Version effective as of September 23, 2026

TESS TECNOLOGIA LTDA. (“Tess,” “we,” “us,” or “our”) respects privacy and is committed to protecting the personal information processed through the Tess AI platform, its websites, applications, integrations, support channels, and other related services (together, the “Platform” or the “Services”).

This Privacy Policy explains how Tess collects, uses, stores, shares, transfers, and protects personal information, as well as the rights that data subjects may exercise.

Tess seeks to conduct its processing activities in accordance with applicable data-protection and privacy laws, including, without limitation, the Brazilian General Data Protection Law (Law No. 13.709/2018 — “LGPD”), the European Union General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), when applicable, and other rules that may apply to Tess, the Services, or data subjects.

This Policy forms part of the Terms of Use. In the event of a conflict between this Policy and the Terms of Use on privacy matters, this Policy will prevail to the extent necessary to comply with applicable law.

This Policy should be read together with the Privacy Notice, the Cookie Policy, the Data Processing Agreement (DPA), when Tess acts as a processor, and the Trust Center. The Notice describes, in accessible language and with a focus on the LGPD, the legal bases by purpose and the channel for exercising rights. The Cookie Policy details trackers, advertising, and opt-out choices. The DPA and the Trust Center describe the processor regime and the updated list of subprocessors.

1. WHO THIS POLICY APPLIES TO

This Policy applies to people who use or interact with the Services, including registered users, visitors to our websites, people who contact Tess, workspace administrators, users of enabled integrations, and, where applicable, representatives of business customers.

The Services are intended exclusively for persons 18 (eighteen) years of age or older, as set out in the Terms of Use. Tess does not direct the Services to persons under 18.

2. ROLES AND RESPONSIBILITIES IN PROCESSING

When Tess determines the purposes and means of processing personal information in the context of the Services, it acts as a controller, data controller, business, or other equivalent responsible entity, according to the terminology of applicable law.

In certain circumstances, especially in relation to data entered by business customers on the Platform for their own purposes, Tess may act as a processor, service provider, contractor, or equivalent role, according to the applicable contract and relevant law.

Providers of artificial intelligence models, infrastructure, hosting, connectivity, payments, support, and other vendors may process personal information on Tess’s behalf as processors, service providers, or contractors, as applicable, subject to contractual obligations of confidentiality, security, and purpose limitation. The updated list of subprocessors is available in the Trust Center. Business customers will find the processor terms in the DPA.

3. PERSONAL INFORMATION WE MAY COLLECT

Depending on your interaction with the Platform, we may collect or receive the following categories of personal information:

Category Main sources
Account and identification data directly from you or from your workspace administrator
Contact and support data directly from you
Payment and contracting data directly from you and payment providers; Tess does not store full card data when payment is processed by a specialized provider
Content and data provided on the Platform directly from you, from authorized users, or from enabled integrations
Usage, device, and advertising data automatically through the Platform, cookies, pixels, tags, SDKs, and similar technologies
Integration data directly from you, from your administrator, and from the integrated application
Security and fraud-prevention data automatically, from you, and from security providers
Advertising and remarketing data automatically through cookies, pixels, tags, SDKs, advertising and marketing partners, and your interaction with our websites, content, and campaigns

Examples by category:

  • Account and identification data: name, email address, username, account identifiers, organization or workspace
  • Contact and support data: email, messages, requests, support records, and information provided in communications with us
  • Payment and contracting data: contracted plan, payment status, transaction history, and billing identifiers
  • Content and data provided on the Platform: prompts, instructions, responses, files, images, videos, audio, documents, credentials entered for integrations, and other content you submit
  • Usage and device data: IP address, online identifiers, cookie and device identifiers, browser, operating system, access logs, pages viewed, video views, engagement events, traffic source, date, time, and usage metrics
  • Integration data: information needed to authenticate, connect, and run integrations you enable
  • Security and fraud-prevention data: security events, technical logs, abuse indicators, access attempts, and information needed to protect the Services
  • Advertising and remarketing data: information about membership in or eligibility for advertising audiences, such as engagement, page-view, and video-view audiences; information related to interaction with campaigns and ads

Depending on the content you choose to enter on the Platform, some information may constitute sensitive personal data, special categories of personal data, or sensitive personal information, under applicable law. For example, prompts and files may contain health, biometric, authentication, financial, racial or ethnic, religious, political, or other sensitive information.

