Privacy Policy
Last Updated: October 6, 2026
TESSA Security ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services. Our services include SOC-as-a-Service (24/7 security monitoring), Penetration Testing, Continuous Penetration Testing, Security Audits, Compliance Advisory (DORA, NIS2, ISO 27001), and Cybersecurity Consulting. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the site or use our services.
1. INFORMATION WE COLLECT
We may collect information about you in a variety of ways. The categories of information we collect include:
1.1 Personal Information You Provide
When you register for services, request a free security assessment, or engage any of our offerings — including SOC-as-a-Service, Penetration Testing, Continuous Pen Testing, Security Audits, Compliance Advisory, or Consulting — we collect:
- ›Contact Information: Name, company name, email address, phone number, business address
- ›Account Credentials: Username, password, security questions
- ›Billing Information: Billing address, tax identification numbers, and payment details required for invoicing
- ›Contract Information: Electronic signature data via DocuSign, company authorization details
- ›Assessment & Scoping Data: Details about your security posture, penetration test scope (URLs, IP ranges, systems), audit requirements, compliance needs (DORA, NIS2, ISO 27001, PCI DSS, HIPAA), and consulting objectives
- ›Free Assessment Submissions: Information submitted through our online Free Security Assessment form, including company size, industry, and specific security concerns
1.2 Information Collected Automatically
When you access our website or use our services, we automatically collect certain information, including:
- ›Device Information: IP address, browser type, operating system, device identifiers
- ›Usage Data: Pages visited, time spent on pages, links clicked, referring URLs
- ›Cookies and Tracking: We use cookies and similar tracking technologies to track activity and hold certain information
1.3 Security Monitoring Data (SOC-as-a-Service Customers)
If you subscribe to our SOC-as-a-Service, we collect and process:
- ›Network Data: Network traffic logs, firewall logs, intrusion detection/prevention logs
- ›Endpoint Data: Security agent data from monitored endpoints, process information, file hashes, behavioral analytics
- ›Authentication Logs: Login attempts, access patterns, identity and access management logs
- ›Security Events: Alerts, incidents, threat intelligence indicators, vulnerability scan results
- ›User Activity: User behavior analytics for security monitoring purposes only
This data is collected solely for the purpose of providing security monitoring services and is handled with the highest level of confidentiality.
1.4 Penetration Testing & Continuous Pen Testing Data
When you engage our penetration testing or continuous security validation services, we collect and process:
- ›Scope & Target Information: IP addresses, domain names, URLs, network ranges, application details, and system inventories provided for testing
- ›Test Findings: Vulnerability details, proof-of-concept data, exploit paths, and risk ratings discovered during testing
- ›Remediation Tracking: Status of identified vulnerabilities, fix verification records, and re-test results
- ›Platform Data (Continuous Testing): Data processed by automated testing platforms (e.g., RidgeBot, NodeZero, Pentera, Cymulate) on your behalf
All penetration testing data is strictly confidential and used solely to deliver findings and reports to you. Raw exploit data is securely deleted after report delivery.
1.5 Compliance & Audit Engagement Data
When you engage our compliance advisory or security audit services (DORA, NIS2, ISO 27001, and others), we collect:
- ›Organizational Documentation: Policies, procedures, risk registers, and governance documents shared for review
- ›Gap Analysis Data: Results of compliance assessments, control evaluations, and regulatory gap findings
- ›Remediation Plans: Action plans, timelines, and accountability records for addressing compliance gaps
- ›Audit Evidence: Supporting documentation and evidence provided or gathered during audit activities
Compliance and audit data is treated as highly confidential. It is used solely to deliver advisory services and is never shared with third parties without your explicit consent.
1.6 Consulting Engagement Data
During cybersecurity consulting engagements (including vCISO services, security strategy, and policy development), we may collect:
- ›Business Context: Organizational structure, technology landscape, business processes, and strategic objectives relevant to security planning
- ›Security Posture Information: Current security controls, past incident history, and existing policy documentation
- ›Deliverables Data: Information used to develop security roadmaps, policies, training materials, and strategic recommendations
2. HOW WE USE YOUR INFORMATION
Having accurate information about you permits us to provide you with a smooth, efficient, and secure experience. Specifically, we may use information collected about you to:
- ›Provide Services: Deliver SOC-as-a-Service monitoring, conduct penetration testing (standard and continuous), perform security audits, provide compliance advisory for DORA, NIS2 & ISO 27001, and deliver cybersecurity consulting including vCISO services
- ›Process Transactions: Process payments and send invoices
- ›Contract Management: Facilitate electronic signing via DocuSign and maintain service agreements
- ›Security Operations: Monitor for threats, detect security incidents, investigate anomalies, and respond to security events
- ›Reporting: Generate security reports, compliance documentation, and analytics dashboards
- ›Customer Support: Respond to inquiries, provide technical support, and communicate service updates
- ›Service Improvement: Analyze usage patterns, improve our monitoring algorithms, enhance threat detection capabilities
- ›Compliance: Fulfill legal obligations, comply with regulatory requirements, and enforce our terms
- ›Marketing: Send newsletters, service updates, and promotional materials (with your consent)
3. DISCLOSURE OF YOUR INFORMATION
We do not sell, trade, or rent your personal information to third parties. We may share your information in the following situations:
3.1 Service Providers
We share data with trusted third-party service providers who assist us in operating our services:
- ›Stripe: Payment processing and subscription billing management
- ›DocuSign: Electronic signature services for contract execution
- ›Security Tool Vendors: SIEM, EDR, and other security platforms used to deliver monitoring services
- ›Cloud Infrastructure: Hosting providers for data storage and processing
These service providers are contractually obligated to keep your information confidential and use it only for the purposes we specify.
