Taildesk

Loading Taildesk…
Skip to content
Taildesk
Get involved

Privacy & security

GDPR, EU hosting and who sees your data

What we commit to, what we cannot prove yet, and what you should hold us to.

Tell us what you need

An animal rescue processes more personal data than most people assume: adopters' addresses, volunteers' phone numbers, notes from home checks, donor records, sometimes the reason an animal was given up. So anyone looking for GDPR-compliant software is rarely looking for a certificate, but for two solid answers: where does the data sit, and who can see it? Both are below — together with what we expressly cannot claim at this point.

  • Where the data sits

    Taildesk is developed in Germany and hosted in the European Union. That is not a marketing line, it is the precondition for an organisation to be able to justify the processing cleanly at all, without having to deal with third-country transfers and their legal basis. That applies to more than the database. The services around it — photo storage, sending email, usage analytics — belong in the same legal space, otherwise you only move the problem one level down.

  • Who has access

    Volunteers need the rota and the animals they work with. They do not need an adopter's address, the reason for a surrender or the donor list. So access rights are tied to roles and not to trust. That is not a statement about volunteers — it is the only arrangement that still holds when someone leaves, when a device goes missing, or when a person covers briefly for somebody else. Who gets which role is decided by your organisation.

  • What you can demand from us

    As a processor we owe you a data processing agreement under Article 28 GDPR, information about which sub-processors are involved, and cooperation when a data subject asks for access or deletion. On top of that comes the point that counts most day to day: export. You must be able to get your data out in a readable format at any time — without asking, without a fee and without a cancellation conversation. A system that holds data back is a risk regardless of any encryption.

  • Deletion that actually deletes

    A home check from six years ago does not need to be findable any more. Nor does the address of someone who enquired once and then said no. So retention limits belong in the software and not in a good intention. At the same time there is data an organisation has to keep — in Germany, donation records are subject to statutory retention periods. Squaring the two cleanly is part of the work and not a setting a charity should have to decide in passing.

  • What we do not claim

    There is no ISO certification for Taildesk, no privacy seal, no passed audit and no penetration test by an independent third party. The product is pre-launch, and all of that presupposes a running operation. We write this down because a page about security that leans on badges it does not have has missed its own point. What is written here are commitments you can hold us to — not proof already delivered.

What you can hold us to

  • Hosting and processing within the EU, including the services around it.

  • A data processing agreement under Article 28 GDPR on request.

  • Role-based access rights instead of everything for everyone.

  • Data export in a readable format, at any time and without a fee.

  • Deletion on request, with an eye on statutory retention periods.

  • No passing on to third parties, no data sales, no advertising funding.

Taildesk is not in use anywhere yet. This page describes commitments and design principles, not verified facts: so far there is no audit, no certificate and no independent security test. If your organisation is missing a particular piece of evidence it needs in order to work with us, tell us — that is one of the most useful things you can send our way.

Common questions about privacy

Is Taildesk GDPR-compliant?

That is how we are building it: processing in the EU, role-based access rights, a data processing agreement under Article 28, export and deletion on request. Formally, though, GDPR compliance is not something a provider creates on its own — it also depends on how you use the system. Anyone claiming otherwise is selling a feeling.

Do we get a data processing agreement?

Yes. For an organisation that has personal data about members, volunteers and adopters processed on its behalf, that is not an option but a requirement. Ask for it before you load real data.

Who on your side can see our data?

In operation: nobody who does not need to be there to fix a fault. Access by us should be the exception with a reason, not the norm. We deliberately write that here as a commitment and not as proof — proving it takes an audit, and there is not one yet.

Also worth a look

What evidence do you need?

Some organisations need a particular document before they are even allowed to start. Tell us which one — then we know what has to exist first.

Tell us what you need

Taildesk

Stronger Shelters. Happier Animals.

Shelter operations and community — developed in close collaboration with the shelters helping shape it.

Get involved

Newsletter

Occasional, honest updates from Taildesk.

© 2026 Taildesk. All rights reserved.

Diese Seite auf Deutsch