Seven documents covering the agreement to use Tephlo, what happens to personal data, who else touches it, and how the platform is secured. Each one describes what the software actually does today.
They were written alongside the code they describe, so the facts in them — what is stored, for how long, who it is shared with, what deletion actually removes — are accurate. What they have not yet had is review by a qualified lawyer in [OPERATING JURISDICTION], which is what turns an accurate description into an enforceable agreement.
Nothing here is legal advice. A few facts only the operating company can supply — its registered name and address, the governing jurisdiction, the named data protection contact, and each document’s effective date — are marked as gaps rather than filled with a plausible guess. If you are evaluating Tephlo and need a signed agreement, ask us and you will get the reviewed version rather than this page.
Start with the Privacy Policy if you are a customer messaging a business, or the DPA if you are a business evaluating Tephlo.
The agreement for using the platform: accounts, acceptable use, availability, fees, liability, termination and governing law.
Updated 15 August 2026 · Draft 1.0What personal data the platform handles — separately for the customers who message a business and for the staff who run a workspace — why, for how long, and what rights apply.
Updated 15 August 2026 · Draft 1.0The processor terms for business customers: scope of processing, security measures, sub-processors, breach notification, audit, and deletion or return of data.
Updated 15 August 2026 · Draft 1.0Every third party the platform sends data to, what it is used for, which categories of data reach it, and where it operates.
Updated 15 August 2026 · Draft 1.0What a business may not use the assistant for, which limits are enforced in code rather than by policy alone, and what happens when a limit is crossed.
Updated 15 August 2026 · Draft 1.0A plain account of what is stored in a browser: no analytics or advertising cookies anywhere, one currency preference, and the session cookies the consoles need to log you in.
Updated 15 August 2026 · Draft 1.0How the platform protects data in plain language — isolation, encryption, authentication, audit trails and data lifecycle — plus what it deliberately does not claim.
Updated 15 August 2026 · Draft 1.0A policy that promises more protection than the software provides is worse than no policy, because it is relied on. So the following are stated here once, plainly, rather than being quietly absent:
Each document carries the date it was last updated. Material changes to the Terms, the Privacy Policy or the DPA will be notified to workspace administrators by email before they take effect, with the notice period stated in the Terms. New sub-processors are published on the sub-processor page before they start processing data.
Questions about any of this go to support@tephlo.com, or through the contact page. Requests about personal data should reach the data protection contact at [DATA PROTECTION CONTACT] — until that address is published, the general address reaches the same team.