This policy applies to all users of our Services. Additional terms, notices, or agreements may supplement this Privacy Policy, such as in service-specific terms or data processing agreements.
We collect personal and usage information necessary to deliver and improve our Services. This includes:
We do not knowingly collect or process Protected Health Information (PHI) unless contractually required, and in those cases, we do so in compliance with HIPAA and appropriate Business Associate Agreements (BAAs).
We use your information to:
Under GDPR, we process your personal data on the following lawful bases:
We may share your personal information with:
Data retention by service providers: Usage and Technical Data may be retained by certain service providers for up to 90 days, solely for monitoring and abuse detection purposes.
We do not sell your personal data to third parties.
We implement robust technical and organizational measures aligned with ISO 27001, SOC 2 Type II, and HIPAA standards to ensure the confidentiality, integrity, and availability of your data. These include:
While we do not process or store payment card data ourselves, we ensure that any payment processing is handled exclusively through PCI-certified providers.
We retain personal information only as long as necessary to fulfill the purposes for which it was collected, or to comply with legal, regulatory, or contractual obligations. Data may be anonymized or securely deleted after the retention period.
Depending on your jurisdiction, you may have rights to:
To exercise these rights, please contact us at support@tutaki.com.
Some of our analytics and service providers may process your data in countries outside the European Economic Area (EEA), including the United States. If we transfer your data outside of your country or the European Economic Area (EEA), we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses, adequacy decisions).
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes via our website or direct communication.