Government and Law Enforcement Data Request Policy

Telltale AI Ltd. Co.
Last updated: 28 July 2026

Telltale AI Ltd. Co. ("Telltale") processes personal data on behalf of the merchants who use our retention platform. We occasionally receive requests from courts, law enforcement, regulators, or other public authorities seeking access to that data. This policy sets out the process we follow whenever such a request arrives. It applies to all personal data we hold, including data obtained from third-party platforms such as advertising and commerce providers.

1. Every request receives a legality review

We do not disclose data in response to an informal or voluntary request.

Before any data is disclosed, the request is reviewed to confirm that:

  • it is made under a valid, identified legal authority;
  • the requesting authority has jurisdiction over Telltale and over the data sought;
  • it has been served through the correct legal process for the data requested; and
  • it is specific enough to identify what is actually being sought.

If any of these cannot be established, we do not disclose data. Requests that arrive by email, telephone, or other informal channels are not actioned until they are properly served, except where there is a genuine, imminent risk of death or serious physical injury, which is handled under the emergency process in section 5.

2. We challenge requests that are overbroad or unlawful

Where a request appears to be unlawful, overbroad, vague, or inconsistent with the rights of the individuals concerned, Telltale will object to it. Depending on the circumstances, we will seek to narrow its scope, require the authority to use the correct legal process, or formally challenge or move to quash it, including through counsel where appropriate.

We do not treat a request as valid simply because it comes from a public authority.

3. We disclose the minimum data necessary

Any disclosure is limited to the narrowest set of data that is actually responsive to the request. We do not provide bulk exports, whole database extracts, or entire customer records where a targeted subset answers the request. Where a request can be satisfied with aggregated, de-identified, or hashed data, we provide that in preference to identifiable personal data.

Personal data we hold is minimised by design: customer email addresses are stored as one-way cryptographic hashes, and third-party access credentials are encrypted at rest.

4. We document every request

For each request received we record:

  • the requesting authority and the date received;
  • the legal instrument or authority relied on;
  • the data sought and the data actually disclosed, if any;
  • the legal reasoning applied, including the basis for any objection or refusal; and
  • the individuals within Telltale who reviewed, approved, or responded to the request.

These records are retained so that our handling of any request can be reviewed after the fact.

5. Emergency requests

Where an authority asserts a genuine emergency involving an imminent risk of death or serious physical injury, we may disclose the minimum information necessary to address that risk without waiting for formal process. Emergency disclosures are documented under section 4 in the same way as all other requests, including the basis on which the emergency was assessed.

6. Notice to affected merchants

Where Telltale acts as a processor for a merchant, our default position is to redirect the authority to that merchant, who controls the data. Where we are nonetheless required to respond directly, we will notify the affected merchant so they can seek to protect their own interests, unless we are legally prohibited from giving notice or an emergency under section 5 applies. Where a non-disclosure obligation is imposed, we will seek to limit its duration and notify the merchant once it lapses.

7. Contact

Legal requests should be directed to lisa@telltale.pro. Requests sent to other addresses may not be actioned.