vertrauliche Informationen. Diese Pflicht besteht auch nach Beendigung dieser AVV und der Vereinbarung fort. Tale stellt sicher, dass alle Personen mit Zugriff einer angemessenen Vertraulichkeitspflicht unterliegen. ## 13. Aufbewahrung und Löschung ### 13.1 Während der Vereinbarung Tale bewahrt personenbezogene Daten für die Laufzeit der Vereinbarung und gemäß den dokumentierten Weisungen des Kunden auf. ### 13.2 Bei Beendigung Bei Beendigung oder Ablauf der Vereinbarung wird Tale auf schriftlichen Wunsch des Kunden: a) alle personenbezogenen Daten in einem gängigen, maschinenlesbaren Format an den Kunden zurückgeben oder b) alle personenbezogenen Daten sicher löschen und dies schriftlich bestätigen. Stellt der Kunde innerhalb von 30 Tagen nach Beendigung keinen schriftlichen Antrag, löscht Tale alle personenbezogenen Daten innerhalb von 90 Tagen nach Beendigung. ### 13.3 Gesetzliche Aufbewahrung Verlangt geltendes Recht von Tale, bestimmte personenbezogene Daten über die Beendigung hinaus aufzubewahren, informiert Tale den Kunden, beschränkt die weitere Verarbeitung auf das gesetzlich Erforderliche und schützt die Daten weiterhin gemäß dieser AVV. ## 14. Haftung Die Haftung aus dieser AVV unterliegt den Haftungsbeschränkungen und -ausschlüssen der Vereinbarung, soweit nach anwendbarem Datenschutzrecht zulässig. Weder diese AVV noch die Vereinbarung schließen die Haftung einer Partei für Schäden aus vorsätzlichem oder grob fahrlässigem Verstoß gegen anwendbares Datenschutzrecht aus oder beschränken sie. ## 15. Verhältnis zur Vereinbarung ### 15.1 Vorrang Bei Widersprüchen zwischen dieser AVV und der Vereinbarung gehen die Bestimmungen dieser AVV hinsichtlich der Verarbeitung personenbezogener Daten vor. ### 15.2 Einbeziehung Diese AVV ist Bestandteil der Vereinbarung. Alle übrigen Bestimmungen der Vereinbarung bleiben vollumfänglich bestehen. ### 15.3 Salvatorische Klausel Ist eine Bestimmung dieser AVV ungültig oder nicht durchsetzbar, bleiben die übrigen vollumfänglich bestehen. ### 15.4 Änderungen Tale kann diese AVV von Zeit zu Zeit aktualisieren, um Änderungen der Verarbeitungspraktiken oder des anwendbaren Datenschutzrechts abzubilden. Wesentliche Änderungen werden dem Kunden vorab mitgeteilt. Die fortgesetzte Nutzung der Leistungen nach Inkrafttreten der Änderungen gilt als Annahme der aktualisierten AVV. Änderungen, die Abschnitt 5 (KI-Verarbeitung — keine Nutzung zum Training oder zur Verbesserung) betreffen, erfordern eine gesonderte schriftliche Vereinbarung gemäß Abschnitt 5.3 und treten nie durch fortgesetzte Nutzung in Kraft. ## 16. Anwendbares Recht und Gerichtsstand Diese AVV unterliegt dem materiellen Recht der Schweiz, unter Ausschluss der Kollisionsnormen und des UN-Übereinkommens über Verträge über den internationalen Warenkauf (CISG). Streitigkeiten aus oder im Zusammenhang mit dieser AVV unterliegen der ausschließlichen Zuständigkeit der zuständigen Gerichte des Kantons Bern, Schweiz, soweit nicht zwingendes Recht entgegensteht. ## 17. Kontakt Bei Fragen zu dieser AVV oder zu Verarbeitungstätigkeiten erreichst du uns über unser [Kontaktformular](https://tale.dev/contact). **Ruler GmbH** Seestrasse 4 3700 Spiez Schweiz --- ## Anhang A — Unterauftragsverarbeiter Dieser Anhang listet die Dritt-Parteien, die Tale zur Verarbeitung personenbezogener Daten im Auftrag des Kunden für Tale Cloud einsetzt — jeweils mit Firma, ladungsfähiger Adresse, Art der Leistung und Ort der Verarbeitung. Self-hosted-Deployments werden vom Kunden betrieben; deren Unterauftragsverarbeiter-Liste ist der vom Kunden zusammengestellte Stack. ### Aktuelle Unterauftragsverarbeiter Jeder Name verlinkt auf die öffentlich zugängliche AVV (oder gleichwertige Bedingungen) des jeweiligen Anbieters; Zertifizierungen und Trust-Seiten stehen unter den Tabellen. Das Plattform-Hosting folgt der Datenresidenz-Wahl des Kunden: Tabelle A.1 gilt für Kunden in der EU/im EWR, Tabelle A.2 für Schweizer Kunden. KI-Aufrufe (LLM-Inferenz, Audio- und Bild-Verarbeitung) werden für alle Kunden in der EU/im EWR verarbeitet; sie verlassen die EU/den EWR nicht und werden zu keinem Zeitpunkt in Drittstaaten wie den USA verarbeitet. #### A.1 — Kunden in der EU/im EWR | Unterauftragsverarbeiter (Firma) | Ladungsfähige Adresse | Art der Leistung | Ort der Verarbeitung | | ----------------------------------------------------- | ----------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | | [Akenes SA (Exoscale)](https://www.exoscale.com/dpa/) | Boulevard de Grancy 19A, 1006 Lausanne, Schweiz | Bereitstellung der Cloud-Infrastruktur (Rechenzentrum): Hosting der Tale-Cloud-Plattform — VMs, Container-Runtime, Datenbank und Storage. | Deutschland (Region Frankfurt). | | [OpenRouter, Inc.](https://openrouter.ai/privacy) | 169 Madison Avenue, New York, NY 10016, USA | Bereitstellung der LLM-Inferenz (Chat, Vision, Embeddings), der Audio-Verarbeitung (Speech-to-Text und Text-to-Speech) sowie der Bild-Verarbeitung und -Generierung. | Europäische Union (In-Region-Routing über `eu.openrouter.ai`: Prompts und Antworten werden ausschließlich innerhalb der EU verarbeitet). | #### A.2 — Schweizer Kunden | Unterauftragsverarbeiter (Firma) | Ladungsfähige Adresse | Art der Leistung | Ort der Verarbeitung | | ----------------------------------------------------- | ----------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------- | | [Akenes SA (Exoscale)](https://www.exoscale.com/dpa/) | Boulevard de Grancy 19A, 1006 Lausanne, Schweiz | Bereitstellung der Cloud-Infrastruktur (Rechenzentrum): Hosting der Tale-Cloud-Plattform — VMs, Container-Runtime, Datenbank und Storage. | Schweiz (Zürich; Disaster-Recovery-Replikat in Genf). | | [OpenRouter, Inc.](https://openrouter.ai/privacy) | 169 Madison Avenue, New York, NY 10016, USA | Bereitstellung der LLM-Inferenz (Chat, Vision, Embeddings), der Audio-Verarbeitung (Speech-to-Text und Text-to-Speech) sowie der Bild-Verarbeitung und -Generierung. | Europäische Union (In-Region-Routing über `eu.openrouter.ai`). | Für Schweizer Kunden bleibt das Plattform-Hosting vollständig in der Schweiz. Der KI-Unterauftragsverarbeiter bietet keine Schweizer Verarbeitungs-Region an; diese Aufrufe werden in der EU/im EWR verarbeitet. Alle EU-/EWR-Staaten stehen auf der Staatenliste des Bundesrats nach Art. 16 FADP — die Übermittlung erfordert keine zusätzlichen Garantien. ### Datenkategorien und Trainings-Verbot | Unterauftragsverarbeiter | Datenkategorien | Training auf Kundendaten | | ------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------ | | Akenes SA (Exoscale) | Anwendungs-Daten in Transit und at rest auf der gehosteten Runtime und Storage. | Nein (nur Infrastruktur; kein KI-Training). | | OpenRouter, Inc. | Prompts und Antworten des jeweiligen Inferenz-Aufrufs; Audio-Payloads und transkribierter oder synthetisierter Text; Bild-Prompts und generierte Bilder. | Nein — vertraglich untersagt (Enterprise-Bedingungen). | ### Zertifizierungen und Trust-Seiten Jeder Unterauftragsverarbeiter führt eigene Sicherheitszertifizierungen und veröffentlicht sie auf seiner Trust-Seite: - **Akenes SA (Exoscale)** — ISO/IEC 27001:2022, ISO/IEC 27017, ISO/IEC 27018, SOC 2 Type II, PCI DSS v4.0, HDS, BSI C5, TISAX. Trust-Seite: [exoscale.com/compliance](https://www.exoscale.com/compliance/). - **OpenRouter, Inc.** — SOC 2; Nachweise über das zugangsbeschränkte Trust-Portal [trust.openrouter.ai](https://trust.openrouter.ai). Für Übermittlungen außerhalb der EU/des EWR gelten EU-Standardvertragsklauseln. ### Hinweise - Der KI-Unterauftragsverarbeiter wird nur eingesetzt, wenn eine KI-Funktion einen Aufruf an ihn routet. Eine Org, die weder LLM-Inferenz, Audio noch Bild-Funktionen nutzt, sendet keine Daten an OpenRouter, Inc. - Modell-Anbieter, die über OpenRouter erreichbar sind (etwa Anthropic, Google, Meta, Mistral, OpenAI), sind Upstream-Anbieter von OpenRouter und keine direkten Unterauftragsverarbeiter von Tale. Die Standard-Audio-Modelle — Whisper für Speech-to-Text und gpt-4o-mini-tts für Text-to-Speech — sind auf diesem Weg erreichte OpenAI-Modelle. Sie unterliegen den eigenen Vertragsbedingungen von OpenRouter, die das Training auf gerouteten Payloads untersagen; das In-Region-Routing beschränkt jeden Aufruf auf Anbieter-Endpunkte innerhalb der EU. - Jeder Unterauftragsverarbeiter setzt eigene Unter-Auftragsverarbeiter ein (Cloud-Hosting, CDN, Secret-Stores). Diese Listen sind öffentlich auf den oben verlinkten Trust-Seiten der Anbieter verfügbar; Tale verfolgt wesentliche Änderungen über denselben 30-Tage-Hinweis-Mechanismus aus Abschnitt 6.2. - Die Middleware, der Anwendungs-State und die unterstützende Infrastruktur von Tale Cloud laufen auf Exoscale in der vom Kunden gewählten Region. Jeder KI-Aufruf wird an die EU-/EWR-Region des jeweiligen Anbieters geroutet. # Technische und organisatorische Maßnahmen Source: https://tale.dev/de/legal/technical-organizational-measures **Letzte Aktualisierung:** 01.05.2026 Dieses Dokument beschreibt die technischen und organisatorischen Maßnahmen ("TOM"), die die Ruler GmbH ("Tale") zum Schutz personenbezogener Daten umsetzt, die im Auftrag ihrer Kunden verarbeitet werden, wie in Abschnitt 7 der [Auftragsverarbeitungsvereinbarung](/de/legal/data-processing-agreement) referenziert. Es gilt für Tale Cloud. Self-Hosted-Deployments werden vom Kunden betrieben; dort bestimmt und setzt der Kunde eigene Maßnahmen um, während Tale gehärtete Defaults und dokumentierte Kontrollen bereitstellt. Tale überprüft diese Maßnahmen mindestens einmal jährlich und kann sie aktualisieren, sofern das Gesamtniveau des Schutzes personenbezogener Daten nicht wesentlich abnimmt. ## 1. Vertraulichkeit ### 1.1 Zutrittskontrolle — physisch Tale betreibt keine eigenen Rechenzentren. Die physische Infrastruktur wird durch die in Anhang A der [Auftragsverarbeitungsvereinbarung](/de/legal/data-processing-agreement) gelisteten Unterauftragsverarbeiter bereitgestellt. Jeder Anbieter ist nach ISO/IEC 27001 (oder gleichwertig) zertifiziert und betreibt Zutrittskontrollen einschließlich 24/7-Personal, Videoüberwachung, Badge- oder biometrischem Zugang, Schleusen und Besucherprotokollen. Nachweise sind auf Anfrage über die Trust-Seiten der Unterauftragsverarbeiter verfügbar. ### 1.2 Zugangskontrolle — Systeme a) Multi-Faktor-Authentifizierung ist für jeden Tale-Mitarbeitenden mit Produktionszugang obligatorisch. b) Zugang zu Produktionssystemen wird nach dem Least-Privilege- und Need-to-Know-Prinzip vergeben und mindestens vierteljährlich überprüft. c) Personalzugang wird über einen zentralen Identitätsanbieter bereitgestellt und innerhalb eines Werktags nach Rollenwechsel oder Austritt entzogen. d) Privilegierte Operationen erfordern ein genehmigtes Change-Ticket und werden mit Akteur, Aktion und Zeitstempel protokolliert. e) Der Kundenzugang zur Plattform wird per E-Mail und Passwort (mit optionalem WebAuthn- oder TOTP-Zweitfaktor) oder per SSO (OIDC) authentifiziert, wenn der Kunde dies konfiguriert hat. ### 1.3 Zugriffskontrolle — Daten a) Personenbezogene Daten werden auf Anwendungsebene mandantenisoliert; jede Datenbankabfrage ist auf die anfragende Organisation eingegrenzt. b) Produktionsdaten werden nie in Nicht-Produktionsumgebungen kopiert. Für Entwicklung und Tests werden synthetische oder anonymisierte Daten verwendet. c) Vom Kunden ausgestellte API-Keys werden im Ruhezustand gehasht und sind über die Admin-Oberfläche widerrufbar. ### 1.4 Trennungskontrolle a) Jede Kundenorganisation ist ein separater logischer Mandant; Mandantenkennungen sind in jeder Zeile der Datenbank vorhanden und werden auf Abfrageebene durchgesetzt. b) Backups werden pro Mandantenschlüssel verschlüsselt; eine Wiederherstellung in einen anderen Mandanten wird auf Ebene der Schlüsselverwaltung verhindert. c) Workloads laufen in isolierten Containern; Netzwerkrichtlinien verhindern mandantenübergreifenden Verkehr. ### 1.5 Pseudonymisierung und Verschlüsselung a) Personenbezogene Daten werden während der Übertragung mit TLS 1.2 oder höher verschlüsselt, mit erzwungenem HSTS auf jedem öffentlichen Endpunkt. b) Personenbezogene Daten werden im Ruhezustand mit AES-256 (oder