Legal

Privacy Policy

Version 1.0 · Last updated: May 8, 2026

This policy is a starting point provided for reference. Tessarac legal will provide the definitive policy. By using the Service you agree to the most recent version of this Privacy Policy published at this URL.

1. Scope and Roles

This Privacy Policy describes how Tessarac, LLC ("Tessarac", "we", "us", or "our") collects, uses, and shares personal information in connection with our marketing website at tessarac.com, the Tessarac platform (the "Service"), and related sales, support, and operational activities.

For personal information processed in the Service on behalf of a Tessarac customer (the "Customer"), Tessarac acts as a data processor and the Customer is the controller. The terms governing that processing are set out in theData Processing Agreement. For personal information collected through our marketing website, sales activities, support tickets, and billing operations, Tessarac acts as the controller.

2. Information We Collect

We collect personal information from the following sources:

2.1 Information you provide directly

  • Account information — name, business email, phone number, organization, role.
  • Authentication information — sign-in to the Service is handled through our authentication provider, which supports SSO, OAuth, passkeys, and multi-factor authentication. We collect the associated authentication metadata, such as your authentication-provider user identifier, MFA enrollment status, and sign-in timestamps.
  • Sales and support communications — content of emails, calls, chats, and demo requests.
  • Billing information — invoicing contact, payment method, billing address, tax IDs.

2.2 Information collected automatically

  • Usage data — pages visited, features exercised, time on page, referring URL.
  • Device and connection data — IP address, browser type, OS, screen resolution, time zone.
  • Operational telemetry — error logs, latency metrics, performance traces (anonymized where feasible) used to operate, secure, and improve the Service.

2.3 Information from third parties

  • Identity providers — when you sign in via SSO, your IdP shares the attributes you've authorized (typically name, email, group membership).
  • Marketing partners — limited contact data from publicly available sources or opt-in marketing partners, used only for prospecting and only where lawful.

3. How We Use Information

We use personal information for the following purposes:

  • Provide and operate the Service — authenticate users, route requests to the correct tenant, safeguard cryptographic material (including mint/rotation of platform keys and encryption of customer-provided provider API keys), enforce policy, and deliver platform features.
  • Secure the Service — detect and prevent fraud, abuse, security incidents, and policy violations; maintain audit logs required by compliance frameworks (SOC 2, ISO 27001, FedRAMP, HIPAA, PCI-DSS).
  • Customer support — respond to inquiries, troubleshoot issues, and notify customers about material service events.
  • Billing and account management — invoice for fees, process payments, and handle disputes.
  • Marketing — send product updates, newsletters, and event invitations to customers and opted-in prospects. You may opt out at any time via the unsubscribe link in each message.
  • Improve the Service — analyze aggregated, de-identified usage patterns to inform product and engineering decisions.
  • AI-assisted security analysis — triage security alerts using an AI model that only ever receives de-identified evidence: internal identifiers are tokenized and high-risk free-text is dropped before any model call, and the token-to-value map never leaves Tessarac. The model provider does not train on this data. SeeHow Tessarac uses your data for AI-assisted security analysis.
  • Legal compliance — comply with applicable laws, regulations, and lawful requests from governmental authorities.

4. Lawful Basis for Processing (GDPR)

For personal information subject to the EU/UK General Data Protection Regulation, we rely on the following lawful bases:

  • Performance of a contract — to provide the Service, process payments, and deliver customer support.
  • Legitimate interests — to secure the Service, prevent fraud, market our products to existing customers, and improve our offerings.
  • Consent — where required by law (for example, marketing emails to prospects in jurisdictions that require opt-in).
  • Legal obligation — to comply with applicable laws, court orders, and regulatory requirements.

5. How We Share Information

We share personal information only as described below. We do not sell personal information.

  • Sub-processors — vetted third-party service providers that operate hosting infrastructure, authentication and identity, payment processing, email delivery, customer support tools, and analytics. A current sub-processor list is published in ourTrust Center.
  • Customer's controller — when you use the Service via a Customer (your employer, for example), the Customer controls your personal information and our processing is governed by theData Processing Agreement.
  • Legal authorities — when required by law, court order, or to protect Tessarac's rights, users, or the public.
  • Business transfers — in connection with a merger, acquisition, or sale of all or part of our business, with notice to affected individuals where required by law.

