Privacy policy
Last updated 24 September 2026
This policy explains what personal data Tessel handles, why, and what your rights are. Tessel is provided by Tessel. Contact us at cmheimvik@gmail.com about anything in this policy.
Who is responsible
For the accounts of people who sign in to the portal, and for this website, we are the data controller. For the information a firm and its people put on their cards, the firm is the controller and we process it on the firm’s behalf.
What we collect
- Account details: name, email address and password (the password is handled by our sign-in provider, never stored by us).
- Card details: whatever a person chooses to put on their card, such as title, phone numbers, email, address, photo and a short bio.
- Tap statistics: when a card is opened or saved, the type of device, and the optional one-tap answer to “who are you?” (client, colleague or someone else). We do not store the IP address of people who tap a card; repeated attempts to open links that don’t exist are counted by IP address for a short time, to block guessing.
- Security logs: changes made in the portal, with the IP address they were made from, to protect accounts and investigate misuse.
- Billing: the firm’s plan and its customer reference at our payment provider. Card details are handled by Stripe and never reach us.
Why we use it
- To provide the service a firm has signed up for: showing cards, the portal and its statistics (performance of a contract).
- To keep the service secure and prevent misuse (legitimate interest).
- To send the emails the service needs, such as invitations (performance of a contract).
- To meet accounting and legal obligations (legal obligation).
We don’t sell personal data, and we don’t use it for advertising.
Who we share it with
We use these providers to run the service, each bound by a data processing agreement:
- Vercel (hosting) and Neon (database)
- Clerk (sign-in and accounts)
- Stripe (payments)
- Resend (email)
Some of these providers may process data outside the EU/EEA, such as in the United States. Where they do, the transfer is protected by the EU Commission’s standard contractual clauses or an adequacy decision.
Cookies
We only use what the service needs to work: cookies that keep you signed in and remember which firm you are looking at, and, on a card page, a note in your browser of your answer to “who are you?” so you aren’t asked twice. There are no analytics or advertising cookies, so there is nothing to consent to.
How long we keep it
We keep account and card data for as long as the firm’s account exists. When a card, a person or a firm is deleted, its data is deleted with it; when a firm closes its account, we delete its data within 30 days, except where the law requires us to keep it, such as accounting records.
Your rights
You can ask to see, correct or delete your personal data, to restrict or object to how it is used, and to receive it in a portable form. You can change your own account details and delete your account at any time under “Your account” in the portal. For anything else, email cmheimvik@gmail.com. If the data is on a firm’s card, we may pass your request to that firm, which decides as the controller.
If you think we handle your data unlawfully, you can complain to the Norwegian Data Protection Authority (Datatilsynet).