Skip to content

Introduction

01 / 20

The TISA · Legal

Privacy Policy

How we collect, use, protect, and share your personal information — and the choices you have.

Effective January 2025Updated August 4, 202620 sectionsinfo@thetisa.com
00

Introduction

Why this policy exists and who it covers.

Welcome to The TISA – Your Trusted AI-Powered Software Development Partner.

At The TISA - AI Powered Software Development Company, we are deeply committed to protecting your privacy and ensuring complete transparency in how we collect, use, process, and safeguard your personal information. This Privacy Policy outlines our comprehensive privacy practices and explains how we handle data from our clients, service users, website visitors, and business partners.

We believe that privacy is a fundamental right, and we've built our operations around the principle that respecting your data is not just a legal obligation, but a core value that defines our company culture.

01

1. Information We Collect

What you give us, what we gather automatically, and what we never seek out.

We collect information that helps us deliver exceptional software development services, improve our offerings, and maintain secure communications. Here's what we collect and why:

1.1 Information You Provide Directly

A. Account & Registration Information

Full name, email address, phone number
Company name, job title, business type
Billing and shipping addresses
Username and password (encrypted)
Professional background and experience
Communication preferences

Where collected: Contact forms, service registration, account creation, subscription pages

B. Service Engagement Information

Project specifications and requirements
Technical documentation and code repositories
Business objectives and goals
Budget and timeline information
Communication records (emails, messages, calls, video conferences)
Feedback and testimonials
Support tickets and inquiries

Where collected: Project intake forms, meetings, service agreements, support channels

C. Payment Information

Credit card details, bank account information
Billing address and payment history
Invoice records and transaction receipts
Tax identification details (for invoicing purposes)

Important

We do NOT store full credit card details on our servers. Payment processing is handled by industry-standard, PCI-DSS compliant payment gateways. See Section 1.5 for details.

D. Communication Data

Content of emails, messages, and correspondence
Call recordings (only with consent)
Video conference recordings (only with consent)
Chat logs and support conversations
Feedback, suggestions, and complaints

Consent Required: We only record calls/videos with explicit written consent from all parties.

1.2 Information Collected Automatically

A. Website & Platform Analytics

IP address (to determine location and identify abuse)
Device information (operating system, browser type, device type)
Cookie data (tracking preferences, session information)
Pages visited and time spent on each page
Referral source (how you found us)
Search queries on our website
Click patterns and navigation behavior
Log data (access times, files requested)

Purpose: Improve user experience, identify technical issues, detect security threats, understand audience demographics

Tools Used: Google Analytics 4, Hotjar, Microsoft Clarity (See Section 5: Cookies & Tracking)

B. Behavioral & Interaction Data

Form submissions and responses
Download history
API usage patterns (if using our development APIs)
Resource access logs
Feature usage analytics
Error reports and crash data

1.3 Third-Party Information Sources

We may receive information about you from:

Business partners - Project referrals, partnership data
Payment processors - Transaction verification data
Public databases - Company information verification
Social media platforms - Profile data (if you connect via social login)
CRM systems - Client interaction history
Email providers - Email engagement metrics
LinkedIn & professional networks - Professional background verification

Note: We only use third-party data where legally permissible and transparently disclosed.

1.4 Special Categories of Data

We do NOT intentionally collect sensitive personal data such as:

Race, ethnicity, or national origin
Religious or political beliefs
Sexual orientation or gender identity
Biometric data or genetic information
Health or medical information
Trade union membership

Exception: If you voluntarily provide such information (e.g., in project requirements), we will:

  1. 1

    Treat it with the highest level of protection

  2. 2

    Use it only for the stated purpose

  3. 3

    Ensure strict access controls

  4. 4

    Comply with GDPR Article 9 and equivalent regulations

1.5 Payment Information & PCI Compliance

We prioritize payment security through:

Zero-knowledge payment processing - We don't store credit cards on our servers
PCI-DSS Level 1 compliance - Highest industry security standard
Tokenization - Payment details converted to secure tokens
SSL/TLS encryption - All payment data encrypted in transit

Trusted payment partners:

Stripe (PCI Level 1)
PayPal (PCI Compliant)
2Checkout (PCI DSS Certified)

Your payment data is handled exclusively by these third-party processors. We have Data Processing Agreements (DPAs) with all payment providers.

