Privacy

Privacy Notice

How Tierora handles personal data across its website, waiting list, newsletter and business change-management service, and how to exercise your rights.

Draft updated

Draft for review. Hosting details, operational retention arrangements and the remaining legal provisions must be confirmed before this notice is final. Product sections describe processing when a customer is onboarded; joining the waiting list does not open a product account.

1. Who is responsible for your information

Tierora is a product owned and operated by stackwiz labs OÜ, a company registered in Estonia. In this notice, “Tierora”, “we”, “us” and “our” refer to stackwiz labs OÜ when providing Tierora.

  • Legal operator and data controller for the purposes described in this notice: stackwiz labs OÜ.
  • Estonian registry code: 17454751.
  • Registered address: Uus tn 2-11, Ervita 73002 Järva county, Estonia.
  • Privacy contact: privacy@tierora.com. Use this address for privacy questions, requests and communication preferences.
  • Tierora support: support@tierora.com. Tierora product enquiries can also be sent to hello@tierora.com.

This notice concerns Tierora. Other stackwiz labs products have their own privacy notices. Any appointed data protection officer or representative relevant to Tierora will be identified here where required.

2. What this notice covers

This notice covers visitors to Tierora’s public website and documentation, people who contact us, waiting-list members, newsletter subscribers, and business contacts and users of a Tierora customer workspace.

Tierora is currently in development. The public forms collect enquiries and confirmed interest without creating a customer workspace, taking payment or connecting to your company’s systems. Sections about the product apply only when access is separately provided.

A customer’s own privacy notices explain why it uses Tierora to process information about its employees, contractors, service owners and other contacts. This notice does not replace those notices, the customer’s agreement with Tierora or its Data Processing Agreement (DPA).

3. Tierora’s role and your organisation’s role

We determine how personal data is used to run our website, respond to enquiries, manage subscriptions to our communications, administer our customer relationships and protect our own service. For those purposes, we act as a data controller.

For personal data that a customer places in its workspace or instructs us to obtain through an integration, the customer normally acts as controller and Tierora acts as processor. If the customer is itself processing data for another organisation, Tierora may act as its subprocessor. The applicable DPA documents those responsibilities.

Workspace membership, access rules, approval policies and notification destinations are set by the customer. We process customer-controlled data to provide the agreed service and follow documented instructions, subject to applicable law. A workflow instruction does not authorise us to use its contents for unrelated marketing.

4. Website enquiries, waiting list and newsletter

We collect the information you choose to submit. Please keep enquiries relevant and do not include passwords, integration credentials, production logs or personal data about other people unless needed to answer your request.

  • Contact form: your name, email address, selected topic and message. Resend delivers the message to Tierora’s inbox, with your address available for our reply. Contacting us does not subscribe you to either mailing list.
  • Waiting list: your email address and preferred plan, including “Not sure yet”. We send a confirmation email and save the preference after you explicitly confirm. Your selection is non-binding and is not newsletter consent.
  • Newsletter: your email address and confirmation of your request to subscribe. Newsletter and waiting-list memberships are recorded separately, although Resend can hold both against the same email contact.
  • Delivery and consent information: confirmation status, segment membership, recorded plan preference, unsubscribe or suppression status, and provider records about message delivery, failures or complaints.
  • Technical requests: our website receives an IP address and standard request information, such as the requested address, browser information and time of the request. Hosting and email providers may retain technical logs to deliver and protect their services.
  • Optional website analytics: if you opt in, Google Analytics measures public page visits and successful contact, waiting-list and newsletter requests. The request category is recorded, not your name, email, message or plan selection. A request event is not proof that an email subscription was later confirmed.

5. Information processed in a customer workspace

The data processed depends on the features your organisation enables and the information its users and connected tools provide. Relevant categories include:

  • Identity and access: business email, display name, user and organisation identifiers, memberships, roles, identity-provider claims and group identifiers. The sign-in service also handles session information and authentication tokens; your identity provider handles its own login credentials.
  • Service context: service names, ownership and contact details, team and container structures, dependencies, environments, policies and configuration. A service map can include personal data where it identifies owners or contacts.
  • Change and workflow records: declarations, reasons, schedules, risk information, workflow definitions and revisions, comments, approval eligibility and decisions, execution results, retries, overrides and cancellations.
  • Integrations and communications: connection configuration and authorised credentials, external ticket or run references, relevant status or health data, notification recipients, message content and delivery evidence.
  • Audit and support: actor identifiers, timestamps, recorded events, evidence exports and information you provide when requesting support. Support correspondence may contain customer data if you include it.
  • Account administration: business and billing contacts, the chosen plan, usage and entitlement records, and payment or invoice references when paid service becomes available. Payment-provider details will be disclosed before payments are collected.

