TIH Foundation Workspace
Privacy Policy and Data Processing Addendum
1Introduction and Scope
This Privacy Policy explains how TIH Industries LLC (“TIH,” “we,” “us,” or “our”) collects, uses, shares, and protects personal data in connection with the TIH Foundation Workspace, also referred to as TIH Workspace, and the website at www.tihworkspace.com, together with all related pages, subdomains, and client workspaces (collectively, the Sites). This Policy applies to visitors to the Sites, to prospects and clients, and to the personal data that clients process through the Workspace, as further described in Section 11 and in the Data Processing Addendum in Part Two.
2Information We Collect
We collect the following categories of personal data:
Identity and contact data. Name, business name, email address, telephone number, and business mailing address.
Account and transaction data. Account credentials, tier selected, and records of purchases. Full payment card numbers are collected and stored by our payment processors, not by TIH.
Client end-user data. When you use the Workspace, you submit personal data about your own customers, prospects, and contacts. TIH processes this data on your behalf as described in Section 11 and the Data Processing Addendum.
Communications and content. Messages you send us, quiz and form responses, and, where you consent or are notified, recordings and transcripts of meetings.
Text-message and telephone data. Where you use messaging features, information necessary to send messages and honor opt-outs.
Technical and usage data. IP address, device and browser information, and how you interact with the Sites, collected through cookies and similar technologies as described in Section 5.
Sensitive data. TIH does not seek to collect sensitive categories of personal data through the Sites. TIH does not sell sensitive personal data, and will not sell any sensitive personal data without prior consent where required by law.
3How We Use Information
We use personal data to: provide, maintain, secure, and support the Workspace and the Sites; process transactions and manage accounts; respond to inquiries and provide customer support; send administrative and transactional messages about your account and service; and, separately and only where permitted, send marketing communications. You may opt out of marketing communications at any time without affecting the administrative and transactional messages necessary to operate your account.
Use of artificial intelligence. We use artificial-intelligence tools to help deliver certain services, including generating drafts, content, snapshots, and formatted notes. Output is reviewed as part of our service delivery, and you remain responsible for reviewing AI-assisted output relating to your business before you rely on or publish it.
4How We Share Information
We share personal data only as follows:
Service providers and sub-processors. With providers that perform services on our behalf, including the underlying customer-relationship-management platform, payment processors, an email and text-message delivery provider, video-conferencing and scheduling providers, analytics providers, and artificial-intelligence service providers. These providers are bound by contract to protect personal data and to use it only to provide their services.
Legal and safety. Where required by law, subpoena, or legal process, or to protect the rights, property, or safety of TIH, our clients, or others.
Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to the commitments in this Policy.
We do not sell your personal data, and we do not share your personal data for cross-context behavioral advertising.
5Cookies and Tracking
The Sites use cookies and similar technologies that are necessary for the Sites to function and to measure and improve the performance of our own Sites through first-party analytics. You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Sites.
6Your Privacy Choices and Rights
TIH qualifies as a small business under the applicable United States Small Business Administration size standard. As a small business, TIH is exempt from most obligations of the Texas Data Privacy and Security Act, Texas Business and Commerce Code Chapter 541. TIH nonetheless offers the following choices to every user as a matter of policy: you may request access to the personal data we hold about you, request correction of inaccurate data, request deletion of your data, and opt out of marketing communications. To make a request, contact us at privacy@tihworkspace.com. We honor these requests in good faith, subject to reasonable verification of your identity and to technical feasibility, and we will not discriminate against you for making a request.
Some state privacy laws grant residents additional rights. Where a statutory right actually applies to TIH, TIH will comply with it and will respond within the period that the law requires. If you are a client and your request concerns personal data you process through the Workspace, see Section 11 and the Data Processing Addendum, because for that data you are the controller and TIH acts on your instructions.
7Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal data appropriate to its sensitivity. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we determine that a breach of security has compromised sensitive personal data, we will notify affected individuals without unreasonable delay and not later than the sixtieth day after we determine the breach occurred, as provided by the Identity Theft Enforcement and Protection Act, Texas Business and Commerce Code Section 521.053(b). Where a breach involves at least two hundred fifty Texas residents, we will notify the Texas Attorney General as soon as practicable and not later than the thirtieth day after we determine the breach occurred, as provided by Section 521.053.
