1. Policy summary and purpose
Last updated: May 2024
Turrior company, registered in the United States of America at 9429 HARDING AVE STE 207, SURFSIDE, FL 33154, Turrior, “us”, “we”, or “our” operates the turrior.com website (the “Site”) and provides international recruitment and management services (the “Services”), which are available through the Site.
Turrior has developed a global privacy policy under which we offer the same high standards of privacy protection regardless of where you are in the world.
This Privacy Policy informs you of how information about you is collected, used, and disclosed by us.
This Privacy Policy forms part of our Turrior Terms of Service. Unless otherwise defined in this Privacy Policy, capitalized terms used in this Privacy Policy have the same meanings as in our Terms of Service.
2. Scope of application
This Privacy Policy applies to the following individuals:
Visitors of the Site with whom Turrior does not have a contractual relationship
Clients who use our Services, including client UBOs or representatives
Independent Contractors who use our Services
Suppliers who provide products or services to Turrior
Candidates
Prospects
Individuals with whom we interact with and process their personal data
By using our Site and/or our Services, as well as engaging with Turrior in any way, you agree to the collection and use of your information in accordance with this Privacy Policy.
3. Information collection
Turrior collects and stores certain information about you. This information can be used on its own or in combination with other information to identify you (“Personal Information”). Below is a list of types of Personal Information that we may collect and use about you.
Categories of Personal Information Description
Contact Information we use to contact you, including physical addresses, email addresses, and phone numbers
Identification Information we use to identify you, including full name, DoB, and photo
Locational Information we get about where you are, including country and IP address. This may come from your mobile phone or the place where you connect a computer to the internet. It may also include locations where you used your card.
Usage Information about the usage of our Services and Site including metadata
Technical Information on the devices and technology you use, including IP address, login data, browser type and version, timezone, operating system, browser type
Communications Information from communications between us or with other users, including any personal data you may share with us or with other users in your messages, communication metadata
Professional Information about professional career and educational background, including current and old job positions, degrees, qualifications
Public and third-party records Information about you that is in public records and information about you that is publicly available on the internet. We also collect information about you which we receive from other companies, such as (without limitation) credit reference or fraud protection agencies (see below for more information).
Consents Any permissions, consents, or preferences that you give us
Other Information Any other information you choose to provide to us through all available channels, participating in user/customer surveys, or otherwise visiting and interacting with our Site and/or Services.
To avoid doubt, Personal Information shall not include any personal information that is anonymized, after which the identifiable data is destroyed.
Turrior may also collect and use non-Personal Information to analyze the effectiveness of our Services and to improve our Services. We may collect Non-Personal Information through the Services, the Site, and through cookies.
SMS Verification Data
We collect your phone number, one-time verification codes, and opt-in/opt-out status solely to protect your Turrior account.
Data is shared only with Twilio Inc. for message delivery and kept for up to 18 months for fraud-prevention and audit purposes.
To review or delete your SMS data, email support@turrior.com.
4. Sources of your personal information
We may collect Personal Information about you or your businesses from any of these sources:
Directly for you when you use our Services, complete a contact form, request marketing communications, participate in surveys or contact us
Turrior collects profile and usage data when you interact with our Site and/or Services, including, without limitation, your security details, app or web browser settings, marketing choices, and data from the devices you use to connect to our platform so we can provide you with our products or services
We also collect information through the use of cookies and other internet tracking software while you are using our website or mobile apps, as described in detail in our Cookie Policy.
5. Google User Data and Gmail Integration
Turrior allows authenticated company users to connect a Google account and communicate with registered Turrior talent users who have made their email address publicly available on the Turrior platform for contact by companies.
5.1 Google Data Accessed and How It Is Used
Turrior requests access to Google account profile information and Gmail data solely to provide user-facing email functionality.
Turrior uses:
– Gmail read access to retrieve the lists, metadata, content, and attachments of messages available through the Turrior email functionality;
– Gmail send access to send messages and replies from the connected Google account;
– Gmail modify access to create and apply the Turrior label and to mark an opened message as read;
– Gmail settings access to create filters that apply the Turrior label to future messages sent to or received from saved Turrior contacts; and
– Google profile access to display the connected account’s email address, name, and profile picture.
