Legal
Privacy Policy
Last updated: September 24, 2026
1. Who we are
This policy is published by TERTIQ ("we", "us", "our"), the operator of the TERTIQ platform and service. Registered office and principal place of business details are available to account holders on request through their account team.
For privacy matters, contact your account team, or the privacy correspondence channel established for your workspace. General privacy enquiries may also be addressed through in-application feedback. For enquiries handled under the privacy oversight channel, please also address correspondence to a designated privacy oversight channel. Where a Data Protection Officer is formally appointed under applicable law, their contact details are provided to account holders on request.
2. Scope of this policy
This policy describes how we handle personal data when you use the TERTIQ application, our public website, customer support channels, and related services (collectively the “Service”). It covers account holders, their team members, supplier contacts entered into the product, and visitors to our site.
This policy does not replace any contract, data processing agreement, or customer terms you may have with us. If a signed agreement conflicts with this policy, the agreement takes precedence.
3. Data we collect
We limit collection to information reasonably necessary to deliver, secure, and support the Service. Categories include:
- Account information. Work email address, display name, role, organization (workspace) assignment, and any profile preferences you set.
- Authentication records. Session tokens, email verification tokens, and login timestamps required to deliver passwordless sign-in and protect against abuse.
- Supplier and vendor data submitted by users. Supplier names, service categories, jurisdictions, contact names, contact emails, phone numbers, assessment answers, evidence metadata, findings, remediation assignments, and any other content you or your team enter into a workspace.
- Service and security logs. Request metadata, timestamps, error reports, IP-based coarse geographic data, user-agent strings, rate-limit counters, and internal telemetry required to operate, scale, and secure the platform.
- Email communications. Content and headers of messages you send to support, sales, or disclosure contacts, and records of transactional emails sent by the Service (sign-in links, notifications you opted into).
- Billing and subscription metadata. If you purchase a paid plan, TERTIQ stores reference information needed to operate your subscription, such as the Stripe customer identifier, the Stripe subscription identifier, the specific plan or price reference, the current subscription status reported by Stripe, billing period start and end dates, and any cancellation-at-period-end flag. TERTIQ does not store full payment card numbers or card security codes (CVC/CVV) in its own database; payment details are provided directly to Stripe during checkout and are processed by Stripe under its own privacy and security practices.
We do not operate advertising, affiliate, or third-party behavioural tracking on our public site or in the application. Please also see our Cookie Policy.
4. Why we process data
We process each category above for one or more of the following lawful bases, as applicable under the laws applicable to your use of the service. The relevant supervisory authority and jurisdiction details for your account are documented in any executed customer agreement, or are available on request.
- Performance of a contract with you, or to take steps before entering one.
- Your consent, where we specifically ask for it and you can withdraw it.
- Our legitimate interests, proportionally pursued (security, abuse prevention, product improvement, legal claims).
- A legal or regulatory obligation to which we are subject.
5. Infrastructure and sub-processors
Data is processed and stored using a small set of reputable infrastructure and support providers. Current categories include PostgreSQL database hosting, serverless compute and edge delivery, transactional email delivery, optional object storage for evidence uploads, and subscription payment processing via Stripe.
Stripe is used exclusively to process subscription payments. Billing and payment information necessary to complete a transaction may be provided directly to Stripe by you during checkout; TERTIQ only stores the subscription reference metadata described in Section 3 above. Stripe processes your payment information under its own privacy and security practices.
Details of the providers used, their roles, and processing locations are maintained ina current subprocessor list maintained by TERTIQ and made available to account holders on request. Changes are communicated to active account administrators.
6. Data retention principles
We retain personal data only for as long as the purpose for which it was collected continues, or as long as the law requires or permits. Illustrative periods:
- Active account and workspace data: retained for the life of your subscription.
- Authentication logs and security records: a bounded rolling window, subject to commercially reasonable retention windows calibrated to the purpose of collection, applicable law, tax, accounting, and operational requirements. Retention schedules for specific categories are available to account holders on request.
- Supplier and vendor records entered by users: owned by your workspace; retained until deleted by an authorized workspace owner or legal hold ends.
- Support correspondence: retained for a reasonable period after case closure.
- Tax, accounting, and compliance records: retained as required by applicable law.
Where you close your workspace or request deletion, we remove or anonymize your data within a commercially reasonable window, subject to legal holds, backup restoration cycles, and records we are required to keep.
7. Your rights
Subject to applicable law, you may have the right to: access your personal data; request correction or deletion; restrict or object to processing; request data portability; withdraw consent previously given; and, where processing is based on legitimate interests, object on grounds relating to your particular situation.
To exercise these rights, or to raise a concern, write to your account team, or the privacy correspondence channel established for your workspace. General privacy enquiries may also be addressed through in-application feedback. We will respond within the timeframe required by applicable law. If you remain unhappy, you may have the right to lodge a complaint with your local supervisory authority, as referenced in the laws applicable to your use of the service. The relevant supervisory authority and jurisdiction details for your account are documented in any executed customer agreement, or are available on request.
8. Children
The Service is not directed to individuals under the age of majority, and we do not knowingly collect personal data from children. If we become aware of such collection, we will take steps to delete it.
9. Changes to this policy
We may update this policy from time to time. Material changes will be notified by in-app notice or email to the primary contact on your account before they take effect. The “Last updated” date at the top of this page always reflects the current version.
10. Contact
Questions, requests, or complaints about this policy or our handling of personal data should be addressed to your account team, or the privacy correspondence channel established for your workspace. General privacy enquiries may also be addressed through in-application feedback. with a copy to the privacy oversight channel referenced above, where applicable.
Security-specific concerns should follow the responsible disclosure process listed on our Security page.
