Last updated: 2026-08-18
1. Who This Notice Covers
Tessora LLC ("Tessora", "we", "us", or "our") operates Notavia, a business notification service in the SaaS Infrastructure suite.
This Notice applies to personal data we handle as controller about:
- visitors to our websites;
- adults who create, administer, or use a Notavia account for a Customer;
- adult sole proprietors, sole traders, freelancers, and independent developers using the service for professional activity;
- authorized adult personnel of incorporated or unincorporated business Customers;
- people who contact support, sales, security, or another business mailbox; and
- other natural persons whose data we receive for our own account, security, billing-administration, or product-operation purposes.
Notavia is offered worldwide for business and professional use. It is not offered for personal, family, or household use. That commercial-use restriction does not remove privacy rights that a natural person has under applicable law.
A Customer may use Notavia to send notifications to its own end-users or other recipients ("Recipients"). Section 2 explains why Tessora normally acts as the Customer's processor, rather than controller, for that Recipient data.
2. Who We Are and Our Privacy Roles
Tessora LLC is a company organized under the State of Wyoming, United States, with the public mailing address 30 N Gould St Ste N, Sheridan, WY 82801 US. Our worldwide privacy contact is support@saas-infrastructure.com.
2.1 Tessora as controller
Tessora determines why and how it handles personal data for:
- the public website, including contact and waitlist submissions;
- account creation, invitations, authentication, access control, and account administration;
- service security, fraud and abuse prevention, audit records, and incident response;
- Paddle transaction reconciliation, subscription administration, invoicing records, and tax or accounting administration that Tessora performs;
- support and other business communications;
- essential website and service preferences;
- consented website analytics; and
- limited product-operation and service-improvement measurements.
For those activities, Tessora is the controller or equivalent business under applicable privacy law.
2.2 Tessora as processor for Customer Recipient data
The Customer decides which Recipients to contact, what notification content to send, why to send it, and which lawful basis or other permission applies. When Tessora stores or transmits Recipient identifiers, notification content, preferences, suppression data, and delivery events on the Customer's instructions, Tessora acts as processor or service provider for the Customer.
The Customer is responsible for its own notices, lawful basis, instructions, and handling of Recipient requests. Tessora does not use the Customer's contract with Tessora as Tessora's lawful basis for the Customer's processing of Recipient data. A processor does not replace the Customer's required lawful basis. Our processing duties and assistance commitments are described in the Data Processing Agreement.
If you are a Recipient, contact the business that sent or arranged the notification first. We will support that Customer's response and will route a request to the Customer where appropriate. You may also contact us at support@saas-infrastructure.com if you cannot identify or reach the Customer. This role allocation does not limit any right you have against an applicable controller.
2.3 Other organizations acting as controllers
Paddle is our Merchant of Record and acts as an independent controller for the buyer and payment information it handles to sell the service, process payment, calculate tax, prevent fraud, and meet its legal obligations. Paddle's own privacy notice applies to that processing. Authentication providers and Customer-selected delivery providers may also act under their own privacy terms for activities they determine.
