Tessi Privacy Policy
This Privacy Policy (“Policy”) explains how Tessi Technologies Inc. (“Tessi,” “we,” “us,” or “our”) collects, uses, discloses, and protects your Personal Data in connection with the Tessi Platform (the “Platform”). This Privacy Policy is a separate document that is incorporated into, and supplements, the Tessi Platform Terms of Service (the “Terms of Service”). Capitalized terms not defined in this Policy have the meanings given in the Terms of Service.
This Policy is designed to meet the requirements of applicable data protection laws worldwide, including the EU General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), U.S. state privacy laws (including the California Consumer Privacy Act, as amended by the California Privacy Rights Act, “CCPA/CPRA”), Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable privacy and data protection laws. Some Users may be citizens of, or located in, jurisdictions outside the United States; this Policy addresses those situations.
“Personal Data” or “Personal Information” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to you.
1. Data Controller / Business
Tessi Technologies Inc. acts as an independent data controller (under GDPR/UK GDPR) and as a business (under CCPA/CPRA) with respect to the Personal Data it collects from Homeowners through the Platform. Tessi determines the purposes and means of processing your Personal Data.
Contact: Tessi Technologies Inc., Attn: Privacy, privacy@tessi.ai
2. Categories of Personal Data Collected
We collect the following categories of Personal Data:
- (a) Identity Data — Full name, date of birth, and government-issued identification (if required for verification).
- (b) Contact Data — Email address, telephone number, and mailing address.
- (c) Property and Location Data — Property address, property type, geographic location, and details regarding property damage (including damage descriptions and classifications).
- (d) Financial, Insurance, and Funding Data — Insurance carrier name, policy type, coverage status, claim status, deductible information, funding eligibility indicators, and related financial information you provide or that is derived from available data.
- (e) Photos and Media — Photographs, videos, and other media of property damage that you upload to the Platform.
- (f) Device and Usage Data — IP address, browser type, operating system, device identifiers, pages visited, clickstream data, access times, referring URLs, and other usage and diagnostic data collected automatically when you use the Platform.
- (g) Communications Data — Records of your communications with Tessi, including support requests, feedback, and survey responses.
- (h) SMS / Text Messaging Data — Phone number, message content, consent status, opt-in source, timestamps, and delivery/interaction data collected in connection with our SMS text messaging services.
- (i) Inferred Data — Information inferred or derived from the above, including Damage Estimates, lead classifications, and risk or eligibility scores generated by Tessi's models.
3. Sources of Personal Data
We collect Personal Data directly from you (when you create an account, submit information, or communicate with us), automatically through your use of the Platform (via cookies, pixels, and similar technologies), from publicly available sources (such as property records and geographic data), and from third-party vendors, service providers, and data partners that Tessi uses in the operation of its business (such as identity-verification, fraud-prevention, credit, insurance, property, geospatial, mapping, and analytics providers).
You authorize Tessi to access, obtain, collect, and use any information about you that is available to Tessi through any such third-party vendor, service provider, or data partner, including, without limitation, identity-verification and authentication data; credit reports, credit scores, and other creditworthiness or financial information; insurance coverage, policy, claims, and loss-history information; property ownership, characteristics, valuation, and condition data; geographic, geospatial, and mapping data; risk, hazard, and catastrophe data; and fraud-prevention and analytics data, and to combine that information with other information we hold about you, in each case in connection with operating our business and providing the Services.
4. Purposes of Processing and Legal Bases
We process your Personal Data for the following purposes. Where required by GDPR or UK GDPR, we identify the legal basis for each purpose:
- Providing the Services and performing our contract with you (Legal basis: performance of contract) — to create and manage your account, generate Damage Estimates, provide insurance and funding information, facilitate referrals to Restoration Providers, and otherwise deliver the Services.
- Sharing information with Restoration Providers at your election (Legal basis: consent) — to share your information with Restoration Providers when you affirmatively elect to receive a referral.
- Improving and developing the Platform (Legal basis: legitimate interests) — to develop, train, test, and improve Tessi's databases, AI models, estimator tools, algorithms, and the Platform generally. Our legitimate interest is improving the accuracy and quality of our services for all users.