6. International Data Transfers

Tessarac operates globally. Personal information may be transferred to and processed in jurisdictions outside your home country, including the United States. Where required by law, we implement appropriate safeguards, including Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Addendum.

Where offered for the applicable plan (US by default, with EU data residency available on Enterprise and Federal plans), Customers may select a regional Hosted SaaS deployment so that Customer Data resides within the chosen region. TheData Processing Agreementgoverns transfers of Customer Data.

7. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with our legal obligations, resolve disputes, and enforce our agreements. Default retention windows include:

  • Customer Data — for the duration of the subscription, then ninety (90) days post-termination.
  • Audit logs — twelve (12) months at minimum, longer where compliance frameworks require.
  • Billing records — seven (7) years for tax and audit purposes.
  • Marketing data — until you unsubscribe or two (2) years of inactivity, whichever is sooner.

8. Security Measures

Tessarac maintains commercially reasonable administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of personal information. Controls include:

  • encryption in transit (TLS 1.2+) and at rest (AES-256-GCM);
  • envelope encryption of secrets and customer-provided provider API keys, with key management via cloud key-management systems and BYOK/HYOK options (single-tenant HSM custody available as the Dedicated HSM add-on);
  • least-privilege access enforced through role-based access control and just-in-time elevation;
  • continuous vulnerability scanning, penetration testing, and a published responsible-disclosure program;
  • SOC 2 Type II audit controls; FedRAMP, ISO 27001, HIPAA, and PCI-DSS alignment per theTrust Center;
  • incident-response procedures with notification timelines that meet or exceed regulatory requirements.

No system is perfectly secure. While we work hard to protect personal information, we cannot guarantee absolute security.

9. Your Rights

Depending on your jurisdiction, you may have the right to: access, correct, or delete your personal information; object to or restrict certain processing; request portability of your data; and withdraw consent. To exercise these rights, contact us at privacy@tessarac.com. We will respond within the timeframe required by applicable law (typically thirty (30) days).

If your personal information is processed by Tessarac on behalf of a Customer (e.g., your employer), please submit your request directly to that Customer; we will support the Customer in fulfilling its obligations under applicable law.

10. CCPA / CPRA Disclosures (California)

California residents have the right to: know what personal information we collect, use, disclose, and retain; request access to and deletion of personal information; correct inaccurate personal information; limit the use and disclosure of sensitive personal information; and not be discriminated against for exercising these rights.

We do not sell personal information and we do not share personal information for cross-context behavioral advertising. Categories of personal information collected, purposes, and third-party recipients are described in this Privacy Policy.

To submit a verifiable consumer request under the CCPA/CPRA, email privacy@tessarac.com. You may also designate an authorized agent to make a request on your behalf.

11. GDPR Rights (EEA, UK, Switzerland)

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the GDPR (and equivalent laws):

  • Right of access — request a copy of personal information we hold about you.
  • Right to rectification — request correction of inaccurate or incomplete data.
  • Right to erasure — request deletion of personal information, subject to legal exceptions.
  • Right to restriction — limit how we use personal information.
  • Right to data portability — receive your data in a structured, commonly used format.
  • Right to object — object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent — withdraw consent at any time where processing is based on consent.
  • Right to lodge a complaint — with your local data protection authority.

12. Children's Privacy

The Service is intended for business use and is not directed at children under the age of sixteen (16). We do not knowingly collect personal information from children. If we learn that we have collected such information, we will delete it promptly.

13. Cookies and Tracking

The marketing website uses a small number of essential cookies to remember your theme preference and to maintain session state where applicable. We do not use third-party analytics cookies on the marketing website; we rely on server-side, privacy-respecting analytics that do not set tracking cookies.

Within the Service, we use first-party cookies for authentication, CSRF protection, and tenant routing. These cookies are essential to the Service's operation and cannot be disabled without breaking functionality.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-product notice at least thirty (30) days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

15. Contact and Data Protection Officer

For privacy questions or to exercise your rights, contact us at privacy@tessarac.com or viaour contact page.

See also: Terms of Service,Data Processing Agreement,Service Level Agreement.