3. Categories of Personal Data and Where They Come From
| Category | Examples | Main source |
|---|---|---|
| Website and business-contact data | Name, business email, company, selected contact topic, message, waitlist email, source page, IP address, and user agent | You and your browser |
| Account and organization data | Email, optional display name, organization name, membership, role, account and organization identifiers, selected plan, account dates, and organization configuration | You; an organization owner or administrator who invites you; service records generated when the account is used |
| Authentication data | Password hash, sign-in state, multifactor state, recovery and authenticator information, external-login provider and provider identifier, SSO identity link, IP address, user agent, and sign-in events | You; your browser or device; Google, Microsoft, or a Customer-configured identity provider when selected; our authentication service |
| Billing-administration data | Plan, subscription state and dates, invoice number and amounts, actual transaction currency, Paddle customer, subscription and transaction identifiers, card brand and last four digits where returned, and Paddle transaction, address, and tax information, including billing country | Paddle; the Customer's authorized buyer; service-generated billing records |
| Preferences and local storage | Consent choice, theme, dashboard environment, documentation-interface state, workflow-editor state, and website currency preference | You and your browser |
| Security, audit, and service-usage data | Request and event timestamps, IP address and user agent where recorded, paths, methods, response codes, security and account events, configuration changes, data-access events, organization-keyed product milestones, notification-volume statistics, and diagnostic logs | Your use of the website or service; our applications and infrastructure |
| Support and business communications | Sender and recipient details, message content, attachments, routing topic, and related account or organization details | You, the Customer, or another person communicating with us |
| Legal acknowledgement evidence | A unique event identifier; user and organization identifiers and names; user email; document slug, version, and effective date; attestation identifier, version, exact copy or immutable hash; UTC timestamp; context; affirmative action and source; IP address and user agent where recorded; and, at checkout where available, billing country, transaction currency, and Paddle customer, transaction, or subscription identifiers | You, the account or checkout interface, your browser, and Paddle |
| Recipient data handled for a Customer | Email address, phone number, device or inbox identifier, notification content and variables, template and channel data, preferences, suppressions, send and delivery timestamps, delivery state, bounce or complaint data, provider error details, email-open and link-click events, clicked destination, user agent where recorded, machine-open classification, and event counts and timestamps | The Customer; the Recipient through preference or inbox features; the Customer's connected delivery provider; events generated when a tracking-enabled email is opened or a tracked link is followed |
We do not receive or store a full payment-card number in Notavia. Billing country is Paddle transaction, address, and tax information. It is not a customer residence classification or legal-region setting.
USD or EUR selection is an organization billing preference. The actual currency of each transaction is recorded separately. The public website may store a currency display preference in the browser. None of these values selects a privacy regime, customer territory, hosting region, or governing law.
4. Why We Use Controller Data and the Lawful Bases We Rely On
The lawful basis depends on the person, purpose, and law that applies. Under the GDPR and UK GDPR, we use the following bases where relevant:
| Purpose | Data involved | Lawful basis |
|---|---|---|
| Respond to a requested contact, support, sales, security, or waitlist interaction | Website and business-contact data; communications | Steps requested before a contract or performance of a contract where the individual is the contracting person; otherwise our and the Customer's legitimate interests in responding to professional enquiries and supporting the service |
| Create and administer accounts, authenticate users, provide requested service functions, and communicate operational messages | Account, organization, authentication, preference, and service-usage data | Contract where the individual is the contracting person; otherwise our and the Customer's legitimate interests in providing an organization account to authorized personnel |
| Administer subscriptions, reconcile Paddle transactions, maintain invoices, and handle tax and accounting | Account, organization, and billing-administration data | Contract where the individual is the contracting person; legitimate interests in administering the Customer relationship; and legal obligation for records the law requires us to keep |
| Protect accounts, infrastructure, Customers, and Recipients; detect fraud or abuse; investigate incidents; enforce service rules | Authentication, security, audit, usage, and communication data | Our, the Customer's, and users' legitimate interests in a secure and reliable service; legal obligation where a specific security or compliance duty applies |
| Provide support and manage disputes, legal claims, complaints, and compliance requests | Account, organization, security, billing, acknowledgement, and communication data | Contract where applicable; legitimate interests in resolving issues and establishing, exercising, or defending legal claims; legal obligation where applicable |
| Record which legal documents and attestations were presented and acknowledged or agreed | Legal acknowledgement evidence | Legal obligation where recordkeeping is required; legitimate interests in demonstrating the applicable terms, notice, authority statement, and affirmative action |
| Measure organization-keyed service milestones and aggregated service performance | Organization identifiers, product milestones, and aggregated usage statistics | Legitimate interests in operating, troubleshooting, and improving the business service, balanced against the limited and organization-focused data used |
| Run PostHog analytics on the public website | Page views, referrer, interactions, device and browser information, approximate location derived from network data, and PostHog identifiers | Consent only. The website makes no PostHog analytics request before affirmative consent, regardless of the visitor's country. Consent can be withdrawn through Cookie preferences |
| Meet legal, tax, regulatory, and valid authority requirements | Relevant account, billing, security, communication, and acknowledgement data | Legal obligation; legitimate interests in responding to claims and lawful requests where legal obligation is not the applicable basis |
Where we rely on legitimate interests, the interests are the ones stated in the table. We consider the professional context, the data's sensitivity, the relationship among Tessora, the Customer, and the individual, and available limits such as role-based access, retention controls, and opt-outs. You may object as described in Section 10.
