Our Privacy Commitment, In Plain Language
TFALKE is built on a Zero-Tracking, Minimal-Data architecture. We do not use tracking cookies. We do not run behavioral analytics. We do not read the files stored on your endpoints. Where you use our optional AI Agent, we store your conversation with it - including commands run and their output - so you can resume a troubleshooting session, as described in Section 3. Beyond that, we collect only the small amount of data required to keep your account running and your devices connected.
This Privacy Policy explains, in plain and legally binding terms, exactly what data TFALKE PRIVATE LIMITED ("TFALKE," "we," "us," or "the Company"), a company incorporated in India, collects from you when you or your organization ("Customer," "you") use our real-time endpoint management platform and any associated natural language AI agent (collectively, the "Service"), why we collect it, and the rights you have over it under the laws that apply to you, including the EU/UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended ("CCPA"), and India's Digital Personal Data Protection Act, 2023 ("DPDPA").
This Policy is written for public consumption but is a legally binding part of our Terms of Service. Where a term is capitalized and not defined in this Policy, it has the meaning given in our Master Services Agreement and Terms of Service.
1. Zero Cookies and Zero Analytics Declaration
1.1 No Tracking Cookies, Beacons, or Pixels
TFALKE does not deploy cookies, web beacons, tracking pixels, device fingerprinting scripts, or any similar technology for the purpose of behavioral advertising, user profiling, or usage analytics, on our website, our dashboard, or within the Service. Certain strictly necessary cookies may be set by TFALKE's third-party infrastructure providers - such as our content delivery network, fraud-prevention system, and PCI-compliant payment processor - solely to operate, secure, and process payment for the Service. These cookies are not used by TFALKE to track, profile, or analyze user behavior, and are limited to those necessary for the underlying provider's own security or transaction function. A current list of these strictly necessary cookies, by provider and purpose, is available at https://tfalke.com/cookies. Because we do not deploy any cookie for advertising, profiling, or analytics purposes, this Policy does not require, and our website does not display, a cookie-consent banner for tracking purposes.
1.2 No Behavioral Analytics or Usage Profiling
We do not collect, process, infer, or derive any analytical data, user behavior metrics, clickstream data, session-replay data, or performance-analytics profiles that identify or relate to an individual user's behavior, from your use of the Service. We do not build advertising or marketing profiles of you, your organization, or your Authorized Users. This does not include TFALKE's own internal system-health and uptime monitoring, described in our Service Level Agreement, which measures the availability and technical performance of our infrastructure as a whole and does not identify, profile, or track any individual user's behavior within the Service.
1.3 No Sale or Sharing of Data
We do not sell, rent, or "share" (as that term is defined under the CCPA/CPRA) any personal information for cross-context behavioral advertising or any other third-party commercial purpose. We have no advertising business model and no data-monetization relationship with any third party.
2. Minimal Data Collection
2.1 What We Actually Collect
TFALKE's platform is architected around data minimization by design. We collect only the following categories of data, each strictly limited to what is necessary to operate, secure, and bill for the Service:
- Account Creation Details: the name, business email address, and authentication credentials of the individual(s) who create and administer your account;
- Billing Information: the minimum information required to process payment and administer your subscription, such as billing name, business address, and a payment instrument token generated by our third-party, PCI-compliant payment processor (we do not store full payment card numbers ourselves); and
- Connection Metadata: technical data strictly necessary to establish and maintain a live connection between an enrolled device ("Endpoint") and the Service, such as a device identifier, connection timestamp, agent heartbeat status, IP address, and agent software version.
2.2 What We Do Not Collect
Except for AI Agent Session Data described in Section 3, we do not ingest, store, read, index, or otherwise process the substantive content of your Endpoint payloads, files, documents, screen contents, keystrokes, or other deep organizational data. Outside of the AI Agent, our platform is built to function on Connection Metadata alone.
Specifically, outside of AI Agent Session Data described in Section 3, we do not access or retain: the files stored on your Endpoints; the substantive content of documents, emails, or messages on your Endpoints; screen captures, keystrokes, or clipboard contents; or any other payload beyond the limited Connection Metadata described in Section 2.1.
2.3 Retention
We retain Connection Metadata and Billing Information only for as long as reasonably necessary to provide the Service, comply with our legal, tax, and accounting obligations, and resolve disputes, after which it is deleted or irreversibly anonymized in accordance with our internal data retention schedule, available on request.
3. Bring Your Own Key (BYOK) AI Agent - How Your Data Flows
3.1 You Control the AI Provider, Not Us
The Service includes an optional natural language AI agent (the "AI Agent") that allows you to issue instructions to a single Endpoint in plain language. The AI Agent operates exclusively using API key(s) that you obtain, own, and configure yourself from one or more third-party large language model providers of your choice (such as OpenAI or Anthropic) (each, a "Third-Party LLM Provider"). You may configure more than one Third-Party LLM Provider, in which case the Service may automatically route your request to an alternative configured provider if your primary provider is unavailable or unable to process the request. We do not provide, resell, or act as an intermediary for any Third-Party LLM Provider's services.
3.2 How Your AI Agent Conversations Are Stored
When you use the AI Agent, your messages and its replies are sent to our servers, placed on a processing queue, and relayed to your configured Third-Party LLM Provider using the corresponding API key (or, where you have configured more than one provider, to an alternative configured provider if the primary one is unavailable); the provider's response is then relayed back to you and, where applicable, to your Endpoint. Because the AI Agent supports multi-turn troubleshooting conversations you can return to later, we store this conversation in two ways: (a) a working copy is cached for up to twenty-four (24) hours to support the active session; and (b) a permanent session record - including your messages, the AI Agent's replies, any commands run, and their output (including standard-output and standard-error text) - is retained in our database until you delete it, request its deletion, or it is deleted under our data retention schedule. We do not use this content to train or fine-tune our own models, and we do not manually review it except as reasonably necessary to investigate a suspected Acceptable Use Policy violation, security incident, or a support request you raise with us.
