Legal
Privacy notice
Last updated:
In plain English: We collect the minimum we need to run this website, answer your enquiry and run the Tesylate service. We don’t run advertising, we don’t sell your details, and this site has no analytics trackers. Your business data inside Tesylate belongs to you — we only process it on your instructions. Everything below is the detail behind those sentences.
1. Who we are
Tesylate Ltd is the controller of the personal data described in this notice.
- Company: Tesylate Ltd, registered in England and Wales, company number 11281502
- Registered office: 22 Apollo Way, Hemel Hempstead, England, HP2 5QG
- Contact: support@tesylate.com · 020 3880 9872
We have no statutory requirement to appoint a Data Protection Officer and have not appointed one. Privacy questions go to support@tesylate.com and Adam Rowles, Founder, answers them.
2. The two hats we wear
In plain English: For this website and your dealings with us as a company, we decide what happens to your data — we’re the “controller”. For the business data you sync into the Tesylate platform, you decide — we’re the “processor” and act only on your instructions.
- Controller. When you visit tesylate.com, contact us, book a demo, become a customer or receive our invoices, Tesylate Ltd decides how and why your personal data is used. This notice covers that.
- Processor. When your organisation uses the Tesylate service, the data we sync from your business systems (which may contain personal data about your staff, customers and suppliers) is processed on your documented instructions under our Data Processing Addendum. Questions about that data go first to your organisation — it is the controller.
3. What we collect, why, and on what legal basis
In plain English: Website visits leave almost nothing with us. Fill in the contact form and we get what you typed. Become a customer and we hold what any supplier holds: contact, contract and billing details.
3.1 Visiting tesylate.com
The site is static. We run no analytics and no advertising trackers. Our hosting provider (Microsoft Azure) records standard server logs — IP address, request URL, timestamp, user agent — to keep the site running and secure.
- Purpose: operating and securing the website.
- Legal basis: legitimate interests (Article 6(1)(f) UK GDPR) — running a working, secure website.
- Retention: typically 30–90 days.
3.2 Contacting us or filling in the contact form
The contact form posts into Tesylate’s own system — no third-party form provider. We receive what you type: typically your name, work email, company and message.
- Purpose: answering your enquiry and, where relevant, following up about Tesylate.
- Legal basis: legitimate interests (Article 6(1)(f)) — responding to a business enquiry you initiated.
- Retention: 24 months from last contact, then deleted.
3.3 Booking a demo
Demo bookings run through Calendly. If you book, Calendly collects your name, email and chosen slot and passes them to us. Calendly is its own controller for its booking pages — see Calendly’s privacy notice. Calendly is a US company; the transfer safeguard for booking data is described in section 6.
- Purpose: scheduling and holding the demo.
- Legal basis: legitimate interests (Article 6(1)(f)) — arranging a meeting you asked for.
3.4 Being a customer (or a customer’s named contact)
If your organisation takes a trial or subscription, we hold business contact details (name, role, work email, phone), contract and account records, support correspondence, and billing records.
- Purpose: delivering the service, support, invoicing and payment collection, and keeping the accounting records the law requires.
- Legal basis: performance of a contract (Article 6(1)(b)); legal obligation (Article 6(1)(c)) for tax and accounting records; legitimate interests (Article 6(1)(f)) for service and renewal correspondence with your named contacts.
- Retention: for the life of the contract, then accounting records for 6 years plus the current financial year as HMRC requires; other customer records for 24 months after contract end.
3.5 Email
We use Microsoft 365 for mailbox email, and Twilio SendGrid to send transactional service notifications (for example support-ticket status updates). We do not send marketing email to people who have not dealt with us.
4. What we don’t do
- No sale of personal data. Ever.
- No advertising or cross-site tracking.
- No analytics cookies on this site (see the cookie policy).
- No automated decisions about you with legal or similarly significant effects.
- No data about children — Tesylate is a business-to-business service.
5. Who we share personal data with
In plain English: A short, named list of suppliers who help us run the company — and nobody else, unless the law makes us.
- Microsoft — hosting (Azure, UK/EU regions) and mailbox email (Microsoft 365).
- Twilio SendGrid — transactional email delivery.
- Zoho — billing and invoicing (Zoho Books).
- GoCardless — Direct Debit payment collection.
- Calendly — demo scheduling, only if you book a demo.
- Anthropic — only processes customer platform data, and only when a customer switches on the AI assistant features; it does not receive website or enquiry data. See the sub-processor list.
- Professional advisers and authorities — accountants, insurers, legal advisers, and HMRC or other authorities where the law requires it.
The full, current list of suppliers who touch customer platform data, with locations and safeguards, is the sub-processor list.
6. International transfers
The service runs on Microsoft Azure in UK/EU regions. Some suppliers are US companies:
- Calendly (US) — the EU-US Data Privacy Framework, including its UK Extension.
- Twilio SendGrid (US parent) — Twilio’s data protection addendum, incorporating the UK Addendum / IDTA.
- Anthropic (US) — applies only when a customer enables AI features; the safeguard is set out in the sub-processor list.
Where a transfer outside the UK happens, we rely on a UK adequacy regulation (including the UK Extension to the EU-US Data Privacy Framework where the recipient is certified) or the ICO’s International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.
7. Security
Access to systems holding personal data is restricted and credentialed, the service runs on Microsoft Azure infrastructure, and connections are encrypted in transit. We deliberately make no certification claims here (no ISO 27001 or SOC 2 badge) because we hold neither — if that changes, this notice will say so.
8. Your rights
You have the right to:
- access a copy of your personal data;
- rectify anything inaccurate;
- erase data we no longer need to hold;
- restrict or object to processing based on legitimate interests;
- portability of data you gave us, where processed by automated means under contract or consent;
- withdraw consent at any time, where consent is the basis (it rarely is — see section 3).
Email support@tesylate.com and we will respond within one month. You can also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113 — though we would rather you told us first so we can fix it.
9. Changes to this notice
We will post changes here with a new “last updated” date, and tell customers directly about any material change.
Tesylate Ltd, registered in England and Wales, No. 11281502. Registered office: 22 Apollo Way, Hemel Hempstead, HP2 5QG.