6. Where product information comes from

Information may come from you, an authorised workspace administrator, other users in your organisation, your company’s identity provider, or tools that your organisation connects to Tierora.

For example, your organisation may add you as a service owner or approver, resolve your group membership through its identity system, or include your details in a ticket or announcement. Your administrator is the first contact for questions about why the organisation has included you.

Connecting a provider authorises the configured exchange of information. It does not mean Tierora continuously copies every record in that provider. The actual exchange depends on the enabled integration, granted permissions and workflow configuration.

7. Why we process data and our legal bases

Where the GDPR or UK GDPR applies to processing for which we are controller, we rely on the following bases. Other applicable privacy laws may describe these requirements differently.

  • Enquiries and business relationships: our legitimate interest in responding to relevant requests and managing relationships with business representatives. Contract necessity applies where the individual is personally entering, or asking us to enter, a contract.
  • Waiting-list updates and newsletters: consent for the separate communication you request. We use confirmation to check that you control the email address. Withdrawing consent does not affect earlier lawful processing.
  • Service administration, troubleshooting and abuse prevention: our legitimate interests in keeping the service functional, secure and accountable. We consider the necessity of the information and its impact on individuals.
  • Legal and accounting requirements: compliance with applicable obligations. Necessary records may also be used for our legitimate interest in establishing, exercising or defending legal claims.
  • Website analytics: your consent to help us understand which pages people use and where interest comes from. Rejecting or withdrawing analytics consent does not prevent access to the website or its forms.

For customer-controlled workspace data, the customer identifies its lawful basis and provides the relevant notices. Tierora’s authority as processor comes from the DPA and documented instructions, not from treating each employee’s use of the workspace as marketing consent.

Providing contact and subscription information is voluntary. Without an email address, we cannot reply or send the requested confirmation. For product access, the information required by your organisation’s identity and access configuration may be necessary to use its workspace.

8. Who may receive information

We disclose information only for the purposes described in this notice and as permitted by the relevant agreement and law.

  • Authorised Tierora personnel and service providers who need the information to deliver communications, operate the service, respond to support requests or perform administration, under appropriate confidentiality and data-protection arrangements.
  • Your organisation’s authorised users and administrators, according to the access available in its workspace. Approval and audit records may remain visible to the organisation after a user leaves.
  • Recipients and external providers selected by your organisation. An announcement can send information outside the workspace through a channel or distribution list. The customer is responsible for choosing appropriate recipients and permissions.
  • Professional advisers, authorities or courts where disclosure is necessary and lawful, including to meet a binding legal requirement or protect legal rights.
  • A potential or actual successor in a merger, acquisition or transfer of the business, subject to safeguards and any notice required by law.

We do not sell personal data or disclose customer workspace contents for third-party advertising. A recipient’s own handling of information, including copies in an email inbox, ticket system or exported file, is governed by its responsibilities and applicable policies.

9. Service providers and connected tools

Resend, operated by Plus Five Five, Inc., is the email and contact-management provider used for public enquiries, confirmation emails, waiting-list preferences and newsletter subscriptions. Contact enquiries also pass into Tierora’s receiving mailbox.

Google Analytics 4, provided for our European business by Google Ireland Limited with processing by Google and its affiliates, is our optional website measurement service. Its tag loads only after you accept analytics. We do not send customer workspace data, user IDs or form contents to this service, and we do not enable Google Signals, user-provided data collection or advertising personalisation.

Website hosting and receiving-mailbox provider details are pending confirmation for the public deployment. Before customer onboarding, we will also identify the product’s actual hosting, storage, support and other subprocessors, their functions and relevant processing locations. A planned cloud platform or an integration logo is not evidence that a provider currently receives customer data.