gleichwertig) auf Speicherebene verschlüsselt. c) Verschlüsselungsschlüssel werden vom Key Management Service des Cloud-Unterauftragsverarbeiters verwaltet; eine Schlüsselrotation erfolgt mindestens einmal jährlich. d) Wo Pseudonymisierung ohne Funktionsverlust möglich ist, bevorzugt Tale pseudonyme Kennungen gegenüber Klartextidentifikatoren in Logs und Analysen. ## 2. Integrität ### 2.1 Weitergabekontrolle a) Sämtlicher Eingangs- und Ausgangsverkehr über öffentliche Netze wird während der Übertragung verschlüsselt. b) Interner Service-zu-Service-Verkehr verwendet authentifiziertes mTLS oder signierte Tokens. c) Aufrufe an KI-Unterauftragsverarbeiter werden in eine Region geroutet, die der Datenresidenzwahl des Kunden entspricht (Schweiz oder EU); das Routing wird serverseitig durchgesetzt. ### 2.2 Eingabekontrolle a) Jede administrative Aktion in der Plattform wird in einem unveränderlichen Audit-Log mit Akteur, betroffener Ressource und Zeitstempel erfasst. b) Audit-Logs werden für die vom Kunden konfigurierte Dauer aufbewahrt (Default 365 Tage, ohne Obergrenze) und werden durch Snapshot-Wiederherstellungen nicht verändert. c) System-Logs von Infrastrukturkomponenten werden 90 Tage aufbewahrt und sind nur für autorisiertes Tale-Personal zugänglich. ## 3. Verfügbarkeit und Belastbarkeit ### 3.1 Verfügbarkeitskontrolle a) Anwendungsdienste laufen in redundanten Konfigurationen hinter Load Balancern, mit automatischem Failover zwischen Verfügbarkeitszonen innerhalb der gewählten Region. b) Das Monitoring deckt Verfügbarkeit, Fehlerraten, Latenz und Queue-Tiefe ab; On-Call-Engineers werden bei Schwellwertüberschreitungen alarmiert. c) Die Statusseite von Tale veröffentlicht Vorfallsbenachrichtigungen und historische Verfügbarkeitsdaten. ### 3.2 Wiederherstellbarkeit a) Tale erstellt täglich Snapshots der Anwendungsdatenbanken und stündlich des Objektspeichers. Snapshots werden im Ruhezustand mit vom Cloud-Unterauftragsverarbeiter verwalteten Schlüsseln verschlüsselt. b) Eine Disaster-Recovery-Replik wird innerhalb der vom Kunden gewählten Region vorgehalten (Genf für die Schweiz, Dublin für die Europäische Union). c) Wiederherstellungen aus Snapshots werden vom Kunden über den Support angestoßen und erfüllen das im Service Agreement genannte Recovery Time Objective. d) Die Backup-Integrität wird mindestens vierteljährlich durch Wiederherstellung eines repräsentativen Snapshots in eine isolierte Umgebung verifiziert. ### 3.3 Kapazität und Leistung a) Produktionsumgebungen sind auf die erwartete Spitzenlast dimensioniert und werden mit wachsender Auslastung horizontal skaliert. b) Rate-Limits und Back-Pressure-Mechanismen verhindern, dass ein einzelner Mandant den Dienst für andere beeinträchtigt. ## 4. Verfahren zur regelmäßigen Überprüfung, Bewertung und Evaluierung ### 4.1 Schwachstellenmanagement a) Tale führt bei jedem Commit automatisiertes Dependency-Scanning durch und verfolgt Sicherheits­hinweise zu allen Produktions­abhängigkeiten. b) Sicherheits­patches werden innerhalb der in Tales Schwachstellen­management­richtlinie vorgegebenen Fristen eingespielt: kritisch innerhalb von 7 Tagen, hoch innerhalb von 30 Tagen, mittel innerhalb von 90 Tagen. c) Container-Images werden mindestens monatlich neu gebaut, um vorgelagerte Sicherheits­aktualisierungen aufzunehmen. ### 4.2 Penetrationstests a) Tale beauftragt mindestens jährlich einen externen Penetrationstest. Befunde werden nach Schweregrad behoben, und ein Attestschreiben ist Kunden auf Anfrage unter NDA über den Support verfügbar. ### 4.3 Audits und Zertifizierungen a) Tale unterhält für Tale Cloud Zertifizierungen nach ISO/IEC 27001 und SOC 2 Type II (oder gleichwertige Standards). b) Kunden können Kopien des aktuellen SOC-2-Type-II-Berichts und des ISO-27001-Zertifikats beim Support anfordern; beide werden unter NDA ausgehändigt. ### 4.4 Interne Überprüfung a) Das Security-Team überprüft Zugriffsprotokolle, Konfigurationsabweichungen und Vorfallsmuster fortlaufend wöchentlich. b) Das Privacy-Team überprüft die Bearbeitung von Betroffenenanfragen und das Aufbewahrungs­verhalten mindestens vierteljährlich. c) Wesentliche Befunde aus jeder Überprüfung fließen in einen verfolgten Behebungs-Backlog mit Verantwortlichen und Fristen zurück. ## 5. Vorfallreaktion ### 5.1 Vorfallserkennung a) Produktionssysteme senden Telemetrie an eine zentrale Logging- und Monitoring-Plattform. b) Automatisierte Alarme alarmieren den diensthabenden Engineer bei Anomalien einschließlich erhöhter Fehlerraten, unbefugter Zugriffsversuche und ungewöhnlicher Daten-Egress-Muster. ### 5.2 Verfahren zur Vorfallreaktion a) Tale unterhält ein dokumentiertes Verfahren zur Vorfallreaktion, das Erkennung, Eindämmung, Beseitigung, Wiederherstellung und Nachbereitung abdeckt. b) Das Verfahren wird mindestens einmal jährlich durch eine Tabletop-Übung oder Live-Drill getestet. c) Schweregrade und Eskalationspfade sind vorab definiert; der diensthabende Engineer ist befugt, ohne Verzögerung an die Geschäftsleitung zu eskalieren. ### 5.3 Kundenbenachrichtigung a) Tale benachrichtigt betroffene Kunden unverzüglich, in jedem Fall innerhalb von 72 Stunden nach Kenntniserlangung eines Datenschutzvorfalls, der ihre personenbezogenen Daten betrifft, wie in Abschnitt 8 der [Auftragsverarbeitungsvereinbarung](/de/legal/data-processing-agreement) festgelegt. b) Benachrichtigungen enthalten die nach anwendbarem Datenschutzrecht erforderlichen Informationen: Art des Vorfalls, betroffene Kategorien und ungefähre Zahlen, voraussichtliche Folgen sowie Maßnahmen zur Behebung. ## 6. Personal ### 6.1 Vertraulichkeit a) Jeder Tale-Mitarbeitende, Auftragnehmer und Berater unterzeichnet eine schriftliche Vertraulichkeitsvereinbarung, die personenbezogene Daten, Quellcode und Kundeninformationen abdeckt. Die Verpflichtung überdauert das Ende der Beauftragung. ### 6.2 Hintergrundprüfungen a) Hintergrundprüfungen werden bei Tale-Mitarbeitenden mit Produktionszugang durchgeführt, soweit nach lokalem Recht zulässig. ### 6.3 Schulungen a) Neue Mitarbeitende absolvieren innerhalb der ersten 30 Tage Schulungen zu Sicherheit und Datenschutz. b) Sämtliches Personal absolviert mindestens jährlich Auffrischungsschulungen, darunter Themen wie Phishing-Sensibilisierung, sichere Entwicklung und Datenumgang. ### 6.4 Offboarding a) Zugänge werden innerhalb eines Werktags nach Austritt oder Rollenwechsel entzogen. b) Geräte werden gelöscht und eingezogen; physische Zugangsmittel werden zurückgegeben und deaktiviert. ## 7. Verwaltung von Unterauftragsverarbeitern ### 7.1 Auswahl a) Unterauftragsverarbeiter werden nach einer Sicherheits- und Datenschutzprüfung ausgewählt, die ihre Zertifizierungen, Datenschutzverpflichtungen und Verarbeitungsstandorte abdeckt. ### 7.2 Vertragliche Pflichten a) Jeder Unterauftragsverarbeiter ist vertraglich — durch schriftliche Vereinbarung — an Datenschutzpflichten gebunden, die nicht weniger schützend sind als die in der [Auftragsverarbeitungsvereinbarung](/de/legal/data-processing-agreement) festgelegten, einschließlich der Nicht-Training-Verpflichtung in Abschnitt 5. ### 7.3 Laufende Überprüfung a) Zertifizierungen und Auditberichte von Unterauftragsverarbeitern werden mindestens jährlich überprüft. b) Wesentliche Änderungen an der Sicherheits- und Datenschutz­position eines Unterauftragsverarbeiters lösen eine Benachrichtigung an Kunden über den 30-Tage-Mechanismus aus Abschnitt 6.2 der AVV aus. ## 8. Datenminimierung, Aufbewahrung und Löschung ### 8.1 Datenminimierung a) Die Plattform erhebt nur die personenbezogenen Daten, die zur Bereitstellung der angeforderten Funktionalität erforderlich sind. b) Kunden steuern selbst, welche Daten sie übermitteln; Tale reichert vom Kunden übermittelte Daten ohne ausdrückliche Einwilligung nicht mit Drittquellen an. ### 8.2 Aufbewahrung a) Aufbewahrungs­fristen für jede Datenkategorie sind in Tales [Datenschutzerklärung](https://tale.dev/de/legal/privacy-policy) und in der produktinternen Aufbewahrungs­konfiguration dokumentiert. b) Mindestaufbewahrungs­fristen für Audit-Logs werden vom Kunden konfiguriert; der Plattform-Default beträgt 365 Tage ohne Obergrenze. ### 8.3 Löschung a) Bei Beendigung der Vereinbarung werden personenbezogene Daten gemäß Abschnitt 13 der [Auftragsverarbeitungsvereinbarung](/de/legal/data-processing-agreement) zurückgegeben oder gelöscht. b) Die Löschung erstreckt sich auf jeden Speicher, der die Daten enthält, einschließlich Objektspeicher und Backups (letzteres durch Schlüsselzerstörung innerhalb des Backup-Aufbewahrungs­fensters). c) Kunden können die Löschung einzelner Betroffener über den produktinternen Datenschutz-Anfrage-Workflow auslösen. ## 9. Governance ### 9.1 Richtlinien a) Tale unterhält schriftliche Informations­sicherheits- und Datenschutz­richtlinien, die mindestens jährlich überprüft werden. b) Richtlinien­änderungen werden allen Mitarbeitenden mitgeteilt; wesentliche Änderungen gehen mit verpflichtenden Schulungen einher. ### 9.2 Rollen und Verantwortlichkeiten a) Tale benennt eine Person, die für Informations­sicherheit verantwortlich ist, und eine Person, die für Datenschutz verantwortlich ist. Beide berichten an die Geschäftsleitung. b) Ihre Kontaktadressen sind `security@tale.dev` und `privacy@tale.dev`. ### 9.3 Risikomanagement a) Tale unterhält ein Risikoregister, das technische, organisatorische und rechtliche Risiken abdeckt. b) Risiken werden mindestens vierteljährlich und nach jedem wesentlichen Vorfall überprüft, wobei Mitigationen bis zum Abschluss verfolgt werden. ## 10. Kontakt Für Fragen zu diesen TOMs oder zur Anforderung von Audit-Nachweisen kontaktiere uns über unser [Kontaktformular](https://tale.dev/de/contact). **Ruler GmbH** Seestrasse 4 3700 Spiez Schweiz # Personalisierung — Datenschutzhinweis Source: https://tale.dev/de/legal/personalization **Letzte Aktualisierung:** 27.09.2026 ## 1. Die Zusage Die Personalisierungsschicht von Tale — deine benutzerdefinierten Anweisungen — basiert auf einer einzigen Zusage: > **Innerhalb von Tale kann kein anderer Nutzer — auch nicht die Admins deiner Organisation — deine benutzerdefinierten Anweisungen über eine Oberfläche oder API einsehen. Benutzerdefinierte Anweisungen sind standardmäßig AUS und gelten erst, wenn du sie unter Einstellungen › Personalisierung einschaltest oder wenn ein Admin sie für deine Organisation standardmäßig einschaltet und du sie nicht selbst ausgeschaltet hast.