For your company.
Company members can read Public work. Collaborators can read Public work only in the subjects they have been given, plus their own posts.
SECURITY & PRIVACY
Understand who can access your company’s work, where it is processed and how to manage it.
Company members can read Public work. Collaborators can read Public work only in the subjects they have been given, plus their own posts.
Only the person who wrote it and the subject’s current owners can read it. Before it has a subject, only its author can. Administrators have no automatic reading exception.
Only the people in a talk can read it. Company admins can’t open it. Someone added later reads from the moment they join. Decisions and tasks that leave a talk keep the visibility chosen for them.
Like a talk, only its members can read it. Inside it, the AI reads only that brainstorm’s messages, and only what every current member can read.
You choose Public or Private when you write. Replies and attachments follow the same rule as the post they belong to.
Database access controls separate each company’s data. Company members can read Public work. Collaborators can read Public work in their granted subjects and their own posts.
Private work is limited to its author and current subject owners. Administrators have no automatic reading exception. Replies and attachments follow the post’s access rules.
Access changes reach disconnected devices when they reconnect. Handled is not end-to-end encrypted.
Your data is stored in the EU (Frankfurt) and is never used to train AI. That is where the database and attachment storage sit; Handled works the same from the United States or anywhere else. The API runs on Railway in the EU (Netherlands) and processes request content there. Web hosting, email and the AI model that matches posts to subjects, drafts wrap-ups, draws brainstorm maps and answers Ask AI can process data outside the EU, including in the United States; a company can turn AI matching off. Handled does not offer EU-only processing.
The Data Processing Agreement lists providers, transfer arrangements and limitations, including account-specific safeguards and retention periods that remain unverified.
Web and desktop connections use HTTPS. The production database connection verifies its TLS certificate. Email sign-in links work once and expire after 15 minutes; the server stores hashes of sign-in and session tokens.
Google sign-in is available when configured. Microsoft sign-in is currently unavailable; Microsoft directory connections are a separate feature. Handled does not provide its own second factor or enterprise single sign-on. Your identity provider may apply its own authentication policy.
The native app encrypts saved workspace data and uses the operating system credential store. Browser workspace storage does not have that native encryption protection. Protect access to your device and any files you download or export.
Configured AI can route work and prepare suggestions. Requested setup, conversation assistance and delegated-agent actions can send relevant context to a model provider. People review setup proposals and approve agent results. AI output can be wrong and needs review.
Directory connections use read-only access and prepare drafts for review. Importing does not automatically invite people or change ownership. Feature availability depends on configuration. The AI purpose statement and Privacy Policy explain the data involved.
Authorized administrators can export available records as JSON. The export includes attachment metadata; files require separate authorized downloads. Contact us if these tools do not meet your data-return needs.
Workspace personal data is deleted from the active service within 30 days of account closure. Individual erasure requests have a separate 7-day grace period. Removing access alone does not delete company records, and retained company text may still identify a person.
Handled-managed recovery archives have a separate limit of 35 days after active-service erasure. Provider-held copies and operational records have different periods and exceptions. See the retention schedule. Previously agreed stronger deletion rights remain in force.
We’re glad to support your security review — we can share available security documentation and answer your company’s questions. Handled has completed an internal adversarial security review and addressed the findings, and the safeguards described here and in the DPA are actively maintained.
The DPA describes our data-protection commitments, retention limits and safeguards. The Terms contain the commercial commitments. This page does not replace those agreements.
Connecting Outlook does not enable background checks. Where available, each person can choose to enable checks of their own Inbox and Sent Items, then review private suggestions and prepare reply drafts. No reply is sent and no company work is published automatically.
Suggestions and supporting excerpts are encrypted, restricted to that person and expire after 30 days. Keyed dismissal records contain no message text and expire after 90 days. People can pause checks, turn them off, disconnect Outlook and export their own source-validated suggestions. The Privacy Policy and DPA describe model processing and separate backup retention.
Contact hello@handledspace.com about security, privacy or access to your data. We assess incidents and notify affected customers and authorities where required.
Handled is operated by TON Creative Studios AB, Sweden.
FREE FOR YOUR WHOLE COMPANY FOR 30 DAYS
Bring your whole team in from day one.
Everyone is free for the first 30 days.
Create your company, show the join code at your next meeting, and everyone is in. After 30 days the first three people stay free.
Create your free accountFirst 3 people free. USD 6.99 per additional person or activated AI agent, per month, excluding VAT.
Already have an account? Sign in ↗