Cuddly.

Security & privacy

Your deal data is not our leverage.

We hold M&A cultural findings — the sort of thing a target would rather not see quoted back at them. What follows is what we do about it, what you can do about it, and what we can’t yet honestly claim.

Where the data lives

EU-hosted, Postgres-native, encrypted in transit and at rest.

Every engagement is stored in a Postgres database hosted in the European Union. Traffic between your browser and the platform is TLS-only; storage is encrypted at rest. Backups run daily to encrypted object storage inside the same jurisdiction, with an off-site mirror to a second EU region — see the deployment runbook for the retention and restore-drill schedule.

  • Primary region: EU (Postgres + application tier)
  • TLS-only traffic (HSTS enforced)
  • Encryption at rest via provider-managed keys
  • Daily backups + quarterly restore drills

Who can see it

Role-aware permissions per engagement — including us.

Access to an engagement is decided by that engagement's member roster, not by which company an account belongs to. Takko Advisory staff have no read access to your engagement unless you invite them. The superadmin role — used for support and platform operations — is restricted to @takkoadvisory.com email domains; every access it performs is written to an audit event you can query at any time.

  • Six engagement roles: lead_advisor · analyst · orchestrator · deal_sponsor · integration_lead · hr_lead
  • Only the roles you invite see the engagement
  • Superadmin restricted to Takko domain; all access audited
  • Audit log visible to you — filter by actor, date and event type

Getting it back — and deleting it

Full export any time. GDPR erasure on request.

Your canvas, friction register, evidence and reports are exportable as JSON (canvas) and PDF (memos + packs) at any point from inside the platform. On subscription end nothing is deleted — the engagement drops to read-only until you decide. If you invoke your right to erasure, the request is processed within the statutory window and completion is confirmed via the audit trail.

  • Export canvas + config as JSON from every engagement
  • Export Culture Risk Memo + Deal Committee Pack as branded PDFs
  • Read-only on subscription expiry — nothing is deleted
  • GDPR Article 17 erasure endpoint — request via legal@thecuddly.app

What we don't yet have

Honest gap section.

Cuddly is a young platform. Some certifications and controls typical for enterprise SaaS are not yet in place; we are open about it rather than smooth over. When the below become true, this section shrinks.

  • SOC 2 Type II — not yet in scope; a Type I is on the FY-26 roadmap
  • ISO 27001 — not certified
  • SSO (SAML / OIDC) — Enterprise plan feature; wiring live for Google + Microsoft Entra pending OAuth-app registration
  • Bug-bounty programme — not yet launched

Legal documents

For the binding contract text, jurisdiction and data-processing terms, see the legal surfaces below.

Terms of ServicePrivacy policyData Processing AddendumCookies