** Diese Seite dokumentiert, was diese Zusage abdeckt und was nicht. Fünf Einschränkungen sind dem Betrieb eines KI-Dienstes auf einem fremden Modell und auf einer Datenbank, die jemand betreiben muss, inhärent und können durch Tales Code allein nicht beseitigt werden. ## 2. Einschränkungen aus dem LLM-Stack ### 2.1 Deine benutzerdefinierten Anweisungen gehen bei jedem Chat-Turn an deinen konfigurierten LLM-Anbieter Wenn du eine Chat-Nachricht sendest und benutzerdefinierte Anweisungen für dich gelten, werden sie in den System-Prompt aufgenommen, der an das von deiner Organisation konfigurierte Upstream-LLM geht (OpenAI, Anthropic, Google, Azure, dein selbst gehostetes Modell usw.). Damit unterliegen sie den Aufbewahrungs- und Missbrauchskontrollbedingungen dieses Anbieters. Die meisten großen Hosted-Anbieter speichern Ein- und Ausgaben zur Missbrauchskontrolle für einen begrenzten Zeitraum (üblicherweise 7–30 Tage, Stand Mitte 2026) und bieten Zero-Data-Retention oder vergleichbare Programme für qualifizierte Enterprise-Kunden an. Dauern und Voraussetzungen ändern sich häufig — maßgeblich ist der Vertrag, den deine Organisation mit dem Anbieter hat, sowie die jeweils veröffentlichte Anbieter-Richtlinie: - Anthropic — [Datenschutzerklärung](https://www.anthropic.com/legal/privacy) · [FAQ zur Datenaufbewahrung](https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data) - OpenAI — [API Data Usage Policies](https://openai.com/policies/api-data-usage-policies/) - Google Vertex AI / Gemini — [Data Governance für generative KI](https://cloud.google.com/vertex-ai/generative-ai/docs/data-governance) - Azure OpenAI / Microsoft Foundry — [Daten, Datenschutz & Sicherheit](https://learn.microsoft.com/en-us/azure/ai-foundry/responsible-ai/openai/data-privacy) · [Missbrauchskontrolle](https://learn.microsoft.com/en-us/azure/ai-foundry/openai/concepts/abuse-monitoring) Für selbst gehostete Modelle oder benutzerdefinierte OpenAI-kompatible Endpunkte (Ollama, vLLM, interne Gateways usw.) gilt keine Drittanbieter-Aufbewahrung — die Aufbewahrung wird vollständig vom Betreiber dieses Endpunkts bestimmt. Sobald deine Anweisungen gesendet wurden, **kann Tale sie nicht zurückholen**. Wenn du sie änderst oder entfernst, enthalten künftige Anfragen den neuen Stand, aber bereits gesendete Kopien beim Anbieter unterliegen dessen Aufbewahrungsplan. ### 2.2 Self-Hosting: Der Betreiber des Deployments kann Rohdaten lesen Tale speichert deine benutzerdefinierten Anweisungen in der Postgres-Datenbank deines Deployments, in der Tabelle `app.user_preferences`. Wer in deinem Deployment Zugriff auf die Datenbank oder ihre Backups hat, kann diese Zeilen direkt lesen — Tales rollenbasierte Admin-Sperre („Admins können keine Inhalte sehen“) **gilt nicht auf Datenbankebene**. Beim Self-Hosting solltest du davon ausgehen, dass deine Datenbankbetreiber Zugriff auf alle Personalisierungsinhalte haben. SOC-2- und ISO-Kontrollen für DB-Zugriff liegen in deiner Verantwortung. ### 2.3 Assistenten-Antworten können deine benutzerdefinierten Anweisungen zitieren oder paraphrasieren Die Antwort des Modells kann deine benutzerdefinierten Anweisungen wörtlich oder paraphrasiert wiedergeben. Diese Antwort wird dann in deinem Chat gespeichert und folgt den **Sichtbarkeitsregeln des Chats**, nicht den Regeln, die deine Anweisungen schützen: Teilst du den Chat, enthält die geteilte Kopie auch diese Antwort. Wenn du deine Anweisungen änderst oder entfernst, werden vergangene Antworten nicht rückwirkend geschwärzt. ### 2.4 Datenbank- und Server-Logs Tales Anwendungscode hält deine benutzerdefinierten Anweisungen aus den eigenen Logs und Fehlerberichten heraus. Der Datenbankserver und die Infrastruktur drumherum führen jedoch eigene Logs: Schaltet dein Betreiber in Postgres das Statement-Logging ein, kann der gespeicherte Text dort landen. Diese Logs kann Tale nicht schwärzen. ### 2.5 Missbrauchskontrolle der Anbieter Große LLM-Anbieter führen automatische Missbrauchserkennung über die empfangenen Eingaben durch. Als verdächtig markierte Inhalte können vom Missbrauchsteam des Anbieters überprüft werden. Sofern verfügbar, kann mit Zero-Data-Retention-Endpunkten (ZDR) ausgestiegen werden. Personalisierungs-Anfragen unterscheiden sich diesbezüglich nicht von anderen Anfragen. ## 3. Was Tale durchsetzt - **Standardmäßig aus.** Ohne Organisations-Standard und ohne eigene Wahl werden benutzerdefinierte Anweisungen nie an das Modell gesendet. Leere Anweisungen gelten als nicht vorhanden, auch wenn die Funktion eingeschaltet ist. - **Zwei Ebenen.** Ob deine benutzerdefinierten Anweisungen gelten, entscheiden zwei Einstellungen: - **Organisations-Standard** — von Admins gesteuert unter Einstellungen › Richtlinien › Richtlinien & Limits. Ist er eingeschaltet, sind die Anweisungen für Mitglieder standardmäßig eingeschaltet, sonst ausgeschaltet. - **Deine Wahl** — schaltest du sie unter Einstellungen › Personalisierung selbst ein oder aus, hat deine Wahl in beide Richtungen Vorrang vor dem Organisations-Standard. Die Seite zeigt dir, ob du dem Organisations-Standard folgst oder ihn überschreibst. - **Kein Admin-Bypass.** Auch die Admin-Rolle verschafft keinen Zugriff auf die Zeile eines anderen Nutzers. Jeder Lese- und Schreibzugriff erreicht nur die eigene Zeile der angemeldeten Person und prüft die Mitgliedschaft bei jeder Anfrage neu, damit ein bereits entfernter Nutzer mit noch gültiger Sitzung diese Zeile nicht mehr lesen kann. - **Ausschalten löscht nichts.** Schaltest du benutzerdefinierte Anweisungen aus, werden sie nicht mehr gesendet, der Text bleibt aber gespeichert und ist wieder da, sobald du sie einschaltest. Um ihn zu entfernen, leere das Feld und speichere; frühere Fassungen bewahrt Tale nicht auf. - **Endgültige Löschung per Kaskade.** Das Entfernen eines Nutzers aus einer Organisation, das Löschen der Organisation oder die Ausführung einer Löschungsanfrage für diesen Nutzer (von einem Admin eingereicht unter Einstellungen › Richtlinien › Anfragen betroffener Personen) löscht im selben Vorgang die Präferenzen des Nutzers in dieser Organisation endgültig, benutzerdefinierte Anweisungen eingeschlossen. Ein aktiver Legal Hold auf dem Nutzer oder auf der ganzen Organisation blockiert alle drei Vorgänge, bis er aufgehoben ist. Das Audit-Log hält jeden dieser Vorgänge fest, aber nie den Text der Anweisungen. Das eigene Konto zu löschen ist noch nicht möglich; sobald es geht, löscht das diese Zeilen ebenfalls. ## 4. AVV-Anhang (Entwurf) Kunden, die eine Erweiterung ihrer Auftragsverarbeitungsvereinbarung (AVV) für Personalisierungsinhalte benötigen, sollten den **Personalization Processor Annex** anfordern, der Folgendes abdeckt: - Kategorien personenbezogener Daten: freitextliche, vom Nutzer verfasste Anweisungen; Audit-Metadaten ohne Inhalt der Anweisungen. - Zwecke: ausschließlich Personalisierung der Chat-Antworten pro Nutzer. - Unterauftragsverarbeiter: der pro Organisation konfigurierte LLM-Anbieter (siehe „Deine benutzerdefinierten Anweisungen gehen…“ oben). - Aufbewahrung: unbefristet, solange der Nutzer Mitglied der Organisation ist, auch bei ausgeschalteter Funktion; sofortige Löschung, wenn der Nutzer das Feld leert, beim Entfernen des Mitglieds, beim Löschen der Organisation oder bei Ausführung einer Löschungsanfrage. - Grenzüberschreitende Übermittlung: richtet sich nach der Datenresidenz des LLM-Anbieters und der vom Kunden gewählten Anbieterregion. - Betroffenenrechte: Löschung der Inhalte (Art. 17 per Kaskade beim Entfernen des Mitglieds und beim Löschen der Organisation sowie per Löschungsanfrage). Audit-Log-Metadaten (ohne Inhalt) werden zur Compliance aufbewahrt. Ein vom Betreiber ausführbarer Export (Art. 15/20) steht gegen die zugrunde liegenden Tabellen zur Verfügung; produktinterner Self-Service-Export ist für v2 geplant. # Conditions d’utilisation Source: https://tale.dev/fr/legal/terms-of-service **Dernière mise à jour :** 18.05.2026 ## 1. Introduction Les présentes conditions d’utilisation (« Conditions ») régissent ton accès et ton usage du site [https://tale.dev](https://tale.dev) (« Site ») exploité par Ruler GmbH (« nous »). En accédant au Site ou en l’utilisant, tu acceptes d’être lié par ces Conditions. Si tu n’es pas d’accord avec une partie, n’utilise pas le Site. Ces Conditions ne s’appliquent qu’au Site. L’usage des produits et services Tale est régi séparément par notre [Service Agreement](/files/Service_Agreement_Template.pdf) et notre [Hardware Agreement](/files/Hardware_Agreement_Template.pdf), selon applicabilité. ## 2. Exploitant **Ruler GmbH** Seestrasse 4 3700 Spiez Suisse Registre du commerce : CHE-186.532.610 ## 3. Utilisation du Site ### 3.1 Usage autorisé Tu peux utiliser ce Site à des fins légales et conformément à ces Conditions. Le Site informe sur Tale, nos produits et services, et facilite la communication avec nous. ### 3.2 Comportement interdit Tu t’engages à ne pas : - utiliser le Site d’une manière qui viole le droit local, national ou international applicable ; - tenter un accès non autorisé au Site, à ses serveurs ou aux systèmes et réseaux connectés ; - interférer ou perturber l’intégrité ou la performance du Site ou de son infrastructure sous-jacente ; - utiliser des systèmes automatisés, bots ou scrapers sans notre consentement écrit préalable, sauf pour l’indexation standard par moteurs de recherche ; - transmettre via nos formulaires de contenu illégal, menaçant, abusif, diffamatoire ou autrement répréhensible ; - te faire passer pour une autre personne ou entité, ou déformer ta relation avec une personne ou entité ; - tenter de faire du reverse engineering, décompiler ou désassembler une partie du Site non couverte par une licence open source. ## 4. Propriété intellectuelle ### 4.1 Contenu du Site Le contenu de ce Site — notamment textes, graphiques, logos, images et design global — est la propriété de Ruler GmbH et protégé par le droit suisse et international de la propriété intellectuelle (droit d’auteur, marques, etc.), sauf indication contraire. ### 4.2 Logiciel open source Tale est sous licence MIT et libre d’usage, de modification et de redistribution selon les termes MIT. Les composants open source sont régis par leurs licences respectives. La licence MIT ne s’applique qu’au logiciel Tale et ne couvre pas le contenu du Site, le branding ou les marques. ### 4.3 Marques « Tale », le logo Tale et « Ruler GmbH » sont des marques de Ruler GmbH. Tu ne peux pas les utiliser sans notre autorisation écrite préalable, sauf dans la mesure raisonnablement nécessaire pour désigner nos produits ou notre société. ## 5. Formulaires et soumissions En soumettant des informations via nos formulaires de contact ou de demande de démo, tu déclares que les informations fournies sont exactes et que tu as l’autorité de les partager. Nous traitons toutes les données personnelles soumises via ces formulaires selon notre [politique de confidentialité](/fr/legal/privacy-policy). La soumission d’un formulaire ne crée pas de relation contractuelle entre toi et Ruler GmbH. Une relation contractuelle n’est établie qu’à la signature d’un accord distinct. ## 6. Liens de tiers, URL soumises et analyse vidéo ### 6.1 Liens depuis le Site Notre Site peut contenir des liens vers des sites, services ou ressources tiers qui ne nous appartiennent ni ne sont contrôlés par nous, y compris notre site de documentation, formations et accords de service. Nous n’avons pas de contrôle et n’assumons aucune responsabilité pour le contenu, les pratiques de confidentialité ou la disponibilité de sites ou services tiers. L’inclusion d’un lien ne vaut pas approbation. Nous t’encourageons à lire les conditions et politiques de confidentialité de tout site tiers visité. ### 6.2 URL que tu soumets au Service Lorsque tu soumets une URL au Service pour récupération, transcription ou analyse (y compris des liens vidéo), tu déclares et garantis que : - tu disposes des droits, licences ou des exceptions légales applicables au titre du droit d’auteur et des droits voisins de ta juridiction pour récupérer et traiter le contenu situé à cette URL ; - ton usage du Service est conforme aux conditions d’utilisation de la plateforme source et à l’ensemble du droit applicable ; et - le contenu n’est pas contrefaisant, diffamatoire, illicite ou autrement exclu d’un traitement par un tiers. Les transcriptions, sous-titres, résumés et autres artefacts que le Service dérive de l’URL soumise constituent des œuvres dérivées du contenu source sous-jacent. L’ensemble des droits de propriété intellectuelle sur le contenu original demeure entre les mains de leur titulaire d’origine ; le Service ne te confère aucun droit nouveau sur les artefacts dérivés au-delà de ta licence existante d’utilisation du contenu source. Dans la relation entre toi et le Service, les artefacts dérivés t’appartiennent — sous réserve constante des droits sous-jacents du titulaire des droits — et le Service ne revendique aucune propriété sur les transcriptions ou résumés que tu génères à partir de tes propres URL soumises. Tale agit en tant que sous-traitant suivant tes instructions à l’égard des contenus que tu soumets (récupération d’URL, transcription, stockage). Tale agit en qualité de responsable de traitement pour les métadonnées d’exploitation générées par le Service (compteurs de limitation de débit, classification d’erreurs, télémétrie nécessaire à la fourniture du Service). Nous ne sélectionnons, n’examinons ni n’approuvons les URL soumises par les utilisateurs. ### 6.3 Pouvoir d’appréciation Nous pouvons refuser, limiter, suspendre ou supprimer toute URL soumise ou toute sortie stockée à notre seule discrétion, notamment en cas de plainte, si le traitement dépasse les limites de la plateforme ou si la plateforme source bloque nos requêtes. Nous pouvons également rejeter certaines catégories d’URL (par exemple les diffusions