We ask that you not enter sensitive personal information on the Platform except when necessary for the intended legitimate purpose and when you have a legal basis to do so. You are responsible for ensuring that you have all rights, authorizations, and legal bases needed to enter, submit, or make available to Tess personal information of third parties.

4. HOW WE USE PERSONAL INFORMATION

We may process personal information for the following purposes:

  • create, authenticate, administer, and maintain accounts, workspaces, and subscriptions;
  • provide, operate, personalize, maintain, protect, and support the Services;
  • run prompts, process files, generate responses, and deliver features you request;
  • enable and run integrations you have chosen to activate;
  • process payments, prevent fraud, administer billing, and fulfill contractual obligations;
  • communicate updates, operational notices, support responses and, where permitted, communications about products and services;
  • protect the Platform, and detect, investigate, and prevent security incidents, abuse, fraud, misuse, and violations of the Terms of Use;
  • comply with legal, regulatory, tax, accounting, judicial, and administrative obligations;
  • establish, exercise, or defend rights in judicial, administrative, or arbitral proceedings; and
  • analyze and improve features unrelated to training of artificial intelligence models, in a manner compatible with this Policy, the Terms of Use, and applicable law.
  • measure, attribute, administer, personalize, and optimize paid-acquisition, advertising, and remarketing campaigns, including through the creation, updating, and use of audiences based on engagement, page views, and video views, according to your privacy preferences and applicable law.

For these purposes, Tess may use cookies, pixels, tags, SDKs, and similar technologies of advertising and marketing partners, including Meta (Pixel), Google Ads/Analytics, and ManyChat. Where required by applicable law, these technologies will be activated only after obtaining the applicable consent or observing the data subject’s valid opt-out preferences.

Tess does not use prompts, associated system instructions, cached content, uploaded files, responses, or content generated on the Platform to train or improve its own or third-party artificial intelligence models.

Under the Terms of Use, on current individual Pro (Professional) plans and on legacy individual plans, Tess receives a license to use generated Assets. That license does not authorize the use of generated data or content to train or improve artificial intelligence models. Personal information that may be contained in that content remains subject to this Policy. The legal basis for that use, when it involves personal information, is performance of the contract.

Tess does not use sensitive personal information to infer characteristics about you. When it processes this type of information, Tess does so only to the extent necessary to provide, protect, maintain, support, and perform the requested Services, including to run prompts, or for other purposes permitted by applicable law. When Tess acts as a controller and processing of sensitive data or special categories is necessary, the applicable basis will, as a rule, be specific or explicit consent (LGPD, art. 11, I; GDPR, art. 9(2)(a)), unless another legal ground applies. Details on photo and voice for avatars are in the Privacy Notice. When Tess acts as a processor for a business customer, the legal basis is the controller’s responsibility, under the DPA.

Tess does not make solely automated decisions that produce legal or similarly significant effects concerning you, within the meaning of GDPR art. 22. Automated processing used to generate the content you requested, apply the Terms of Use, filter abuse, or protect the Platform does not, by itself, constitute that type of decision. The review right provided for in LGPD art. 20 may be exercised through the channels in the Privacy Notice.

