This Privacy Policy explains how Tensho Labs LLC ("Tensho Labs", "we", "us", or "our") collects, uses, discloses, and protects personal information when you visit our websites, contact us, or use our products and services. We operate globally, with activities in the United States and Germany.
If you have questions, contact us at privacy@tensholabs.com. Our registered mailing address is: (see addresses below).
1) Scope & Roles
- This Policy covers personal information we process as a controller for our public websites, marketing, recruiting, and customer relationship management.
- For client projects and hosted solutions where Tensho Labs processes data on a client’s behalf, we act as a processor/service provider and our processing is governed by a separate contract and data processing addendum (DPA).
2) Definitions (plain‑English)
- Personal information / personal data: any information that identifies or can reasonably be linked to a person.
- Sensitive personal information: categories defined by applicable laws (e.g., precise geolocation, government IDs, health data).
- Sell/Share: terms used in certain laws (e.g., the California Privacy Rights Act or "CPRA"). "Sell" includes exchanging personal information for money or other value; "Share" includes cross‑context behavioral advertising.
- Controller / Processor: Under the GDPR/UK GDPR, a controller decides why/how data is used; a processor acts on the controller’s instructions.
3) What we collect
We collect information in three ways: (a) directly from you, (b) automatically via your device, and (c) from third parties.
A) Information you provide directly
- Contact & identifiers: name, email, phone, company, job title, country/region.
- Account & auth (for our hosted tools): username, credentials, role/permissions.
- Business content: messages, project briefs, uploads (e.g., files, images, prompts for AI features), support requests, feedback.
- Billing: limited payment details (handled primarily by our payment processor, e.g., Stripe); invoicing details (company, VAT/tax IDs, billing contact).
- Recruiting: CV/resume, cover letter, portfolio links, interview notes.
B) Information collected automatically
- Usage & device data: pages viewed, links clicked, referrer, browser/OS type, device identifiers, IP address, coarse location (derived from IP), session timestamps.
- Cookies & similar tech: pixels, SDKs, local storage for analytics, performance, security, and (if enabled) marketing.
C) Information from third parties
- Lead/CRM tools (e.g., Apollo, HubSpot): business contact details and firmographics, where permitted by law.
- Auth/SSO providers (if used): account identifiers and profile basics.
- Vendors we integrate (e.g., Google Analytics, Firebase, Render, Stripe, Twilio, email/SMS providers, call/voice vendors, error monitoring tools): metadata needed to operate the service. See Sub‑processors below.
Children: Our services and websites are not directed to children under 16. We do not knowingly collect children’s data.
4) Why we use personal information (purposes)
- Provide & secure services: operate websites, apps, and features; authenticate users; detect/prevent fraud, abuse, and spam; ensure availability and performance.
- Customer success: respond to inquiries; provide support; manage trials, demos, proofs of concept, and projects.
- Payments & billing: process transactions and manage subscriptions.
- Product improvement & R&D: analyze usage trends; develop new features; maintain and improve quality, accessibility, and security. Where feasible, we use aggregated or de‑identified data.
- Communications & marketing: send service notices, updates, event invites, and—if permitted—newsletters or promotional content. You may opt out of marketing at any time.
- Compliance: meet legal obligations; enforce contracts; protect rights, safety, and property.
5) AI‑specific disclosures
- Customer content & prompts: We process content you submit (e.g., prompts, documents, audio) to generate outputs and to operate, troubleshoot, and secure the service.
- Model training: We do not use your non‑public customer content to train our or third‑party foundation models unless you explicitly opt in (via contract, setting, or written consent). Publicly available content or de‑identified/aggregated analytics may be used for general improvement.
- Human review: Limited, role‑based human review may occur for safety, debugging, or abuse prevention, subject to confidentiality and access controls.
- Automated decision‑making: We do not make decisions with legal or similarly significant effects on individuals solely by automated means in our public websites. For client solutions, automated outputs are under the client’s control and intended to assist—not replace—human judgment.
6) Legal bases (EEA/UK/Switzerland)
Where the GDPR/UK GDPR applies, our processing bases include: — Contract (Art. 6(1)(b)): to deliver services or take steps at your request. — Legitimate interests (Art. 6(1)(f)): e.g., to secure, improve, and market our services to business users, balanced against your rights. — Consent (Art. 6(1)(a)): for non‑essential cookies/marketing and any optional data uses. — Legal obligation (Art. 6(1)(c)): to comply with laws and regulations.
7) Sharing & disclosures
We do not sell personal information for money. We may share personal information for the purposes above with:
- Service providers / sub‑processors: infrastructure, storage, analytics, logging/monitoring, communications, authentication, payments, customer support, and similar vendors performing services for us (e.g., Render, Firebase/Google Cloud, Stripe, Twilio, email/SMS providers, analytics tools, CRM/marketing platforms).
- Professional advisors: lawyers, accountants, auditors, insurers.
- Corporate transactions: in a merger, acquisition, financing, or sale of assets, data may transfer as part of that transaction subject to this Policy.
- Legal & safety: to comply with law, enforce agreements, or protect rights, property, or safety.
- Affiliates: within the Tensho Labs corporate family for the purposes described here.
We maintain contracts with service providers limiting their use of personal information to the services they provide to us, with confidentiality, security, and (where applicable) cross‑border transfer safeguards.