02

2. How We Use Your Information

The legitimate purposes for which we process your data.

We use collected information for specific, legitimate purposes. Here's exactly how we use your data:

2.1 Service Delivery & Fulfillment

Primary Purpose: Provide software development services

Creating and managing your account
Processing service requests and support tickets
Delivering custom software solutions
Project management and updates
Quality assurance and testing
Technical support and troubleshooting
Invoicing and billing

Legal Basis: Performance of contract (we need this to serve you)

2.2 Communication & Notifications

Purpose: Keep you informed

Responding to inquiries and support requests
Sending project updates and milestones
Notifying about account changes
Service announcements and maintenance alerts
Newsletter and marketing communications (with consent)
Compliance notices and legal updates

Your Control: You can manage communication preferences in your account settings or via unsubscribe links in emails

2.3 Business Intelligence & Improvement

Purpose: Enhance our services

Analyzing user behavior to identify pain points
Understanding feature usage and adoption
Improving website performance and UX
Developing new features based on demand
Identifying market trends in software development
Training our AI models (anonymized data only)

Legal Basis: Legitimate business interest in service improvement

Data Protection: We use anonymization and aggregation for analytics. Individual user behavior is not profiled.

2.4 Marketing & Business Development

Purpose: Grow our business responsibly

Email marketing campaigns (with opt-in consent)
Webinar invitations and event announcements
Case study opportunities (with explicit written consent)
Product launch updates to relevant audiences
Industry insights and thought leadership content
Partnership identification and business development

Your Rights:

Opt-out of marketing at any time
Control marketing preferences
Request removal from all lists
No automated decision-making

Important

We will never use your project data in marketing without explicit consent. Case studies require written approval from you.

2.5 Security & Fraud Prevention

Purpose: Protect your data and prevent misuse

Detecting and preventing fraud, abuse, and unauthorized access
Investigating security incidents and breaches
Implementing security measures
Monitoring for suspicious activity
Preventing DDoS attacks and hacking attempts
Compliance with legal obligations

Legal Basis: Legal obligation and legitimate interest in security

2.6 Legal Compliance & Obligations

Purpose: Meet regulatory requirements

Complying with GDPR, CCPA, and other privacy regulations
Responding to legal requests and court orders
Maintaining compliance records
Tax compliance and financial reporting
Contractual obligation fulfillment

Transparency: We will inform you of legal requests unless legally prohibited from doing so.

2.7 AI Model Training (Anonymized Only)

Important

The TISA uses AI-powered tools for software development.

How we handle data for AI:

Only anonymized, aggregated data used for model improvement
No personal data is used to train AI models
Code samples are pseudonymized (names/IDs removed)
No sensitive business information in training data
Separate storage from production systems

Your Control: You can opt-out of analytics data being used for model improvement. Learn more about our AI practices →

03

3. How We Protect Your Data

Technical, organizational, and compliance measures we use to keep data safe.

At The TISA, data security is non-negotiable. We implement enterprise-grade security measures:

3.1 Technical Security Measures

A. Encryption

Data in Transit:

TLS 1.3 protocol for all communications
256-bit AES encryption for data transmission
Certificate pinning for API communications

Data at Rest:

AES-256 encryption for stored data
Database-level encryption
Field-level encryption for sensitive data
Encrypted backups with separate key management

B. Access Controls

Role-Based Access Control (RBAC) - Employees access only necessary data
Multi-Factor Authentication (MFA) - Required for all admin accounts
Zero-Trust Architecture - Every access request verified
Least Privilege Principle - Minimum necessary permissions granted
Audit Logging - All data access recorded and monitored

C. Infrastructure Security

Cloud Security: ISO 27001 certified data centers
Network Security: DDoS protection, WAF (Web Application Firewall)
Intrusion Detection: 24/7 monitoring for threats
Vulnerability Scanning: Regular penetration testing and security audits
Incident Response: Security Operations Center (SOC) monitoring

3.2 Organizational & Administrative Security

A. Employee Training

Annual Security Training: Mandatory for all employees
Data Privacy Certification: All staff complete privacy training
Phishing Simulations: Regular testing and awareness programs
Code of Conduct: Strict data handling guidelines

B. Data Protection Policies

Data Retention Policy: See Section 4: Data Retention
Data Classification: Sensitive data flagged and protected
Incident Response Plan: 24/7 breach response procedures
Vendor Management: Strict security requirements for third parties

C. Compliance Certifications

ISO 27001 - Information Security Management
SOC 2 Type II - Security, availability, and confidentiality
GDPR Compliant - EU data protection standards
CCPA Compliant - California privacy law
HIPAA Ready - Healthcare data standards (if needed)
PCI-DSS Level 1 - Payment card industry standards

3.3 What We Can't Guarantee

Important Disclaimer

While we implement robust security, no system is 100% secure.

