Legal

Privacy Policy

Effective August 20, 2026

Tecosys (“Tecosys”, “we”, “us”) builds an AI operating system for SMBs and enterprises. We take the security and privacy of your data — and your customers’ data — seriously. This policy explains what we collect, how we use it, and the safeguards we apply, including our HIPAA, GDPR, and SOC 2 aligned practices.

1. Information we collect

  • Account & contact data — name, work email, company, role, and billing details when you sign up or book a demo.
  • Customer content — data you or your users submit into the platform (leads, call transcripts, chat messages, CRM records, documents, and knowledge bases).
  • Usage & device data — log data, IP address, browser type, and product interactions used to operate and improve the service.
  • Cookies — strictly-necessary and analytics cookies (see section 9).

2. How we use information

  • To provide, maintain, and secure the platform and its AI agents.
  • To process transactions and provide customer support.
  • To detect, prevent, and investigate fraud, abuse, and security incidents.
  • To comply with legal obligations and enforce our agreements.

We do not sell your personal data, and we do not use your customer content to train shared/foundation models without your explicit instruction.

3. Data security

  • Encryption — data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Access control — least-privilege access, role-based permissions, and audited administrative actions.
  • Isolation — logical tenant separation so one customer’s data is never exposed to another.
  • Monitoring — continuous logging, alerting, and vulnerability management.
  • Secrets management — credentials and keys are stored in managed secret vaults, never in source code.

4. HIPAA compliance

For healthcare customers, Tecosys supports the handling of Protected Health Information (PHI) in accordance with the U.S. Health Insurance Portability and Accountability Act (HIPAA):

  • We enter into a Business Associate Agreement (BAA) with covered entities and business associates before any PHI is processed.
  • Administrative, physical, and technical safeguards under the HIPAA Security Rule are applied to all systems that store or transmit PHI.
  • PHI access is restricted to authorized personnel on a strict need-to-know basis and is fully audit-logged.
  • Breach notification procedures are maintained in line with the HIPAA Breach Notification Rule.

5. GDPR & data subject rights

For individuals in the EU/EEA and UK, we process personal data under the General Data Protection Regulation (GDPR). Depending on the context, our lawful bases include contract performance, legitimate interests, legal obligation, and consent.

You have the right to:

  • access, rectify, or erase your personal data;
  • restrict or object to processing;
  • data portability;
  • withdraw consent at any time; and
  • lodge a complaint with your supervisory authority.

For customer content, Tecosys acts as a data processor and processes personal data only on your documented instructions under a Data Processing Agreement (DPA). International transfers are protected using Standard Contractual Clauses (SCCs) where applicable.

6. SOC 2 & operational practices

Our controls are aligned with the SOC 2 Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, and Privacy). Our operating procedures for enterprise customers include:

  • documented change-management and CI/CD with peer review before production releases;
  • encrypted, access-controlled backups and tested disaster-recovery procedures;
  • vendor/sub-processor due diligence and ongoing risk review;
  • employee security training and background checks where permitted by law;
  • a formal incident-response plan with defined severity levels and timelines.

7. Sub-processors

We use vetted infrastructure and service providers (for example, cloud hosting, storage, and communications) to deliver the platform. Each sub-processor is bound by data-protection obligations at least as protective as this policy. A current list is available to enterprise customers on request.

8. Data retention

We retain personal data only for as long as necessary to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. On termination, customer content is deleted or returned in accordance with your agreement and applicable law.

9. Cookies

We use strictly-necessary cookies to run the site and optional analytics cookies to understand usage. You can control non-essential cookies through your browser settings.

10. Contact us

For privacy questions, data-subject requests, or to request a BAA/DPA, contact our team at avishek@nutaan.com.

We may update this policy from time to time. Material changes will be posted on this page with a revised effective date.