TarraCoata ("TarraCoata", "we", "us") respects your privacy and is committed to protecting personal data processed through our website, our professional services and the TarraOne platform. This policy explains what we collect, why we collect it, how long we keep it, and the rights available to you under the EU General Data Protection Regulation (GDPR) and the Israeli Privacy Protection Law, 5741-1981 and its regulations.
1. Who is responsible for your data
For the TarraCoata website, marketing activity and professional services, TarraCoata is the data controller.
For customer data processed inside the TarraOne platform, the customer (the organisation operating the workspace) is the controller and TarraCoata acts as data processor on that customer's documented instructions. See the Data Processing Agreement.
- Business name: TarraCoata
- Company / VAT number: [Company Number]
- Registered address: [Registered Address]
- Privacy contact: [privacy@tarracoata.com]
- General contact: tarracoatainfo@gmail.com
2. Personal information we collect
Information you provide directly
- Contact forms and quote requests: full name, email address, phone number, project type, budget range and the content of your message.
- Newsletter and marketing sign-up: email address and language preference.
- TarraOne accounts: name, work email, organisation name, role, authentication identifiers and billing contact details.
- Content you upload into a TarraOne workspace, including CRM records, files, notes and messages.
Information collected automatically
- Server logs: request URL, HTTP method, response status, timestamp and referrer.
- Device and technical information: browser type and version, operating system, screen resolution, language and time zone.
- IP address (used for security, abuse prevention and coarse geographic statistics).
- Cookies and similar technologies, as described in the Cookies Policy.
- Analytics events: pages viewed, session duration, navigation paths and aggregated interaction data.
Information from third parties
- Authentication providers (for example Google Sign-In) supply your name, email address and profile identifier when you choose to sign in with them.
- Payment providers confirm transaction status; we do not receive or store full card numbers.
We do not intentionally collect special categories of data (health, biometric, political or religious data). Please do not submit such data through our forms.
3. Why we process your data and on what legal basis
| Purpose | Legal basis |
|---|---|
| Responding to enquiries and preparing proposals | Steps prior to entering a contract |
| Delivering contracted development, automation and platform services | Performance of a contract |
| Operating, securing and improving the website and TarraOne | Legitimate interests |
| Analytics and product measurement | Consent (analytics cookies) |
| Marketing emails and newsletters | Consent, withdrawable at any time |
| Accounting, invoicing and tax records | Legal obligation |
| Preventing fraud, abuse and security incidents | Legitimate interests and legal obligation |
4. Marketing communications
We send marketing email only where you have opted in, or where you are an existing customer receiving information about closely related services, as permitted under Section 30A of the Israeli Communications Law. Every message includes a one-click unsubscribe link, and you may also unsubscribe by writing to [privacy@tarracoata.com]. Withdrawing consent does not affect transactional messages such as invoices, security alerts or service notices.
5. Third-party services and processors
We use vetted service providers under written data processing terms. Categories include:
- Cloud hosting and database infrastructure — application hosting, database and file storage.
- Email delivery — transactional and notification email.
- Analytics — aggregated website and product usage measurement.
- AI model providers — generation and analysis features described in the AI Usage & Disclaimer.
- Payment processing — subscription billing for TarraOne.
A current list of TarraOne sub-processors is maintained in the Data Processing Agreement. We do not sell personal data, and we do not share it for third-party advertising.
6. International transfers
Our providers may process data outside Israel and the European Economic Area. Where that happens, transfers are protected by an adequacy decision, the European Commission's Standard Contractual Clauses, or an equivalent lawful transfer mechanism, together with supplementary technical measures such as encryption in transit and at rest. You may request a copy of the relevant safeguards at [privacy@tarracoata.com].
7. Data retention
- Contact form submissions and CRM lead records: up to 36 months after last contact, unless an engagement begins.
- Newsletter subscribers: until unsubscribe, plus a suppression record to honour the opt-out.
- Accounting and invoicing records: seven years, as required by Israeli tax law.
- Server and security logs: up to 12 months.
- TarraOne workspace content: for the life of the subscription, then deleted or returned within 30 days of termination as described in the DPA.
- Backups: rolling encrypted backups purged within 35 days.
8. Security
We apply technical and organisational measures appropriate to the risk, including TLS encryption in transit, encryption at rest, row-level authorisation in our databases, least-privilege access control, multi-factor authentication for administrative accounts, audit logging and regular dependency scanning. Full detail is published in the Security Policy. No system is perfectly secure, and we cannot guarantee absolute security.
9. Your rights
Subject to applicable law, you may request to:
- Access the personal data we hold about you and receive a copy.
- Rectify inaccurate or incomplete data.
- Erase data where there is no overriding legal basis to retain it.
- Restrict or object to processing, including profiling and direct marketing.
- Port data you provided to us in a structured, machine-readable format.
- Withdraw consent at any time, without affecting prior lawful processing.
Send requests to [privacy@tarracoata.com]. We verify identity before acting and respond within 30 days. If you are in the EEA you may lodge a complaint with your local supervisory authority; in Israel you may contact the Privacy Protection Authority.
10. Children's privacy
Our website, services and TarraOne are intended for businesses and adults. We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us with personal data, contact [privacy@tarracoata.com] and we will delete it promptly.
11. Automated decision-making
TarraOne includes AI-assisted lead scoring and content suggestions. These outputs are advisory, are reviewed by a human before any decision with legal or similarly significant effect, and can be disabled per workspace on request.
12. Changes to this policy
We may update this policy to reflect changes in our services or in the law. Material changes are announced on this page and, where appropriate, by email. The "last updated" date above always reflects the current version, and previous versions are retained in our version history.
13. Contact
Questions, requests or complaints: [privacy@tarracoata.com] · tarracoatainfo@gmail.com · [Phone Number] · [Registered Address]. Further details are on the Contact & Legal Information page.