We commit to:

Using industry-standard security practices
Maintaining continuous security monitoring
Promptly addressing vulnerabilities
Transparently reporting breaches (within 72 hours)

However, you should understand that:

Online transmission carries inherent risks
No guarantee against sophisticated cyberattacks
Your password security is your responsibility
Public networks (WiFi) are inherently less secure

Your Responsibility: Use strong passwords, enable MFA, keep devices updated, and avoid sharing login credentials.

04

4. Data Retention & Deletion

How long we keep data and how you can ask us to erase it.

We retain information only as long as necessary. Here's our retention schedule:

4.1 Retention Schedule

Data Type

Account Information

Retention Period

During service + 3 years after termination

Reason

Tax compliance, dispute resolution

Data Type

Transaction/Payment Records

Retention Period

7 years

Reason

Tax and legal requirements

Data Type

Project Documentation

Retention Period

Duration of project + 2 years

Reason

Warranty claims, bug fixes

Data Type

Support Tickets

Retention Period

3 years

Reason

Customer service continuity

Data Type

Email Communications

Retention Period

2 years (business) / 6 months (marketing)

Reason

Business records, compliance

Data Type

Website Analytics

Retention Period

26 months

Reason

Google Analytics retention limit

Data Type

Cookies & Tracking

Retention Period

See Section 5

Reason

Session to 2 years

Data Type

Call Recordings

Retention Period

90 days (if approved)

Reason

Quality assurance purposes

Data Type

API Logs

Retention Period

90 days

Reason

Security and troubleshooting

Data Type

Deleted Accounts

Retention Period

30 days (recovery period) then permanent deletion

Reason

GDPR right to erasure

4.2 Data Deletion Process

When data reaches end-of-life:

  1. 1

    Secure Deletion: Data permanently deleted using NIST guidelines

  2. 2

    Multiple Overwrites: Sensitive data overwritten 3+ times

  3. 3

    Cryptographic Erasure: Encryption keys destroyed permanently

  4. 4

    Verification: Independent confirmation of deletion

  5. 5

    Audit Trail: Documented for compliance purposes

4.3 Your Deletion Rights

You have the right to request deletion:

Right to Erasure (GDPR Article 17) - Request account deletion
Complete Profile Removal - All personal data removed
Data Portability (GDPR Article 20) - Export your data first
Right to Be Forgotten - Removal from marketing lists

How to Request: Email info@thetisa.com with "Data Deletion Request" in subject line

Our Response Time: Within 30 days (GDPR compliant)

Exceptions: We may retain data if legally required (tax, legal compliance, active disputes)

05

5. Cookies, Tracking Technologies & Analytics

How cookies and analytics work on our site, and how you control them.

5.1 What Are Cookies?

Cookies are small files stored on your device to remember preferences and track behavior. We use cookies for:

Session management (keeping you logged in)
User preferences (language, theme settings)
Analytics and performance monitoring
Security and fraud prevention
Personalized content recommendations
Marketing attribution and retargeting

5.2 Types of Cookies We Use

A. Essential Cookies (Required)

Cookie Name

session_id

Purpose

Maintain login session

Duration

Session (until logout)

Opt-out

Not possible (required for service)

Cookie Name

csrf_token

Purpose

Prevent cross-site attacks

Duration

Session

Opt-out

Not possible (security)

Cookie Name

user_preferences

Purpose

Save language/theme choices

Duration

1 year

Opt-out

Yes (via settings)

B. Analytics Cookies (Consent Required)

Tool

Google Analytics 4

Purpose

User behavior, traffic sources

Data Collected

Pages visited, time on site, referrals, device type

Third-Party Opt-out

Yes — Google Analytics Opt-out

Tool

Hotjar

Purpose

User journey mapping, heatmaps

Data Collected

Clicks, scroll depth, mouse movements

Third-Party Opt-out

Yes — Hotjar Opt-out

Tool

Microsoft Clarity

Purpose

Performance monitoring

Data Collected

Page interactions, session recordings

Third-Party Opt-out

Yes — Clarity Opt-out

Important

Session recordings on Clarity do not include personal data, passwords, or form inputs on sensitive fields.

