Protecting your data with the same rigor we bring to protecting our clients.
Effective Date: January 1st, 2026
This Privacy Policy explains how Teisoft LLC collects, uses, discloses, retains, and protects personal information in connection with:
1. Scope and roles
Teisoft may process information in different roles.
Teisoft as a business or controller
Teisoft acts as the business or controller when it determines why and how personal information is processed, including:
Teisoft as a service provider or processor
When a customer submits information to Teisoft Exposure Platform or provides information for cybersecurity services, Teisoft generally processes that information on the customer’s behalf and according to the customer agreement.
In that context, the customer is responsible for providing appropriate notices, obtaining required permissions, and responding to requests from individuals whose information appears in customer data.
Requests concerning customer-controlled data may be referred to the relevant customer.
2. Information we collect
Information you provide
We may collect:
Account and authentication information
For platform users, we may process:
Teisoft should not receive or retain the secret generated by a user’s authenticator application except as technically required by the authentication system.
Platform and cybersecurity data
Depending on the service, Teisoft may process:
Some of this information may relate to identifiable individuals, such as account owners, administrators, employees, customers, or users whose identifiers appear in authorized logs.
Automatically collected information
When you use the Website or platform, we may collect:
Advertising and Analytics Information
When Teisoft uses analytics and advertising technologies, we and our providers may collect:
We use this information to analyze Website performance, measure advertising effectiveness, understand campaign attribution, create or manage advertising audiences, and deliver more relevant advertising where permitted.
Payment information
Payments may be processed by third-party payment providers.
Teisoft may receive transaction identifiers, subscription details, billing status, and limited payment-related information, but should not retain complete payment-card data unless explicitly disclosed and supported by appropriate controls.
Information from other sources
We may receive information from:
3. How we use information
Teisoft may use information to:
4. Legal bases for processing
Where applicable law requires a legal basis, Teisoft relies on:
Consent may be withdrawn where processing is based on consent.
5. How we disclose information
Teisoft may disclose information to:
Service providers and subprocessors
Companies that provide:
These providers are authorized to process information only for the services they provide to Teisoft, subject to applicable contractual obligations.
Customer account administrators
Platform administrators may access information associated with users and activity within their organization’s account.
Customers
Information obtained while providing services may be disclosed to the customer that engaged Teisoft, consistent with the service scope and agreement.
Professional advisors
Information may be disclosed to lawyers, accountants, insurers, auditors, and consultants where reasonably necessary.
Legal and safety disclosures
Teisoft may disclose information when it reasonably believes disclosure is necessary to:
Corporate transactions
Information may be transferred in connection with a merger, financing, acquisition, reorganization, sale of assets, or similar transaction, subject to appropriate confidentiality protections.
6. Sale and sharing of personal information
Teisoft does not sell personal information in exchange for monetary compensation.
Teisoft uses Google Analytics, Google Ads, Meta advertising technologies, and related cookies, pixels, tags, and identifiers to measure website activity, evaluate advertising performance, understand how visitors interact with our Website, create advertising audiences, and deliver or measure advertisements.
These technologies may collect or receive information such as:
Depending on the applicable law and the configuration of these technologies, disclosing online identifiers and internet activity to advertising providers may constitute “sharing,” “targeted advertising,” or “cross-context behavioral advertising,” even when Teisoft does not receive money in exchange.
Teisoft may share the following categories of personal information with advertising and analytics partners:
The recipients may include:
Where required by applicable law, Teisoft will obtain consent before activating nonessential analytics or advertising technologies.
Residents of jurisdictions that provide an opt-out right may opt out of the sale or sharing of personal information, targeted advertising, or cross-context behavioral advertising through:
Opting out does not prevent Teisoft from using information for strictly necessary activities such as Website security, fraud prevention, authentication, service delivery, or non-personalized measurement where permitted.
7. Cookies and similar technologies
Teisoft may use cookies and similar technologies for:
Details and available choices are described in the Cookie Policy.
Where required, nonessential cookies will not be activated until appropriate consent is obtained.
8. Marketing communications
Teisoft may send business and marketing communications when permitted by law.
Recipients may unsubscribe through the link in the communication or by contacting Teisoft.
Unsubscribing from marketing does not prevent Teisoft from sending transactional, security, legal, or service-related communications.
9. Retention
Teisoft retains personal information only for as long as reasonably necessary to provide its services, protect its systems and customers, satisfy contractual obligations, maintain business and security records, comply with applicable law, and establish, exercise, or defend legal claims.
