Privacy Policy

Effective Date: 4 November 2025
Last Updated: 4 August 2026

Tessera AI Limited ("Tessera", "we", "us", or "our") respects your privacy. This Privacy Policy explains how we collect, use, and protect your personal data when you use our platform, including the Tracker Agent and other Tessera products (the "Services").

1. WHO WE ARE

Tessera (Tessera AI Limited) is a company incorporated in England and Wales under company number 16614786 (VAT number GB 522 8478 77) with its registered office at 20 Wenlock Road, London, N1 7GU. We act as the data controller for information we collect directly from you.

2. INFORMATION WE COLLECT

We collect information necessary to deliver and improve our Services, including:

Tessera does not intentionally collect or process special category personal data as defined under UK GDPR Article 9. Such data may occasionally appear incidentally in email content. Where this occurs, we apply the same minimisation principles as for all other personal data: we extract only what is necessary for campaign tracking, and we do not use incidental sensitive data to profile, categorise, or make decisions about individuals.

3. HOW WE USE INFORMATION

We use personal data to provide and operate our Services, manage billing, improve functionality, communicate with users, develop features, and comply with legal obligations. Tessera does not use Customer Data to train artificial intelligence or machine-learning models.

We process data under one or more lawful bases, including performance of a contract, legitimate interests (to improve and secure our platform), compliance with legal obligations, and consent where required (e.g., marketing communications).

We act as a controller when we use data to improve our own Services; our lawful basis for this processing is legitimate interest, and we have carried out a Legitimate Interests Assessment (available on request). You may object to this processing at any time via privacy@usetessera.com. Where the data concerns influencer contacts provided to us by our customers, we keep any improvement-related use anonymised, unless you have separately consented to Tessera using your Customer Data in identifiable form to improve the Services, and rely on the customer's Article 14 notice (see Section 5.4).

5. SHARING OF DATA

We use the following trusted subprocessors:

OpenAI (United States) — AI processing for email summarization and campaign insights

Anthropic (United States) — AI processing for email summarization and campaign insights

Cloudflare (Global: 200+ data centers worldwide) — Infrastructure, CDN, and application platform

Neon (United States — AWS us-east-1) — PostgreSQL database hosting

Microsoft 365 (Global) — Email (Outlook), file storage (OneDrive / SharePoint), and directory; your data remains in your Microsoft tenant

Google Workspace (Global) — Authentication and file storage (your data remains in your Google Drive)

Postmark (United States) — Transactional email delivery

The provider used for a given AI feature may vary by feature and over time; both OpenAI and Anthropic are listed above as subprocessors. All subprocessors are subject to written Data Processing Agreements (or, for Anthropic, its no-training Commercial Terms) requiring equivalent data protection and security standards. This list is our canonical subprocessor register; a copy with contact details is available on request.

Subprocessor (certified entity) Transfer mechanism
OpenAI (OpenAI OpCo, LLC) SCCs / UK IDTA (not DPF-certified); no-training DPA
Anthropic (Anthropic, PBC) SCCs / UK IDTA (not DPF-certified); no-training Commercial Terms
Cloudflare UK-US Data Bridge (DPF); SCCs / IDTA fallback
Neon (Databricks, Inc.) UK-US Data Bridge (DPF); SCCs / IDTA fallback
Microsoft UK-US Data Bridge (DPF); SCCs / IDTA fallback; your own Microsoft terms
Google Workspace UK-US Data Bridge (DPF); your own Google terms
Postmark (AC PM, LLC) UK-US Data Bridge (DPF); SCCs / IDTA fallback

5.1 Third-Party AI Processing (OpenAI)

To provide AI-powered email summarization and campaign tracking features, we use OpenAI's API services. When you use our Services, email content from your connected Gmail or Outlook accounts is transmitted to and processed by OpenAI to:

OpenAI processes this data under a Data Processing Agreement (DPA) that prohibits using your data to train their models. Your email content is sent to OpenAI only for the specific purpose of providing these features. Unless we have agreed a zero-data-retention arrangement, OpenAI may retain content sent through its API for a limited period (currently up to around 30 days) for security and abuse-monitoring, after which it is deleted; where a zero-data-retention arrangement is in place, content is not retained after the response is returned. Tessera uses OpenAI's United States API endpoints; we do not currently offer regional data residency (see Section 6). For more information about OpenAI's data practices, see https://openai.com/policies/privacy-policy.

5.2 Third-Party AI Processing (Anthropic)

To provide AI-powered email summarization and campaign tracking features, we also use Anthropic's API services (Claude). When you use our Services, email content from your connected Gmail or Outlook accounts is transmitted to and processed by Anthropic to:

Anthropic processes this data under its Commercial Terms of Service, which expressly state that Anthropic does not train its models on customer content from its API services. Your email content is sent to Anthropic only for the specific purpose of providing these features. Unless we have agreed a zero-data-retention arrangement, Anthropic may retain content sent through its API for a limited period (currently up to around 30 days) for security and abuse-monitoring, after which it is deleted; where a zero-data-retention arrangement is in place, content is not retained after the response is returned, save for limited safety-classification metadata. Tessera uses Anthropic's United States API endpoints; we do not currently offer regional data residency (see Section 6). For more information about Anthropic's data practices, see https://privacy.claude.com.

5.3 Google and Microsoft API Usage

API Services Compliance: Tessera's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Our use of Microsoft Graph APIs complies with Microsoft API Terms of Use.