C. Marketing Cookies (Consent Required)

Cookie Name

_fbp

Purpose

Facebook pixel tracking

Source

Facebook

Duration

3 months

Cookie Name

_ga_

Purpose

Campaign attribution

Source

Google Ads

Duration

2 years

Cookie Name

utm_campaign

Purpose

Marketing source tracking

Source

Our system

Duration

Session

Cookie Name

remarketing_id

Purpose

Display ad retargeting

Source

Google/Meta

Duration

Varies

D. Social Media Cookies

We use social media tracking:

LinkedIn Insight Tag - For B2B audience understanding
Facebook Pixel - For campaign tracking
Twitter Pixel - For engagement tracking

None of these track personally identifiable information directly.

5.3 Your Cookie Preferences

On First Visit: Our cookie banner explains each category. You control:

Essential (always enabled)
Analytics (click to enable)
Marketing (click to enable)
Personalization (click to enable)

Manage Preferences:

Click "Cookie Settings" in footer
Visit your browser's privacy settings
Install privacy extensions (e.g., uBlock Origin)
Email: info@thetisa.com with cookie preferences

Browser-Level Control:

Chrome: Settings → Privacy → Cookies
Firefox: Preferences → Privacy → Enhanced Tracking Protection
Safari: Preferences → Privacy → Manage Website Data

5.4 Third-Party Cookie Disclosure

Service

Google Analytics

Category

Analytics

Purpose

Traffic & behavior analysis

Privacy Policy

Google Privacy

Service

Stripe

Category

Payment

Purpose

Secure payment processing

Privacy Policy

Stripe Privacy

Service

LinkedIn

Category

Analytics

Purpose

B2B audience insights

Privacy Policy

LinkedIn Privacy

Service

Hotjar

Category

Analytics

Purpose

User experience analysis

Privacy Policy

Hotjar Privacy

Service

Intercom

Category

Support

Purpose

Chat & customer support

Privacy Policy

Intercom Privacy

5.5 Google Analytics Specifics

We use Google Analytics 4 with enhanced privacy features:

IP Anonymization: Last octet of IPs removed
Data Retention: Set to 14 months (not maximum)
Consent Mode: Respects your privacy choices
No Personal Data: Analytics limited to behavior metrics
Secure Transfer: HTTPS-only data transmission

View Google's Privacy Policy →

06

6. Your Privacy Rights & Choices

GDPR, CCPA, and global rights — plus how to exercise them.

6.1 GDPR Rights (European Users)

If you're in the European Union or European Economic Area:

A. Right to Access (Article 15)

Request copy of all data we hold about you
In human-readable format
Within 30 days

B. Right to Rectification (Article 16)

Correct inaccurate or incomplete data
Update your profile information
We'll verify changes before implementation

C. Right to Erasure (Article 17)

Request deletion of your personal data
"Right to be forgotten" applies
Exceptions: Legal obligations, contract fulfillment

D. Right to Restrict Processing (Article 18)

Limit how we use your data
Useful during disputes or corrections
Data stored but not actively processed

E. Right to Data Portability (Article 20)

Receive your data in machine-readable format
Export all information you've provided
Transfer to another service provider
Standard format (JSON, CSV, XML)

F. Right to Object (Article 21)

Opt-out of marketing communications
Object to automated processing
Exercise right at any time

G. Automated Decision-Making & Profiling (Article 22)

We do NOT use automated decision-making for contracts
We DO NOT profile individuals for eligibility decisions
All decisions involving you have human review

6.2 CCPA Rights (California Users)

If you're in California:

A. Right to Know

Know what personal data we collect, use, and share

B. Right to Delete

Request deletion of personal data
With limited legal exceptions

C. Right to Opt-Out

Opt-out of data sales (we don't sell data)
Opt-out of targeted advertising
Opt-out of profiling

D. Right to Non-Discrimination

No discrimination for exercising your rights
No service denial or degradation
No higher charges or different treatment

