Privacy Policy
Last updated: 13 July 2026
This Privacy Policy explains how Tegis (“we”, “us”) handles personal data. It covers two distinct roles: the people who run platforms on Tegis (our customers), and the end-users who watch video delivered through Tegis (our customers’ viewers). Our design goal for the delivery path is to store no viewer personal data at all.
1. Viewer data — the no-PII design
The Tegis delivery path is built so that no raw viewer identifiers are persisted. We do not store viewer email addresses, names, IP addresses, or account identifiers. Where a signal is needed to enforce entitlements or detect abuse (for example, rate-limiting or leak attribution), it is reduced to an unlinkable, salted one-way value with a short retention window and cannot be reversed to a person. Content delivered through our CDN sub-processors is encrypted; they never receive viewer data or plaintext video.
2. Customer data we process
When you sign up for and operate a Tegis account, we process:
- account data: your name, organization/app name, and email address;
- authentication data: hashed credentials and session records (via our authentication provider);
- operational data: tenant configuration, API-key metadata, and audit logs of administrative actions;
- billing data: subscription and usage records (payment card details are handled by our payment processor, not stored by us).
3. Product analytics and error monitoring
In the tenant console we use privacy-friendly product analytics and error monitoring to operate and improve the Service. Analytics is off by default and is only enabled after you accept it in the consent banner; you can decline without losing functionality. Error monitoring runs to keep the Service reliable and is configured not to collect unnecessary personal data.
4. Why we process data (legal bases)
- to provide the Service and perform our contract with you;
- our legitimate interest in securing, operating, and improving the Service;
- your consent, where required (for example, non-essential analytics cookies);
- compliance with legal obligations.
5. Retention
We keep customer account data for as long as your account is active and as needed to comply with legal obligations. Operational signals on the delivery path use short automated retention windows and are then deleted. Reduced abuse-detection values expire on a rolling basis.
6. Sub-processors
We use a small set of infrastructure sub-processors to run the Service, including providers for compute, content delivery, edge/DNS, payments, and transactional email. Sub-processors on the delivery path handle only encrypted content. A current list is available on request and will be published here on legal review.
7. International transfers
We operate our infrastructure in the EU where practical. Where data is transferred outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses.
8. Your rights
Subject to applicable law (including the GDPR), you may request access, correction, deletion, or portability of your personal data, and object to certain processing. Contact admin@tegis.io and we will respond within the legally required timeframe.
9. Security
We protect data with encryption in transit and at rest, scoped access controls, and audited administrative actions. To report a vulnerability, see our security policy or email security@tegis.io.
10. Contact
Data-protection questions: admin@tegis.io.