en direct, les contenus à accès restreint par l’âge ou les points d’extrémité de listes de lecture) pour des motifs techniques ou de politique interne. ### 6.4 Procédure de notification et d’action Si tu estimes qu’un contenu stocké par le Service porte atteinte à tes droits ou contrevient au droit applicable, contacte-nous à l’adresse indiquée à la Section 14 en précisant : (i) l’œuvre ou le droit protégé en cause ; (ii) l’URL du contenu stocké ; (iii) tes coordonnées ; et (iv) une déclaration faite de bonne foi du fondement de ta réclamation. Nous examinons les signalements rapidement et pouvons, à notre discrétion, supprimer le contenu ou en restreindre l’accès dans un délai raisonnable. Cette procédure s’ajoute, sans s’y substituer, aux droits et procédures dont tu disposes au titre du droit d’auteur ou de la modération des contenus applicables (notamment l’article 16 du règlement (UE) 2022/2065 — Digital Services Act, lorsqu’il s’applique). ### 6.5 Aucune garantie de service La récupération d’URL et la transcription sont fournies sur la base de meilleurs efforts. Nous ne garantissons pas qu’une URL donnée puisse être traitée, que les transcriptions soient exactes ou complètes, ni que le traitement soit disponible à un moment donné. La précision de la transcription automatique varie selon la qualité audio, la langue et le comportement de la plateforme source. ## 7. Exclusion de garanties Le Site est fourni « tel quel » et « selon disponibilité », sans garantie d’aucune sorte, explicite ou implicite — notamment les garanties implicites de qualité marchande, d’adéquation à un usage particulier ou de non-contrefaçon. Nous ne garantissons pas que le Site sera ininterrompu, sans erreur ou exempt de virus. Bien que nous nous efforcions d’assurer des informations exactes et à jour, nous ne garantissons pas la complétude, l’exactitude ou la fiabilité du contenu. Les informations du Site sont fournies à titre informatif général et ne constituent pas des conseils professionnels, juridiques, financiers ou techniques. ## 8. Limitation de responsabilité Dans toute la mesure permise par la loi applicable, Ruler GmbH, ses dirigeants, employés et agents ne sont pas responsables des dommages indirects, accessoires, spéciaux, consécutifs ou punitifs — notamment perte de profits, données, goodwill ou opportunités d’affaires — découlant de ou liés à ton usage ou incapacité à utiliser le Site. Notre responsabilité totale cumulée pour toute réclamation découlant ou liée à l’usage du Site n’excédera pas CHF 100. Cette limitation ne s’applique pas aux dommages causés par intention ou négligence grave, ni lorsqu’une telle limitation n’est pas permise par la loi applicable. ## 9. Indemnisation Tu t’engages à indemniser, défendre et tenir indemne Ruler GmbH ainsi que ses dirigeants, employés et agents de toute réclamation, responsabilité, dommage, perte ou dépense (y compris frais juridiques raisonnables) découlant de ou liée à ta violation des Conditions ou à ton usage du Site en violation de la loi applicable. ## 10. Modifications des Conditions Nous nous réservons le droit de modifier ces Conditions à tout moment. La version à jour est publiée sur cette page avec une nouvelle date « Dernière mise à jour ». Ton usage continu après ces changements vaut acceptation des Conditions révisées. Nous t’encourageons à consulter ces Conditions régulièrement. ## 11. Divisibilité Si une disposition est jugée invalide ou inapplicable par un tribunal compétent, les dispositions restantes restent en vigueur. La disposition invalide ou inapplicable sera remplacée par une disposition valide et applicable qui reflète au mieux l’intention originale. ## 12. Renonciation L’absence d’exercice par Ruler GmbH d’un droit ou d’une disposition ne constitue pas une renonciation. Toute renonciation doit être par écrit et signée par Ruler GmbH pour être effective. ## 13. Droit applicable et for Ces Conditions sont régies et interprétées selon le droit matériel de la Suisse, à l’exclusion des règles de conflit de lois et de la Convention des Nations unies sur les contrats de vente internationale de marchandises (CVIM). Tout litige découlant ou lié à ces Conditions relève de la compétence exclusive des tribunaux compétents du canton de Berne, Suisse, sauf si une loi impérative en décide autrement. ## 14. Contact Pour toute question sur ces Conditions, contacte-nous : **Ruler GmbH** Seestrasse 4 3700 Spiez Suisse # Politique de confidentialité Source: https://tale.dev/fr/legal/privacy-policy **Dernière mise à jour :** 01.04.2026 ## 1. Introduction Ruler GmbH (« nous », « notre ») exploite le site [https://tale.dev](https://tale.dev) et la plateforme Tale. Nous nous engageons à protéger tes données personnelles et à respecter ta vie privée. Cette politique de confidentialité explique comment nous collectons, utilisons, stockons et protégeons tes données personnelles lorsque tu visites notre site ou interagis avec nous. Cette politique respecte la Loi fédérale suisse sur la protection des données (LPD/nLPD) et, le cas échéant, le Règlement général sur la protection des données (RGPD) de l’Union européenne. ## 2. Responsable du traitement Le responsable du traitement de tes données personnelles est : **Ruler GmbH** Seestrasse 4 3700 Spiez Suisse Registre du commerce : CHE-186.532.610 Pour toute question ou demande concernant la protection des données, contacte-nous via notre [formulaire de contact](https://tale.dev/contact). ## 3. Données que nous collectons ### 3.1 Formulaires de contact et de demande de démo Quand tu soumets notre formulaire de contact ou demandes une démo, nous collectons : - Nom - Adresse email - Nom de l’entreprise (optionnel au formulaire de contact, obligatoire pour la demande de démo) - Numéro de téléphone (optionnel, demande de démo uniquement) - Domaine d’intérêt (demande de démo uniquement) - Contenu du message ou commentaires supplémentaires ### 3.2 Données collectées automatiquement Notre site mesure une fréquentation agrégée avec Umami, un outil d’analytics open source que nous hébergeons nous-mêmes sur notre propre serveur à Francfort (Allemagne). Il est servi depuis notre propre domaine, ne dépose aucun cookie, ne stocke aucun identifiant dans ton navigateur et n’envoie rien à des tiers — aucune donnée d’analyse ne quitte jamais notre infrastructure et nous ne te suivons pas sur d’autres sites. Pour chaque page vue, nous enregistrons l’adresse consultée, la page référente, ta localisation approximative (pays, région, ville), la taille de ton écran ainsi que ton navigateur, ton système d’exploitation et ton type d’appareil. Ton adresse IP sert uniquement à déduire cette localisation approximative et, combinée à un secret renouvelé régulièrement, à produire un hachage à sens unique qui regroupe les requêtes d’une même visite ; l’adresse IP elle-même n’est jamais stockée. Nous ne constituons aucun profil de visiteur et ne pouvons pas t’identifier à partir de ces données. Pour livrer le site, nous traitons par ailleurs temporairement des données techniques minimales (voir Journaux serveur ci-dessous) ; le site stocke également un cookie fonctionnel de langue et une préférence de thème dans ton navigateur (voir Cookies ci-dessous). Seuls le chemin de la page et l’origine de provenance sont collectés ; les paramètres de recherche, fragments et titres de page sont omis. La langue du navigateur est incluse. Les demandes de contact et de démo abouties sont comptées sans le contenu du formulaire. Do Not Track et Global Privacy Control désactivent la collecte. ### 3.3 Journaux serveur Quand tu visites notre site, notre serveur web auto-opéré et notre infrastructure d’hébergement ([hébergeur — à confirmer avant publication]) peuvent traiter temporairement des données techniques comme ton adresse IP, type de navigateur et timestamps d’accès afin de livrer le site et maintenir la sécurité (par exemple le rate limiting). Ces données relèvent des opérations standard d’un serveur web, ne sont conservées que brièvement et ne sont pas utilisées par nous à d’autres fins. ## 4. Finalité et base légale du traitement Nous traitons tes données personnelles pour les finalités suivantes : | Finalité | Données concernées | Base légale (LPD) | Base légale (RGPD) | | ------------------------------------------- | -------------------------------------------------------------------------------------------------- | ----------------- | --------------------------------------------- | | Répondre à ta demande | nom, email, entreprise, message | intérêt légitime | Art. 6(1)(f) RGPD — intérêt légitime | | Organiser et conduire une démo produit | nom, email, téléphone, entreprise, domaine | intérêt légitime | Art. 6(1)(b) RGPD — mesures précontractuelles | | Maintenir et sécuriser le site | données techniques (IP, navigateur) | intérêt légitime | Art. 6(1)(f) RGPD — intérêt légitime | | Mesurer la fréquentation du site | adresse consultée, page référente, localisation approximative, données d’appareil et de navigateur | intérêt légitime | Art. 6(1)(f) RGPD — intérêt légitime | | Établir une relation d’affaires potentielle | données du formulaire de contact | intérêt légitime | Art. 6(1)(f) RGPD — intérêt légitime | Sous la LPD suisse, le traitement de données personnelles est généralement permis tant qu’il ne viole pas les droits de la personnalité de la personne concernée. Nous traitons tes données de bonne foi, de manière proportionnée et uniquement aux fins indiquées. ## 5. Partage des données Nous ne vendons, ne louons ni ne partageons tes données personnelles avec des tiers à des fins marketing ou publicitaires. Tes données peuvent être accessibles aux catégories suivantes de prestataires qui les traitent en notre nom et selon nos instructions : - **Infrastructure d’hébergement :** le site est opéré par Ruler GmbH sur une infrastructure auto-hébergée fournie par [hébergeur — à confirmer avant publication], située à [emplacement du data center — à confirmer avant publication]. - **Fournisseur CRM :** nous stockons les soumissions du formulaire de contact dans un CRM hébergé en Suisse. Ces prestataires agissent comme sous-traitants et sont liés par des accords de traitement selon l’art. 9 LPD et l’art. 28 RGPD. ## 6. Transferts internationaux Tes données personnelles sont principalement stockées et traitées en Suisse. [À confirmer avant publication : indiquer où se trouvent les serveurs du site — Suisse ou UE/EEE — et ajuster cette section en conséquence.] Tous les États membres de l’UE/EEE sont reconnus par le Conseil fédéral suisse comme assurant un niveau adéquat de protection selon l’art. 16 LPD. La Commission européenne reconnaît également la Suisse comme offrant une protection adéquate selon le RGPD. Aucune donnée personnelle n’est transférée dans des pays sans niveau adéquat de protection. ## 7. Conservation des données Nous ne conservons tes données personnelles que le temps nécessaire aux finalités pour lesquelles elles ont été collectées : - **Soumissions du formulaire de contact :** sans relation d’affaires établie, tes données sont supprimées dans les 12 mois suivant ta dernière interaction. - **Demandes de démo :** sans relation d’affaires établie, tes données sont supprimées dans les 12 mois suivant ta dernière interaction. - **Relations d’affaires en cours :** si une relation est établie, les données sont conservées pour la durée de la relation et pour la période requise par les obligations légales de conservation applicables (typiquement 10 ans selon le droit commercial suisse). - **Journaux serveur :** les données techniques sont traitées sur notre propre infrastructure, uniquement à des fins opérationnelles et de sécurité de courte durée, puis supprimées automatiquement. ## 8. Tes droits Sous la LPD suisse et, le cas échéant, le RGPD, tu as les droits suivants : - **Droit d’accès :** demander si et quelles données personnelles nous traitons à ton sujet. - **Droit de rectification :** demander la correction de données inexactes. - **Droit à l’effacement :** demander la suppression de tes données, sous réserve d’obligations légales de conservation. - **Droit à la portabilité :** demander que tes données te soient fournies ou transmises à un tiers dans un format couramment utilisé et lisible par machine. - **Droit d’opposition :** t’opposer à tout moment au traitement de tes données. - **Droit de retrait du consentement :** quand le traitement repose sur le consentement, tu peux le retirer à tout moment sans affecter la licéité du traitement antérieur. Pour exercer ces droits, contacte-nous via notre [formulaire de contact](https://tale.dev/contact). Nous répondons dans les 30 jours. Si tu estimes que tes droits sont violés, tu peux déposer une plainte auprès du Préposé fédéral à la protection des données et à la transparence (PFPDT) en Suisse ou, le cas échéant, auprès d’une autorité de contrôle dans ton État membre UE/EEE. ## 9. Cookies Notre site n’utilise pas de cookies à des fins d’analytics ou de tracking — l’analyse auto-hébergée décrite ci-dessus ne dépose aucun cookie et ne stocke aucun identifiant dans ton navigateur. Il stocke exactement un cookie fonctionnel : `tale_locale`, qui retient ton choix de langue pendant un an pour que les pages se chargent dans ta langue à ta prochaine visite. Il ne contient ni donnée personnelle ni identifiant. Ta préférence de thème clair/sombre reste dans le stockage local de ton navigateur et ne quitte jamais ton appareil. Si nous introduisons à l’avenir des cookies ou services tiers nécessitant un consentement, nous mettrons à jour cette politique et implémenterons un mécanisme de consentement approprié. ## 10. Sécurité des données Nous prenons des mesures techniques et organisationnelles appropriées pour protéger tes données personnelles contre l’accès non autorisé, la perte, l’usage abusif ou la destruction. Ces mesures incluent le chiffrement en transit (TLS/SSL), des contrôles d’accès et une infrastructure d’hébergement durcie et auto-opérée. Ruler GmbH est certifiée ISO 27001 et SOC 2. ## 11. Vie privée des enfants Notre site et nos services ne s’adressent pas aux personnes de moins de 16 ans. Nous ne collectons pas sciemment de données auprès d’enfants. Si nous apprenons avoir collecté par erreur des données d’un enfant de moins de 16 ans, nous les supprimons rapidement. ## 12. Modifications de cette politique Nous pouvons mettre à jour cette politique de temps en temps pour refléter les changements dans nos pratiques, services ou exigences légales. La version à jour est publiée sur cette page avec une nouvelle date « Dernière mise à jour ». Nous t’encourageons à consulter cette page régulièrement. ## 13. Contact Pour toute question ou préoccupation concernant cette politique ou nos pratiques de traitement, contacte-nous : **Ruler GmbH** Seestrasse 4 3700 Spiez Suisse # Accord de traitement des données Source: https://tale.dev/fr/legal/data-processing-agreement **Dernière mise à jour :** 11.06.2026 Le présent accord de traitement des données (« DPA ») est un avenant au Service Agreement (« Contrat ») entre Ruler GmbH (« Tale », « nous ») et l’entité ou la personne qui accepte le Contrat (« Client », « tu »). Il s’applique chaque fois que Tale traite des données personnelles pour le compte du Client dans le cadre de la fourniture des services. En exécutant le Contrat, le Client conclut ce DPA en son nom et, dans la mesure requise par le droit applicable, au nom de ses utilisateurs autorisés et sociétés affiliées. Ce DPA prend effet à la date du Contrat. ## 1. Définitions Les termes capitalisés non définis ici ont la signification donnée dans le Contrat. **« Droit applicable à la protection des données »** — la LPD suisse et ses ordonnances, le RGPD de l’UE, et toute autre législation applicable, telles qu’amendées ou remplacées. **« Responsable du traitement »** — l’entité qui détermine les finalités et moyens du traitement. Pour ce DPA, le Client est le Responsable. **« Violation de données »** — une violation de sécurité menant à la destruction, perte, altération accidentelles ou illicites, ou à la divulgation ou à l’accès non autorisés aux données personnelles traitées par Tale pour le Client. **« Personne concernée »** — la personne physique identifiée ou identifiable à laquelle se rapportent les données. **« Données personnelles »** — toute information relative à une personne physique identifiée ou identifiable, traitée par Tale pour le Client dans le cadre des services. **« Traitement »** — toute opération sur des données personnelles, automatisée ou non. **« Sous-traitant »** — l’entité qui traite des données personnelles pour le Responsable. Pour ce DPA, Tale est le Sous-traitant. **« Sous-traitant ultérieur »** — tout tiers que Tale engage pour traiter des données personnelles pour le Client. La liste actuelle figure à l’**Annexe A**. ## 2. Périmètre et détails du traitement ### 2.1 Rôles Le Client est Responsable. Tale est Sous-traitant. Tale traite les données personnelles uniquement pour fournir et maintenir les services et selon les instructions documentées du Client. ### 2.2 Détails du traitement | Élément | Description | | -------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Finalité** | Fourniture de la plateforme Tale et des services liés selon le Contrat, y compris automatisation de workflows IA, gestion des conversations et fonctionnalités opérationnelles. Les endpoints et flux de données sont décrits dans la [documentation API](https://platform.tale.dev/docs) publique. | | **Nature** | Stockage, extraction, organisation, structuration, calcul, transmission et affichage nécessaires à la fourniture des services. | | **Catégories de personnes concernées** | Déterminées par le Client ; peuvent inclure employés, utilisateurs finaux, clients, prestataires, contacts commerciaux et toute personne dont les données sont soumises. | | **Catégories de données** | Déterminées par le Client ; peuvent inclure noms, adresses e-mail, numéros de téléphone, informations sur l’entreprise, contenus de messages, conversations, workflows, documents et toute autre donnée soumise par le Client. | | **Durée** | La durée du Contrat, plus la période requise pour la restitution ou la suppression (voir section 13). | ### 2.3 Responsabilités du Client Le Client : a) dispose d’une base légale valable au titre du droit applicable pour le traitement et pour les instructions données à Tale ; b) a fourni les informations et obtenu les consentements ou autorisations nécessaires auprès des Personnes concernées ; c) s’assure que ses instructions à Tale sont conformes au droit applicable ; d) est seul responsable de l’exactitude, de la qualité et de la légalité des données qu’il soumet. ## 3. Instructions du Client Le Client instruit Tale de traiter les données personnelles dans la mesure nécessaire à la fourniture des services prévus au Contrat. Toute instruction supplémentaire ou différente requiert un accord écrit. Si Tale conclut qu’une instruction enfreint le droit applicable, Tale en informe le Client sans délai et peut suspendre le traitement concerné jusqu’à réception d’une instruction conforme. ## 4. Obligations de Tale en tant que Sous-traitant Tale : a) traite les données personnelles uniquement sur la base d’instructions documentées du Client — y compris ce DPA et le Contrat —, sauf si le droit applicable en dispose autrement (auquel cas Tale en informe le Client avant le traitement, sauf interdiction légale) ; b) s’assure que les personnes autorisées à traiter les données sont tenues à la confidentialité ; c) met en œuvre et maintient les mesures techniques et organisationnelles décrites à la section 7 ; d) n’engage de Sous-traitant ultérieur que conformément à la section 6 ; e) assiste le Client — en tenant compte de la nature du traitement et des informations à la disposition de Tale — sur les demandes des Personnes concernées (section 9), la sécurité des données, la notification de violations, les analyses d’impact et les consultations préalables des autorités de contrôle ; f) restitue ou supprime, au choix du Client, toutes les données personnelles à la fin des services (section 13) ; g) met à disposition toutes les informations raisonnablement nécessaires pour démontrer le respect de ce DPA et contribue aux audits (section 10). ## 5. Traitement par IA — aucune utilisation pour l’entraînement ou l’amélioration ### 5.1 Pas d’entraînement, pas de fine-tuning, pas d’amélioration de modèle Tale n’utilise pas les données personnelles — y compris prompts, entrées, sorties, embeddings, payloads audio, images ou tout artefact dérivé — pour entraîner, ajuster, évaluer, comparer ni autrement améliorer un modèle d’IA ou d’apprentissage automatique, qu’il soit propre à Tale ou à un tiers. Les données personnelles sont traitées uniquement pour produire la sortie demandée pour l’appel concerné. ### 5.2 Obligations des Sous-traitants ultérieurs concernant l’entraînement Chaque Sous-traitant ultérieur d’IA listé à l’**Annexe A** est contractuellement tenu — via les conditions Enterprise ou API en vigueur entre Tale et ce fournisseur — de ne pas utiliser les payloads soumis par le Client pour entraîner, ajuster ou améliorer ses modèles ou services. Tale fournit la preuve de ces conditions sur demande écrite raisonnable au titre de la section 10. ### 5.3 Opt-in — accord écrit séparé requis Les sections 5.1 et 5.2 ne peuvent être modifiées que par un **accord écrit séparé signé par les deux Parties** précisant (a) le périmètre des données personnelles concernées, (b) la finalité d’entraînement ou d’amélioration autorisée, (c) la durée et (d) les garanties applicables. L’usage continu des services, l’acceptation de conditions mises à jour, des interrupteurs dans le produit ou toute forme de consentement implicite ne constituent **pas** un opt-in. ## 6. Sous-traitants ultérieurs ### 6.1 Autorisation générale Le Client accorde à Tale une autorisation écrite générale d’engager des Sous-traitants ultérieurs pour traiter les données personnelles. La liste actuelle figure à l’**Annexe A** et est reprise sur [/fr/legal/subprocessors](/fr/legal/subprocessors). ### 6.2 Notification des changements Tale notifie le Client au moins 30 jours avant l’engagement d’un nouveau Sous-traitant ultérieur ou le remplacement d’un Sous-traitant existant, en mettant à jour l’Annexe A et la liste publique, et — lorsque le Client a souscrit à ces notifications — par e-mail. ### 6.3 Droit d’opposition Le Client peut s’opposer par écrit à un Sous-traitant ultérieur nouveau ou remplaçant dans les 30 jours suivant la notification, pour des motifs raisonnables liés à la protection des données. Tale s’efforce alors, dans des limites commercialement raisonnables, de proposer une alternative. À défaut d’accord dans les 30 jours suivant l’opposition, chaque Partie peut résilier les services concernés au titre du Contrat. ### 6.4 Obligations répercutées et responsabilité Tale impose à chaque Sous-traitant ultérieur, par accord écrit, des obligations de protection des données au moins équivalentes à celles du présent DPA — y compris l’engagement de non-entraînement de la section 5. Tale reste pleinement responsable envers le Client de l’exécution des obligations de chaque Sous-traitant ultérieur. ## 7. Mesures techniques et organisationnelles ### 7.1 Mesures de sécurité Tale met en œuvre et maintient des mesures techniques et organisationnelles appropriées pour protéger les données personnelles contre tout traitement non autorisé ou illicite et contre la perte, la destruction, le dommage ou la divulgation accidentels, notamment : a) chiffrement des données en transit et au repos ; b) mesures garantissant la confidentialité, l’intégrité, la disponibilité et la résilience continues des systèmes et services de traitement ; c) mesures permettant la restauration rapide de la disponibilité et de l’accès aux données après un incident physique ou technique ; d) contrôles d’accès limitant les données personnelles au personnel autorisé selon le principe du besoin d’en connaître ; e) tests, évaluations et examens réguliers de l’efficacité des mesures ; f) mesures de sécurité physique pour les centres de données et l’infrastructure ; g) sensibilisation à la sécurité pour le personnel. ### 7.2 Certifications Tale détient les