Legal · Effective August 5, 2026
Privacy Policy
How we collect, use, share, and protect personal data.
This Privacy Policy explains how Tenfold Research ("Tenfold", "we", "us") collects, uses, discloses, and protects personal data when you visit our website, contact us, apply for a role, or use our products and services, including w00t.ai (together, the "Services"). It applies wherever Tenfold acts as a controller of personal data — that is, wherever we decide why and how that data is processed.
Where we process personal data on a customer's behalf as a processor, that processing is governed by our Data Processing Addendum and by that customer's own privacy notice, not by this policy. Section 2 explains the boundary.
1. Who we are and how to reach us
Tenfold Research is the controller responsible for the personal data described in this policy. You can reach us about any privacy matter at hello@tenfoldresearch.com, and about the security of personal data at security@tenfoldresearch.com. For our registered entity details, or the contact details of a data protection officer or local representative where one is appointed, write to us at the address above and we will provide them.
2. Scope of this policy
Personal data we control. This policy covers the personal data we hold in our own right: enquiry and contact data, recruitment data, subscription data, account data about the people who use the Services on a customer's behalf, and usage and technical data about how the Services are accessed and perform.
Personal data we process for a customer. Content a customer submits to, or generates within, the Services is that customer's data, and we process it only on that customer's instructions under the Data Processing Addendum. If you are an individual whose personal data was submitted by an organisation using the Services, please direct requests to that organisation in the first instance; we will assist it in responding.
Other sites and products. This policy does not cover third party websites or services we link to, which have their own policies. Individual products or programmes may publish a supplementary notice where they involve materially different processing; where they do, that notice applies in addition to this one.
3. Personal data we collect
Contact and enquiry data. Your name, email address, organisation, role, and the content of your message when you contact us or make a partnership, media, or early access enquiry — including details about your organisation such as its website, markets, and licensing position where you choose to give them.
Recruitment data. Your name, email address, the information in your application, any links you share, and any résumé, CV, or supporting document you attach when you apply for a role or offer to contribute.
Subscription data. Your email address and the publication or report concerned, when you ask to receive research or to be notified on release.
Account data. Identifiers and profile details for people authorised to access the Services, such as name, work email address, organisation, role, and authentication and access records.
Usage and technical data. Data generated automatically when you use the Services or visit our website, such as IP address, approximate location derived from it, device and browser characteristics, the pages or features accessed, timestamps, referring pages, and the diagnostic and error information recorded in server logs.
Communications data. Records of our correspondence with you, including support requests and the notes we keep about an enquiry or a relationship.
We do not seek special categories of personal data — such as data revealing health, religion, ethnicity, or political opinions — and we ask that you do not send them to us unless we have specifically requested them for a lawful purpose. We do not collect payment card details or government identifiers through our website.
4. How we collect it
Directly from you, when you complete a form, send us a message, apply for a role, subscribe, or use the Services. Automatically, through the technical operation of our website and the Services, including hosting and server logs. From others, including the organisation that arranged your access to the Services, people who refer you, and public professional sources where relevant to a business relationship or a role.
Where a form marks a field as required, providing that data is necessary for us to act on your request; without it we may be unable to respond, assess an application, or provide access. Other fields are optional.
5. Why we use personal data, and our legal bases
To respond to you and manage relationships — answering enquiries, evaluating and progressing partnership and early access requests, and keeping our records of that correspondence. Legal basis: performance of a contract, or our legitimate interest in responding to business enquiries directed to us.
To provide, secure, and support the Services — authenticating users, delivering functionality, providing support, and preventing fraud, abuse, and unauthorised access. Legal basis: performance of a contract, and our legitimate interest in keeping the Services secure and reliable.
To operate, analyse, and improve — understanding how the Services are used, diagnosing faults, and developing our products, standards, and research. Legal basis: our legitimate interest in improving what we offer. Any research corpus we derive from activity in the Services is aggregated and anonymised so that it no longer identifies any individual.
To assess applications — evaluating candidates and communicating with you about a role or a contribution. Legal basis: our legitimate interest in recruiting, and steps taken at your request before entering a contract.
To send you what you asked for — publications, report access, and release notifications. Legal basis: your consent, which you may withdraw at any time, or our legitimate interest in business to business communications where applicable law permits it.
To meet legal and regulatory obligations — responding to lawful requests, keeping required records, and establishing, exercising, or defending legal claims. Legal basis: compliance with a legal obligation, and our legitimate interest in protecting our rights.
Where we rely on a legitimate interest, we weigh that interest against your rights and reasonable expectations, and you may object as described in section 11.
6. Cookies and similar technologies
Our website does not use advertising cookies, analytics cookies, or third party tracking technologies, and we do not build advertising profiles of visitors. Where our website or the Services use cookies or browser storage, it is strictly necessary — for example to keep you signed in or to remember a setting you chose.