5. LEGAL BASES

Where required by applicable law, each purpose has a corresponding legal basis. The detailed table with LGPD articles is in the Privacy Notice. The bases applicable to cookies and trackers are in the Cookie Policy. For the processing described in this Policy, the bases are, in summary:

Purpose Legal basis (LGPD / GDPR, where applicable)
Create and administer account, workspace, authentication, and subscription Performance of a contract (LGPD, art. 7, V; GDPR, art. 6(1)(b))
Run prompts, process files, generate responses, and provide the Services Performance of a contract (art. 7, V; art. 6(1)(b))
Integrations you enable Performance of a contract; consent to connect the third-party account, where required
Payment, billing, and tax documents Performance of a contract and legal obligation (art. 7, V and II; art. 6(1)(b) and (c))
Operational communications, support, and account security Performance of a contract and legitimate interest in the operation and security of the Platform
Communications about products and services, where permitted Consent or legitimate interest, as described in the Privacy Notice
Security, fraud and abuse prevention, and enforcement of the Terms Legitimate interest in protecting the Platform, users, and third parties; legal obligation, where applicable
Improvement of features unrelated to model training Legitimate interest in improving the Services
Advertising, paid acquisition, and remarketing Consent, where required; in California, subject to opt-out of sharing
Non-essential cookies and trackers Consent, where required — see the Cookie Policy
Comply with law, authority orders, and defense of rights Legal obligation and regular exercise of rights (art. 7, II and VI; art. 6(1)(c) and (f))

When Tess relies on legitimate interest, the interest consists, as the case may be, in operating, protecting, and maintaining the Platform, preventing fraud and abuse, administering the contractual relationship, and improving features that do not involve model training, taking into account the data subject’s fundamental rights and freedoms.

Where processing is based on consent, you may withdraw it at any time through the channels indicated in this Policy, without affecting the lawfulness of processing carried out before withdrawal. Refusal or withdrawal of consent for non-essential cookies or for marketing communications does not prevent use of the core functions of the Services; refusal of data necessary for the account, payment, or security may prevent contracting or continuation of the service.

6. HOW WE SHARE PERSONAL INFORMATION

Tess may disclose or make personal information available only when necessary and compatible with this Policy, including to:

  • service providers and contractors: providers of infrastructure, hosting, storage, AI models, connectivity, payment, support, security, email, communications, audit, and professional services, which process data on our behalf and under contractual instructions;
  • integrations you enable: when you activate an integration, the information needed to run it may pass through connectivity providers and the third-party application you chose;
  • workspace administrators: when your account is linked to a workspace, administrators may have access to certain information and activity histories according to the workspace settings and features;
  • authorities and authorized third parties: when necessary to comply with law, a court order, legal process, a legitimate request from a competent authority, or to protect the rights, safety, and integrity of Tess, users, or third parties;
  • corporate transactions: in connection with a merger, acquisition, reorganization, financing, sale of assets, or similar transaction, subject to applicable legal requirements; and
  • other authorized disclosures: with your consent, under your direction, or as permitted by law.
  • Advertising, paid acquisition, and remarketing. Tess does not sell personal information for money. However, when using cookies, pixels, tags, SDKs, and similar technologies for advertising, paid acquisition, and remarketing, Tess may disclose to advertising and marketing partners certain identifiers and online activity information, such as IP address, cookie or device identifiers, browser, pages viewed, video views, engagement events, and information related to interaction with campaigns.

These partners currently include Meta (Pixel), Google Ads/Analytics, and ManyChat. The disclosure may be used to measure campaigns, attribute conversions, create or update advertising audiences, and carry out cross-context behavioral advertising, including for engagement, page-view, and video-view audiences.

Under the CCPA/CPRA, this activity may constitute “sharing” of personal information for cross-context behavioral advertising, even if there is no exchange of money. Advertising and marketing partners receive this information as third parties for their own advertising purposes and are not treated by Tess as service providers or contractors in relation to this specific processing.

Tess does not use prompts, associated system instructions, cached content, uploaded files, responses, or content generated on the Platform to train or improve its own or third-party artificial intelligence models. In addition, that content is not sold or shared with advertising or marketing partners for cross-context behavioral advertising.