certifications ISO 27001 et SOC 2 Type II (ou des standards équivalents) et en fournit la preuve sur demande raisonnable. ### 7.3 Mises à jour Tale peut mettre à jour ses mesures de sécurité à tout moment, à condition que le niveau global de protection des données personnelles ne diminue pas substantiellement. ## 8. Notification des violations de données ### 8.1 Notification au Client Tale notifie le Client sans retard injustifié, et en tout état de cause dans les 72 heures, après avoir eu connaissance d’une violation de données affectant des données personnelles traitées pour le Client. ### 8.2 Contenu de la notification La notification inclut, dans la mesure raisonnablement disponible : a) une description de la nature de la violation, y compris si possible les catégories et le nombre approximatif de Personnes concernées et d’enregistrements ; b) les coordonnées du point de contact de Tale pour plus d’informations ; c) les conséquences probables de la violation ; d) les mesures prises ou proposées pour y remédier, y compris pour atténuer les effets négatifs possibles. ### 8.3 Coopération Tale coopère avec le Client et prend des mesures commercialement raisonnables pour aider à l’enquête, à l’atténuation et à la résolution de la violation. ### 8.4 Pas de reconnaissance de responsabilité Une notification au titre de la présente section ne constitue pas une reconnaissance de faute ou de responsabilité. Le Client est seul responsable de déterminer si la violation déclenche des obligations de notification au titre du droit applicable et d’y satisfaire. ## 9. Droits des Personnes concernées ### 9.1 Assistance Tale assiste le Client — en tenant compte de la nature du traitement — par des mesures techniques et organisationnelles appropriées pour répondre aux demandes des Personnes concernées au titre du droit applicable (accès, rectification, effacement, limitation, portabilité, opposition). ### 9.2 Transmission des demandes Si Tale reçoit une demande directement d’une Personne concernée portant sur des données traitées pour le Client, Tale la transmet sans délai au Client et n’y répond pas directement, sauf instruction du Client ou exigence du droit applicable. ### 9.3 Frais Lorsque l’assistance aux demandes des Personnes concernées requiert un effort significatif au-delà de ce qui est raisonnablement attendu, Tale peut facturer au Client des frais raisonnables fondés sur ses coûts administratifs. ## 10. Audits et inspections ### 10.1 Rapports d’audit Tale met à disposition, sur demande raisonnable et pas plus d’une fois par an, des copies des rapports d’audit tiers ou certifications pertinents (rapports SOC 2 Type II, certificats ISO 27001) pour démontrer le respect de ce DPA. ### 10.2 Audits complémentaires Si le Client estime raisonnablement que les informations fournies au titre de la section 10.1 sont insuffisantes pour vérifier la conformité, il peut demander un audit complémentaire. Ces audits : a) sont à la charge du Client, sauf si l’audit révèle un manquement substantiel de Tale ; b) sont précédés d’un préavis écrit d’au moins 30 jours ; c) se déroulent pendant les heures ouvrées habituelles et de manière à minimiser la perturbation des opérations de Tale ; d) sont menés par le Client ou par un auditeur tiers indépendant, non concurrent de Tale et soumis à des obligations de confidentialité appropriées ; e) sont limités dans leur portée au traitement des données personnelles du Client. ### 10.3 Confidentialité des conclusions Les rapports d’audit, conclusions et informations obtenus dans le cadre des audits sont des informations confidentielles de Tale et soumis aux dispositions de confidentialité du Contrat. ## 11. Transferts internationaux de données ### 11.1 Lieux de traitement Tale héberge la plateforme et stocke les données personnelles en Suisse pour les clients suisses et dans l’Union européenne pour tous les autres clients. Les appels IA (inférence LLM, traitement audio et traitement d’images) sont traités dans l’UE/EEE pour tous les clients — aucun Sous-traitant ultérieur d’IA engagé par Tale n’opère de région de traitement suisse. Pour les clients suisses, ce traitement s’appuie sur l’adéquation des pays de l’UE/EEE au sens de l’art. 16 LPD (liste des États du Conseil fédéral). Le lieu du traitement de chaque Sous-traitant ultérieur figure à l’**Annexe A**. Lorsque le Client déploie Tale sur sa propre infrastructure (on-premises ou cloud privé), le Client détermine les lieux de traitement. ### 11.2 Pays adéquats Tale peut traiter les données personnelles dans les pays reconnus comme offrant un niveau de protection adéquat par le Conseil fédéral suisse au sens de l’art. 16 LPD, ou par la Commission européenne au sens de l’art. 45 RGPD. ### 11.3 Garanties pour les autres transferts Tale ne transfère pas de données personnelles vers des pays sans niveau de protection adéquat à moins que des garanties appropriées soient en place — telles que les clauses contractuelles types approuvées par la Commission européenne ou reconnues par le PFPDT, ou un autre mécanisme de transfert légalement reconnu. ### 11.4 Transparence Les lieux de traitement actuels et les éventuels mécanismes de transfert figurent à l’**Annexe A**. ## 12. Confidentialité Tale traite toutes les données personnelles relevant de ce DPA comme des informations confidentielles. Cette obligation survit à la résiliation de ce DPA et du Contrat. Tale s’assure que toutes les personnes ayant accès aux données personnelles sont soumises à des obligations de confidentialité appropriées. ## 13. Conservation et suppression ### 13.1 Pendant le Contrat Tale conserve les données personnelles pendant la durée du Contrat et conformément aux instructions documentées du Client. ### 13.2 À la résiliation À la résiliation ou à l’expiration du Contrat, Tale, sur demande écrite du Client : a) restitue toutes les données personnelles au Client dans un format couramment utilisé et lisible par machine ; ou b) supprime de manière sécurisée toutes les données personnelles et en fournit confirmation écrite. À défaut de demande écrite du Client dans les 30 jours suivant la résiliation, Tale supprime toutes les données personnelles dans les 90 jours suivant la résiliation. ### 13.3 Conservation légale Lorsque le droit applicable exige de Tale qu’il conserve certaines données personnelles au-delà de la résiliation, Tale en informe le Client, limite le traitement ultérieur à ce que la loi exige et continue de protéger les données conformément à ce DPA. ## 14. Responsabilité La responsabilité au titre de ce DPA est soumise aux limitations et exclusions de responsabilité prévues au Contrat, dans la mesure autorisée par le droit applicable. Rien dans ce DPA ou dans le Contrat ne limite ni n’exclut la responsabilité d’une Partie pour les dommages résultant d’un manquement intentionnel ou d’une négligence grave au droit applicable. ## 15. Relation avec le Contrat ### 15.1 Prééminence En cas de conflit entre ce DPA et le Contrat, ce DPA prévaut concernant le traitement des données personnelles. ### 15.2 Incorporation Ce DPA est incorporé au Contrat et en fait partie. Toutes les autres dispositions du Contrat restent en vigueur. ### 15.3 Divisibilité Si une disposition de ce DPA est invalide ou inapplicable, les autres dispositions restent en vigueur. ### 15.4 Modifications Tale peut mettre à jour ce DPA à tout moment pour refléter des changements dans ses pratiques de traitement ou dans le droit applicable. Les modifications substantielles sont communiquées au Client à l’avance. L’usage continu des services après l’entrée en vigueur des modifications vaut acceptation du DPA mis à jour. Les modifications affectant la section 5 (Traitement par IA — aucune utilisation pour l’entraînement ou l’amélioration) requièrent un accord écrit séparé au titre de la section 5.3 et ne prennent jamais effet par usage continu. ## 16. Droit applicable et juridiction Ce DPA est régi par le droit matériel suisse, à l’exclusion de ses règles de conflit de lois et de la Convention des Nations Unies sur les contrats de vente internationale de marchandises (CVIM). Tout litige relatif à ce DPA est soumis à la compétence exclusive des tribunaux du Canton de Berne, Suisse, sauf disposition impérative contraire. ## 17. Contact Pour toute question relative à ce DPA ou aux activités de traitement, contacte-nous via notre [formulaire de contact](https://tale.dev/contact). **Ruler GmbH** Seestrasse 4 3700 Spiez Suisse --- ## Annexe A — Sous-traitants ultérieurs La présente annexe liste les tiers que Tale engage pour traiter des données personnelles pour le compte du Client sur Tale Cloud — chacun avec son entité juridique, l’adresse de son siège, la nature de la prestation et le lieu du traitement. Les déploiements auto-hébergés sont opérés par le Client ; pour ceux-ci, la liste des Sous-traitants ultérieurs est celle des fournisseurs que le Client assemble. ### Sous-traitants ultérieurs actuels Chaque nom renvoie au DPA public du fournisseur (ou aux conditions équivalentes) ; les certifications et pages de confiance figurent sous les tableaux. L’hébergement de la plateforme suit la résidence de données choisie par le Client : le tableau A.1 s’applique aux clients de l’UE/EEE, le tableau A.2 aux clients suisses. Les appels IA (inférence LLM, traitement audio et traitement d’images) sont traités dans l’UE/EEE pour tous les clients ; ils ne quittent pas l’UE/EEE et ne sont à aucun moment traités dans des pays tiers comme les États-Unis. #### A.1 — Clients de l’UE/EEE | Sous-traitant ultérieur (entité juridique) | Adresse du siège | Nature de la prestation | Lieu du traitement | | ----------------------------------------------------- | -------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | | [Akenes SA (Exoscale)](https://www.exoscale.com/dpa/) | Boulevard de Grancy 19A, 1006 Lausanne, Suisse | Infrastructure cloud (centre de données) : hébergement de la plateforme Tale Cloud — VM, runtime conteneurs, base de données et stockage. | Allemagne (région de Francfort). | | [OpenRouter, Inc.](https://openrouter.ai/privacy) | 169 Madison Avenue, New York, NY 10016, États-Unis | Inférence LLM (chat, vision, embeddings), traitement audio (Speech-to-Text et Text-to-Speech) ainsi que traitement et génération d’images. | Union européenne (routage in-region via `eu.openrouter.ai` : prompts et réponses traités exclusivement dans l’UE). | #### A.2 — Clients suisses | Sous-traitant ultérieur (entité juridique) | Adresse du siège | Nature de la prestation | Lieu du traitement | | ----------------------------------------------------- | -------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------- | | [Akenes SA (Exoscale)](https://www.exoscale.com/dpa/) | Boulevard de Grancy 19A, 1006 Lausanne, Suisse | Infrastructure cloud (centre de données) : hébergement de la plateforme Tale Cloud — VM, runtime conteneurs, base de données et stockage. | Suisse (Zurich ; réplique de reprise après sinistre à Genève). | | [OpenRouter, Inc.](https://openrouter.ai/privacy) | 169 Madison Avenue, New York, NY 10016, États-Unis | Inférence LLM (chat, vision, embeddings), traitement audio (Speech-to-Text et Text-to-Speech) ainsi que traitement et génération d’images. | Union européenne (routage in-region via `eu.openrouter.ai`). | Pour les clients suisses, l’hébergement de la plateforme reste intégralement en Suisse. Le Sous-traitant ultérieur d’IA n’offre pas de région de traitement suisse ; ces appels sont traités dans l’UE/EEE. Tous les pays de l’UE/EEE figurent sur la liste d’adéquation du Conseil fédéral au sens de l’art. 16 LPD — le transfert n’exige aucune garantie supplémentaire. ### Catégories de données et interdiction d’entraînement | Sous-traitant ultérieur | Catégories de données | Entraînement sur les données du Client | | ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------- | | Akenes SA (Exoscale) | Données applicatives en transit et au repos sur le runtime et le stockage hébergés. | Non (infrastructure uniquement ; aucun entraînement IA). | | OpenRouter, Inc. | Prompts et réponses de l’appel d’inférence concerné ; payloads audio et texte transcrit ou synthétisé ; prompts d’images et images générées. | Non — contractuellement interdit (conditions Enterprise). | ### Certifications et pages de confiance Chaque Sous-traitant ultérieur détient ses propres certifications de sécurité et les publie sur sa page de confiance : - **Exoscale (Akenes SA)** — ISO/IEC 27001:2022, ISO/IEC 27017, ISO/IEC 27018, SOC 2 Type II, PCI DSS v4.0, HDS, BSI C5, TISAX. Page de confiance : [exoscale.com/compliance](https://www.exoscale.com/compliance/). - **OpenRouter, Inc.