- Communicating with you (Legal basis: contract; legitimate interests) — to send service-related communications (including SMS text messages for support, scheduling, intake, and recovery-related purposes), respond to inquiries, and provide customer support.
- Safety, security, and fraud prevention (Legal basis: legitimate interests; legal obligation) — to detect, prevent, and address fraud, security incidents, and technical issues.
- Compliance with law (Legal basis: legal obligation) — to comply with applicable legal and regulatory requirements, respond to lawful requests, and enforce the Terms of Service.
- Marketing and analytics (Legal basis: consent or legitimate interests, as applicable) — to understand how Users interact with the Platform and, where permitted, to send promotional communications. You may opt out of marketing communications at any time.
- SMS messaging services (Legal basis: consent) — to send SMS text messages for service delivery, support, scheduling, intake, and recovery-related communications where you have opted in to receive such messages.
Consent: Where we rely on your consent, you may withdraw it at any time by contacting us at privacy@tessi.ai or through the settings in your account. Withdrawal of consent does not affect the lawfulness of processing performed prior to withdrawal.
5. Sensitive / Special Category Data
We generally do not seek to collect sensitive personal data or special categories of data (as defined under GDPR Article 9 or equivalent laws). However, certain information you provide—such as precise geolocation or financial circumstances—may be considered sensitive under some jurisdictions' laws. Where required, we will obtain your explicit consent before processing such data or rely on another lawful basis permitted by applicable law.
Under CCPA/CPRA, to the extent we process “sensitive personal information,” we will limit our use to purposes permitted under applicable law or obtain your consent, and you may direct us to limit such use as described in Section 11 (Consumer Rights — United States) of this Privacy Policy.
6. Sharing and Disclosure of Personal Data
We may share your Personal Data with the following categories of recipients:
- Restoration Providers (at your election): When you elect to receive a referral, we share your general geographic location, property-damage information, and insurance and funding status with Restoration Providers in your area. If a provider accepts your referral, we share additional details necessary for the provider to contact you and perform Restoration Services.
- Service providers and processors: We engage third-party service providers who process Personal Data on our behalf to support the Platform (e.g., cloud hosting, data analytics, customer support, email delivery, and SMS/messaging infrastructure vendors). These providers are contractually required to process your data only as instructed by Tessi and to maintain appropriate security measures.
- Professional advisors: Attorneys, accountants, auditors, and insurers who provide professional services to Tessi, subject to confidentiality obligations.
- Corporate transactions: In connection with a merger, acquisition, reorganization, sale of assets, financing, or similar transaction, your Personal Data may be disclosed to or transferred to the acquiring or successor entity, subject to applicable law.
- Legal requirements: We may disclose your Personal Data where required by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect the rights, safety, or property of Tessi, our Users, or others, or to detect, prevent, or address fraud or security issues.
- With your consent: We may share your Personal Data with other parties when you have given us your explicit consent to do so.
Sale / Sharing Disclosure (CCPA/CPRA): Tessi does not “sell” Personal Information as defined by the CCPA/CPRA. Tessi does not “share” Personal Information for cross-context behavioral advertising purposes.
7. International Data Transfers
Tessi is based in the United States. If you are located outside the United States (including in the European Economic Area, United Kingdom, Canada, or elsewhere), your Personal Data will be transferred to and processed in the United States and potentially other countries that may not provide the same level of data protection as your jurisdiction of residence. Where required by applicable law, we implement appropriate safeguards for international data transfers, including:
- EU Standard Contractual Clauses (SCCs): For transfers of Personal Data from the EEA, we rely on the European Commission's Standard Contractual Clauses (Module 1: controller-to-controller, and/or Module 2: controller-to-processor, as applicable) adopted under Commission Implementing Decision (EU) 2021/914.
- UK International Data Transfer Agreement / Addendum: For transfers of Personal Data from the United Kingdom, we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs, as adopted by the UK Information Commissioner's Office.
- Adequacy decisions and derogations: Where applicable, we may rely on adequacy decisions by relevant authorities or statutory derogations (such as transfer necessary for performance of a contract with the data subject) as permitted by applicable law.
