Introduction
Why this policy exists and who it covers.
Welcome to The TISA – Your Trusted AI-Powered Software Development Partner.
At The TISA - AI Powered Software Development Company, we are deeply committed to protecting your privacy and ensuring complete transparency in how we collect, use, process, and safeguard your personal information. This Privacy Policy outlines our comprehensive privacy practices and explains how we handle data from our clients, service users, website visitors, and business partners.
We believe that privacy is a fundamental right, and we've built our operations around the principle that respecting your data is not just a legal obligation, but a core value that defines our company culture.
1. Information We Collect
What you give us, what we gather automatically, and what we never seek out.
We collect information that helps us deliver exceptional software development services, improve our offerings, and maintain secure communications. Here's what we collect and why:
1.1 Information You Provide Directly
A. Account & Registration Information
Where collected: Contact forms, service registration, account creation, subscription pages
B. Service Engagement Information
Where collected: Project intake forms, meetings, service agreements, support channels
C. Payment Information
Important
We do NOT store full credit card details on our servers. Payment processing is handled by industry-standard, PCI-DSS compliant payment gateways. See Section 1.5 for details.
D. Communication Data
Consent Required: We only record calls/videos with explicit written consent from all parties.
1.2 Information Collected Automatically
A. Website & Platform Analytics
Purpose: Improve user experience, identify technical issues, detect security threats, understand audience demographics
Tools Used: Google Analytics 4, Hotjar, Microsoft Clarity (See Section 5: Cookies & Tracking)
B. Behavioral & Interaction Data
1.3 Third-Party Information Sources
We may receive information about you from:
Note: We only use third-party data where legally permissible and transparently disclosed.
1.4 Special Categories of Data
We do NOT intentionally collect sensitive personal data such as:
Exception: If you voluntarily provide such information (e.g., in project requirements), we will:
- 1
Treat it with the highest level of protection
- 2
Use it only for the stated purpose
- 3
Ensure strict access controls
- 4
Comply with GDPR Article 9 and equivalent regulations
1.5 Payment Information & PCI Compliance
We prioritize payment security through:
Trusted payment partners:
Your payment data is handled exclusively by these third-party processors. We have Data Processing Agreements (DPAs) with all payment providers.
2. How We Use Your Information
The legitimate purposes for which we process your data.
We use collected information for specific, legitimate purposes. Here's exactly how we use your data:
2.1 Service Delivery & Fulfillment
Primary Purpose: Provide software development services
Legal Basis: Performance of contract (we need this to serve you)
2.2 Communication & Notifications
Purpose: Keep you informed
Your Control: You can manage communication preferences in your account settings or via unsubscribe links in emails
2.3 Business Intelligence & Improvement
Purpose: Enhance our services
Legal Basis: Legitimate business interest in service improvement
Data Protection: We use anonymization and aggregation for analytics. Individual user behavior is not profiled.
2.4 Marketing & Business Development
Purpose: Grow our business responsibly
Your Rights:
Important
We will never use your project data in marketing without explicit consent. Case studies require written approval from you.
2.5 Security & Fraud Prevention
Purpose: Protect your data and prevent misuse
Legal Basis: Legal obligation and legitimate interest in security
2.6 Legal Compliance & Obligations
Purpose: Meet regulatory requirements
Transparency: We will inform you of legal requests unless legally prohibited from doing so.
2.7 AI Model Training (Anonymized Only)
Important
The TISA uses AI-powered tools for software development.
How we handle data for AI:
Your Control: You can opt-out of analytics data being used for model improvement. Learn more about our AI practices →
3. How We Protect Your Data
Technical, organizational, and compliance measures we use to keep data safe.
At The TISA, data security is non-negotiable. We implement enterprise-grade security measures:
3.1 Technical Security Measures
A. Encryption
Data in Transit:
Data at Rest:
B. Access Controls
C. Infrastructure Security
3.2 Organizational & Administrative Security
A. Employee Training
B. Data Protection Policies
C. Compliance Certifications
3.3 What We Can't Guarantee
Important Disclaimer
While we implement robust security, no system is 100% secure.
We commit to:
However, you should understand that:
Your Responsibility: Use strong passwords, enable MFA, keep devices updated, and avoid sharing login credentials.
4. Data Retention & Deletion
How long we keep data and how you can ask us to erase it.