Where consent is the basis, refusing or withdrawing consent does not affect the lawfulness of processing before withdrawal. Website analytics stays off unless and until affirmative consent is recorded.
Customer Recipient processing
Tessora processes Recipient data only on the Customer's documented instructions, subject to the DPA and applicable processor duties. The Customer—not Tessora—must identify the Article 6 basis or other legal permission for the Customer's notification activity. Tessora's service contract defines our processor instructions and obligations; it is not Tessora's Article 6 basis for the Customer's Recipient processing.
The email channel currently enables open and link-click tracking by default unless the Customer changes the environment setting or a permitted send-level override. Open tracking adds a remote image; link tracking replaces eligible links with a redirect through Notavia. The service records the event details listed in Section 3 and then redirects a tracked click to the Customer-supplied destination. Unsubscribe links are not rewritten. Blocking remote images can prevent an open event, and not following a tracked link prevents a click event, but those browser choices are not represented as a complete Recipient opt-out mechanism. The Customer controls whether to use this tracking and is responsible for its notice, permission or lawful basis, and Recipient choice. Contact the Customer first to object or exercise a Recipient right; Tessora will support the Customer under the DPA. This Customer-directed tracking is not PostHog, is not controlled by the website cookie banner, and is not converted into Tessora consent by an analytics choice.
5. Cookies, Local Storage, and Analytics
Our Cookie Policy lists the current cookies and browser-storage items, their purpose, duration, and provider.
The website and service use essential storage for authentication, antiforgery protection, consent state, interface preferences, and similar requested functions. Website currency storage is only a display preference. The application also stores selected interface state, such as theme, dashboard environment, and workflow-editor state, in the browser.
PostHog website analytics is optional worldwide and is active from 18 August 2026, after the activation gates earlier versions of this notice enumerated were closed: a data processing agreement with PostHog Inc. was executed on 13 August 2026, and the project's console settings — an EU Cloud project, plan-defined retention with an available deletion path, support access reviewed against the executed agreement, IP discard on with replay and surveys off, the exercised opt-out from PostHog's product- and model-development use of Customer Content, and the authorised production domains — were verified by the accountable owner on 18 August 2026, with evidence filed in the internal evidence register. Whether a key is present or not, the website does not initialize PostHog or make a PostHog analytics request before affirmative consent. Reject remains as easy as Accept. Withdrawal changes the client to memory-only persistence, opts out, resets it, targets the recognized ph_ and __ph_ browser-storage names for deletion, and reloads. PostHog's EU ingestion endpoint is the configured host and matches the verified EU Cloud project; it is not a legal-region selector for the visitor or Customer.
The intended browser configuration enables page-view, page-leave, and autocaptured interaction events and defines waitlist_submitted with a source property and contact_submitted with a topic property. It uses persistent identifiers with person profiles limited to identified users, disables session recording, and enables the client Do-Not-Track option. No website code calls PostHog identify. Account-specific masking and exclusions, IP discard, surveys, feature flags, cross-domain behavior, retention and deletion, subprocessor chain, data-use/model-training opt-out, project region, legal entity, administrator route, DPA, transfer terms, and security evidence are unavailable. The installed client does not default all of those controls to the required restrictive position. PostHog must remain inactive until the role-based Owner captures and approves the project and account evidence.
