In plain English
- We are Taurus Intelligence Ltd, a UK company. We are the data controller for the personal data on this site and the platform.
- We collect what we need to run the platform and nothing more: your account details, your uploaded account list, your usage activity, and the public research our systems generate about the accounts you ask us to track.
- We rely on legitimate interest for B2B business research and on contract for everything you've signed in for.
- We use named sub-processors (Supabase, OpenAI, Perplexity, Vercel, Calendly). Two of those process data in the United States; we use Standard Contractual Clauses for those transfers.
- You can ask us to access, correct, export, or delete your data at any time. Email nick@taurusintelligence.com.
- You have the right to complain to the UK Information Commissioner's Office (ICO) if you think we've handled your data badly.
1. Who we are
Taurus Intelligence Ltd ("Taurus", "we", "us", "our") operates the Taurus revenue intelligence platform at taurusintelligence.com.
For the purposes of UK GDPR and the EU GDPR (where applicable), we are the data controller for the personal data described in this policy. If you are a customer organisation using Taurus to process your own customer or prospect data, we are the data processor for that data and we act on your written instructions in our Data Processing Agreement.
Registered address: United Kingdom (full address available on request).
Contact: nick@taurusintelligence.com
2. What personal data we collect
We collect personal data in a small number of categories, all listed below.
From you, when you sign in or use the platform:
- Account details: email address, name, role, employer name.
- Authentication data: securely hashed credentials managed by Supabase Auth.
- Subscription and billing details (when you become a paying customer).
- Usage activity within the platform (which pages you visit, when, and for how long), used to improve product performance.
From you, when you upload account or prospect data:
- Company names you want to research.
- Any contact data you choose to upload (names, titles, email addresses of business contacts at the companies you research).
- CRM data you choose to sync (Salesforce, HubSpot) if you authorise the integration.
- Meeting notes and transcripts you choose to upload for MEDDICC inspection.
From public sources, generated by our systems:
- News, regulatory filings, executive announcements and other public information about the companies you ask us to track. This may include the names and job titles of public-facing executives at those companies.
- This research is performed via Perplexity and synthesised via OpenAI. It is grounded in public sources only.
Automatically:
- Standard server logs (IP address, browser type, referrer, timestamps) for security and operational purposes.
- Strictly necessary cookies (session token) for keeping you signed in. We do not currently use analytics, marketing, or advertising cookies. If we add them, we will request your explicit consent first.
3. Why we collect it — and our lawful basis
We rely on the following lawful bases under UK GDPR / EU GDPR Article 6:
| What we do | Lawful basis |
|---|---|
| Provide and operate the platform for you | Contract (Art. 6(1)(b)) |
| Take payment | Contract (Art. 6(1)(b)) |
| Send service emails (password resets, security notices) | Contract / Legitimate interest (Art. 6(1)(b) / Art. 6(1)(f)) |
| Research and score public companies you ask us to track | Legitimate interest (Art. 6(1)(f)) — B2B research is widely recognised as a legitimate interest for the seller and the lawful processing of public information about businesses |
| Improve product quality, debug, and prevent abuse | Legitimate interest (Art. 6(1)(f)) |
| Comply with legal obligations (tax, fraud, court orders) | Legal obligation (Art. 6(1)(c)) |
| Send marketing emails (only if you opt in) | Consent (Art. 6(1)(a)) |
4. AI processing — how it works
Taurus uses third-party AI services (OpenAI and Perplexity) to research the public companies you ask us to track, score them, and generate intelligence reports. We want to be explicit about how that works:
- The data sent to OpenAI and Perplexity for research is limited to the company names you have asked us to research and the seller-context block you have configured in your account settings.
- We do not send your private CRM data, meeting transcripts, or stakeholder contact information to OpenAI or Perplexity for the public research step.
- Both OpenAI and Perplexity contractually agree, under their API terms in force at the time of writing, that prompts and responses sent via their API are not used to train their models.
- Strategic Fit reasoning produced by AI is grounded in cited public sources; we surface those citations to you on the Forecast page so you can verify the source of any AI-generated claim.