We retain information only as long as necessary. Here's our retention schedule:
4.1 Retention Schedule
Data Type
Account Information
Retention Period
During service + 3 years after termination
Reason
Tax compliance, dispute resolution
Data Type
Transaction/Payment Records
Retention Period
7 years
Reason
Tax and legal requirements
Data Type
Project Documentation
Retention Period
Duration of project + 2 years
Reason
Warranty claims, bug fixes
Data Type
Support Tickets
Retention Period
3 years
Reason
Customer service continuity
Data Type
Email Communications
Retention Period
2 years (business) / 6 months (marketing)
Reason
Business records, compliance
Data Type
Website Analytics
Retention Period
26 months
Reason
Google Analytics retention limit
Data Type
Cookies & Tracking
Retention Period
See Section 5
Reason
Session to 2 years
Data Type
Call Recordings
Retention Period
90 days (if approved)
Reason
Quality assurance purposes
Data Type
API Logs
Retention Period
90 days
Reason
Security and troubleshooting
Data Type
Deleted Accounts
Retention Period
30 days (recovery period) then permanent deletion
Reason
GDPR right to erasure
4.2 Data Deletion Process
When data reaches end-of-life:
- 1
Secure Deletion: Data permanently deleted using NIST guidelines
- 2
Multiple Overwrites: Sensitive data overwritten 3+ times
- 3
Cryptographic Erasure: Encryption keys destroyed permanently
- 4
Verification: Independent confirmation of deletion
- 5
Audit Trail: Documented for compliance purposes
4.3 Your Deletion Rights
You have the right to request deletion:
How to Request: Email info@thetisa.com with "Data Deletion Request" in subject line
Our Response Time: Within 30 days (GDPR compliant)
Exceptions: We may retain data if legally required (tax, legal compliance, active disputes)
6. Your Privacy Rights & Choices
GDPR, CCPA, and global rights — plus how to exercise them.
6.1 GDPR Rights (European Users)
If you're in the European Union or European Economic Area:
A. Right to Access (Article 15)
B. Right to Rectification (Article 16)
C. Right to Erasure (Article 17)
D. Right to Restrict Processing (Article 18)
E. Right to Data Portability (Article 20)
F. Right to Object (Article 21)
G. Automated Decision-Making & Profiling (Article 22)
6.2 CCPA Rights (California Users)
If you're in California:
A. Right to Know
B. Right to Delete
C. Right to Opt-Out
D. Right to Non-Discrimination
E. Right to Correct
6.3 Global Privacy Rights
Regardless of location, you have the right to:
6.4 How to Exercise Your Rights
Submit a Privacy Request:
- 1
Email: info@thetisa.com
- 2
Subject Line: [Type of Request - Access/Delete/Rectify/Export]
- 3
Include: Your full name and email; Specific data you're requesting; Reason for request (optional); Contact details for response
Our Response:
You also have the right to lodge a complaint with:
7. Data Sharing & Third Parties
Who receives data, when we share for legal reasons, and what we never sell.
7.1 Who We Share Your Data With
We share information only when necessary and with protection measures:
7.2 Essential Service Providers
We share data with:
Cloud Infrastructure
Amazon Web Services (AWS) - Data hosting
Azure - Backup and disaster recovery
Payment Processing
Stripe, PayPal, 2Checkout - Process payments only
Communication Tools
Email Providers (SendGrid, Mailgun) - Send newsletters & notifications
Communication Platform (Intercom, Zendesk) - Customer support
Analytics & Monitoring
Google Analytics, Hotjar, Clarity - Site analytics
7.3 Legal & Compliance Sharing
We may share data without consent when:
Transparency: We notify you of such disclosures unless legally prohibited.
7.4 We DO NOT Sell Your Data
Explicitly:
We may use aggregated, anonymized data for:
7.5 Business Transfers
In case of merger, acquisition, or sale of assets:
8. International Data Transfers
Where data may move globally and the safeguards that travel with it.
8.1 Cross-Border Data Movement
The TISA operates globally. Your data may be transferred to/processed in:
8.2 GDPR Data Transfer Protection
For EU/EEA users, we ensure:
Document Available: Request SCCs/DPAs from info@thetisa.com
8.3 Your Control Over Transfers
9. Children's Privacy
Age limits, what we do not collect, and parental rights.
9.1 Age Restrictions
Our services are NOT intended for children under 13 (or applicable local age of digital consent).
Important:
9.2 Parental Rights
If your child's data was collected without consent:
- 1
Notify us immediately: info@thetisa.com with "Child Data" in subject
- 2
Provide proof of age and parental relationship
- 3
Request deletion of all child's data
- 4
Receive confirmation within 30 days
We will delete without questions asked.
10. California Resident Specific Rights
CCPA rights, response times, and non-discrimination guarantees.
10.1 CCPA Compliance
If you're a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
A. Right to Know
Request Here: Complete this Data Access Request Form
B. Right to Delete
Note: We may retain anonymized data and aggregate information
C. Right to Opt-Out
Declaration: We do NOT sell personal information. Sharing with service providers for business purposes is not considered a "sale" under CCPA.
D. Right to Limit Use
E. Shine the Light Law
10.2 California Response Times
10.3 Non-Discrimination
We will NOT discriminate against you for exercising CCPA rights:
11. EU & UK GDPR Compliance
Legal bases for processing, our privacy lead, and where to complain.