Separately, the service contains an organization-keyed server route, active from 18 August 2026 with a production key configured. Its current five events are organization_registered with plan and region; first_notification_sent with channel; api_key_created with environment and scope; plan_changed with plan, previous_plan, and status; and inbox_first_rendered with no custom property. The sender adds the organization UUID as distinct_id and $groups.organization. The reviewed call sites contain no name, email address, message content, Recipient data, person identifier, or hidden payload. A code-level allow-list enforces that list. The sending code refuses an event or property that is not declared and refuses a value that is not a short plain token, refusing outright rather than trimming silently, and tests cover the list and every call site. This separate service-operation route relies on the legitimate-interests assessment in Section 4, not website consent; a website rejection does not opt an organization out. An organization can object from the dashboard, under Settings → Privacy & Data; the sending code checks that objection before every send and stops for that organization from the moment it is recorded, and the objection carries its date and can be withdrawn. You may also object through Section 13. Both controls are in the image production runs, and they are what governs this route now that it is active.
Our website runs no anti-bot challenge, and contacts no third party when you open a form page. Neither the contact page nor the waitlist page requests a script from Cloudflare Turnstile or from any comparable service, and no submission is checked against one. What protects those two forms is a hidden decoy field on both, and a per-IP-address submission limit on the waitlist form.
We state this because it is a change and because the direction matters. An earlier release did request the Turnstile script on both form pages, unconditionally, so opening either page disclosed to Cloudflare what that script collects — by Cloudflare's own material, IP address, TLS fingerprint, user agent, site key, origin and related bot-detection signals — while no server-side check ever ran on the resulting token. A challenge that collects from every visitor and gates nothing is not security, so we removed it rather than describe it. If we introduce one later it will fail closed on a missing, rejected or unreachable verification, check the expected hostname and the form the token was issued for, and we will publish the vendor's contract, transfer, retention, deletion and subprocessor position before it is switched on.
6. Who Receives Personal Data
We disclose personal data only as needed for the activities described in this Notice, including to:
- authorized Tessora personnel who need it for operations, support, security, billing administration, or compliance;
- the Customer and its authorized administrators for organization membership, service administration, billing, support, and Recipient-request coordination;
- Hetzner for managed application and database hosting in Germany;
- AWS SES for managed email delivery, on the
eu-central-1(Frankfurt) route described in Section 8; Amazon Web Services, Inc. is a United States company with global operations, so administrative and support access from outside the European Union must be treated as possible; - Paddle for Merchant of Record, checkout, payment, fraud, address, tax, and buyer-support functions;
- PostHog, only if the separate website or server activation gates are closed, for consented website analytics or limited organization-keyed service milestones;
- Cloudflare for authoritative DNS, off-site backup storage, and the other delivery and infrastructure functions described in the Subprocessor List;
- Google, Microsoft, or a Customer-configured identity provider when a user chooses or is required to authenticate through it;
- Tailscale and GitHub for restricted operational-access and deployment workflows where limited account, log, or failure-path data may be exposed;
- Customer-selected email, SMS, push, chat, webhook, or other delivery providers used on the Customer's instructions; and
- professional advisers, courts, regulators, law enforcement, counterparties, or acquirers where disclosure is necessary for legal advice, a valid legal process, protection of rights, or a corporate transaction.
The current vendor inventory, locations, roles, and service functions are in our Subprocessor List. A company named there is not necessarily Tessora's processor for every activity; for example, Paddle acts as an independent controller for its buyer and payment processing.
We do not sell personal data. We do not share personal data for cross-context behavioral advertising or use Recipient data for Tessora advertising.
7. International Processing and Data Location
The managed Notavia application and its primary database are hosted in Germany (European Union). That statement is a data-location fact only. It does not classify a Customer as EU, EEA, UK, US, or any other legal region, and it does not promise that all processing occurs in Germany.