Public or user‑directed disclosures
Some features allow you to publish or share content (e.g., testimonials, portfolio items). Please do not share confidential or sensitive personal information in public areas.
8) Cookies, analytics, and advertising
- We use necessary cookies for core functionality and security; performance/analytics cookies to understand usage; and marketing cookies/pixels only if enabled.
- You can manage non‑essential cookies via our cookie banner or your browser/device settings. Disabling cookies may affect functionality.
- Where required by law, we obtain your consent before setting non‑essential cookies.
- We honor Global Privacy Control (GPC) signals where feasible by treating them as an opt‑out of "sale"/"sharing" for cross‑context advertising.
9) International data transfers
We operate globally. When transferring personal data across borders (e.g., from the EEA/UK/Switzerland to the U.S.), we rely on lawful mechanisms such as the EU Commission Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, plus technical/organizational safeguards.
10) Data retention
We retain personal information only as long as necessary for the purposes described, including to comply with legal, tax, or accounting requirements, resolve disputes, and enforce agreements. Typical retention periods:
- Website analytics logs: 12–24 months (shorter where feasible, longer if aggregated).
- CRM & communications: for the active business relationship and a reasonable period thereafter.
- Account data: for the life of the account and as required by law after closure.
- Support tickets / project records: for contract duration plus a reasonable period for audit/compliance.
- Recruiting data: generally 12–24 months unless local law permits/requires longer or you request deletion sooner.
11) Security
We employ administrative, technical, and physical safeguards aligned with industry practices (e.g., access controls, encryption in transit/at rest where supported by the platform, vulnerability management, logging/monitoring, employee training). No system is 100% secure; please use strong, unique passwords and enable multi‑factor authentication where available.
12) Your privacy rights
Your rights vary by jurisdiction and may include:
EEA/UK/Switzerland (GDPR/UK GDPR)
- Access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests.
- Withdraw consent at any time for processing based on consent.
- Complaint to a supervisory authority (see Contacts below).
United States (e.g., California CPRA; similar rights may exist in CO/CT/VA/etc.)
- Know/Access: request the categories and specific pieces of personal information collected, sources, purposes, and categories of recipients.
- Delete: request deletion of personal information, subject to exceptions.
- Correct: request correction of inaccurate personal information.
- Opt‑out of sale or sharing: opt out of cross‑context behavioral advertising and certain disclosures. Use our cookie banner, send a GPC signal, or visit Do Not Sell or Share My Personal Information.
- Limit use of sensitive info (where applicable).
- Non‑discrimination: we will not discriminate for exercising rights.
Other regions
We honor applicable local rights under relevant privacy laws. Contact us to exercise your rights.
How to exercise your rights
Submit a request to privacy@tensholabs.com with: (1) what right you’re invoking, (2) details of your request, and (3) a way to verify your identity (we may ask for additional information to confirm your identity). Authorized agents may submit requests where permitted by law with proof of authorization.
13) Do Not Sell or Share / Targeted Ads
We do not sell personal information for monetary consideration. We may engage in limited advertising/analytics that could be considered a "share" or "sale" under CPRA when non‑essential cookies/pixels are enabled. You can opt out via: (a) our cookie controls, (b) browser GPC signals, or (c) emailing privacy@tensholabs.com.
14) Third‑party links and services
Our websites may link to third‑party sites, plug‑ins, or services. Their privacy practices are governed by their own policies. Please review them before providing data.
15) Job applicants & contractors
If you apply for a role or work with us as a contractor, we process your information for recruiting, onboarding, compliance, and workforce management under appropriate legal bases and retention rules. Additional notices may be provided at collection.
16) Sub‑processors (illustrative, not exhaustive)
Depending on the specific product or engagement, we may use vendors such as: Render (hosting), Google Cloud/Firebase (hosting, auth, storage), Stripe (payments), Twilio/telephony providers (voice/SMS), email service providers, analytics tools (e.g., Google Analytics), CRM/marketing platforms (e.g., Apollo/HubSpot), log/error monitoring providers. A project‑specific list is available upon request or in your DPA.
17) Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new effective date and, where required, notify you (e.g., via banner, email, or in‑product notice). Continued use after the effective date constitutes acceptance of the changes.
18) Contact us & regional representatives
USA Office (Mailing)
Tensho Labs
1441 Woodmont Ln NW #2118
Atlanta, GA 30318
United States
- EU/UK representative & DPO (if appointed): Not applicable / To be announced.
- Supervisory authority (EEA/UK): You may lodge a complaint with your local authority or (for the EU) the authority where you live or work. We would appreciate the chance to address your concerns first.
19) Controller vs. processor summary
- Website, marketing, recruiting: Tensho Labs is the controller.
- Client solutions/hosted services: Tensho Labs is typically a processor/service provider acting on the client’s documented instructions under a DPA.
Quick reference (non‑contractual summary)
- We collect contact, usage, and business content to run our sites/services, respond to you, secure our systems, and improve our offerings.
- We don’t train foundation models on your non‑public content unless you opt in.
- We don’t sell your data for money; you can opt out of cookie‑based ads/analytics.
- You have rights to access, delete, correct, or object depending on your location.
- Email privacy@tensholabs.com for requests or questions.