Privacy Policy
This policy explains how Klimber Technologies (“Klimber,” “Turn3,” “we,” “us,” or “our”) collects, uses, protects, and shares information when you use the Turn3 quality-loop service.
Turn3 is a customer-controlled observability and session-analysis service. You decide what telemetry to send, which governed sources to connect, who can access your workspace, and when to delete it. We process that information to provide the service, secure it, measure reliability, and support your account.
1. Scope
This Privacy Policy applies to the Turn3 dashboard, APIs, SDKs, OTLP endpoints, governed source connectors, support and sales forms, and related websites and services (collectively, the “Service”). It does not govern third-party products that you connect to Turn3; those products have their own terms and privacy policies.
If you use Turn3 on behalf of an organization, that organization is the data controller or business customer for workspace data, and you should direct workspace-data requests to its administrator first.
2. Information we collect
Automatically collected technical data
We may collect IP address, browser and device information, request metadata, security logs, diagnostic events, and approximate usage information needed to operate and protect the Service.
Content recording is your choice
Telemetry may contain prompts, responses, tool arguments, retrieved context, or other content only when your application or connected provider records and sends it. Do not send information you are not authorized to process. Configure provider content-capture settings and Turn3 redaction controls for your use case.
3. How we use information
- Provide, maintain, secure, troubleshoot, and improve the Service.
- Build session timelines, stitch traces, normalize content, identify failure modes, run evaluations, and produce diagnosis or Turnguard decisions requested by you.
- Apply workspace permissions, plan limits, retention rules, metering, billing, and audit controls.
- Respond to support requests, sales inquiries, regional-demand requests, and service communications.
- Detect abuse, fraud, security incidents, and violations of the Terms of Use.
- Produce aggregated or de-identified operational metrics that do not reasonably identify a customer or individual.
We do not use your workspace telemetry to train a general-purpose model unless you separately authorize that use in writing.
4. Sharing and service providers
We share information only as needed to provide the Service, protect users, comply with law, or complete a transaction. Depending on your configuration, service providers may include cloud hosting, identity, object storage, databases, message buffers, observability, billing, email, and customer-support providers.
When you configure a governed source, Turn3 uses the credentials and permissions you provide to retrieve the selected records. We do not obtain access to a source that you have not connected, and we do not control the privacy practices of that source.
We may disclose information to professional advisers, a successor in a merger or acquisition, or authorities when legally required or reasonably necessary to protect rights, safety, and the Service. We do not sell personal information.
5. Retention and deletion
Retention follows your workspace plan and configured data policy:
- Free: up to 100 sessions per month, with a 7-day session-retention window.
- Pro: up to 10,000 sessions per month, with a 365-day session-retention window.
- Enterprise: contract-defined limits, retention, and deployment controls.
Billing, security, and audit records may be retained longer where needed for accounting, fraud prevention, dispute handling, or legal obligations. Workspace deletion is delayed for a 30-day grace period; ingestion is paused while deletion is pending, and an administrator may cancel the request during that period. After the applicable deletion workflow completes, remaining copies may persist temporarily in encrypted backups until they expire.
6. Security
We use access controls, tenant boundaries, encryption in transit, encrypted storage where configured, secret management, audit logging, least-privilege service roles, and redaction controls designed to protect the Service. No method of transmission or storage is completely secure, so you remain responsible for protecting credentials and selecting appropriate telemetry content.
Report a suspected security or privacy issue promptly at turn3@klimber.io. Do not include secrets or sensitive payloads in an initial email.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or export personal information, or to object to certain processing. Workspace administrators can manage members, connected sources, retention, and deletion through the Service. Contact us at turn3@klimber.io for a privacy request; we may verify your identity and coordinate with your workspace administrator.
You can control optional browser storage by signing out and clearing site data. Some strictly necessary storage is required for authentication and security.
8. Children, changes, and contact
The Service is intended for business and professional use and is not directed to children. We may update this policy as the Service or legal requirements change. We will post the revised version with a new “Last updated” date and provide additional notice when required.
For questions about this policy or a privacy request, contact turn3@klimber.io. Turn3 is a product of Klimber Technologies.