Customer-selected identity providers, ticketing systems, CI/CD tools, observability services and communication platforms operate under the customer’s arrangements with those providers. Their role differs from a subprocessor Tierora engages to run its own service. The customer should review the data it authorises each connection to exchange.

10. Processing locations and international transfers

Public-form data handled by Resend is stored and processed in the United States. Choosing an EU email-sending region does not move Resend’s stored contact or message data into the EU.

Resend’s DPA includes the European Commission’s Standard Contractual Clauses, with UK and Swiss adaptations where applicable. These contractual safeguards address transfers to countries whose laws may differ from those where you live. You can review the provider’s DPA below and contact us for information about the safeguards relevant to your data.

When you accept analytics, Google may process measurement information internationally, including in the United States. Google’s applicable data-processing terms provide transfer safeguards, including Standard Contractual Clauses where applicable. This is not an EU-only processing promise. Google states that Analytics 4 uses IP addresses during collection and does not log or store them in Analytics; this does not make cookie identifiers or usage information anonymous.

Product hosting regions and any other international transfers must be specified for the actual service deployment and its DPA before customer data is processed. An Enterprise namespace, customer-managed SSO or an EU cloud region alone does not establish that every support, email or connected-provider operation stays in that region. We do not currently promise an EU-only or Switzerland-only service.

11. How long information is kept

Retention depends on the purpose, the applicable agreement and legal requirements. Product-plan retention is separate from the information needed to answer an enquiry or record a communication preference.

  • Enquiries and support correspondence: for the duration of the request and any resulting business relationship, and afterwards only where needed for a defined legal, security or dispute-resolution purpose. We remove information that no longer serves those purposes.
  • Waiting-list information: while your early-access request remains active, until you withdraw it or we close the list. If access is offered, joining the product requires a separate onboarding process; the waiting list is not an indefinite marketing subscription.
  • Newsletter information: while your subscription remains active. When you unsubscribe, we stop newsletter use; a limited suppression record may remain to prevent accidental resubscription.
  • Confirmation links: valid for 24 hours. Expiry prevents confirmation but does not by itself delete the email, provider delivery records or a subscription you already confirmed.
  • Delivery and security records: for troubleshooting, abuse prevention and any applicable legal requirement. Resend’s message and log retention is governed by its service settings; this is distinct from its stored contacts and from copies delivered to an inbox.
  • Website analytics: the Tierora property is configured to retain user-level and event-level data for two months, with reset on new user activity disabled. These settings do not apply to most aggregated standard reports. Our browser preference and analytics cookies have separate lifetimes of up to 180 days; withdrawing consent stops future measurement but does not automatically erase data already processed by Google.
  • Customer workspace data: for the agreed service duration and record-retention period, followed by the return or deletion arrangements in the DPA. Published plan periods describe the intended product record window; they are not a claim that automatic deletion is already operating during development.
  • Backups, consent evidence and legal holds: retained only for their defined recovery, accountability or legal purpose. A legal hold can delay deletion of the affected records. Deleted data in a backup must remain restricted until it expires under the agreed backup schedule.

The deployment’s deletion schedule, including backup expiry and post-termination handling, must be established before operational customer data is onboarded. Contact us to ask which retention criteria apply to a particular record or to request deletion. Copies already received or exported by a customer or external recipient must be handled by that recipient.

12. Cookies, browser storage and email measurement

You can accept or reject optional Google Analytics in our cookie prompt, or choose in Cookie preferences in the footer. Analytics is off until you opt in. Browsing, contacting us and joining either mailing list do not require analytics consent.

Necessary preference storage: tierora_cookie_preferences is first-party local storage written when you save a choice. It records whether analytics is allowed, the policy version, and save/expiry times, without a visitor identifier. It lasts 180 days and is not sent with web requests or shared with Resend. Expired or superseded records trigger a new choice; a previous necessary-only record does not grant permission for analytics.

Optional analytics cookies: Google Analytics uses _ga to distinguish browsers and _ga_P6DE95HLJX to maintain session information. We configure these first-party cookies for up to 180 days, without extending their lifetime on each event. They are used only after analytics consent. Your browser may apply a shorter lifetime.