Separately and independently of TFALKE's own storage described above, your chosen Third-Party LLM Provider also receives, and is responsible for handling, storing, and processing, the content of your prompts and its own generated outputs, under that provider's own privacy policy and data processing terms, once we relay that content to it using your API key. We encourage you to review your chosen Third-Party LLM Provider's privacy policy before enabling the AI Agent, and to configure any data-retention or model-training opt-outs that provider offers, directly with that provider.
3.3 Our Role Is Limited to the Connection and Safety Confirmation, Not the Content
TFALKE's infrastructure relays your instructions to your Third-Party LLM Provider, relays that provider's response back to you, classifies and presents high-risk commands for your Accept/Reject confirmation, and stores the resulting session record as described in Section 3.2. We do not exercise control over, and make no representation regarding, how your Third-Party LLM Provider separately uses, stores, or retains the data you send it once we relay it there.
4. Your Rights Under GDPR (Europe / UK)
If you are located in the European Economic Area or United Kingdom, you have the following rights in relation to the limited personal data described in Section 2 that TFALKE processes about you:
- Right of Access - to obtain confirmation of, and a copy of, the personal data we hold about you;
- Right to Rectification - to correct inaccurate or incomplete personal data;
- Right to Erasure ("Right to be Forgotten") - to request deletion of your personal data, subject to limited exceptions (e.g., legal or tax record-keeping obligations);
- Right to Restriction of Processing and Right to Object - to limit or object to certain processing, including any processing carried out on the basis of our legitimate interests;
- Right to Data Portability - to receive your personal data in a structured, commonly used, machine-readable format; and
- Right to Lodge a Complaint - with your local data protection supervisory authority.
Because our architecture collects almost no personal data by design, most access and portability requests are quick to fulfil in full: there is very little to locate, and virtually nothing beyond your account and billing record to export. We do not hold any hidden behavioral, tracking, or profiling data that would otherwise complicate a request.
To exercise any of these rights, contact us using the details in Section 7. We will respond within the timeframes required by GDPR (generally one month, extendable in limited circumstances). Where you have interacted with the AI Agent, any prompts or outputs held by your Third-Party LLM Provider are not in our possession and must be requested directly from that provider.
5. Your Rights Under CCPA / CPRA (California)
If you are a California resident, you have the following rights with respect to the limited personal information described in Section 2:
- Right to Know / Access - to request disclosure of the categories and specific pieces of personal information we have collected about you, and the purposes for which it is used;
- Right to Delete - to request deletion of your personal information, subject to limited statutory exceptions;
- Right to Correct - to request correction of inaccurate personal information;
- Right to Opt Out of Sale or Sharing - not applicable in practice, as described below; and
- Right to Non-Discrimination - for exercising any of the above rights.
We do not sell or share personal information, and we do not use tracking cookies or analytics. As a result, there is no advertising or tracking profile to opt out of - the opt-out right exists on paper because the law requires us to state it, but there is nothing for it to act upon under our architecture.
To exercise any of these rights, contact us using the details in Section 7. We will verify your request using the account information available to us and respond within the timeframes required by the CCPA/CPRA (generally 45 days, extendable once by 45 additional days where necessary).
6. Your Rights Under India's DPDP Act, 2023
If you are a Data Principal under India's Digital Personal Data Protection Act, 2023, you have the right to obtain a summary of the personal data we process about you and the processing activities undertaken, the right to correction and erasure of your personal data, the right to grievance redressal through our designated contact (Section 7), and the right to nominate another individual to exercise these rights on your behalf in the event of death or incapacity. We will address grievances in accordance with the timelines prescribed under the DPDPA and its rules.
7. How to Contact Us / Exercise Your Rights
You may exercise any of the rights described in this Policy, or ask any question about our data practices, by contacting our privacy team at: [email protected] or by writing to: TFALKE PRIVATE LIMITED, Building No 15/48, Jameela Manzil, Chala East, Kannur, Kerala, India, 670621. We may ask you to verify your identity before processing certain requests, using only the minimal account information already described in this Policy.
8. International Data Transfers
Because TFALKE is incorporated in India and serves a global customer base, the limited Connection Metadata and Billing Information described in Section 2 are processed on TFALKE's cloud infrastructure, hosted by TFALKE's infrastructure sub-processor on Oracle Cloud Infrastructure, UAE East (Dubai) region, and by TFALKE's payment processor in the United Kingdom, or such other locations as TFALKE's infrastructure or payment processor may operate from time to time, consistent with TFALKE's Data Processing Agreement. Where such transfers involve personal data originating in the EEA/UK, we rely on Standard Contractual Clauses or another lawful transfer mechanism recognized under GDPR. Data you send directly to a Third-Party LLM Provider under Section 3 is transferred according to that provider's own data transfer practices, independent of TFALKE.
9. Security
We apply administrative, technical, and organizational safeguards appropriate to the limited categories of data we hold, including encryption in transit, access controls limiting internal access to Connection Metadata and Billing Information on a need-to-know basis, and regular security review of our infrastructure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or legal requirements. We will post the updated Policy with a revised "Last Updated" date and, where changes are material, provide reasonable additional notice (such as an email or in-product notice) before the changes take effect.