E. Right to Correct

Request correction of inaccurate data

6.3 Global Privacy Rights

Regardless of location, you have the right to:

Understand what data we collect (this policy)
Control your data and privacy settings
Rectify inaccurate information
Delete your personal information
Port your data to another service
Opt-out of marketing and analytics
Lodge complaints with regulators

6.4 How to Exercise Your Rights

Submit a Privacy Request:

  1. 1

    Email: info@thetisa.com

  2. 2

    Subject Line: [Type of Request - Access/Delete/Rectify/Export]

  3. 3

    Include: Your full name and email; Specific data you're requesting; Reason for request (optional); Contact details for response

Our Response:

Verification of identity (for security)
Response within 30 days (GDPR), 45 days (CCPA)
Information about fulfillment process
Honest explanation if we must deny request

You also have the right to lodge a complaint with:

EU Users: Your national Data Protection Authority
US Users: FTC (Federal Trade Commission)
Others: Your country's privacy regulator
07

7. Data Sharing & Third Parties

Who receives data, when we share for legal reasons, and what we never sell.

7.1 Who We Share Your Data With

We share information only when necessary and with protection measures:

7.2 Essential Service Providers

We share data with:

Cloud Infrastructure

Amazon Web Services (AWS) - Data hosting

AWS Privacy Policy
Data Residency: Your choice of region
Compliance: ISO 27001, SOC 2 Type II

Azure - Backup and disaster recovery

Microsoft Privacy Policy
Encryption: End-to-end

Payment Processing

Stripe, PayPal, 2Checkout - Process payments only

See Section 1.5: Payment Information
We share: Billing name, amount, payment reference only
We do NOT share: Full card details (encrypted by processors)

Communication Tools

Email Providers (SendGrid, Mailgun) - Send newsletters & notifications

Limited data: Name, email, communication preference
SendGrid Privacy

Communication Platform (Intercom, Zendesk) - Customer support

Data shared: Support tickets, emails, chat logs
Intercom Privacy

Analytics & Monitoring

Google Analytics, Hotjar, Clarity - Site analytics

Limited to: Behavioral data, not personal identification
See Section 5: Cookies & Tracking

7.3 Legal & Compliance Sharing

We may share data without consent when:

Law Enforcement: Court order or legal process
Regulatory Compliance: Government agency requests
Safety & Security: Prevent harm or fraud
Business Operations: Process claims or disputes

Transparency: We notify you of such disclosures unless legally prohibited.

7.4 We DO NOT Sell Your Data

Explicitly:

We do NOT sell personal data to third parties
We do NOT profit from your information
We do NOT broker data to data brokers
We do NOT share data for marketing to other companies

We may use aggregated, anonymized data for:

Market research
Industry reports
Product development insights
AI model training (anonymized only)

7.5 Business Transfers

In case of merger, acquisition, or sale of assets:

Your data would transfer to the acquiring company
We'd notify you of the change
Privacy protections would remain (or you can opt-out)
Same or stronger protections apply
08

8. International Data Transfers

Where data may move globally and the safeguards that travel with it.

8.1 Cross-Border Data Movement

The TISA operates globally. Your data may be transferred to/processed in:

United States (primary data center)
European Union (GDPR compliance center)
India (development & support operations)
Canada (backup and disaster recovery)

8.2 GDPR Data Transfer Protection

For EU/EEA users, we ensure:

Standard Contractual Clauses (SCCs) - EU-approved transfer mechanism
Adequacy Decisions - Where available
Supplementary Measures - Additional safeguards beyond SCCs
Data Processing Agreements (DPAs) - With all processors

Document Available: Request SCCs/DPAs from info@thetisa.com

8.3 Your Control Over Transfers

You can request data processing in specific regions
You can opt-out of international transfers
We'll discuss alternatives (may affect service availability)
Some services require multi-region processing for redundancy
09

9. Children's Privacy

Age limits, what we do not collect, and parental rights.

9.1 Age Restrictions

Our services are NOT intended for children under 13 (or applicable local age of digital consent).

Important:

We do NOT knowingly collect data from children under 13
If we discover child data, we delete it immediately
Parents: Contact info@thetisa.com if concerned

9.2 Parental Rights

If your child's data was collected without consent:

  1. 1

    Notify us immediately: info@thetisa.com with "Child Data" in subject

  2. 2

    Provide proof of age and parental relationship

  3. 3

    Request deletion of all child's data

  4. 4

    Receive confirmation within 30 days

We will delete without questions asked.