11.1 Our Legal Basis for Processing
Under GDPR, we process data based on:
Purpose
Service delivery
Legal Basis
Contract fulfillment
Your Rights
Portability, rectification
Purpose
Payment processing
Legal Basis
Legal obligation
Your Rights
Access, deletion
Purpose
Marketing (opt-in)
Legal Basis
Your consent
Your Rights
Withdraw anytime
Purpose
Fraud prevention
Legal Basis
Legitimate interest
Your Rights
Object to processing
Purpose
Compliance
Legal Basis
Legal obligation
Your Rights
Access to legal requests
Purpose
Analytics (opt-in)
Legal Basis
Your consent
Your Rights
Opt-out anytime
11.2 Data Protection Officer
We maintain privacy best practices through:
11.3 Supervisory Authority Complaints
You have the right to lodge complaints with:
European Union:
12. Security Incident Notification
What we do if a breach happens, and what you should do next.
12.1 In Case of Data Breach
Our Commitment:
Notification Methods:
- 1
Email to registered email address
- 2
Notice on website homepage (prominent)
- 3
Call/SMS if high-risk breach
- 4
Credit monitoring services (if applicable)
12.2 What to Do if Notified of Breach
- 1
Change Password: Immediately update your account password
- 2
Enable MFA: Activate multi-factor authentication
- 3
Monitor Account: Watch for unauthorized activity
- 4
Review Data: Check our notification for what data was affected
- 5
Report to Authorities: File report if you're in EU/California
- 6
Contact Us: Email info@thetisa.com with concerns
12.3 Breach Disclosure Transparency
We maintain a public Security & Incident Report page:
13. Third-Party Links & Integrations
External sites and connected tools — and what we are not responsible for.
13.1 External Links
Our website links to:
Important
We are NOT responsible for third-party privacy practices.
Recommendations:
13.2 Connected Integrations
If you connect your account with:
Data Sharing:
View our Integration Privacy Policy →
14. Contact & Privacy Inquiries
How to reach the privacy team and our DPO for formal requests.
14.1 Contact Information
Privacy Questions? Get in Touch:
info@thetisa.com
Phone
+91 9610590090
Mailing Address
The TISA - Privacy Team
1st Floor, 72-73, opposite Hotel Narayan Palace, Patel Nagar, Govindpura, Rajasthan
Jaipur, India, 302012
Urgent Issues
info@thetisa.com (24/7 response)
Online Form: Privacy Contact Form
14.2 Data Protection Officer (DPO)
For GDPR/CCPA Inquiries:
Response Time:
15. Policy Updates & Changes
When we revise this policy and how we notify you.
15.1 When We Update This Policy
This Privacy Policy is reviewed annually and updated when:
15.2 How We Notify You of Changes
For Material Changes:
For Minor Clarifications:
15.3 Version History
Version
2.0
Date
August 4, 2026
Changes
AI practices added, CCPA section expanded
Version
1.5
Date
January 2025
Changes
Initial comprehensive policy
View Previous Versions: info@thetisa.com
16. Additional Resources
Related policies, legal frameworks, and privacy education links.
16.1 Related Policies
16.2 Legal Frameworks & Standards
We comply with:
16.3 Useful Privacy Resources
16.4 Complaint & Regulatory Bodies
Global Privacy Regulators:
17. Special Sections
Sensitive data, marketing preferences, and automated decisions.
17.1 Sensitive Data Handling
If you provide sensitive data:
Examples: Health information, financial data, identification numbers, biometric data
Our Guarantees:
Request: Email info@thetisa.com for sensitive data handling procedures
17.2 Marketing Communications
What You'll Receive:
Email Communications:
Manage Preferences:
Opt-Out Process:
- 1
Click unsubscribe link
- 2
Select communication types
- 3
Confirm preference change
- 4
Receive confirmation email
Note: We cannot unsubscribe you from critical security alerts.
17.3 Automated Decision-Making
Important
We do NOT use automated decision-making for:
We DO use automation for:
Your Right: You have the right to human review of automated decisions. Request via info@thetisa.com
18. Acknowledgment & Questions
What using our services means, and where to ask next.
18.1 You Acknowledge That You Have:
By using The TISA services, you:
18.2 Still Have Questions?
We're here to help! Contact us:
Quick Question
General Privacy Inquiry
Legal Matter
info@thetisa.com with "LEGAL" subject line
Urgent/Breach
info@thetisa.com (immediate response)
Chat Support
Available in-app Open Chat
Final Words
Our closing commitment to treating privacy as a human right.
At The TISA - AI Powered Software Development Company, we believe that privacy is a human right, not just a compliance checkbox.
We've designed this policy to be:
Your privacy matters to us. Every decision we make puts your data protection first.
Thank you for trusting The TISA with your information.