Tess acts as an orchestration layer and may send to artificial intelligence model providers only the content needed to perform the inference you requested — for example, prompts, files, and task context — without adding account or identification data beyond what you have entered in that content. Those providers process the information, as a rule, as processors, service providers, or contractors, as applicable.

The categories of model providers currently used include laboratories and platforms such as OpenAI, Anthropic, Google, Meta, Mistral, DeepSeek, xAI, and other equivalent providers. The list of available models is updated frequently and does not constitute a static inventory of this Policy. The current catalog may be consulted in Tess’s documentation, at Models and Pricing. Commercial information about plans and availability may also appear on the pricing page.

You may object to sharing for cross-context behavioral advertising through the “Do Not Sell or Share My Personal Information” link, available on the site and in the Privacy Notice, as well as through the cookie preferences described in the Cookie Policy and the other mechanisms in this Policy, where applicable.

7. INTEGRATIONS WITH THIRD-PARTY APPLICATIONS

The Platform may allow you to connect third-party applications. When you enable an integration, the data needed for its operation may be transmitted to the integrated application and to connectivity providers used to perform that feature.

Connectivity providers used in user-enabled integrations act as service providers, processors, or contractors, as applicable, and are contractually prohibited from retaining, using, or disclosing the transmitted personal information for any purpose other than performing the integration and other purposes permitted by law.

Third-party applications have their own terms and privacy policies. Tess does not control those third parties’ practices and recommends that you review their documents before enabling an integration.

Data obtained via Google and other APIs

When you enable an integration with Google or another API provider, Tess accesses, uses, stores, and transmits only the information needed to perform the visible functionality you requested.

Use of information received from Google Workspace scopes adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Tess does not use data obtained through Google Workspace APIs to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models, whether its own or third-party models.

Human reading of data obtained via third-party APIs, including Google user data, is prohibited, except when:

  • you have given affirmative consent for viewing of specific messages, files, or other data;
  • it is necessary for security purposes, such as investigating a failure, abuse, or incident;
  • it is necessary to comply with law, a court order, or a request from a competent authority; or
  • the data, including derivations, are aggregated and used for internal operations in accordance with applicable law.

Tess ensures that its employees, agents, contractors, and successors observe these restrictions and the user-data policies of the integrated services and APIs, including the Google API Services User Data Policy.

8. COOKIES AND SIMILAR TECHNOLOGIES

Tess and its providers use cookies, pixels, tags, SDKs, logs, and similar technologies to operate the Services, maintain preferences, protect accounts, prevent fraud, measure performance, understand Platform usage and, where permitted, carry out advertising, paid acquisition, campaign measurement, and remarketing.

The advertising and marketing partners currently used may include Meta (Pixel), Google Ads/Analytics, and ManyChat. These technologies may collect or receive online identifiers, IP address, browser or device information, pages viewed, video views, engagement events, and information about interaction with our content and campaigns.

Tess may use this information to create, update, measure, or target advertising audiences, including engagement, page-view, and video-view audiences, according to your preferences and applicable law.
Where required by applicable law, Tess will request your consent before installing or accessing cookies, pixels, tags, SDKs, or similar technologies that are not strictly necessary. You may manage your preferences through the mechanism Tess makes available, provided that withdrawal of consent does not affect the lawfulness of processing carried out before that withdrawal.

Where required by law, Tess recognizes and honors valid privacy-preference signals sent by the browser, such as Global Privacy Control (GPC), as a valid opt-out request from sharing of personal information for cross-context behavioral advertising. Upon detecting such a signal, Tess will, to the extent technically feasible, stop triggering cookies, pixels, tags, and SDKs used for advertising, paid acquisition, and remarketing on that browser or device, without requiring an additional request.

Recognition of a GPC signal does not prevent the use of technologies that are strictly necessary to make the Services available, remember essential settings, protect accounts, prevent fraud, or ensure the security of the Platform.