A company user cannot enter an arbitrary recipient address through the Turrior Gmail API. The user selects a saved Turrior contact, and Turrior obtains the recipient address from that talent user’s public Turrior profile.
Turrior does not send Gmail messages without a user-initiated action.
5.2 Message Visibility and Gmail Labels
Turrior’s Inbox, Sent, contact-conversation, message, reply, and attachment functionality is limited to messages carrying the Turrior Gmail label. Messages sent through Turrior are assigned this label. Gmail filters created for saved Turrior contacts apply the label to future messages sent to or received from those contacts.
Existing historical messages are not scanned or labeled retroactively when a Turrior contact is added. Messages without the Turrior label are not made available through Turrior.
Because filtering is based on the saved contact’s email address, future messages to or from that address may be labeled even if they were not originally created through Turrior.
5.3 Storage and Security
Gmail message bodies and attachment contents are retrieved from Google when required for a user-requested action. The Turrior backend processes this content temporarily and does not store permanent copies of Gmail message bodies or attachments in its application database.
Turrior stores limited information required to maintain the integration, including the connected Gmail address, Google profile information, granted OAuth scopes, connection timestamps, encrypted OAuth tokens, and Turrior contact records.
OAuth access and refresh tokens are encrypted at the application level using authenticated AES-256-GCM encryption before they are stored in the database. Encryption key material is maintained separately from the database in protected server-side configuration.
Google user data is transmitted over HTTPS using TLS. Database backups are encrypted on the client before transfer to access-controlled Backblaze storage.
Access to production systems is restricted through authentication, authorization, role, and tenant-ownership controls. General employees do not have direct access to the production database. Production access is limited to specifically authorized administrators who require it to operate or secure the service. Authorized personnel are subject to confidentiality and data-handling obligations.
Turrior does not intentionally include OAuth tokens, Gmail message bodies, or attachment contents in application logs. Operational logs may contain limited technical information such as request paths, response status codes, error codes, timestamps, and identifiers needed to operate and secure the service.
5.4 Assistants, Sharing, and Limited Use
When a user expressly invokes an assistant feature, the specific Gmail data required to fulfill that request may be returned through Turrior’s authenticated interface to the assistant service selected and authorized by the user. Such processing is limited to performing the requested user-facing action.
Turrior does not sell Google user data or use it for advertising, retargeting, creditworthiness, lending, data brokerage, surveillance, or unrelated profiling. Turrior does not use Google Workspace API data to create, train, or improve generalized or non-personalized artificial intelligence or machine-learning models.
Turrior personnel do not read Gmail message content except where the user has expressly requested support involving specific data, where access is necessary to investigate a security issue or abuse, or where access is required by applicable law.
5.5 Retention, Disconnection, and Deletion
OAuth access and refresh tokens are retained only while the Gmail integration remains connected and is required to provide the requested functionality.
When a user disconnects Gmail, Turrior attempts to revoke the authorization with Google and permanently deletes the locally stored OAuth access token, refresh token, and token-expiration information. Disconnecting Gmail does not delete the user’s Turrior account, public profile information, Turrior contacts, or other data belonging to the Turrior service.
Limited Google profile and connection records may remain associated with the Turrior account until the account is deleted or the user submits a valid deletion request. Users may request deletion of their account and associated Google-derived data by business@turrior.com.
Deleted data may remain in encrypted backups for up to 30 days, after which the relevant backups expire according to Turrior’s backup-retention schedule. Backup copies are not restored except for disaster recovery or security purposes.
Turrior’s use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
From third parties:
Companies, business partners, or individuals that introduce you to us
Business partners, service providers, sub-contractors, advertising networks, analytics providers, search information providers, fraud protection services, and Payment Service Providers (PSPs) who help us authenticate your identity, improve the quality of our Services, promote our Services, and protect our business. We may also receive Personal Information