Draft — not reviewed by counsel
This document is a working draft. It has not been reviewed by a lawyer, it contains unfilled placeholders, and it does not yet bind anyone. Do not rely on it.
Privacy Policy
What we collect, why we have it, who else sees it, and how to get it out or deleted.
[LEGAL ENTITY NAME], LLC · Effective [EFFECTIVE DATE] · Last updated [LAST UPDATED]
1.Two kinds of data, two different roles
Account data is about the businesses that use Tensvia — your name, work email, company, billing details, and how you use the product. We decide how that is handled, so we are the controller for it.
Customer Data is your customers' information that flows through the Service — their messages, contact details, bookings, call audio. You decide what happens to that; we only process it to run the Service for you. There we are a processor, and the Data Processing Addendum governs.
If you are someone who messaged a business that uses Tensvia: that business, not Tensvia, decides how your information is used. Contact them first. We will help them respond.
2.What we collect
- Account & identity — name, work email, business name, role, authentication records.
- Billing — plan, invoices, payment method reference. Card numbers go to Stripe directly; we never hold them.
- Business facts you supply — services, prices, hours, policies, uploaded documents and media.
- Customer Data — inbound and outbound messages, contact records, consent state, bookings, and where you enable it, call audio and transcripts.
- Operational — logs, request metadata, IP address, error reports, audit records of who approved what and when.
We do not use tracking cookies for advertising and we do not run third-party ad pixels on this site.
3.Why we have it
To run the Service, authenticate you, bill you, keep the system secure, detect abuse, meet legal obligations, and support you when you ask. For customers in the UK and EEA, our lawful bases are performance of a contract, legitimate interests in securing and improving the Service, and compliance with legal obligations.
4.Models and training
Message content and business context are sent to our model provider to produce a classification or a draft, and are used for that inference only.
We do not use your Customer Data to train general-purpose models, and we do not permit our providers to. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
5.Who else processes it
We use the sub-processors below. Each is bound by contract to confidentiality and to process only on our instructions.
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Supabase | Primary database, authentication, file storage | All Customer Data | United States |
| Vercel | Application hosting and edge delivery | Request metadata, application logs | United States |
| Anthropic | Model inference — classification, drafting, summarisation | Message content and business context sent for a single inference | United States |
| Telnyx | SMS and voice delivery | Phone numbers, message bodies, call audio and transcripts | United States |
| Resend | Outbound and transactional email | Email addresses, message bodies | United States |
| Cal.com | Calendar availability and booking | Name, email, appointment details | United States |
| Stripe | Subscription billing and payment processing | Billing contact and payment method. Card details go to Stripe directly and are never held by Tensvia | United States |
We will give notice before adding a sub-processor that processes Customer Data. We also disclose information where legally compelled, and we will tell you unless we are prohibited from doing so.
6.How long we keep it
Customer Data is kept while your account is active. On termination you have 30 days to export, after which we delete within 30 days. Billing records are retained as long as tax and accounting law requires. Audit and security logs are retained for up to 24 months, because a log you have already deleted cannot tell you what happened.
7.Security
Data is encrypted in transit and at rest. Tenant isolation is enforced at the database with row-level security rather than by application code remembering to filter. Provider credentials are stored as vault references — never written to logs, never placed in model context, never sent to the browser. Access to production data is limited to personnel who need it and is logged.
We hold no SOC 2 report or ISO certification at this time and do not claim one. Report a vulnerability to security@tensvia.com.
8.Your rights
Depending on where you live you may have rights to access, correct, delete, port, or restrict processing of your personal information, to object to processing based on legitimate interests, and to be free from discrimination for exercising them. California residents have the rights set out in the CCPA/CPRA; UK and EEA residents those in the UK GDPR and GDPR.
Email privacy@tensvia.com. We will verify your identity and respond within the period the applicable law requires. For Customer Data, we forward the request to the business that controls it.
9.International transfers
We operate in the United States and our sub-processors are located there. If you access the Service from outside the U.S., your information is transferred to and processed in the U.S. Where required for UK/EEA transfers we rely on Standard Contractual Clauses.
10.Children
The Service is for businesses. We do not knowingly collect personal information from anyone under 18. If you believe a minor's information has reached us, write to privacy@tensvia.com and we will delete it.
11.Changes
We will post updates here and, for material changes, notify account holders at least 30 days before they take effect.
Questions about this document: legal@tensvia.com