Effective Date: 20-April-2026
Last Updated: 20-April-2026
Tassos Consultancy Services Private Limited provides Tassos Talk (the “App”), a secure messaging platform integrated with Mobile Device Management (MDM) capabilities for enterprise use.
This Privacy Policy explains how we collect, use, disclose, and protect personal data in compliance with:
- General Data Protection Regulation (GDPR)
- Digital Personal Data Protection Act 2023
1. Nature of the Service
Tassos Talk is an enterprise-grade secure communication platform with optional MDM controls. The App:
- Enables encrypted messaging
- May enforce device-level policies (via MDM)
- Connects to self-hosted or organization-managed servers
Important: Your employer/organization may act as the Data Controller, while we act as a Data Processor.
2. Categories of Data We Collect
2.1 Account & Identity Data
- Name, username
- Email address / phone number
- Organization ID
2.2 Communication Data
- Messages (text, attachments)
- Metadata (timestamps, delivery status)
2.3 Device & MDM Data
(Critical for Apple Review)
If MDM is enabled, we may collect:
- Device identifiers (Device ID, IMEI where permitted)
- OS version, device model
- Security posture (passcode status, encryption status)
- Installed app inventory (if enabled by organization)
- Device compliance status
We do NOT access personal photos, personal apps, or unrelated personal data unless explicitly configured by the organization.
2.4 Technical & Usage Data
- IP address
- Log data (crash logs, diagnostics)
- Connection status
3. Purpose of Processing
We process data for:
- Secure message delivery
- Device security enforcement (MDM policies)
- Authentication and access control
- Compliance with organizational security policies
- Fraud prevention and misuse detection
- Service performance and reliability
We do not use data for advertising, profiling, or selling to third parties.
4. Legal Basis for Processing (GDPR)
- Contractual necessity – to provide the service
- Legitimate interest – security and fraud prevention
- Legal obligation – compliance requirements
- Consent – where explicitly required
5. Data Fiduciary Obligations (India DPDP Act)
- We act as a Data Processor, while your organization is the Data Fiduciary
- Data is processed only for lawful purposes
- Users have rights to:
- Access data
- Correct data
- Erase data
- Grievance redressal
6. Data Storage & Hosting
- Data is stored on:
- Self-hosted servers, or
- Organization-managed infrastructure
- Server location: Determined by organization
We do not centrally store enterprise data unless explicitly contracted.
7. Data Sharing
We do NOT sell data.
We may share data only:
- With your organization (as Data Controller)
- With infrastructure providers (strictly for hosting)
- To comply with legal obligations
8. Security Measures
- End-to-end or TLS encryption
- Device authentication
- Role-based access control
- MDM enforcement policies
- Secure APIs and hardened infrastructure
9. Data Retention
- Defined by organization policies
- Users may request deletion via organization/admin
- Logs retained only for operational/security purposes
10. Your Rights
Under GDPR:
- Access, rectification, erasure
- Restriction of processing
- Data portability
- Lodge complaint with authority
Under DPDP Act:
- Access and correction
- Erasure
- Withdraw consent
- Grievance redressal
11. Cross-Border Transfers
Data may be transferred outside your jurisdiction depending on server deployment. Appropriate safeguards are applied.
12. Apple-Specific Disclosures
- The App may use Apple Push Notification service (APNs)
- No third-party tracking or advertising SDKs are used
- Data collection is limited to functionality and security
13. Children’s Privacy
Not intended for users under 13 (or applicable age). No intentional data collection from children.
14. Contact Information
Tassos Consultancy Services Private Limited
Email: info@tassosconsultancy.com
Address: 406-FF, Abhishree Complex, Satellite Road, Star Bazaar, Ahmedabad – 380 015, Gujarat (India)