The inventory of trackers, legal bases by category, partners (including Meta, Google Ads, and ManyChat), duration, transfers, and how to manage preferences are in the Cookie Policy.

9. INTERNATIONAL TRANSFERS

The Services involve processing and international transfer of personal information. Account data, content necessary for inference (prompts, files, and task context), and tracker data may be processed in Brazil and the United States, and in other countries where Tess or its infrastructure, connectivity, and artificial intelligence model providers maintain operations, as described in the Privacy Notice and the Cookie Policy.

These transfers observe arts. 33 to 36 of the LGPD and, where the GDPR applies, Chapter V of the GDPR. Tess adopts appropriate safeguards, such as adequacy decisions, standard contractual clauses or standard data-protection clauses, and other guarantees recognized by the competent authority. Systematic transfer to model and infrastructure providers is not based solely on a one-off contractual necessity.

Business customers will find the contractual detail in the DPA. Destinations and subprocessors are listed in the Trust Center. You may request information about the safeguard mechanisms, including a copy of the applicable clauses, to the extent commercial confidentiality permits, through [email protected].

10. RETENTION AND DELETION

Tess retains personal information only for the period necessary to fulfill the purposes described in this Policy, provide the Services, meet legal, tax, regulatory, accounting, and audit obligations, resolve disputes, exercise or defend rights, and enforce contracts.

Retention periods may vary according to the nature of the information, the purpose of processing, account and plan settings, applicable legal obligations, and security needs. After the applicable period ends, the information will be deleted, anonymized, or kept securely when retention is required or permitted by law.

Account data

  • Examples: name, email, username, user ID, preferences
  • Purpose: create and administer the account; authentication; support
  • Retention basis/justification: performance of the contract; legitimate interest; legal obligation
  • Retention period: while the account is active + 30 to 90 days after deletion
  • Trigger: account creation or deletion
  • Disposition at end of period: deletion or anonymization
  • Exceptions: retention if needed for litigation, fraud, or a legal obligation

Profile/workspace data

  • Examples: organization, members, permissions, settings
  • Purpose: workspace management and access controls
  • Retention basis/justification: performance of the contract
  • Retention period: while the workspace is active + 30 to 90 days after closure
  • Trigger: workspace closure
  • Disposition at end of period: deletion or anonymization
  • Exceptions: data needed for audit or dispute may be retained

Prompts, responses, and generated content

  • Examples: prompts, outputs, images, videos, audio, documents, and files
  • Purpose: fulfill requests, make history and product features available
  • Retention basis/justification: performance of the contract; user instructions
  • Retention period: while kept by the user or according to plan configuration; after deletion, up to 30 days for operational removal
  • Trigger: user deletion, account termination, or plan-defined expiration
  • Disposition at end of period: deletion from active systems; expiration in backups according to policy
  • Exceptions: deletion hold due to legal order, fraud prevention, or dispute

Uploaded files

  • Examples: images, videos, documents, audio, and attachments
  • Purpose: process prompts and deliver the Services
  • Retention basis/justification: performance of the contract
  • Retention period: while needed for the feature and/or while the user keeps the file; operational removal within 30 days after deletion
  • Trigger: deletion or account termination
  • Disposition at end of period: deletion from active storage; later expiration of backups
  • Exceptions: logs and minimal metadata may have a distinct retention period

Integration credentials

  • Examples: tokens, OAuth keys, connection secrets
  • Purpose: authenticate and run an enabled integration
  • Retention basis/justification: performance of the contract; user consent/configuration, where applicable
  • Retention period: while the integration is active; revocation/disconnection immediately or within 30 days
  • Trigger: integration disablement, credential revocation, or expiration
  • Disposition at end of period: revocation and secure deletion
  • Exceptions: minimal audit evidence may be preserved without the secret