Tessora is established in the United States. Personnel and vendors may process data from or in the United States, European Union, United Kingdom, and other countries shown in the Subprocessor List or selected by the Customer for a connected delivery provider. AWS SES managed sending uses eu-central-1 (Frankfurt), so Recipient addresses and message content stay in the European Union on that route. Paddle, Cloudflare, PostHog, Tailscale, GitHub, identity providers, and Customer-selected delivery providers may involve processing outside the country where the individual is located.
Where applicable law requires a transfer mechanism, the relevant controller must ensure that a valid mechanism and any required supplementary measures cover the route. The DPA and the Subprocessor List each record their own open vendor-verification gates, and the production transfer-mechanism review is not represented as complete by this Notice. Contact support@saas-infrastructure.com for the information currently available about a route or safeguard. Countries outside your jurisdiction may not provide the same level of legal protection.
There is no customer-selected legal-region control, country allow-list, or EEA or UK exclusion. Billing country, USD or EUR preference, actual transaction currency, and German hosting do not choose the law that applies to a person.
8. How Long We Keep Data
We keep personal data only for the period or by the criteria below, subject to legal holds, security investigations, disputes, valid authority requests, and legal, tax, or accounting duties.
| Data | Current retention or criterion |
|---|---|
| Account and organization administration data | While the account or organization is active and then through the applicable user-deletion or documented organization-deletion process, except for records retained for a stated legal, security, or claims purpose. Cancelling a subscription does not delete an organization on the day you cancel. It does start a dormancy clock, and the clock starts at the end of the period you already paid for, not on the day you cancel: if 180 days pass after that period ends and the organization sends nothing in that time, we schedule its deletion automatically and give it the same 30-day grace period, during which it can be cancelled like any other deletion. We email the organization's Owners and Administrators the grace end date when that happens, so the grace period is a real choice rather than a notice nobody saw. A legal hold stops the schedule from being set at all |
| Security, configuration, and billing audit entries | 365 days under the current audit-retention configuration |
| Lifecycle audit entries | 180 days under the current audit-retention configuration |
| Data-access audit entries | 90 days under the current audit-retention configuration |
| Notification records and related Customer Recipient data | The current base plan periods are 1 day for Free and Starter, 7 days for Growth, and 30 days for Pro and Scale. An organization override replaces the plan value. An active extended-retention add-on raises a finite effective period to at least 90 days; a null custom value remains without a finite reaper period. Notification events, tracked links, and attachment metadata follow notification deletion by cascade. Stored attachment bytes are purged on terminal delivery or after a 72-hour hard TTL |
| Contact, waitlist, support, legal, billing-administration, and acknowledgement records | The current contact and waitlist handlers do not persist a submission in the application database; they forward it to a system mailbox. Mailbox, provider, support, legal, billing, and acknowledgement periods are not universally configured, so this Notice does not invent one. Each record is kept only while its documented communication, relationship, duty, security, dispute, or proof purpose remains |
| Organization-export artifacts and rights/deletion request records | A generated export file is deleted 7 days after it is produced. A daily job clears the file and records when it did; the download is refused past the deadline even if the job has not run yet. A Recipient access file produced for an individual gets the same 7 days from the same job. The request record itself — who asked, for what, when it closed — is kept as accountability evidence and has no age reaper; it does not contain the exported data |
| Authentication, administrator, preference, and promotion audit records | These are separate from the unified audit categories above. No age reaper was found for them, and their category-specific periods and deletion behavior remain an open implementation gate |
| PostHog website analytics and browser storage | Active from 18 August 2026. Browser collection is permitted only after consent and storage follows the Cookie Policy. Retention follows the verified EU Cloud project's plan-defined schedule, with the settings captured in the internal evidence register on activation |
| Operational logs | No production Seq, container, host, Hangfire, or transport-log retention period and enforcement evidence is currently available. Those stores must receive category-specific periods before launch; no period is inferred here |