Scopes We Request: When you connect your Google or Microsoft account to Tessera, we request permission to:

How We Access Your Email: Tessera enables team collaboration on influencer outreach campaigns. When you authorise email access: we read only emails from/to influencer contacts you have explicitly added to your campaigns (we do NOT access your personal emails, internal team communications, or unrelated business correspondence); email threads involving campaign contacts are shared with members of your marketing agency for team coordination; email content is sent to our AI subprocessors (OpenAI / Anthropic), each under a Data Processing Agreement or equivalent commercial terms, to generate summaries, extract deliverables and pricing, and track negotiation status; and email summaries, metadata, and extracted information are stored in campaign tracking sheets accessible to your agency team members.

Consent Model: By connecting your Google or Microsoft account and joining an agency, you provide affirmative consent to Tessera reading emails involving your campaign contacts, sharing these email threads with your agency team members, AI processing of email content for campaign insights by our AI subprocessors (OpenAI / Anthropic), and storing email summaries and data in shared campaign tracking sheets.

Privacy Protections: We only fetch emails matching tracked contacts using email-specific queries; we verify permission before importing contact lists; you can revoke Tessera's access anytime via Google Account Security or Microsoft Account Privacy; and when agency administrators remove members, we immediately invalidate their sessions and conditionally revoke their OAuth tokens.

Limited Use Compliance: We limit our use of Google and Microsoft data to displaying email threads and AI-generated summaries in campaign trackers, team collaboration within your agency (with your explicit consent), and campaign tracking and reporting. We do NOT sell or transfer your data to third parties (except subprocessors under Data Processing Agreements), use your email data for advertising or marketing, or allow humans to read raw email data except for debugging with your explicit permission, security investigations, or legal compliance requirements.

5.4 Influencer Contact Data (UK GDPR Article 14)

Where our customers use Tessera to manage influencer outreach campaigns, we process personal data about influencer contacts on behalf of those customers. This data (name, email address, and campaign interaction history) is provided to us by our customers and is used solely to deliver the campaign tracking features of our Services. We act as a data processor in relation to this data; our customer is the data controller.

Under Article 14 of the UK GDPR, individuals whose data is collected indirectly (i.e., not directly from them) have the right to be informed about how their data is used. If you are an influencer whose data has been added to a Tessera campaign by one of our customers, you may contact us at privacy@usetessera.com to request details of the processing or to exercise your data subject rights. We will assist our customer in responding to your request in accordance with applicable data protection law.

6. INTERNATIONAL TRANSFERS

Your data may be transferred to and processed in countries outside the UK or European Economic Area. Where such transfers occur, we ensure appropriate safeguards are in place. Transfers from the UK to the United States are made in reliance on the UK-US Data Bridge (where the recipient is certified under the US Data Privacy Framework) or, where applicable, the ICO-approved International Data Transfer Agreement (IDTA). Transfers to other third countries may rely on EU Standard Contractual Clauses or other adequacy mechanisms approved by the relevant supervisory authority.

Tessera's infrastructure is currently hosted with US-based providers (Neon on AWS us-east-1; Cloudflare). EU or UK data residency is not currently offered as a default option and is on our product roadmap for enterprise customers.

7. DATA RETENTION

We retain personal data only for as long as necessary to provide the Services, comply with legal obligations, and resolve disputes. When personal data is no longer needed, it is securely deleted or irreversibly anonymised in accordance with our internal data deletion procedures.

Our retention model distinguishes three categories of data:

Other specific retention periods:

8. YOUR RIGHTS

You have the right to access, correct, delete, or restrict the processing of your personal data, and to withdraw consent where applicable. You also have the right to data portability (export your data in machine-readable format). Tessera responds to privacy requests within one month of receipt (extendable by up to two further months for complex or numerous requests, with notice). Requests may be submitted to privacy@usetessera.com. Your rights include:

8A. ADDITIONAL RIGHTS FOR CALIFORNIA RESIDENTS (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) may afford you additional rights in relation to your personal information. These rights apply to personal information Tessera processes about you as a controller (such as account and contact details). For personal information Tessera processes on behalf of a business customer, please direct your request to that customer as the controller. Your California rights include the right to know, the right to delete, the right to correct, the right to opt out of sale or sharing (we do not sell or share personal information as those terms are defined under the CCPA/CPRA), and the right to non-discrimination. To exercise any of these rights, submit a verifiable consumer request to privacy@usetessera.com. We will respond within 45 days, with a possible extension of a further 45 days where reasonably necessary.

9. SECURITY

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse. Tessera maintains an Information Security Management System (ISMS) certified to ISO/IEC 27001:2022 and undergoes SOC 2 Type II examinations; the current certificate and most recent report are available to enterprise customers on request under NDA. Security controls include encryption (all data encrypted in transit with TLS 1.2 or higher and at rest with AES-256-GCM for OAuth tokens), role-based access control and least privilege, continuous security monitoring and incident response procedures, and security assessment of all subprocessors before onboarding.

9A. COOKIES AND SIMILAR TECHNOLOGIES

Our website uses only strictly necessary cookies, which are required to operate the site and to keep you signed in. We do not currently use analytics, advertising, or other non-essential cookies, and we do not currently operate a cookie banner because no consent is required for strictly necessary cookies. If we introduce analytics or other non-essential cookies, we will ask for your consent before setting them and will provide a means for you to change your choices at any time. You can also block or delete cookies through your browser settings. Where we send marketing by electronic means, we do so in line with the Privacy and Electronic Communications Regulations, relying on your consent or the soft opt-in where it applies, and every message includes an unsubscribe option.

10. UPDATES TO THIS POLICY

We may update this Privacy Policy from time to time and will post updates on our website with a revised effective date. Material changes will be communicated via email to registered users at least 30 days before taking effect.

11. CONTACT AND COMPLAINTS

For privacy questions or to exercise your rights, contact us at privacy@usetessera.com. If you believe we have not handled your personal data properly, you have the right to make a complaint to us directly at that address; we will acknowledge your complaint within 30 days and respond without undue delay. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk.