Effective August 20, 2026
Tecosys (“Tecosys”, “we”, “us”) builds an AI operating system for SMBs and enterprises. We take the security and privacy of your data — and your customers’ data — seriously. This policy explains what we collect, how we use it, and the safeguards we apply, including our HIPAA, GDPR, and SOC 2 aligned practices.
We do not sell your personal data, and we do not use your customer content to train shared/foundation models without your explicit instruction.
For healthcare customers, Tecosys supports the handling of Protected Health Information (PHI) in accordance with the U.S. Health Insurance Portability and Accountability Act (HIPAA):
For individuals in the EU/EEA and UK, we process personal data under the General Data Protection Regulation (GDPR). Depending on the context, our lawful bases include contract performance, legitimate interests, legal obligation, and consent.
You have the right to:
For customer content, Tecosys acts as a data processor and processes personal data only on your documented instructions under a Data Processing Agreement (DPA). International transfers are protected using Standard Contractual Clauses (SCCs) where applicable.
Our controls are aligned with the SOC 2 Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, and Privacy). Our operating procedures for enterprise customers include:
We use vetted infrastructure and service providers (for example, cloud hosting, storage, and communications) to deliver the platform. Each sub-processor is bound by data-protection obligations at least as protective as this policy. A current list is available to enterprise customers on request.
We retain personal data only for as long as necessary to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. On termination, customer content is deleted or returned in accordance with your agreement and applicable law.
We use strictly-necessary cookies to run the site and optional analytics cookies to understand usage. You can control non-essential cookies through your browser settings.
For privacy questions, data-subject requests, or to request a BAA/DPA, contact our team at avishek@nutaan.com.
We may update this policy from time to time. Material changes will be posted on this page with a revised effective date.