** — SOC 2 ; preuves disponibles via le portail de confiance à accès restreint [trust.openrouter.ai](https://trust.openrouter.ai). Les clauses contractuelles types de l’UE s’appliquent aux transferts hors UE/EEE. ### Notes - Le Sous-traitant ultérieur d’IA n’est engagé que lorsqu’une fonctionnalité d’IA route un appel vers lui. Une org qui n’utilise ni l’inférence LLM, ni l’audio, ni les fonctionnalités d’images n’envoie aucune donnée à OpenRouter, Inc. - Les fournisseurs de modèles accessibles via OpenRouter (Anthropic, Google, Meta, Mistral, OpenAI, etc.) sont des fournisseurs amont d’OpenRouter et ne sont pas des Sous-traitants ultérieurs directs de Tale. Les modèles audio par défaut — Whisper pour le Speech-to-Text et gpt-4o-mini-tts pour le Text-to-Speech — sont des modèles OpenAI atteints de cette façon. Ils opèrent sous les conditions contractuelles propres à OpenRouter, qui interdisent l’entraînement sur les payloads routés ; le routage in-region limite chaque appel aux endpoints de fournisseurs situés dans l’UE. - Chaque Sous-traitant ultérieur engage ses propres sous-traitants (hébergement cloud, CDN, magasins de secrets). Ces listes sont publiques sur les pages de confiance ci-dessus ; Tale suit les changements substantiels via le même mécanisme de préavis de 30 jours prévu à la section 6.2. - La middleware, l’état applicatif et l’infrastructure de support de Tale Cloud s’exécutent sur Exoscale dans la région choisie par le Client ; chaque appel IA est routé vers la région UE/EEE du fournisseur concerné. # Mesures techniques et organisationnelles Source: https://tale.dev/fr/legal/technical-organizational-measures **Dernière mise à jour :** 01.05.2026 Ce document décrit les mesures techniques et organisationnelles (« MTO ») que Ruler GmbH (« Tale ») met en œuvre pour protéger les données personnelles traitées pour le compte de ses clients, telles que référencées à la Section 7 de l'[Accord de traitement des données](/fr/legal/data-processing-agreement). Il s'applique à Tale Cloud. Les déploiements auto-hébergés sont exploités par le Client ; dans ce cas, le Client détermine et applique ses propres mesures, tandis que Tale fournit des paramètres durcis par défaut et des contrôles documentés. Tale réexamine ces mesures au moins une fois par an et peut les mettre à jour, à condition que le niveau global de protection des données personnelles ne diminue pas de façon substantielle. ## 1. Confidentialité ### 1.1 Contrôle d'accès — physique Tale n'exploite pas ses propres centres de données. L'infrastructure physique est fournie par les sous-traitants ultérieurs listés à l'Annexe A de l'[Accord de traitement des données](/fr/legal/data-processing-agreement). Chaque fournisseur est certifié ISO/IEC 27001 (ou équivalent) et applique des contrôles d'accès incluant personnel 24/7, vidéosurveillance, accès par badge ou biométrie, sas, et journalisation des visiteurs. Les preuves sont disponibles sur demande via les pages de confiance des sous-traitants. ### 1.2 Contrôle d'accès — systèmes a) L'authentification multifacteur est obligatoire pour chaque employé de Tale ayant un accès en production. b) L'accès aux systèmes de production est accordé selon le principe du moindre privilège et du besoin d'en connaître, et révisé au moins trimestriellement. c) L'accès du personnel est provisionné via un fournisseur d'identité central et révoqué dans un jour ouvré suivant un changement de rôle ou un départ. d) Les opérations privilégiées requièrent un ticket de changement approuvé et sont journalisées avec l'acteur, l'action et l'horodatage. e) L'accès client à la plateforme est authentifié par e-mail et mot de passe (avec second facteur WebAuthn ou TOTP optionnel) ou par SSO (OIDC) lorsque le Client l'a configuré. ### 1.3 Contrôle d'accès — données a) Les données personnelles sont isolées par locataire au niveau applicatif ; chaque requête en base est limitée à l'organisation qui en fait la demande. b) Les données de production ne sont jamais copiées dans des environnements hors production. Des données synthétiques ou anonymisées sont utilisées pour le développement et les tests. c) Les clés API émises par le Client sont hachées au repos et révocables depuis la surface d'administration. ### 1.4 Contrôle de séparation a) Chaque organisation cliente est un locataire logique distinct ; les identifiants de locataire sont présents sur chaque ligne de la base et appliqués au niveau de la requête. b) Les sauvegardes sont chiffrées par clé spécifique au locataire ; la restauration vers un autre locataire est empêchée au niveau de la gestion des clés. c) Les charges de travail tournent dans des conteneurs isolés ; les politiques réseau empêchent tout trafic entre locataires. ### 1.5 Pseudonymisation et chiffrement a) Les données personnelles sont chiffrées en transit avec TLS 1.2 ou supérieur, avec HSTS imposé sur chaque endpoint public. b) Les données personnelles sont chiffrées au repos avec AES-256 (ou équivalent) au niveau du stockage. c) Les clés de chiffrement sont gérées par le service de gestion de clés du sous-traitant cloud ; la rotation des clés a lieu au moins une fois par an. d) Lorsque la pseudonymisation est possible sans nuire à la fonctionnalité, Tale préfère les identifiants pseudonymes aux identifiants personnels en clair dans les journaux et l'analytique. ## 2. Intégrité ### 2.1 Contrôle de transfert a) Tout le trafic entrant et sortant qui traverse des réseaux publics est chiffré en transit. b) Le trafic interne entre services utilise mTLS authentifié ou des jetons signés. c) Les appels aux sous-traitants ultérieurs IA sont routés vers une région correspondant au choix de résidence des données du Client (Suisse ou UE) ; le routage est appliqué côté serveur. ### 2.2 Contrôle d'entrée a) Chaque action administrative dans la plateforme est enregistrée dans un journal d'audit immuable, avec l'acteur, la ressource concernée et l'horodatage. b) Les journaux d'audit sont conservés pour la durée configurée par le Client (par défaut 365 jours, sans limite supérieure) et ne sont pas modifiés par les restaurations de snapshots. c) Les journaux système des composants d'infrastructure sont conservés 90 jours et accessibles uniquement au personnel Tale autorisé. ## 3. Disponibilité et résilience ### 3.1 Contrôle de disponibilité a) Les services applicatifs tournent dans des configurations redondantes derrière des équilibreurs de charge, avec bascule automatique entre zones de disponibilité dans la région choisie. b) La supervision couvre disponibilité, taux d'erreur, latence et profondeur de file ; les ingénieurs d'astreinte sont alertés en cas de dépassement de seuil. c) La page d'état de Tale publie les notifications d'incidents et l'historique de disponibilité. ### 3.2 Récupérabilité a) Tale prend un snapshot quotidien des bases applicatives et un snapshot horaire du stockage d'objets. Les snapshots sont chiffrés au repos avec des clés détenues par le sous-traitant cloud de Tale. b) Une réplique pour reprise d'activité après sinistre est maintenue dans la région choisie par le client (Genève pour la Suisse, Dublin pour l'Union européenne). c) Les restaurations depuis snapshot sont initiées par le Client via le support et respectent l'objectif de temps de reprise indiqué dans le Service Agreement. d) L'intégrité des sauvegardes est vérifiée au moins trimestriellement par restauration d'un snapshot représentatif dans un environnement isolé. ### 3.3 Capacité et performance a) Les environnements de production sont dimensionnés pour la charge de pointe attendue et passent à l'échelle horizontalement à mesure que l'utilisation augmente. b) Des limites de débit et des mécanismes de contre-pression empêchent un locataire de dégrader le service pour les autres. ## 4. Procédures de test, d'évaluation et d'appréciation régulière ### 4.1 Gestion des vulnérabilités a) Tale exécute un scan automatisé des dépendances à chaque commit et suit les divulgations de vulnérabilités sur toutes les dépendances de production. b) Les correctifs de sécurité sont appliqués dans les délais imposés par la politique de gestion des vulnérabilités de Tale : critique sous 7 jours, élevé sous 30 jours, moyen sous 90 jours. c) Les images de conteneur sont reconstruites au moins mensuellement pour intégrer les mises à jour de sécurité amont. ### 4.2 Tests d'intrusion a) Tale commande un test d'intrusion externe au moins une fois par an. Les constats sont corrigés selon la sévérité, et une lettre d'attestation est disponible pour les clients sous NDA via le support. ### 4.3 Audits et certifications a) Tale maintient des certifications ISO/IEC 27001 et SOC 2 Type II (ou normes équivalentes) pour Tale Cloud. b) Les clients peuvent demander des copies du rapport SOC 2 Type II en cours et du certificat ISO 27001 en contactant le support ; les deux sont fournis sous NDA. ### 4.4 Revue interne a) L'équipe sécurité examine les journaux d'accès, les dérives de configuration et les motifs d'incidents sur une base hebdomadaire continue. b) L'équipe protection des données examine le traitement des demandes des personnes concernées et le comportement de rétention au moins trimestriellement. c) Les constats significatifs de toute revue alimentent un backlog de remédiation suivi, avec responsables et échéances. ## 5. Réponse aux incidents ### 5.1 Détection des incidents a) Les systèmes de production émettent de la télémétrie vers une plateforme centralisée de journalisation et de supervision. b) Des alertes automatisées préviennent l'ingénieur d'astreinte en cas d'anomalie, notamment hausse des taux d'erreur, tentatives d'accès non autorisé et schémas d'exfiltration inhabituels. ### 5.2 Procédure de réponse aux incidents a) Tale maintient une procédure documentée de réponse aux incidents couvrant détection, confinement, éradication, récupération et retour d'expérience. b) La procédure est testée au moins annuellement par un exercice sur table ou un exercice grandeur nature. c) Les niveaux de sévérité et chemins d'escalade sont définis à l'avance ; l'ingénieur d'astreinte est habilité à escalader vers la direction sans délai. ### 5.3 Notification au client a) Tale notifie sans délai indu les clients affectés, et en tout état de cause dans les 72 heures suivant la prise de connaissance d'une Violation de données concernant leurs données personnelles, comme prévu à la Section 8 de l'[Accord de traitement des données](/fr/legal/data-processing-agreement). b) Les notifications incluent les informations requises par le droit applicable à la protection des données : nature de la violation, catégories et nombres approximatifs concernés, conséquences probables et étapes de remédiation. ## 6. Personnel ### 6.1 Confidentialité a) Chaque employé, prestataire et consultant de Tale signe un accord de confidentialité écrit couvrant les données personnelles, le code source et les informations clients. L'obligation survit à la fin de l'engagement. ### 6.2 Contrôles d'antécédents a) Des contrôles d'antécédents sont effectués sur les employés de Tale ayant un accès en production, dans la mesure permise par le droit local. ### 6.3 Formation a) Les nouveaux embauchés suivent une formation à la sécurité et à la protection des données dans les 30 premiers jours. b) L'ensemble du personnel suit une formation de remise à niveau au moins annuelle, incluant la sensibilisation au phishing, le développement sécurisé et le traitement des données. ### 6.4 Départ a) Les accès sont révoqués dans un jour ouvré suivant le départ ou un changement de rôle. b) Le matériel est effacé et récupéré ; les moyens d'accès physiques sont rendus et