1. Who we are
TDI Hub (“the Service”) is operated by TD Intelligence (“we”, “us”). The Service is a partner-only workspace for managing devices, firmware, knowledge articles, validation tools, design tools (heatmap mapping & planner), diagnostic webhook captures, and analytics related to TD Intelligence sensor products.
2. Data we collect
- Account data — your email, the organization you belong to, the role granted by your organization administrator, sign-in timestamps, and the version of these terms you have accepted.
- Device & telemetry data — sensor identifiers, firmware versions, status, and operational metrics that you or your devices transmit through the platform.
- Content you upload — including but not limited to:
- Floor-plan images, camera-view images, and click-pair calibration data (Design › Heatmap Mapping).
- Project plans & layouts (Design › Planner).
- Validation runs: parsed XLSX data from Quick Validation and aggregate statistics from Image Validation. The original image bytes from Image Validation are never persisted.
- Diagnostic webhook captures (raw bodies plus extracted metrics, stored under a per-session token you create).
- Knowledge-base attachments uploaded by admins.
- Usage logs — request paths, IP, user-agent, and timestamps, retained for security monitoring and abuse prevention.
3. How we use it
We use the data to operate the Service, support your devices, deliver firmware and content updates, troubleshoot issues, and improve accuracy of analytics. We do not sell your data and we do not use partner-uploaded content to train external AI models.
The on-platform AI Search assistant (knowledge-base Q&A) uses Cloudflare Workers AI for retrieval and answer generation. Cloudflare commits to zero retention for these inference calls. Search queries are stored on TDI Hub for product analytics and quality improvement, scoped to your organization.
4. Where data lives & how it’s protected
- Storage — structured records (users, devices, validations, mappings, audit log, etc.) reside in Cloudflare D1 (managed SQLite). Uploaded files (floor plans, firmware, webhook captures, KB attachments) reside in Cloudflare R2 object storage. Both are operated by Cloudflare on our behalf.
- Data residency— data may be processed in any of Cloudflare’s global regions for performance and availability. We do not currently offer a default single-region (e.g. EU-only) deployment. Partners with jurisdiction-specific residency requirements (e.g. EU GDPR stricter localization) may contact privacy@tdintelligence.wiki to negotiate a Data Processing Addendum.
- Encryption in transit— TLS 1.3 between your browser and Cloudflare’s edge, and between Cloudflare and our compute (Workers). HSTS is enforced on the tdintelligence.wiki domain.
- Encryption at rest — Cloudflare D1 and R2 provide at-rest encryption with platform-managed keys.
- Application-layer encryption— particularly sensitive credentials (e.g. RCS device passwords used by the Hub’s integrations) are additionally encrypted with AES-GCM at the application layer using a master key held only in Cloudflare Worker Secrets, so the ciphertext is unintelligible even to a reader with raw database access.
- Authentication — passwordless sign-in via email magic link (Auth.js v5). We do not store passwords. Sessions are stored in our database and can be revoked centrally by your admin.
- Tenant isolation— every read of partner data in the Service goes through an org-scoped query layer; admins from one partner organization cannot see another partner’s data unless explicitly granted.
5. Audit logging
Administrative actions on TDI Hub (membership changes, role changes, content publishing, password-reset / license workflows, legal-terms acceptance, etc.) are recorded in an audit log scoped to your organization. Your organization administrator can review this log inside Admin › Users › Audit. You may also request an export of audit entries pertaining to your own account. Audit-log entries are retained for two (2) years from the date of the event; older entries are automatically purged by a daily cleanup job.
6. Customer privacy — your responsibility
Some files you may wish to upload (floor plans, validation videos taken on customer premises, webhook captures from customer-deployed devices) can contain information about your end customers. Please avoid uploading content that identifies, or could re-identify, end customersunless your contract with that customer permits processing on TDI’s infrastructure. If you choose to upload such content, your organization remains the data controller; TDI acts as a processor on your instructions.
7. Retention
Account data persists while your organization remains active. Validation reports and design files persist until you or your organization admin deletes them. Webhook captures expire by default 14 days after creation; soft-deleted captures are permanently purged 7 days later. Backups are retained for 30 days then permanently purged.
8. Your rights
Depending on your jurisdiction, you may have rights to access, port, correct, or delete your data. See our GDPR / data subject rights page for the full procedure and our response timeline.
9. Cookies
We use a small set of strictly-necessary cookies for session and theme persistence. See Cookie Policy.
10. Children’s privacy
TDI Hub is a business-to-business service provided to TD Intelligence’s commercial partners and is not designed for, marketed to, or intended to be used by anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has been granted a TDI Hub account, please contact privacy@tdintelligence.wiki and we will remove the account.
11. Changes
For material changes after this initial release, we will post the revised version here at least 14 days before it takes effect, and when the version bumps we will require you to re-accept it on next sign-in. The current version is dated above.
12. Contact
Questions or requests: privacy@tdintelligence.wiki.