Payment data

  • Examples: plan, invoices, payment status, transaction IDs
  • Purpose: billing, invoicing, accounting, and fraud prevention
  • Retention basis/justification: performance of the contract; legal obligation
  • Retention period: 5 (five) years, or the applicable tax, fiscal, and accounting period, whichever is longer
  • Trigger: invoice issuance or end of the relationship
  • Disposition at end of period: secure archiving or deletion according to legal obligation
  • Exceptions: full card data must be handled by the payment processor, not by Tess

Technical and security records

  • Examples: IP, device/browser data, login, security events, access attempts, audit logs
  • Purpose: security, abuse/fraud detection, diagnostics, incident response, and compliance with the Brazilian Internet Civil Framework (Marco Civil da Internet)
  • Retention basis/justification: legitimate interest; legal obligation; security
  • Retention period: access and IP logs, at least 6 (six) months, under art. 15 of Law No. 12.965/2014 (Marco Civil da Internet); 90 to 180 days for other operational logs; 12 to 24 months for security and audit logs, according to risk
  • Trigger: event generation
  • Disposition at end of period: deletion or anonymization
  • Exceptions: incidents, investigations, or a legal obligation may justify longer retention

Analytics and cookie data

  • Examples: cookies, identifiers, usage events, and metrics
  • Purpose: operation, preferences, metrics, and improvement unrelated to AI training
  • Retention basis/justification: consent where required; legitimate interest for strictly necessary cookies
  • Retention period: according to cookie category and configuration; typically 13 months or less for non-essential cookies, subject to local law
  • Trigger: collection or cookie expiration
  • Disposition at end of period: expiration, deletion, or anonymization
  • Exceptions: GPC signals, consent, and opt-out must be honored where required

Support data

  • Examples: emails, tickets, chats, attachments, and recordings, if any
  • Purpose: handle requests, improve support, prevent fraud, and create a history
  • Retention basis/justification: performance of the contract; legitimate interest
  • Retention period: 24 months after ticket closure, unless a distinct need applies
  • Trigger: ticket closure
  • Disposition at end of period: deletion or anonymization
  • Exceptions: communications linked to litigation, fraud, or security may be preserved

Privacy requests

  • Examples: request, identity/verification, response, and handling evidence
  • Purpose: comply with LGPD, GDPR, CCPA/CPRA and demonstrate compliance
  • Retention basis/justification: legal obligation; legitimate interest in compliance
  • Retention period: 24 months after closure of the request, unless a longer period is required by law
  • Trigger: completion of the request
  • Disposition at end of period: deletion or anonymization
  • Exceptions: preserve only the minimum needed for defense and audit

Consent and preference records

  • Examples: consents, refusals, opt-outs, GPC, versions of accepted notices
  • Purpose: prove consent, honor preferences, and audit
  • Retention basis/justification: legal obligation; legitimate interest
  • Retention period: during the relationship and for 5 (five) years after it ends, or a longer limitation or regulatory period where applicable
  • Trigger: recording or change of a preference
  • Disposition at end of period: deletion or anonymization when no longer needed
  • Exceptions: it may be necessary to retain minimal opt-out evidence

Backup data

  • Examples: copies of databases, files, and systems
  • Purpose: business continuity, disaster recovery, and security
  • Retention basis/justification: legitimate interest; security
  • Retention period: 30 to 90 days, according to architecture and backup frequency
  • Trigger: backup creation
  • Disposition at end of period: automatic expiration and overwrite/secure destruction
  • Exceptions: restorations must respect pending or completed deletion requests

Candidate and recruitment data

  • Examples: résumé, contact information, professional history
  • Purpose: conduct a selection process
  • Retention basis/justification: consent, legitimate interest, or pre-contractual measures
  • Retention period: 6 to 24 months, depending on consent and local rules
  • Trigger: closure of the vacancy/process
  • Disposition at end of period: deletion or anonymization
  • Exceptions: anti-discrimination obligations and defense in complaints