You may obtain a copy of the relevant transfer mechanism by contacting us at privacy@tessi.ai.
8. SMS Text Messaging Privacy
This section describes Tessi's privacy practices specific to SMS and text messaging services provided through the Platform.
SMS Data Collected. In connection with our SMS text messaging services, Tessi collects the following information: your phone number, message content, consent status, opt-in source, timestamps, and delivery/interaction data.
Use of SMS Data. Tessi uses SMS-related data solely for the purpose of delivering the messaging service, including sending support communications, scheduling messages, intake-related messages, and recovery-related messages.
No Sale or Sharing of SMS Data. Tessi does not sell, share, or otherwise disclose mobile phone numbers, SMS opt-in data, or consent status to any third party for marketing or promotional purposes. This prohibition applies regardless of any other provision of this Privacy Policy.
SMS Service Providers. SMS data may be shared with service providers necessary to deliver text messages, including telecommunications carriers and messaging infrastructure vendors. These service providers are contractually required to use such data solely for the purpose of facilitating message delivery and are prohibited from using the data for their own marketing or promotional purposes.
SMS Consent Records. Tessi retains records of SMS consent (including opt-in source, timestamps, and consent status) for compliance and audit purposes, in accordance with applicable regulations and carrier requirements.
Opt-Out. You may opt out of receiving SMS messages at any time by replying STOP to any message or by contacting us at privacy@tessi.ai. Upon receipt of your opt-out request, we will cease sending SMS messages to your number, except as required by law.
9. Data Subject Rights — EU/EEA and UK (GDPR / UK GDPR)
If you are located in the European Economic Area or the United Kingdom, you have the following rights under the GDPR or UK GDPR, subject to applicable conditions and exceptions:
- Right of access: to obtain confirmation of whether we process your Personal Data and to receive a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete Personal Data.
- Right to erasure (“right to be forgotten”): to request deletion of your Personal Data in certain circumstances.
- Right to restriction: to request that we restrict processing of your Personal Data in certain circumstances.
- Right to data portability: to receive your Personal Data in a structured, commonly used, machine-readable format and to transmit it to another controller.
- Right to object: to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: to lodge a complaint with your local data protection supervisory authority.
To exercise these rights, please contact us at privacy@tessi.ai. We will respond within one month (extendable by two additional months for complex requests) as required by applicable law.
10. “Do Not Sell or Share My Personal Information”
Tessi does not sell your Personal Information as defined under the CCPA/CPRA, and Tessi does not share your Personal Information for cross-context behavioral advertising. If Tessi’s practices change, we will update this section and provide a conspicuous opt-out link.
11. Consumer Rights — United States (CCPA/CPRA and State Privacy Laws)
If you are a resident of California or another U.S. state with an applicable consumer privacy law (including, without limitation, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states as their laws take effect), you may have some or all of the following rights, subject to applicable conditions, exceptions, and verification requirements:
- Right to know / access: to request disclosure of the categories and specific pieces of Personal Information we have collected about you, the sources, purposes, and categories of third parties with whom we share it.
- Right to delete: to request deletion of Personal Information we have collected from you, subject to certain exceptions.
- Right to correct: to request correction of inaccurate Personal Information.
- Right to opt out of sale or sharing: to direct us not to "sell" or "share" (as defined by applicable law) your Personal Information. As noted above, Tessi does not currently sell or share Personal Information for cross-context behavioral advertising.
- Right to opt out of targeted advertising: to opt out of the processing of your Personal Information for targeted advertising purposes.
- Right to limit use of sensitive personal information: to direct us to limit use of sensitive personal information to purposes permitted by law.
- Right to non-discrimination: we will not discriminate against you for exercising your privacy rights.
- Authorized agent: you may designate an authorized agent to make requests on your behalf, subject to verification.
To exercise your rights, please contact us at privacy@tessi.ai. We will verify your identity before processing your request and will respond within the timeframe required by applicable law (generally 45 days for CCPA/CPRA requests, extendable by an additional 45 days with notice).
