Last updated: 9 March 2026
This Privacy Policy explains how Tacit AI (“Tacit AI”, “we”, “us”, “our”) collects, uses, discloses and protects personal data when you visit tacitx.ai or use our products and services (together, the “Services”). If you do not agree with this Policy, you should not use the Services.
The controller of your personal data for the purposes described in this Policy is:
Email: privacy@tacitx.ai
If you are located in the UK or EEA, we may appoint a representative or DPO as required by law. Their details, if applicable, will be published here or in a separate notice.
This Policy applies to:
This Policy does not override any separate contract or data processing agreement (“DPA”) we sign with a customer. In case of conflict, the signed contract or DPA will control for that relationship.
We act in different capacities depending on the context:
When in doubt, the description of roles in your contract or DPA with us prevails.
When you visit our sites or use the Services, we may automatically collect:
This information is collected using server logs, cookies and similar technologies. See section 7 (Cookies and similar technologies).
Where applicable law (such as UK GDPR or EU GDPR) requires a legal basis, we typically rely on the following:
We process personal data to create and manage user accounts, provide, configure, maintain and support the Services, process and analyze Customer Data as instructed by our customers, and provide demos, pilots and proofs of concept.
Legal basis: performance of a contract with you or your organization, and steps taken at your request before entering into a contract.
We process personal data to monitor, detect and prevent security incidents and abuse, troubleshoot and fix technical issues, and maintain system logs and backups.
Legal basis: our legitimate interests in securing our systems and complying with legal obligations.
We may use aggregated or de-identified data derived from Customer Data and usage data to understand how the Services are used, develop new features and improve performance, and benchmark and create statistics, provided they do not identify individuals or customers.
We use contact details to respond to inquiries and support requests, send operational communications, and manage trials, pilots and customer relationships.
We may use your contact details to send you product updates, newsletters and invitations to events. You can opt out of marketing emails by using the unsubscribe link in the email or contacting us.
Our Services include AI features that generate outputs based on Customer Data and other inputs. We process Customer Data to generate outputs solely on your or your organization’s instructions. We may log prompts and outputs for security, debugging and product improvement, subject to our contracts and DPAs. You and your organization are responsible for reviewing AI outputs before using them in safety critical, regulatory or operational decisions.
We do not use Customer Data submitted to our enterprise Services to train public foundation models.
We use cookies and similar technologies to:
Where required by law, we will obtain your consent before placing non-essential cookies and you can withdraw consent at any time through our cookie management tool or browser settings.
We may share personal data with:
We do not sell personal data in the ordinary meaning of that term.
We may transfer personal data to countries outside your own, including to the United States and other jurisdictions where our infrastructure or providers are located. Where required by law, we use appropriate safeguards for such transfers, which may include standard contractual clauses approved by the European Commission or UK authorities, or other relevant transfer mechanisms permitted by applicable data protection law.
We retain personal data for as long as necessary for the purposes set out in this Policy, in particular:
We implement technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include access controls, encryption in transit and at rest where appropriate, logging and monitoring of production systems, and staff training.
Depending on where you are located and subject to certain conditions, you may have rights including:
To exercise these rights, contact us at privacy@tacitx.ai. If we process your data on behalf of a business customer, we may redirect your request to that customer as the controller.
The Services are not intended for use by children under the age of 16 and we do not knowingly collect personal data from them.
Our sites and Services may contain links to or integrations with third party websites, services or content. We are not responsible for the privacy practices of those third parties.
We may update this Policy from time to time. We will post the updated version on this page and update the “Last updated” date. Your continued use of the Services after the effective date of the updated Policy means you accept the changes.
If you have questions about this Policy or how we handle personal data, contact:
Email: privacy@tacitx.ai