Vendor and B2B representative data

  • Examples: professional contact, contract, billing, and communications
  • Purpose: contract, manage, and pay vendors
  • Retention basis/justification: performance of a contract; legal obligation
  • Retention period: contract term + legal/fiscal and limitation periods
  • Trigger: end of the contract
  • Disposition at end of period: archiving or deletion
  • Exceptions: tax and contractual documents may have a longer legal retention period

11. SECURITY

Tess adopts reasonable and proportionate technical, administrative, and organizational measures to protect personal information against unauthorized access, loss, alteration, destruction, disclosure, or misuse. These measures may include encryption in transit and, where applicable, at rest; access controls; security monitoring; audit logs; security assessments; and incident-response procedures.

No transmission over the internet and no method of electronic storage is completely secure. For that reason, Tess cannot guarantee absolute security.

In the event of a security incident that may result in relevant risk or harm to data subjects, Tess will adopt the response and communication measures required by applicable law.

In Brazil, Tess will notify the National Data Protection Authority (ANPD) and affected data subjects within the legal period of up to 3 (three) business days, counted from knowledge that the incident affected personal data, under LGPD art. 48 and art. 6 of ANPD Board Resolution No. 15/2024. The process in accessible language is also in the Privacy Notice.

Where the GDPR applies, Tess will notify the competent supervisory authority without undue delay and, where required, within 72 (seventy-two) hours after becoming aware of the incident, and will communicate with data subjects when the law so requires. For business customers where Tess acts as a processor, the contractual timelines in the DPA apply in parallel.

12. MINORS

The Services are intended exclusively for persons 18 (eighteen) years of age or older. By accessing or using the Platform, you represent and warrant that you are at least 18 years of age.

Tess does not direct the Services to persons under 18 and does not knowingly solicit personal information from minors. If Tess becomes aware that it has collected personal information from a person under 18 in a manner inconsistent with this Policy or the Terms of Use, it may take reasonable steps to delete such information and terminate or restrict access to the associated account, as applicable.

If you believe that a person under 18 has provided personal information to Tess, please contact us at [email protected].

13. YOUR PRIVACY RIGHTS

Depending on your location and applicable law, you may have rights over your personal information, such as:

  • confirm the existence of processing;
  • request access to the personal information processed;
  • request correction, updating, or rectification of inaccurate information;
  • request anonymization, blocking, restriction, erasure, or deletion, where applicable;
  • request portability;
  • obtain information about entities with which Tess has shared personal information, where required by law;
  • object to certain processing;
  • request restriction of processing in circumstances provided by law;
  • withdraw consent, where consent is the applicable legal basis;
  • object at any time to processing for direct marketing, including related profiling, where the GDPR applies (art. 21(2));
  • request review of automated decisions, under LGPD art. 20, where applicable;
  • lodge a complaint with the National Data Protection Authority (ANPD) or, where the GDPR applies, with the supervisory authority of the country of residence, work, or of the alleged infringement (art. 77); and
  • not suffer discrimination or retaliation for exercising privacy rights.

To exercise your rights, use the interactive form available in the Privacy Notice or send a request to [email protected]. We may request reasonable information to verify your identity and protect your account against fraudulent requests.

Tess will respond within the period required by applicable law: as a rule, within 15 (fifteen) days under the LGPD, unless a special period applies; within 1 (one) month under the GDPR, extendable under art. 12(3); and, for California residents, as described in Section 14. Where permitted, we may extend the period upon notice to the data subject.

You may designate an authorized agent to exercise rights on your behalf when permitted by law. In that case, we may request proof of authorization and verify your identity.

14. NOTICE FOR CALIFORNIA RESIDENTS (CCPA/CPRA)

This section supplements the other provisions of this Policy and applies exclusively to residents of the State of California, United States, to the extent the CCPA/CPRA applies. The terms “personal information,” “sensitive personal information,” “sale,” “sharing,” “business,” “service provider,” and “contractor” have the meanings assigned by the CCPA/CPRA.