Notice at Collection (CCPA/CPRA): The categories of Personal Information we collect and the purposes for which they are used are described in Section 2 (Categories of Personal Data Collected) and Section 4 (Purposes of Processing and Legal Bases) of this Privacy Policy. We do not collect additional categories of Personal Information or use the collected categories for materially different purposes without providing you with notice.
12. Consumer Rights — Canada (PIPEDA)
If you are located in Canada, you have the following rights under PIPEDA and applicable provincial privacy legislation:
- Consent: We will obtain your meaningful consent for the collection, use, and disclosure of your Personal Information, except where permitted or required by law without consent. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice.
- Access: You may request access to your Personal Information held by Tessi and information about our processing practices.
- Accuracy: You may challenge the accuracy and completeness of your Personal Information and request amendments.
- Challenge compliance: You may challenge Tessi's compliance with PIPEDA by contacting our privacy officer or filing a complaint with the Office of the Privacy Commissioner of Canada.
- Accountability: Tessi is responsible for Personal Information in its possession or custody, including information transferred to third parties for processing.
13. Global Baseline
If you are located in a jurisdiction not specifically addressed above, Tessi will honor the data protection rights provided to you under applicable local law. Where local law provides you with rights to access, correct, delete, port, or restrict the processing of your Personal Data, or to object to processing or withdraw consent, you may exercise those rights by contacting us at privacy@tessi.ai. Tessi will process your request in accordance with applicable law and respond within the timeframe required by your jurisdiction.
14. Data Retention
We retain your Personal Data only for as long as reasonably necessary to fulfill the purposes for which it was collected, to provide the Services, to comply with legal obligations, to resolve disputes, and to enforce our agreements. Specific retention periods depend on the nature of the data, the purposes of processing, and applicable legal requirements. When Personal Data is no longer required, we will securely delete or de-identify it in accordance with our data retention policies. De-identified or aggregated data that can no longer reasonably identify you may be retained and used indefinitely for research, analytics, and Platform improvement purposes.
SMS consent records (including opt-in source, timestamps, and consent status) are retained for compliance and audit purposes in accordance with applicable regulations and carrier requirements.
15. Data Security
Tessi implements appropriate technical and organizational measures designed to protect your Personal Data against unauthorized access, alteration, disclosure, or destruction. These measures include, as appropriate, encryption of data in transit and at rest, access controls, regular security assessments, employee training, and incident response procedures. However, no method of transmission over the internet or electronic storage is completely secure, and Tessi cannot guarantee absolute security.
16. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms (or that otherwise triggers notification obligations under applicable law), Tessi will notify the relevant supervisory authority and affected individuals in accordance with applicable data breach notification requirements, including the timeframes prescribed by GDPR (72 hours to the supervisory authority), UK GDPR, CCPA/CPRA, PIPEDA, and other applicable laws.
17. Children's Data
The Platform is not directed to individuals under the age of 18, and we do not knowingly collect Personal Data from children under that age. If we become aware that we have collected Personal Data from a child under the applicable age threshold, we will take steps to promptly delete such data. If you believe a child has provided us with Personal Data, please contact us at privacy@tessi.ai.
18. Cookies and Tracking Technologies
Tessi uses cookies, pixels, web beacons, and similar tracking technologies to operate the Platform, remember your preferences, analyze usage, and improve our Services. These may include:
- Strictly necessary cookies: required for the Platform to function and cannot be disabled.
- Performance/analytics cookies: help us understand how Users interact with the Platform.
- Functionality cookies: remember your preferences and settings.
You can manage your cookie preferences through your browser settings or any cookie preference tool we make available on the Platform.
19. How to Exercise Your Rights; Contact Information
To exercise any of your data protection rights described in this Privacy Policy, or for questions or complaints regarding our privacy practices, please contact us:
Email: privacy@tessi.ai
Mail: Tessi Technologies Inc., Attn: Privacy, 134 Sumner Street, Newton, MA 02459
We will endeavor to respond to all legitimate requests within the timeframe required by applicable law. We may need to verify your identity before processing your request. If you are not satisfied with our response, you have the right to lodge a complaint with the applicable data protection authority in your jurisdiction.