10

10. California Resident Specific Rights

CCPA rights, response times, and non-discrimination guarantees.

10.1 CCPA Compliance

If you're a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

A. Right to Know

What personal information we collect
How we use it
Who we share it with

Request Here: Complete this Data Access Request Form

B. Right to Delete

Request deletion of personal information collected from you
Exceptions: When we need data for contractual or legal purposes

Note: We may retain anonymized data and aggregate information

C. Right to Opt-Out

Opt-out of "sales" of personal information
Opt-out of targeted advertising
Opt-out of profiling for eligibility decisions

Declaration: We do NOT sell personal information. Sharing with service providers for business purposes is not considered a "sale" under CCPA.

D. Right to Limit Use

Restrict how we use sensitive personal information
We only use sensitive data for providing services

E. Shine the Light Law

Know third parties we share data with (annually)
Request this information: info@thetisa.com

10.2 California Response Times

Initial Response: Within 10 business days
Verification: May request additional identification
Fulfillment: Within 45 days (45 more if needed)
No Fee: Requests are free (except excessive requests)

10.3 Non-Discrimination

We will NOT discriminate against you for exercising CCPA rights:

No service denial
No degradation of quality
No different pricing
No different treatment
11

11. EU & UK GDPR Compliance

Legal bases for processing, our privacy lead, and where to complain.

11.1 Our Legal Basis for Processing

Under GDPR, we process data based on:

Purpose

Service delivery

Legal Basis

Contract fulfillment

Your Rights

Portability, rectification

Purpose

Payment processing

Legal Basis

Legal obligation

Your Rights

Access, deletion

Purpose

Marketing (opt-in)

Legal Basis

Your consent

Your Rights

Withdraw anytime

Purpose

Fraud prevention

Legal Basis

Legitimate interest

Your Rights

Object to processing

Purpose

Compliance

Legal Basis

Legal obligation

Your Rights

Access to legal requests

Purpose

Analytics (opt-in)

Legal Basis

Your consent

Your Rights

Opt-out anytime

11.2 Data Protection Officer

We maintain privacy best practices through:

Designated Privacy Lead: info@thetisa.com
Data Protection Impact Assessments: Conducted for high-risk processing
Privacy by Design: Integrated into all systems
Regular Audits: Annual third-party security audits

11.3 Supervisory Authority Complaints

You have the right to lodge complaints with:

European Union:

European Data Protection Board (EDPB)
Your national DPA (Data Protection Authority)
Germany: BfDI
UK: ICO
France: CNIL
Others: EDPB List
12

12. Security Incident Notification

What we do if a breach happens, and what you should do next.

12.1 In Case of Data Breach

Our Commitment:

Notification within 72 hours of discovery (GDPR requirement)
Detail about data affected
Steps we're taking to protect you
Resources to monitor your account
Contact information for more details

Notification Methods:

  1. 1

    Email to registered email address

  2. 2

    Notice on website homepage (prominent)

  3. 3

    Call/SMS if high-risk breach

  4. 4

    Credit monitoring services (if applicable)

12.2 What to Do if Notified of Breach

  1. 1

    Change Password: Immediately update your account password

  2. 2

    Enable MFA: Activate multi-factor authentication

  3. 3

    Monitor Account: Watch for unauthorized activity

  4. 4

    Review Data: Check our notification for what data was affected

  5. 5

    Report to Authorities: File report if you're in EU/California

  6. 6

    Contact Us: Email info@thetisa.com with concerns

12.3 Breach Disclosure Transparency

We maintain a public Security & Incident Report page:

Incident date
Scope of breach
Actions taken
Lessons learned
14

14. Contact & Privacy Inquiries

How to reach the privacy team and our DPO for formal requests.

14.1 Contact Information

Privacy Questions? Get in Touch:

Email

info@thetisa.com

Phone

+91 9610590090

Mailing Address

The TISA - Privacy Team
1st Floor, 72-73, opposite Hotel Narayan Palace, Patel Nagar, Govindpura, Rajasthan
Jaipur, India, 302012

Urgent Issues

info@thetisa.com (24/7 response)

Online Form: Privacy Contact Form

14.2 Data Protection Officer (DPO)

For GDPR/CCPA Inquiries:

Response Time:

Standard inquiry: 3-5 business days
Urgent request: 24 hours
Formal complaint: 30 days (GDPR requirement)
15

15. Policy Updates & Changes

When we revise this policy and how we notify you.

