Legal

Privacy policy

Last updated

Tessaly helps product teams understand how their customers use software. That means we process data about your users on your behalf, and data about you as our customer. This policy explains both, in plain language.

Who we are

Tessaly Inc. operates tessaly.com and the Tessaly analytics service. For data you send us about your own users, you are the controller and we act as your processor under our Data Processing Agreement. For your account data, we are the controller.

Data we collect

We collect only what we need to run the service and bill for it:

  • Account data: your name, work email, company name and role.
  • Billing data: billing address and the last four digits of your card. Full card numbers are held by our payment processor, never by us.
  • Product events you send through the Tessaly SDK or warehouse sync, such as page views, feature usage and plan changes.
  • Service logs: IP address, browser type and request timestamps, kept for 30 days for security.

How we use data

We use account and billing data to provide the service, send operational email and invoice you. We use product events only to compute the reports you ask for. We never sell data, and we never use your customers' events to train models or to benchmark you against other companies without your written consent.

Sharing and subprocessors

We share data only with subprocessors that help us run Tessaly, under contracts at least as protective as this policy. The current list, with each provider's purpose and location, is published on our subprocessors page. We notify customers 30 days before adding a new one.

Retention

  • Product events: for the retention period you choose in workspace settings, from 13 to 60 months.
  • Account data: for as long as your account is open, then 90 days.
  • Invoices: seven years, as required by tax law.

Your rights

Depending on where you live, you can ask us to access, correct, export or delete your personal data, or object to how we process it. To make a request:

  1. Email [email protected] from the address on your account.
  2. Tell us which right you want to exercise and for which workspace.
  3. We confirm within 3 business days and complete the request within 30 days.

Security

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Access to production is limited to on-call engineers, requires hardware keys and is logged. We are audited annually against SOC 2 Type II.

Questions about this policy or a request about your data? Our privacy team answers within three business days.

[email protected]