Privacy policy
Last updated 30 July 2026.
Who we are
Tendal is operated by Better Call Birdman, registered with the Dutch Chamber of Commerce (KvK) under number 84948396. Contact: hello@tendal.io.
For the data in your HubSpot portal you are the controller and we are a processor: we look at it only to produce the audit you asked for, and only in the ways set out below. For your own account and billing details we are the controller.
What Tendal reads
Only what the scopes you granted allow, listed one by one with a reason on the shared data page. Tendal never writes to your portal: it contains no code that changes anything, and it asks for no permission to create, alter or delete a record, a property or a user.
With one exception, which we would rather name here than have you discover on HubSpot's approval screen. Reading your workflows requires the scope HubSpot calls automation, and HubSpot publishes no read-only form of it, so granting it also grants write. Tendal only ever reads it. The scope is optional, and declining it costs you the automation signals and nothing else.
It reads records in order to count them. A contact is read to answer "how many contacts did this user touch"; the answer is a number and the contact itself is never copied out. User email addresses are the exception: they are read so the result can name which person holds a seat they do not use.
What we keep
- Your connection. The OAuth refresh token that lets Tendal reconnect, encrypted at rest. Short-lived access tokens are never written down at all: each scan mints one and discards it. We also keep your portal's own domain, so screens can say who a portal belongs to instead of showing an eight-digit number.
- Your alert channels. Wherever you tell us to send alerts: a Slack, Discord or Google Chat webhook URL, or an email address. Both are encrypted at rest, for different reasons. A webhook URL is a credential, so it gets what a token gets. An email address is not a credential, but it is personal data, so it is not left in plain text either. This is the one address we store, and only because you typed it in: the addresses we read out of your portal are never kept.
- Your trend. One row per scan holding derived figures: seat counts, the projected saving, how many users fell into each category. This history is built so that it cannot contain a name or an email address, which is why the trend can be kept while the underlying detail is not.
- An operational log. When a scan ran and whether it succeeded, so that a broken connection is visible rather than silent. A failed scan records the error HubSpot returned. Those messages are not intended to contain personal data and in practice describe the request rather than the records, but we cannot guarantee that a given error text never quotes a field, so we are naming it rather than claiming otherwise.
We do not keep copies of your contacts, companies, deals or tickets. There is no export, no data warehouse, and no training of anything on your data.
How long
Until you disconnect. Disconnecting Tendal removes the app from your HubSpot account and deletes everything above in the same action: the connection, the channels, the trend and the operational log. So does uninstalling Tendal from HubSpot yourself, the first time we notice the connection is gone.
Backups are the honest caveat. Encrypted off-site backups are rotated on a 90-day cycle, so a copy of deleted data can persist in a backup for up to 90 days before it ages out. Backups are restored only to recover the service, never to bring back an account that asked to be deleted.
Who else touches it
Every company that does, listed with what it holds on the sub-processors page:
- Hetzner Online GmbH (Germany (company), servers and backups in Finland) — hosting and backup storage.
- Paddle.com Market Ltd (United Kingdom) — payments, as merchant of record.
- AhaSend B.V. (Netherlands (company), servers in Germany, Bulgaria and Norway) — sending alert emails.
Your portal data never leaves the European Union: the application, the database and the backups all run on Hetzner in Finland. Two things are the exception, and worth naming rather than glossing. Paddle is our merchant of record and is a United Kingdom company, so your company name, VAT number and invoices sit there. Paddle never receives anything from your HubSpot portal. Alert emails are delivered by AhaSend, a Dutch company, on infrastructure in Germany, Bulgaria and Norway. Norway is in the European Economic Area rather than the European Union, so the same data protection rules apply. AhaSend also runs an optional node in the United States, switched on per account and never used otherwise, not even during an outage. We have not switched it on. An alert holds your email address and the derived figures it reports, never records from your portal.
Alert messages go to the chat platform you choose, at a webhook address you supply; what that platform does with them is governed by your agreement with them, not ours. Email alerts work differently, and the difference matters: there you choose the address but we choose the provider, so that provider is a sub-processor of ours and is named on the sub-processors page. A chat platform you picked yourself is not.
Cookies
The application sets exactly one cookie, which records the HubSpot portals this browser has connected so that only you can see them. It holds no identifier we can trace to a person, expires after 30 days, and there is no way to switch it off because without it the application cannot tell your portal from someone else's.
This website measures page views with a self-hosted, cookieless analytics tool, along with a small set of anonymous interaction counts: which buttons and links are clicked, such as the one that starts a connection or opens the sample. We record the name of the button, never anything you type. It sets nothing on your device and records no identifier, which is why you are not being asked to consent to anything.
Your rights
You can see everything Tendal holds about a portal on that portal's own page in the app, and delete all of it by disconnecting. If you would rather ask us, write to hello@tendal.io and we will answer within 30 days. Under the GDPR you may request access, correction, deletion, restriction, portability, and may object to processing. If you think we have handled your data badly you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Where you are the controller and we the processor, requests from your own contacts should come to you; we will help you answer them.
Changes
If this policy changes in a way that affects what we do with your data, we will tell subscribers by email before it takes effect rather than quietly changing the date at the top.