| Production backups | Nightly backups are running. A production host and an R2 bucket exist, and a scheduled job dumps the whole database each night, compresses it, checks it is a real dump rather than a truncated file, and uploads it off-site; failures alert an operator rather than passing silently. A restore drill has been performed and passed, restoring from the off-site copy — not the local one — into a scratch database and booting the application against it with every outbound credential blanked. Each copy is kept for at least 14 days and then removed, by different mechanisms: the local copy is pruned by age, on the first nightly run at which it is more than 14 whole days old, so in practice on its fifteenth day; the off-site copy is held by a bucket lock plus a lifecycle rule that refuses deletion and overwrite for 14 days and then expires the object, and that expiry is carried out by the storage provider at a moment we do not control. Fourteen days is the floor on how long we keep a backup, not a deadline by which a deletion clears one. A backup is never edited, so a record you ask us to delete stays inside any backup that already exists until that backup itself ages out — in practice about 15 to 16 days after the live deletion, and longer if a nightly run is missed or the provider's expiry sweep lags. We do not publish a shorter figure. What is still not evidenced, and we will not imply it: no drill has restored into production as opposed to a scratch database, and there is no evidence replaying a deletion through the backup set, so this is not a promise that data you asked us to delete is absent from every backup, before or after that period |
| Paddle records | Paddle keeps the buyer, transaction, address, payment, fraud, tax, and accounting records for the periods described in Paddle's privacy notice and required by law. Tessora's local subscription and invoice records follow the organization-deletion process subject to any overriding legal duty |
User deletion
An authenticated user can download the personal-account export currently provided in account settings. It includes the personal-data fields marked by the identity system, display name, external-login provider identifiers, and authenticator key. A user can request immediate deletion of that user account after providing the required confirmation. A sole owner must first transfer ownership or delete the organization. Deleting a user account does not by itself delete the Customer's organization or its notification data.
Organization export and deletion
An organization Owner or Administrator can request an organization export through the current Settings authorization. The current export includes organization and membership information, legal acknowledgement records, Recipients, preferences, suppressions, templates, and up to the latest 5,000 notification records. It does not establish completeness for events, tracked links, attachments, workflows, webhooks, provider settings, credentials, billing, audit/security data, older notifications, rollups, support, or vendor records. A privacy request may require additional searches. Only the person who requested the export can download it — being a member of the organization is not enough, because the file holds every Recipient's data for the whole organization — and the file is deleted 7 days after it is produced.
An organization-deletion request starts a 30-day grace period during which it can be cancelled. The same 30-day grace applies to a deletion we schedule ourselves after 180 days of dormancy following a cancelled subscription, and to one raised through our internal termination procedure. A daily job processes due requests. The current purge explicitly removes the core workflow, notification, Recipient, preference, suppression, template, webhook, integration, credential, environment, membership, local subscription and invoice, and organization-linked legal-acknowledgement rows enumerated in our operating record. It pseudonymizes retained member-actor entries in the unified audit log and marks the organization deleted. It retains the organization tombstone and completed request record, does not automatically delete each user's separate login account, and has not been proved to cover every organization-keyed table, vendor copy, operational log, export artifact, attachment byte, or backup. We therefore verify each deletion against a case-specific manifest rather than describing the current job as permanent removal of all data.
Customer Recipient requests are coordinated with the Customer as controller. We may need the Customer's instruction and enough information to locate the relevant organization and Recipient record.
9. Required and Optional Information; Automated Decisions
Information identified by the relevant account, authentication, contact, or Paddle checkout flow as required is necessary to complete that step. Without it, we may be unable to create or secure an account, answer a request, provide a selected service function, or complete a purchase. Optional information, such as a display name where optional, a company field on a contact form, website currency preference, and website analytics consent, may be withheld without selecting a different privacy regime.
Tessora does not currently make decisions about individuals based solely on automated processing that produce legal effects or similarly significant effects. Automated systems do perform authentication, rate limiting, spam or abuse checks, notification routing, delivery processing, and operational alerting. Paddle and Customer-selected providers may make their own fraud, payment, delivery, or account decisions under their notices. Contact us if you believe a Tessora decision affecting you was made solely by automated means.