Our standard retention periods are described below. A different period may apply when required by law, specified in a customer agreement, necessary to investigate a security incident, or subject to a legal hold.
| Information category | Standard retention period |
| Website inquiries and unconverted sales leads | 24 months after the last meaningful interaction |
| Marketing contacts | Until the individual unsubscribes or after 24 months of inactivity |
| Marketing suppression records | For as long as reasonably necessary to honor the opt-out request |
| Customer and business contact information | For the duration of the business relationship and 24 months afterward |
| Platform user accounts and account profiles | For the duration of the account and up to 24 months after deactivation |
| Authentication, access, audit, and security logs | 24 months, unless a longer period is required for an investigation, customer agreement, or legal obligation |
| Customer platform data, exposure records, findings, remediation records, and related evidence | For the duration of the applicable service and up to 90 days after termination, unless the customer agreement specifies otherwise |
| Penetration-testing raw evidence and temporary working files | Normally 90 days after delivery of the final report, unless otherwise agreed |
| Final penetration-testing reports and formal deliverables | Three years after completion of the engagement, unless the customer requests earlier deletion or the agreement requires a different period |
| Security incident investigation records | Three years after closure, or longer when reasonably necessary for legal, insurance, or contractual purposes |
| Customer-support tickets and communications | Three years after the ticket is closed |
| Contracts, order forms, statements of work, invoices, payment records, and tax records | Seven years after termination of the relationship or completion of the relevant transaction |
| Privacy requests and Teisoft’s responses | Three years after completion of the request |
| Vulnerability disclosure reports | Three years after closure of the reported issue |
| Cookie-consent and privacy-preference records | Three years after the most recent consent or preference event |
| Website analytics information | Up to 13 months, unless a shorter period is configured or required by law |
| Backup copies | Deleted or overwritten through Teisoft’s normal backup-rotation process, ordinarily within 90 days after deletion from active systems |
When information is no longer required, Teisoft will delete it, securely destroy it, or de-identify it in accordance with applicable procedures.
Aggregated or de-identified information that cannot reasonably be linked to an individual or customer may be retained for a longer period for security research, statistical analysis, service improvement, and benchmarking.
Deletion from active systems may not result in immediate deletion from encrypted backup copies. Backup information remains protected, is not restored except for disaster recovery or business continuity purposes, and is deleted through the normal backup-rotation process.
Teisoft may suspend scheduled deletion when information is subject to a legal hold, active dispute, security investigation, regulatory requirement, or other documented legal or contractual obligation.
10. Security
Teisoft uses administrative, technical, and organizational measures designed to protect information.
These may include:
No system is completely secure. Teisoft cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur.
11. International transfers
Teisoft is based in the United States and may process information in the United States and other locations where its providers operate.
Where required, Teisoft will use appropriate contractual or legal mechanisms for international transfers, which may include standard contractual clauses or another recognized mechanism.
12. Your privacy rights
Depending on location and applicable law, individuals may have the right to:
To submit a request, contact:
Teisoft may verify identity and authority before processing a request. Authorized agents may be required to provide evidence of authorization.
Teisoft will not unlawfully discriminate against individuals for exercising privacy rights.
13. Global Privacy Control
Where required by applicable law and relevant to Teisoft’s processing practices, Teisoft will recognize supported browser-based opt-out preference signals, including Global Privacy Control.
This provision must be tested against the cookie-consent platform before publication.
14. Customer-controlled information
If personal information was submitted through a customer’s Teisoft account, the individual should ordinarily contact that customer first.
Teisoft will support customers in responding to applicable requests as required by the relevant agreement and law.
15. Children
The Website and services are intended for businesses and professionals and are not directed to children under 18.
Teisoft does not knowingly collect personal information directly from children under 13 through the Website or platform.
If Teisoft learns that such information was collected improperly, it will take appropriate steps to delete it. COPPA specifically regulates online collection from children under 13, and the FTC amended the COPPA Rule in 2025.
16. Third-party websites
Third-party sites and services have their own privacy practices. Teisoft is not responsible for those practices.
17. Changes to this Policy
Teisoft may update this Policy periodically.
The effective date will be revised when changes are posted. Material changes may also be communicated through the Website, platform, or email where appropriate.
18. Contact
Teisoft LLC
1590 Harbour Side Dr, Weston, FL 33326
Privacy: [email protected]
Legal: [email protected]
Confirm your business email to access the PCI Requirements & Evidences checklist.
Please enter a valid email address.
Click below to download your PCI DSS Requirements & Evidences guide.
⬇ Download PCI GuideThe file will open in a new tab.