Legal

Terms, privacy and how your data is handled.

Seven documents covering the agreement to use Tephlo, what happens to personal data, who else touches it, and how the platform is secured. Each one describes what the software actually does today.

All documents updated 15 August 2026Revision Draft 1.0

These are drafts, pending review by a lawyer

They were written alongside the code they describe, so the facts in them — what is stored, for how long, who it is shared with, what deletion actually removes — are accurate. What they have not yet had is review by a qualified lawyer in [OPERATING JURISDICTION], which is what turns an accurate description into an enforceable agreement.

Nothing here is legal advice. A few facts only the operating company can supply — its registered name and address, the governing jurisdiction, the named data protection contact, and each document’s effective date — are marked as gaps rather than filled with a plausible guess. If you are evaluating Tephlo and need a signed agreement, ask us and you will get the reviewed version rather than this page.

The documents

What each one covers

Start with the Privacy Policy if you are a customer messaging a business, or the DPA if you are a business evaluating Tephlo.

What these documents deliberately do not claim

A policy that promises more protection than the software provides is worse than no policy, because it is relied on. So the following are stated here once, plainly, rather than being quietly absent:

  • No security certification. Tephlo holds no SOC 2 report and no ISO 27001 certificate. The Security Overview describes real, implemented controls, and an independent audit has not assessed them.
  • No uptime guarantee. There is no service level agreement with credits attached. The platform depends on WhatsApp, Telegram, an AI provider and a hosting provider, any of which can fail independently of us.
  • No data residency guarantee. Messages are processed by an AI provider and delivered by messaging providers that operate internationally. We cannot promise data stays within one country or region — the sub-processor list says where each one operates.
  • No end-to-end encryption of message content. To answer a customer’s question, the platform has to read it. Message content is encrypted in transit and stored in an access-controlled database, not sealed from us.
  • No claim that AI answers are always right. The assistant answers from a business’s own knowledge and refuses to guess, but it can still be wrong. It is not a substitute for professional advice, and never confirms a payment or an identity.

Who these documents are for

People messaging a business that uses Tephlo
The Privacy Policy explains what happens to your messages. The business you contacted decides what is collected and why; Tephlo handles it on their instructions, and requests about your data are answered fastest by that business.
Businesses running a workspace
The Terms of Service is the agreement, the DPA covers your customers’ personal data, and the Acceptable Use Policy sets the limits. The sub-processor list is the one to send to your own compliance reviewer.
Security and procurement reviewers
The Security Overview and the DPA security annex are the technical answer, and the product documentation covers how the controls appear in the console.

Changes to these documents

Each document carries the date it was last updated. Material changes to the Terms, the Privacy Policy or the DPA will be notified to workspace administrators by email before they take effect, with the notice period stated in the Terms. New sub-processors are published on the sub-processor page before they start processing data.

Contact

Questions about any of this go to support@tephlo.com, or through the contact page. Requests about personal data should reach the data protection contact at [DATA PROTECTION CONTACT] — until that address is published, the general address reaches the same team.

Reporting a security problem. If you have found a vulnerability, write to [SECURITY CONTACT] (or the general address above) with enough detail to reproduce it. We do not run a paid bug bounty, and we will not pursue anyone who reports a genuine issue in good faith.