désactivés. ## 7. Gestion des sous-traitants ultérieurs ### 7.1 Sélection a) Les sous-traitants ultérieurs sont sélectionnés après une revue sécurité et protection des données couvrant leurs certifications, leurs engagements en matière de protection des données et leurs lieux de traitement. ### 7.2 Obligations contractuelles a) Chaque sous-traitant ultérieur est contractuellement lié — par accord écrit — à des obligations de protection des données au moins aussi protectrices que celles fixées dans l'[Accord de traitement des données](/fr/legal/data-processing-agreement), y compris l'engagement de non-entraînement de la Section 5. ### 7.3 Revue continue a) Les certifications et rapports d'audit des sous-traitants ultérieurs sont revus au moins annuellement. b) Les changements significatifs dans la posture d'un sous-traitant ultérieur déclenchent une notification aux clients via le mécanisme de préavis de 30 jours de la Section 6.2 du DPA. ## 8. Minimisation, conservation et suppression des données ### 8.1 Minimisation des données a) La plateforme ne collecte que les données personnelles nécessaires à la fourniture de la fonctionnalité demandée. b) Les clients contrôlent ce qu'ils soumettent ; Tale n'enrichit pas les données soumises par le Client avec des sources tierces sans opt-in explicite. ### 8.2 Conservation a) Les durées de conservation pour chaque catégorie de données sont documentées dans la [Politique de confidentialité](https://tale.dev/fr/legal/privacy-policy) de Tale et dans la configuration de rétention du produit. b) Les seuils de conservation des journaux d'audit sont configurés par le Client ; le défaut de la plateforme est de 365 jours sans limite supérieure. ### 8.3 Suppression a) À l'expiration du Contrat, les données personnelles sont retournées ou supprimées conformément à la Section 13 de l'[Accord de traitement des données](/fr/legal/data-processing-agreement). b) La suppression couvre tout magasin contenant la donnée, y compris stockage d'objets et sauvegardes (ces dernières par destruction de clé dans la fenêtre de rétention). c) Les clients peuvent initier l'effacement pour des personnes concernées individuelles via le flux interne de demandes d'exercice de droits. ## 9. Gouvernance ### 9.1 Politiques a) Tale maintient des politiques écrites de sécurité de l'information et de protection des données, revues au moins annuellement. b) Les changements de politique sont communiqués à l'ensemble du personnel ; les changements significatifs s'accompagnent d'une formation obligatoire. ### 9.2 Rôles et responsabilités a) Tale désigne une personne responsable de la sécurité de l'information et une personne responsable de la protection des données. Toutes deux rapportent à la direction. b) Leurs adresses de contact sont `security@tale.dev` et `privacy@tale.dev`. ### 9.3 Gestion des risques a) Tale maintient un registre des risques couvrant les risques techniques, organisationnels et juridiques. b) Les risques sont revus au moins trimestriellement et après tout incident significatif, et les mitigations sont suivies jusqu'à clôture. ## 10. Contact Pour toute question concernant ces MTO ou pour demander des preuves d'audit, contacte-nous via notre [formulaire de contact](https://tale.dev/fr/contact). **Ruler GmbH** Seestrasse 4 3700 Spiez Suisse # Personnalisation — Avis de confidentialité Source: https://tale.dev/fr/legal/personalization **Dernière mise à jour :** 27.09.2026 ## 1. L’engagement La couche de personnalisation de Tale — tes instructions personnalisées — repose sur un engagement unique : > **Au sein de Tale, aucun autre utilisateur — pas même les administrateurs de ton organisation — ne peut lire tes instructions personnalisées via une interface ou une API. Les instructions personnalisées sont DÉSACTIVÉES par défaut : elles ne s’appliquent que si tu les actives dans Paramètres › Personnalisation, ou si un administrateur les active par défaut pour ton organisation et que tu ne les as pas désactivées toi-même.** Cette page documente ce que cet engagement couvre et ne couvre pas. Cinq limites sont inhérentes à l’exécution d’un service IA sur un modèle tiers et sur une base de données que quelqu’un doit exploiter ; le seul code de Tale ne peut pas les éliminer. ## 2. Limites inhérentes à la pile LLM ### 2.1 Tes instructions personnalisées sont envoyées au fournisseur LLM configuré à chaque tour de chat Lorsque tu envoies un message et que des instructions personnalisées s’appliquent à toi, elles sont incluses dans le system prompt envoyé au LLM amont configuré par ton organisation (OpenAI, Anthropic, Google, Azure, ton modèle auto-hébergé, etc.). Elles sont alors soumises aux conditions de conservation et de surveillance des abus de ce fournisseur. La plupart des grands fournisseurs hébergés conservent les entrées et les sorties pour la surveillance des abus pendant une fenêtre limitée (typiquement 7 à 30 jours, à la mi-2026) et proposent un programme de Zero-Data-Retention ou équivalent pour les clients entreprise éligibles. Durées et critères changent fréquemment — réfère-toi au contrat que ton organisation a conclu avec le fournisseur, ainsi qu’à la politique publiée par chaque fournisseur : - Anthropic — [Politique de confidentialité](https://www.anthropic.com/legal/privacy) · [FAQ sur la conservation des données](https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data) - OpenAI — [API Data Usage Policies](https://openai.com/policies/api-data-usage-policies/) - Google Vertex AI / Gemini — [Gouvernance des données pour l’IA générative](https://cloud.google.com/vertex-ai/generative-ai/docs/data-governance) - Azure OpenAI / Microsoft Foundry — [Données, confidentialité & sécurité](https://learn.microsoft.com/en-us/azure/ai-foundry/responsible-ai/openai/data-privacy) · [Surveillance des abus](https://learn.microsoft.com/en-us/azure/ai-foundry/openai/concepts/abuse-monitoring) Pour les modèles auto-hébergés ou les endpoints OpenAI-compatibles personnalisés (Ollama, vLLM, passerelles internes, etc.), aucune conservation tierce ne s’applique — la conservation est entièrement régie par l’opérateur de cet endpoint. Une fois tes instructions envoyées, **Tale ne peut pas annuler cet envoi**. Si tu les modifies ou les effaces, les requêtes futures portent le nouveau texte, mais les copies déjà transmises au fournisseur restent soumises à ses durées de conservation. ### 2.2 Déploiements auto-hébergés : l’opérateur du déploiement peut lire les lignes brutes Tale stocke tes instructions personnalisées dans la base de données Postgres de ton déploiement, dans la table `app.user_preferences`. Toute personne ayant accès à cette base ou à ses sauvegardes peut lire ces lignes directement — la restriction de Tale fondée sur les rôles (« un administrateur ne peut pas lire les contenus ») **ne s’étend pas à la couche base de données**. En auto-hébergement, considère les opérateurs de ta base de données comme ayant accès à tout le contenu de personnalisation. Les contrôles SOC 2 / ISO sur l’accès BDD relèvent de ta responsabilité. ### 2.3 Les réponses de l’assistant peuvent citer ou paraphraser tes instructions personnalisées La réponse du modèle peut restituer tes instructions personnalisées textuellement ou sous une forme paraphrasée. Cette réponse est ensuite stockée dans ton chat sous les **règles de visibilité du chat**, et non sous celles qui protègent tes instructions : si tu partages le chat, la copie partagée contient cette réponse. Modifier ou effacer tes instructions ne retire rien des réponses déjà générées. ### 2.4 Journaux de la base de données et du serveur Le code applicatif de Tale tient tes instructions personnalisées à l’écart de ses propres journaux et rapports d’erreurs. Le serveur de base de données et l’infrastructure qui l’entoure tiennent toutefois leurs propres journaux : si ton opérateur active la journalisation des requêtes SQL dans Postgres, le texte que tu enregistres peut s’y retrouver. Tale ne peut pas masquer le contenu de ces journaux. ### 2.5 Surveillance des abus côté fournisseur Les principaux fournisseurs LLM exécutent une détection automatisée d’abus sur les entrées qu’ils reçoivent. Les contenus signalés peuvent être revus par leur équipe de modération. Lorsqu’ils sont disponibles, les endpoints Zero-Data-Retention (ZDR) permettent de s’en désengager. Les requêtes contenant de la personnalisation ne diffèrent pas des autres requêtes à cet égard. ## 3. Ce que Tale applique - **Désactivé par défaut.** Sans valeur par défaut de l’organisation ni choix de ta part, les instructions personnalisées ne sont jamais envoyées au modèle. Des instructions vides sont considérées comme absentes, même lorsque la fonction est activée. - **Deux niveaux.** Deux réglages décident si tes instructions personnalisées s’appliquent : - **Valeur par défaut de l’organisation** — contrôlée par les administrateurs, dans Paramètres › Gouvernance › Politiques et limites. Quand elle est activée, les instructions sont activées par défaut pour les membres ; sinon, elles sont désactivées. - **Ta préférence** — ton choix explicite, activé ou désactivé, dans Paramètres › Personnalisation prime sur la valeur par défaut de l’organisation dans les deux sens. La page t’indique si tu suis cette valeur par défaut ou si tu la remplaces. - **Pas de contournement administrateur.** Le rôle d’administrateur ne donne pas accès à la ligne d’un autre utilisateur. Chaque lecture et chaque écriture n’atteint que la ligne de l’utilisateur connecté et revérifie son appartenance à l’organisation à chaque requête — ainsi un utilisateur déjà retiré dont la session est encore valide ne peut plus lire cette ligne. - **Désactiver conserve le texte.** Désactiver tes instructions personnalisées arrête leur envoi, mais le texte reste enregistré et tu le retrouves quand tu les réactives. Pour le supprimer, vide le champ et enregistre ; Tale ne conserve aucune version antérieure. - **Suppression en cascade.** Le retrait d’un utilisateur d’une organisation, la suppression de l’organisation ou l’exécution d’une demande d’effacement le concernant (déposée par un administrateur dans Paramètres › Gouvernance › Personnes concernées) supprime définitivement les préférences de cet utilisateur dans cette organisation, instructions personnalisées comprises, dans la même opération. Une conservation légale active portant sur l’utilisateur ou sur toute l’organisation bloque ces trois opérations tant qu’elle n’est pas levée. Le journal d’audit consigne chacune de ces opérations, mais jamais le texte des instructions. L’auto-suppression de compte n’est pas encore une fonctionnalité produit ; lorsqu’elle arrivera, elle supprimera aussi ces lignes. ## 4. Annexe DPA (brouillon) Les clients ayant besoin d’un avenant à leur Accord de traitement des données pour le contenu de personnalisation sont invités à demander le **Personalization Processor Annex**, qui couvre : - Catégories de données personnelles : instructions libres rédigées par l’utilisateur ; métadonnées d’audit sans contenu des instructions. - Finalités : personnalisation des réponses de chat par utilisateur uniquement. - Sous-traitants ultérieurs : le fournisseur LLM configuré par organisation (voir « Tes instructions personnalisées sont envoyées… » ci-dessus). - Conservation : illimitée tant que l’utilisateur est membre de l’organisation, y compris lorsque la fonction est désactivée ; suppression immédiate lorsque l’utilisateur vide le champ, lors du retrait du membre, lors de la suppression de l’organisation ou à l’exécution d’une demande d’effacement. - Transferts transfrontaliers : régis par la résidence des données du fournisseur LLM et par la région du fournisseur choisie par le client. - Droits des personnes concernées : effacement du contenu (Art. 17 par cascade lors du retrait de membre et de la suppression d’organisation, ainsi que par demande d’effacement). Les métadonnées du journal d’audit (sans contenu) sont conservées à des fins de conformité. Un export exécutable par l’opérateur (Art. 15/20) est disponible sur les tables sous-jacentes ; un export self-service intégré au produit est prévu pour la v2.