Some pages load resources such as fonts from third party providers. Those providers necessarily receive your IP address and request data in order to serve the resource, and handle it under their own policies. If we introduce cookies or similar technologies that are not strictly necessary, we will give notice and, where required, obtain consent before doing so.
7. How we share personal data
We disclose personal data only as described below, and only to the extent needed for the purpose concerned.
Service providers acting for us. Categories include hosting and content delivery, email delivery and email hosting, productivity and collaboration tools, recruitment and support tooling, and AI model providers used to deliver the Services. Where a provider processes personal data on our behalf as a processor, it is bound by contract to process that data only on our instructions and to protect it. We can tell you which providers are engaged for a given purpose on request, and customers receive notice of changes to subprocessors under the Data Processing Addendum.
Providers of embedded third party resources. The resources described in section 6, such as fonts, are served by their own providers. Those providers are not acting on our instructions: they receive your IP address and request data as independent controllers and handle it under their own policies, and we do not control what they do with it.
Customers and their administrators. Where you access the Services under an organisation's account, that organisation's administrators may access the account and usage data associated with your access.
Professional advisers, authorities, and legal claims. Our auditors, lawyers, and insurers, and regulators, courts, or law enforcement where we are legally required to disclose, or where disclosure is necessary to establish, exercise, or defend legal rights, or to protect the rights, safety, or property of Tenfold or others.
Corporate transactions. A prospective or actual acquirer, investor, or successor, in connection with a financing, merger, acquisition, or reorganisation, subject to appropriate confidentiality protections.
We do not sell personal data, and we do not share it for cross context behavioural advertising or targeted advertising, as those terms are used in applicable privacy laws. We do not disclose personal data to third parties for their own marketing.
8. International transfers
We and our service providers operate in more than one country, so providing the Services may involve transferring personal data across borders, including to countries whose data protection laws differ from those where you are located. Before relying on such a transfer we put in place the safeguards that the applicable privacy laws require for it — for example approved contractual clauses between the parties — and take steps to ensure the data remains protected in the country it reaches. You can ask us which safeguard applies to a particular transfer at the address in section 1.
9. How long we keep it
We keep personal data only as long as we need it for the purposes in section 5, and then delete or anonymise it. In deciding how long that is, we consider how long the relationship or enquiry remains active, whether the data is needed to provide or secure the Services, any legal, accounting, or regulatory retention requirement, and whether the data may be needed for a legal claim.
Indicatively: enquiry and correspondence data is kept for the life of the relationship or enquiry and then retained in our ordinary email and business records; recruitment data is kept for a limited period after a decision so we can consider you for other roles, and longer only with your agreement; subscription data is kept until you unsubscribe; account data is kept for the term of the customer's agreement and a short period afterwards; and usage and technical logs are kept for the shorter operational periods appropriate to diagnostics and security. If you want to know the retention that applies to a particular category of personal data, ask us at the address in section 1 and we will tell you.
10. Security
We maintain technical and organisational measures appropriate to the risk of the processing, covering access control, encryption in transit and at rest where appropriate, separation of environments, logging, and confidentiality obligations for the people who handle personal data on our behalf. We also keep what we collect deliberately limited, which keeps the attack surface small. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If you believe you have found a vulnerability, email security@tenfoldresearch.com.
11. Your rights
Subject to applicable privacy laws, you may have the right to access the personal data we hold about you and receive a copy of it, to have inaccurate data corrected, to have data deleted, to restrict or object to certain processing including processing based on a legitimate interest, to receive data you provided in a portable format, and to withdraw consent at any time where we rely on it. Withdrawing consent does not affect processing already carried out.
If you are in a jurisdiction with consumer privacy rights, such as California, you may also have the right to know the categories and specific pieces of personal data we have collected, the sources, the purposes, and the categories of recipients; to request correction or deletion; to opt out of the sale or sharing of personal data and to limit the use of sensitive personal data — noting that we do not sell or share personal data for those purposes; and not to be discriminated against for exercising any right. An authorised agent may submit a request on your behalf with proof of authority.
To exercise a right, contact hello@tenfoldresearch.com. We may need to verify your identity, and to ask for enough information to locate the data, before we act. We respond within the period applicable law requires. You may also lodge a complaint with your local data protection or privacy supervisory authority, though we would appreciate the chance to address your concern first.
12. Automated decision-making
We do not make decisions that produce legal effects concerning you, or that similarly significantly affect you, solely by automated means. The Services use AI models as working tools, under human direction and review, and we do not use them to evaluate individuals or to profile visitors to our website.
13. Children
The Services are directed at industry professionals — operators, studios, regulators, and testing labs — and are not intended for children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Changes to this policy
We may update this policy as our Services, our operations, and applicable law evolve. We will update the effective date above when we do, and where a change materially affects how we use personal data we will give additional notice as required.
15. Contact
Questions about this policy, or a request about your own personal data: hello@tenfoldresearch.com.