8Data Retention
We retain personal data for as long as needed to provide the Workspace, to comply with legal obligations, to resolve disputes, and to enforce our agreements. For client accounts, Client Data is retained for the duration of the Subscription and is available for export for thirty days after termination, as described in the Terms of Use and Subscription Agreement and the Data Processing Addendum. After that period, Client Data is deleted in the ordinary course unless a longer retention period is required by law.
9Children's Privacy
The Workspace and the Sites are intended for business use and are not directed to children under thirteen. We do not knowingly collect personal data from children under thirteen. If you believe a child has provided us personal data, contact privacy@tihworkspace.com and we will delete it. If you are a client and you process data relating to minors through the Workspace, you are responsible for doing so in compliance with applicable law.
10Data Location and International Processing
The underlying platform that hosts Client Data stores that data on infrastructure located in the European Union, in Ireland. Other service providers may process limited data in the United States. Where personal data is transferred across borders, we take steps intended to ensure the transfer is conducted in accordance with applicable law.
The Workspace is intended for clients located in the United States processing data about United States persons. It is not offered as a service for processing the personal data of individuals located in the European Union or the United Kingdom. A client whose Client Data includes personal data of individuals in the European Union or the United Kingdom must contact TIH to put a separate addendum in place, incorporating the applicable cross-border transfer terms, before processing that data through the Workspace. Clients who require United States data residency for a specific engagement should discuss a custom build, which is governed by a separate agreement.
11Our Roles: Controller and Processor
For personal data about visitors to our Sites, our prospects, and our own clients, TIH acts as a controller and determines how that data is used, as described in this Policy. For the Client Data that a client processes through the Workspace, the client is the controller and TIH acts as a processor, handling that data only on the client's documented instructions. The terms governing that processing are set out in the Data Processing Addendum in Part Two.
12Changes to This Policy
We may update this Policy. We will post the updated Policy with a new version number and effective date, and for material changes we will provide notice through the Sites or by email. Your continued use of the Sites after the effective date constitutes acceptance of the updated Policy.
13Contact
TIH Industries LLC
5900 Balcones Drive #23032, Austin, TX 78731, USA
Email: privacy@tihworkspace.com
Web: www.tihworkspace.com
This Data Processing Addendum (“DPA”) forms part of the Terms of Use and Subscription Agreement between TIH Industries LLC (“TIH”) and the client (“Client”) and applies where TIH processes personal data on the Client's behalf in connection with the TIH Foundation Workspace. Where this DPA applies, it governs that processing. In the event of a conflict between this DPA and the Terms with respect to the processing of Client personal data, this DPA controls.
1Definitions
Controller, Processor, Personal Data, Processing, and Data Subject have the meanings given under applicable data protection law. Client Personal Data means personal data contained in Client Data that TIH processes on the Client's behalf. Sub-processor means a third party engaged by TIH to process Client Personal Data.
2Roles and Scope
With respect to Client Personal Data, the Client is the Controller and TIH is the Processor. The Client is responsible for the accuracy, quality, and legality of Client Personal Data and for the means by which the Client acquired it, and warrants that it has the right and any necessary consent to provide that data to TIH for processing.
This DPA and the Workspace are intended for Client Personal Data relating to individuals located in the United States. If Client Personal Data includes personal data of individuals located in the European Union or the United Kingdom, the Client must contact TIH to put a separate addendum in place, incorporating the applicable cross-border transfer terms required by law, before processing that data through the Workspace. TIH does not provide European Union Standard Contractual Clauses under this DPA.
3Processing on Documented Instructions
TIH will process Client Personal Data only to provide and support the Workspace and on the Client's documented instructions, including the instructions set out in the Terms and this DPA, unless required to act otherwise by law, in which case TIH will inform the Client of that legal requirement unless the law prohibits it. TIH will inform the Client if, in its opinion, an instruction violates applicable data protection law.