3.2 Legal Requirements
We may disclose your information when required by law, such as:
- ›In response to valid legal processes (subpoenas, court orders, warrants)
- ›To comply with applicable laws and regulations
- ›To protect the rights, property, or safety of TESSA Security, our customers, or others
- ›To detect, prevent, or address fraud, security, or technical issues
3.3 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our website before your information becomes subject to a different privacy policy.
3.4 With Your Consent
We may share your information for any other purpose with your explicit consent.
4. DATA SECURITY
We implement comprehensive security measures to protect your personal information:
- ›Encryption: Data in transit is encrypted using TLS/SSL. Data at rest is encrypted using industry-standard encryption algorithms.
- ›Access Controls: Strict role-based access controls ensure only authorized personnel can access your data.
- ›Security Monitoring: Our own infrastructure is monitored 24/7 using the same SOC technologies we provide to customers.
- ›Compliance Certifications: We maintain ISO 27001 certification and comply with GDPR, SOC 2, and other relevant standards.
- ›Regular Audits: We conduct regular security audits and penetration testing of our own systems.
- ›Secure Development: We follow secure coding practices and conduct security reviews of our applications.
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
5. DATA RETENTION
We retain your information for as long as necessary to provide services and fulfill the purposes outlined in this policy:
- ›Account Data: Maintained while your account is active and for a reasonable period afterward for legal and business purposes
- ›Security Logs: Retained per our data retention policy and compliance requirements, typically 12-24 months
- ›Billing Records: Maintained for tax and accounting purposes as required by law (typically 7 years)
- ›Contract Documents: Retained for the contract term plus applicable statute of limitations periods
You may request deletion of your personal data, subject to legal retention requirements. Security monitoring data is typically anonymized after the retention period.
6. YOUR PRIVACY RIGHTS
Depending on your location, you may have certain rights regarding your personal information:
6.1 General Rights
- ›Access: Request a copy of the personal information we hold about you
- ›Correction: Request correction of inaccurate or incomplete data
- ›Deletion: Request deletion of your personal data (subject to legal obligations)
- ›Portability: Request your data in a structured, machine-readable format
- ›Objection: Object to processing of your data for certain purposes
- ›Restriction: Request restriction of processing under certain circumstances
6.2 GDPR Rights (European Economic Area Residents)
If you are located in the EEA, you have additional rights under the General Data Protection Regulation (GDPR):
- ›Right to withdraw consent at any time
- ›Right to lodge a complaint with a supervisory authority
- ›Right to receive information about automated decision-making and profiling
6.3 CCPA Rights (California Residents)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- ›Right to know what personal information is collected, used, shared, or sold
- ›Right to delete personal information held by businesses
- ›Right to opt-out of the sale of personal information (Note: We do not sell personal information)
- ›Right to non-discrimination for exercising CCPA rights
6.4 Exercising Your Rights
To exercise any of these rights, please contact us at info.sec.ks@tessa.group. We will respond to your request within 30 days. You may be required to verify your identity before we process your request.
7. THIRD-PARTY SERVICES
Our services integrate with third-party platforms. This Privacy Policy does not apply to the privacy practices of:
We encourage you to review the privacy policies of any third-party services you access through our platform.
8. INTERNATIONAL DATA TRANSFERS
TESSA Security operates globally. Your information may be transferred to and processed in countries other than your country of residence, including the United States and Kosovo. These countries may have different data protection laws than your jurisdiction.
When we transfer data internationally, we implement appropriate safeguards including:
- ›Standard Contractual Clauses (SCCs) approved by the European Commission
- ›Compliance with Privacy Shield principles where applicable
- ›Data processing agreements with third-party providers
9. COOKIES AND TRACKING TECHNOLOGIES
We use cookies and similar tracking technologies to track activity on our website. You can instruct your browser to refuse all cookies or indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our website.
Types of cookies we use:
- ›Essential Cookies: Required for website functionality
- ›Analytics Cookies: Help us understand how visitors interact with our website
- ›Preference Cookies: Remember your settings and preferences
10. CHILDREN'S PRIVACY
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you become aware that a child has provided us with personal information, please contact us. If we discover that a child under 18 has provided us with personal information, we will delete such information from our systems.
11. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
- ›Posting the new Privacy Policy on this page with an updated "Last Updated" date
- ›Sending an email notification to active subscribers
- ›Displaying a prominent notice on our website
You are advised to review this Privacy Policy periodically for any changes. Changes are effective immediately upon posting.
12. CONTACT US
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
TESSA Security — Privacy Office
Str. Tirana, No. 31, Icon Tower Building
Prishtina 10000, Kosovo
Email: info.sec.ks@tessa.group
Phone: +383 (48) 199 800
Data Protection Officer (DPO): For GDPR-related inquiries, contact our DPO at info.sec.ks@tessa.group