15.1 When We Update This Policy

This Privacy Policy is reviewed annually and updated when:

We introduce new services or features
Regulations change (GDPR, CCPA, other laws)
We improve privacy practices
Security requirements evolve
User feedback suggests improvements

15.2 How We Notify You of Changes

For Material Changes:

Email notification to registered email
Prominent notice on website
30-day notice before effective date
Request for explicit re-consent if required

For Minor Clarifications:

Update posted with "Last Updated" date
No explicit notification required
Continue using service = acceptance

15.3 Version History

Version

2.0

Date

August 4, 2026

Changes

AI practices added, CCPA section expanded

Version

1.5

Date

January 2025

Changes

Initial comprehensive policy

View Previous Versions: info@thetisa.com

16

16. Additional Resources

Related policies, legal frameworks, and privacy education links.

16.1 Related Policies

Cookie Policy & Settings - Detailed cookie management
Terms of Service - Service agreement details
Acceptable Use Policy - What you can/can't do
AI Ethics & Transparency - How we use AI responsibly
Security Policy - Technical security measures

16.2 Legal Frameworks & Standards

We comply with:

GDPR (General Data Protection Regulation) - Learn about GDPR
CCPA (California Consumer Privacy Act) - CCPA Text
PIPEDA (Canada) - PIPEDA Overview
LGPD (Brazil) - LGPD Standards
PDPA (Thailand, Singapore) - Regional compliance

16.3 Useful Privacy Resources

All About Privacy - Privacy education
Future of Privacy Forum - Privacy research
Electronic Frontier Foundation - Digital rights
Your Data Your Rights - Consumer education

16.4 Complaint & Regulatory Bodies

Global Privacy Regulators:

International Conference on Data Protection - Multi-country coordination
EDPB - European privacy authority
FTC - US privacy regulator
Privacy Commissioner of Canada - Canadian authority
17

17. Special Sections

Sensitive data, marketing preferences, and automated decisions.

17.1 Sensitive Data Handling

If you provide sensitive data:

Examples: Health information, financial data, identification numbers, biometric data

Our Guarantees:

Highest level of encryption
Minimal access (only necessary staff)
Separate secure storage
Annual audits of access logs
Immediate deletion if not needed

Request: Email info@thetisa.com for sensitive data handling procedures

17.2 Marketing Communications

What You'll Receive:

Email Communications:

Product updates (if opted in)
Security alerts (always sent)
Newsletter (if subscribed)
Promotional offers (if opted in)
Event invitations (if opted in)

Manage Preferences:

Click "Unsubscribe" at bottom of any email
Update in account settings
Email: info@thetisa.com with email address

Opt-Out Process:

  1. 1

    Click unsubscribe link

  2. 2

    Select communication types

  3. 3

    Confirm preference change

  4. 4

    Receive confirmation email

Note: We cannot unsubscribe you from critical security alerts.

17.3 Automated Decision-Making

Important

We do NOT use automated decision-making for:

Contract eligibility (service provision)
Pricing determinations
Service access decisions
User segmentation for service

We DO use automation for:

Spam filtering
Fraud detection (with human review)
Content recommendations
Site personalization

Your Right: You have the right to human review of automated decisions. Request via info@thetisa.com

18

18. Acknowledgment & Questions

What using our services means, and where to ask next.

18.1 You Acknowledge That You Have:

By using The TISA services, you:

Read this Privacy Policy
Understand how we process data
Accept our data practices
Consent to our use of information
Agree to terms outlined

18.2 Still Have Questions?

We're here to help! Contact us:

19

Final Words

Our closing commitment to treating privacy as a human right.

At The TISA - AI Powered Software Development Company, we believe that privacy is a human right, not just a compliance checkbox.

We've designed this policy to be:

Transparent - No hidden terms or loopholes
Comprehensive - Covers all data practices
User-Friendly - Written in plain language
Empowering - Giving you control of your data

Your privacy matters to us. Every decision we make puts your data protection first.

Thank you for trusting The TISA with your information.