Tendi← Home

Legal

Privacy Policy

Last updated: 11 October 2026 · Version 1.0

Draft template. Review with a privacy professional / legal counsel for your jurisdiction (GDPR, CCPA, local law) before relying on it. Replace bracketed placeholders.

1. Who we are

Tendi is operated by [LEGAL ENTITY] ("we"). For privacy questions contact hello@tendi.cc. [DATA PROTECTION OFFICER / EU REPRESENTATIVE if applicable.]

2. Our principle: least necessary data

Tendi is a monitoring and data-protection tool, so we are deliberately restrained. We do not capture passwords, we do not collect private content beyond what a policy explicitly enables, and we never secretly activate a webcam or microphone. Monitoring is intended to be transparent to the people affected.

3. Data we process

4. How we use data

To provide and secure the Service, operate your account, apply the policies you configure, prevent abuse and brute-force attacks, send transactional email (e.g. password reset), and meet legal obligations. We do not sell your data.

5. Role of the account owner (controller)

When you use Tendi to manage other people's devices (employees, children), you are the controller of that monitoring and are responsible for having a lawful basis, informing users, and honoring their rights. We act as a processor for that content on your behalf.

6. Where data is stored

On Cloudflare infrastructure (database and object storage), encrypted in transit via TLS. Cloudflare maintains its own security certifications (e.g. SOC 2, ISO 27001) for the underlying platform. Each account is fully isolated.

7. Retention

Log snapshots are retained for a limited window (default 30 days) and then deleted automatically. Account and device records are kept while your account is active. When you delete your account, we delete your data from our database and object storage.

8. Your rights

Depending on your location you may have rights to access, correct, delete, export or restrict processing of your personal data, and to object or withdraw consent. You can delete your account and data from the dashboard, or contact us. [GDPR/CCPA SPECIFICS, SUPERVISORY AUTHORITY.]

9. Security

We apply measures including TLS, salted password hashing (PBKDF2), signed sessions, rate-limiting and brute-force lockout, tenant isolation, optional end-to-end encryption of screen content, and audit logging. No method is perfectly secure.

10. International transfers & sub-processors

Data may be processed in regions operated by our infrastructure provider. [LIST SUB-PROCESSORS: Cloudflare (hosting), email provider, etc. + transfer safeguards such as SCCs.]

11. Children

Accounts are for adults. Monitoring a minor child in your guardianship is a supported, lawful use; you remain responsible for complying with applicable laws on children's data.

12. Changes

We may update this Policy; material changes will be notified. The "last updated" date reflects the current version.

Terms of Service · Back to home