10. Security
We use technical and organizational measures proportionate to the service and the risks we have identified. Current controls include TLS in transit, one-way password hashing through the identity framework, encrypted storage for supported provider credentials, scoped and revocable API keys, logical organization separation, restricted operational access, audit records, and incident-response procedures.
No system is completely secure. We do not claim blanket database, disk, or backup encryption where current evidence does not establish it. Our Security page describes the verified controls and open launch work in more detail. Please report a suspected vulnerability to security@saas-infrastructure.com.
11. Your Rights and Choices
Depending on the law that applies to you and Tessora's role, you may have rights to:
- obtain information about processing and access personal data;
- correct inaccurate or incomplete data;
- request deletion;
- restrict or object to processing, including processing based on legitimate interests;
- receive data in a portable form where the legal conditions apply;
- withdraw consent at any time where processing relies on consent;
- opt out of sale, targeted advertising, or qualifying profiling where applicable;
- appeal a refusal where applicable US state law provides that right;
- receive equal service and not be discriminated against for exercising an applicable privacy right; and
- complain to the competent privacy, data-protection, or consumer-protection authority.
Submit a request to support@saas-infrastructure.com. We may need to verify your identity, authority, organization, and the data involved. An authorized agent may submit a request where applicable law permits it, subject to verification of authority. We will respond within the period required by applicable law.
We accept privacy requests through the same worldwide route even where a specific jurisdictional statute does not apply. Voluntarily assisting with a request does not create a statutory right or waive a lawful exception. Rights are determined by applicable law and Tessora's role—not by a customer-selected region, billing country, currency, or hosting location.
If Tessora holds the data only as the Customer's processor, we will normally refer the request to the Customer and assist it under the DPA. If Tessora also holds controller data about the same person, such as account or support data, we will assess that portion directly.
12. EU and UK Contacts and Complaints
Tessora has not appointed a Data Protection Officer and does not claim to have one. Tessora has not appointed a representative in the European Union and has not appointed a representative in the United Kingdom. No appointment is described as underway, and future intent is not treated as satisfying an appointment obligation.
Requests from the EU, EEA, UK, or anywhere else should be sent directly to our worldwide privacy contact at support@saas-infrastructure.com or by mail to 30 N Gould St Ste N, Sheridan, WY 82801 US. This direct route does not replace a representative where applicable law requires one.
You may complain to the supervisory or regulatory authority competent for your location or the processing. You do not have to contact us first where applicable law allows a direct complaint.
13. Children and Recipient Data
Customer accounts are limited to adults acting for business or professional activity. We do not knowingly offer personal or household accounts to children.
A Customer may nevertheless instruct Notavia to process Recipient data relating to a minor. The Customer must determine whether that processing is lawful, provide required notices, obtain any required authorization, and configure the notification appropriately. Tessora will assist the Customer with an applicable request and will act directly for any controller data Tessora holds about the same person.
14. Changes and Acknowledgement
We may update this Notice when our processing, vendors, product, or legal obligations change. The version and last-updated date identify the text presented.
Where an account or checkout interface presents this Notice, the individual acknowledges the identified version. The Customer agrees to the Terms of Service and Data Processing Agreement; the Privacy Notice is acknowledged, not accepted as a contract. We retain the acknowledgement evidence described in Section 3. Recording acknowledgement does not waive privacy rights or make this Notice contractual.
For a material update, we may require a fresh acknowledgement in the account interface and use other notice methods supported at that time. A fresh acknowledgement records which document changed; it does not imply that the interface displays a redline. Changes become operative on the publication or effective date stated for the applicable version, subject to mandatory law.
15. Contact Routes
- Privacy requests and questions: support@saas-infrastructure.com
- Security reports: security@saas-infrastructure.com
- Billing administration: support@saas-infrastructure.com
- General support: support@saas-infrastructure.com
- Mail: Tessora LLC, 30 N Gould St Ste N, Sheridan, WY 82801 US