14.1 Categories, sources, purposes, and recipients

In the past 12 months, Tess may have collected the categories below, from the sources in Section 3, for the purposes in Section 4, and disclosed them to the recipient categories in Section 6.

Category Sold for money Shared (CCPA/CPRA) Disclosed for a business purpose
Identifiers (name, email, username, account IDs) No Yes, to the extent online identifiers (cookie, device, IP) are disclosed to Meta, Google, and ManyChat for cross-context behavioral advertising Yes — service providers, enabled integrations, workspace administrators, authorities when required, and corporate transactions
Commercial information (plan, billing, transaction history) No No Yes — payment processors, support, billing, and legal obligations
Platform content (prompts, files, responses, and Assets) No No Yes — model and infrastructure providers, to the extent needed for the requested inference; enabled integrations
Internet or other electronic network activity No Yes — with Meta, Google, and ManyChat, for measurement, audiences, and remarketing Yes — analytics, security, operations, and providers
Integration data and connection credentials No No Yes — connectivity providers and the application you enabled
Security and fraud-prevention data No No Yes — security, abuse detection, and specialized providers
Sensitive personal information (when you enter it, including integration credentials) No No Yes — only to provide, protect, maintain, and perform the Services, without inferring characteristics

Tess does not sell personal information for money. Sharing for cross-context behavioral advertising is described in Section 6 and in the Cookie Policy.

Tess does not sell or share sensitive personal information for cross-context behavioral advertising. Tess also does not sell or share prompts, files, responses, or content generated on the Platform with advertising or marketing partners for that purpose.

14.2 Rights of California residents

Subject to the conditions, exceptions, and limitations in the CCPA/CPRA, California residents may have the right to:

  • know and access the categories and specific pieces of personal information collected;
  • obtain information about sources, purposes, and categories of recipients of personal information;
  • request deletion of personal information;
  • correct inaccurate personal information;
  • limit the use and disclosure of sensitive personal information to the purposes permitted by the CCPA/CPRA;
  • opt out of the sale or sharing of personal information, including through the “Do Not Sell or Share My Personal Information” link, available on the site and in the Privacy Notice, the preferences described in the Cookie Policy, and opt-out signals recognized by Tess, such as Global Privacy Control (GPC), where applicable; and
  • not suffer discrimination or retaliation for exercising these rights.

Tess will respond to verifiable requests from California consumers within 45 (forty-five) days of receipt. Where permitted, that period may be extended by up to 45 additional days, upon notice.

To submit a request, use the interactive form available in the Privacy Notice or send an email to [email protected]. Authorized agents may submit requests when permitted by law, subject to proof of authorization and identity verification. To limit the use of sensitive personal information to the purposes permitted by the CCPA/CPRA, use the same channels.

15. CHANGES TO THIS POLICY

Tess may update this Policy periodically to reflect changes in the Services, processing practices, applicable law, or other operational, technical, commercial, or security reasons.

When a change is material, Tess will take reasonable steps to inform users before it takes effect, where required by law. The most recent version will be available on this page, with an indication of the effective date.

16. CONTACT AND DATA PROTECTION OFFICER

For questions, comments, privacy-related requests, or exercise of rights, including by data subjects in the European Economic Area, the United Kingdom, or other jurisdictions, contact Tess at [email protected] or through the form available in the Privacy Notice.

Tess Tecnologia LTDA

CNPJ: 60.806.420/0001-91

Address: Av. Prof. Pereira Reis, 76, Loja B, Santo Cristo, Rio de Janeiro, RJ, 20220-800, Brazil

Data Protection Officer (DPO): DPO services are provided on Tess’s behalf by Open CyberSecurity (https://opencybersecurity.com.br/), a privacy and information-security consultancy contracted to support LGPD/GDPR compliance.

Contact: [email protected]

Support: [email protected]