4Confidentiality of Personnel
TIH will ensure that its personnel authorized to process Client Personal Data are bound by appropriate obligations of confidentiality and are informed of the confidential nature of the data. TIH limits access to Client Personal Data to those personnel who need it to provide the Workspace.
5Security
TIH will maintain administrative, technical, and physical measures designed to protect Client Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, alteration, or disclosure, appropriate to the risk. The Client is responsible for its own use of the Workspace, including the security of its account credentials and its configuration choices.
6Sub-processors
The Client authorizes TIH to engage Sub-processors to provide the Workspace. TIH engages Sub-processors in the following categories: the provider of the underlying white-label customer-relationship-management platform, which hosts Client Personal Data on infrastructure located in the European Union, in Ireland; payment processors; an email and text-message delivery provider; video-conferencing and scheduling providers; analytics providers; and artificial-intelligence service providers. TIH enters into a written agreement with each Sub-processor containing data protection obligations no less protective than those in this DPA to the extent applicable to the service the Sub-processor provides. The current list of specific Sub-processors is available to the Client on written request to privacy@tihworkspace.com.
TIH will inform the Client of any intended change involving the addition or replacement of a Sub-processor in time to give the Client the opportunity to object. If the Client reasonably objects to a new Sub-processor on data-protection grounds, TIH will use reasonable efforts to make available an alternative or to recommend a commercially reasonable change. If TIH cannot do so within a reasonable time, the Client may terminate the affected Subscription. TIH remains responsible for the acts and omissions of its Sub-processors with respect to Client Personal Data to the same extent TIH would be responsible if performing the services directly.
7Assistance with Data Subject Requests
Taking into account the nature of the processing, TIH will provide reasonable assistance to the Client, by appropriate technical and organizational measures insofar as possible, to help the Client respond to requests from Data Subjects to exercise their rights under applicable law. If TIH receives such a request directly, it will, to the extent legally permitted, promptly inform the Client and will not respond except on the Client's instructions or as legally required.
8Personal Data Breach Notification
TIH will notify the Client without undue delay after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Client Personal Data processed by TIH or its Sub-processors, so that the Client can meet its own notification deadlines under applicable law, including the sixty-day individual-notification and thirty-day Attorney General deadlines under Texas Business and Commerce Code Section 521.053. TIH will make reasonable efforts to identify the cause of the breach and to take steps within its reasonable control to remediate it, and will provide the Client with information reasonably available to TIH to support the Client's own notification obligations.
9Return and Deletion of Client Personal Data
Upon termination of the Subscription, and on the Client's written request made within thirty days after termination, TIH will make Client Personal Data available to the Client for export in a commonly used format, or provide reasonable access to retrieve it, provided the account is current on fees owed. After that thirty-day period, TIH will delete Client Personal Data in the ordinary course, except to the extent retention is required by law. Deletion by the underlying platform is subject to that platform's processes.
10Information and Attestation Rights
Upon the Client's reasonable written request, and no more than once per year unless required by law or following a confirmed breach, TIH will make available information reasonably necessary to demonstrate its compliance with this DPA, and will provide available third-party certifications or attestations that TIH or its Sub-processors maintain for the relevant services. Because the Workspace runs on a multi-tenant third-party platform that TIH does not own or operate, on-site audits of the underlying platform are not available through TIH; TIH will provide the platform's available compliance documentation instead. Any information provided under this section is confidential.
11Liability
Each party's liability arising out of or related to this DPA is subject to the limitations of liability in the Terms of Use and Subscription Agreement, and any reference in those limitations to the liability of a party means the aggregate liability of that party under the Terms and this DPA together.
12Term, Effect, and Precedence
This DPA takes effect when the Client accepts the Terms and continues for as long as TIH processes Client Personal Data. This DPA supplements and forms part of the Terms. In the event of a conflict between this DPA and the Privacy Policy in Part One with respect to Client Personal Data processed on the Client's instructions, this DPA controls.
TIH Industries LLC
5900 Balcones Drive #23032, Austin, TX 78731, USA
General, support, and cancellation: contact@tihindustries.com
Privacy requests: privacy@tihworkspace.com
Web: www.tihworkspace.com
Trust in Him.