- We do not make any automated decisions about individuals that produce legal or similarly significant effects under Article 22 of the UK GDPR.
5. Who we share your data with — sub-processors
We use a small number of vetted sub-processors to operate the platform. We have a signed Data Processing Agreement (or equivalent) in place with each of them.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase | Database, authentication, file storage | EU (eu-west-2) | Within UK/EEA — no additional mechanism required |
| Vercel | Application hosting, serverless functions, edge CDN | Global edge with EU primary | Standard Contractual Clauses (SCCs) where applicable |
| OpenAI | Synthesis of public research into intelligence outputs | United States | Standard Contractual Clauses (SCCs) |
| Perplexity | Public research and citation retrieval | United States | Standard Contractual Clauses (SCCs) |
| Calendly | Demo booking | United States | Standard Contractual Clauses (SCCs) |
| Slack (optional) | Signal notifications, if you opt in | United States | Standard Contractual Clauses (SCCs) |
| GoDaddy | Domain registration and DNS | United States | Standard Contractual Clauses (SCCs) |
If we add or remove a sub-processor we will update this page and notify customer organisations with an active Data Processing Agreement.
6. International transfers
Some of our sub-processors are based in the United States. Where personal data is transferred outside the United Kingdom or the European Economic Area, we rely on the UK Addendum to the EU Standard Contractual Clauses (or equivalent legal mechanism in force at the time) to provide appropriate safeguards under UK GDPR Article 46.
7. How long we keep your data
| Category | Retention |
|---|---|
| Account details | For the life of your account, plus 30 days after closure |
| Billing records | 7 years (UK tax / company law requirement) |
| Account list and intelligence data you uploaded | For the life of your account, deletable on request at any time |
| Signal feed history | 200 entries per account or 90 days, whichever is greater |
| Server logs | 30 days |
| Marketing consent records | For the life of your consent + 3 years after withdrawal |
8. Your rights
Under UK GDPR and EU GDPR you have the following rights, which we will action within one calendar month:
- Right of access: ask us for a copy of the personal data we hold about you.
- Right to rectification: ask us to correct anything that is wrong.
- Right to erasure: ask us to delete your data where the lawful basis no longer applies.
- Right to restrict processing: ask us to pause processing while a dispute is resolved.
- Right to data portability: ask us to export your data in a structured machine-readable format.
- Right to object: object to processing based on our legitimate interest, including direct marketing.
- Rights related to automated decision-making: we do not perform automated decision-making under Article 22.
- Right to withdraw consent: where we rely on consent, you may withdraw it at any time.
- Right to complain to the ICO: if you believe we have handled your data unlawfully, you can complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.
To exercise any of these rights, email nick@taurusintelligence.com. We may ask you to verify your identity before fulfilling the request.
9. Cookies and similar technologies
We currently use only strictly necessary cookies (your authentication session). These cookies are exempt from consent requirements under the Privacy and Electronic Communications Regulations (PECR) because they are essential to providing the service you have asked for.
We do not currently use analytics, advertising, or marketing cookies. If we add them, we will ask for your explicit consent via a cookie banner before any non-essential cookie is set.
10. Security
We implement appropriate technical and organisational measures under UK GDPR Article 32, including: encryption in transit (TLS 1.2+) and at rest, role-based access controls, separation of production and non-production environments, signed agreements with each sub-processor, and minimum-necessary access for our own team.
If we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the ICO within 72 hours of becoming aware, and the affected individuals or customer organisations without undue delay.
11. Children's data
Taurus is a B2B platform aimed at business users. The platform is not directed at, and we do not knowingly collect personal data from, children under the age of 18.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified to registered users by email. The "last updated" date at the top of this page always reflects the most recent revision.
13. Contact us
For any question about this policy, or to exercise any of your rights, please contact:
Nick Markwell, Founder
Taurus Intelligence Ltd
Email: nick@taurusintelligence.com
You may also contact the UK Information Commissioner's Office at ico.org.uk if you have a complaint that we have not been able to resolve.