# Raintree Security, Data Handling & GDPR Readiness

A plain-language overview of Raintree's approved-source access, customer controls, saved context, EU hosting, and GDPR-ready data handling. See https://raintree.tech/security for the full interactive page.

Raintree Technologies Company Limited is at 45/18, Moo 7, Bang Phra Subdistrict, Si Racha District, Chonburi Province 20110, Thailand. Raintree servers are located within the European Union. This statement concerns Raintree servers and does not mean every connected provider is EU-hosted.

## Website and analytics (https://raintree.tech/security)

Privacy-safe Umami analytics is optional. Where enabled, automatic tracking is off, search terms and URL hashes are excluded, routes and event payloads are sanitized, and DNT/GPC signals prevent tracking. If analytics is not configured for a surface, there is no Umami measurement there. No universal analytics retention period is set on this page.

## Enquiries and onboarding

The contact form asks for name, email, optional organization, and message; Turnstile helps limit automated abuse. Onboarding asks about company, contact, workflow, source intent, preferred channel, setup mode, and notes. Use this information to respond and discuss an appropriate onboarding path. Do not send sensitive personal data in an initial enquiry — start with a high-level description at https://raintree.tech/security.

## Customer data and connected sources

A customer workspace processes information made available for the configured company and agreed use. Depending on setup, approved sources can include Slack, Microsoft Teams, LINE, Gmail, Google Drive, and Google Calendar, obtained through approved permissions and provider connections. Sources, rules, and saved context are kept separate by company in a private memory store and remain scoped to that company's workspace. Connecting a provider does not mean unrestricted access. A write or send remains within the explicit approval boundaries established for the workflow.

## EU hosting, retention, rights

There is no universal retention or deletion period covering every activity or provider — the applicable detail is recorded in the formal policy or customer-specific agreement where established. Where hosting, transfers, or retention are material, request current details before connecting a source. Depending on applicable law, you may have rights to access, correction, erasure, restriction, portability, objection, consent withdrawal, or complaint to a supervisory authority. Contact privacy@raintree.tech. See https://raintree.tech/capability-claims.md for the audited platform ledger.