Analytics information includes approved public page paths, a referring website or public Tierora page, visit/session activity, general browser or device information and cookie identifiers. We strip query strings and fragments, exclude confirmation and unknown pages, and disable automatic form, outbound-link, search and video measurement. We do not send names, email addresses, message contents, confirmation tokens or submitted plan preferences. Google Signals, granular location/device collection, user-provided data collection and advertising personalisation are disabled.

Our consent setup blocks Google’s tag and measurement requests before consent, including cookieless measurement pings. To withdraw, open Cookie preferences, turn Google Analytics off and save, or choose Reject optional. We stop collection, clear this website’s analytics cookies and reload the page to unload the tag. Save any unfinished form first. Changes apply to this browser; use the same controls on other browsers or devices. You may also clear browser storage. If your browser cannot save the choice, analytics stays off for that visit and we show an explanation.

Cookie preferences are separate from enquiries, waiting-list interest and newsletter subscriptions. Resend receives the information needed to process a form request through our server; it does not load a third-party browser script or cookie on these pages. Newsletter and waiting-list subscriptions still require their own email confirmation. Cookie preferences do not give consent to email open or click tracking.

The separate operator application uses necessary cookies for sign-in and workspace selection. Its current session cookie can last up to 14 days, the temporary sign-in cookie up to 10 minutes, and organisation or namespace selection cookies up to 90 days. Signing out or clearing cookies can end access or reset those selections. Your identity provider may use its own cookies.

Hosting security services can process request information independently of the application’s cookies. Links to external websites bring you under those sites’ policies when you follow them.

Resend provides delivery events and offers optional open and click tracking. Tracking configuration must be confirmed before newsletters are sent; we do not treat a message-open signal as confirmation of subscription. Any optional tracking that requires consent will be explained and enabled only with that consent.

13. Security and confidentiality

The public forms use server-side provider credentials, encrypted and expiring confirmation links, explicit confirmation before subscription, input validation and abuse checks. These measures reduce particular risks; they cannot guarantee that no unauthorised access or delivery failure will occur.

For the customer service, the agreed security measures must reflect the sensitivity of operational information and credentials. The DPA and service agreement will describe applicable access restrictions, secure communications, credential handling, logging, backups and incident procedures. We do not claim a certification, a completed independent audit or a particular recovery guarantee merely because those controls appear in a product example.

If a personal data breach affects customer-controlled data, we will notify the customer without undue delay after becoming aware of it and provide the information and assistance required by the DPA and applicable law. Where we act as controller, we will make legally required notifications to authorities or affected individuals.

14. Workflow automation and decisions about people

Tierora is designed to apply customer-defined rules to operational changes: for example, identifying affected services, resolving approvers, selecting notification recipients and progressing configured workflow steps.

These functions are not intended to score employees, decide employment matters or make solely automated decisions about individuals with legal or similarly significant effects. We do not use website or subscription information for such decisions. If a customer proposes a use with that effect, it must establish a lawful basis, safeguards and any required human review before using the service for it.

The current service does not send customer workspace content to a generative-AI model or use it to train one. Any future materially different use would need its own assessment, disclosure and contractual basis before it begins.

15. Your privacy rights

Depending on the law that applies, you can ask for access to personal data, correction of inaccurate information, deletion, restriction of processing, or a portable copy of data that qualifies for portability. You may also object to processing based on legitimate interests and withdraw consent for future processing.

You can unsubscribe through the link in a newsletter or email privacy@tierora.com to withdraw a waiting-list request or change your preference. The current provider uses a global unsubscribe status, so unsubscribing may stop both newsletters and waiting-list messages. Joining either list again does not silently override that status.

For information controlled by your organisation, contact its administrator or privacy team first. We will assist the customer under its DPA, including when a request concerns approval or audit records. Leaving a workspace does not necessarily erase records the organisation lawfully needs to retain.

We may request proportionate information to verify your identity and authority, without asking for more data than necessary. Under the GDPR, requests are normally answered within one month; a permitted extension will be explained within that period. Other applicable deadlines and exceptions may differ.

You can complain to the competent data-protection authority without contacting us first. In Estonia, this is the Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate). In the EEA, you can also complain to the authority where you live, work or consider an infringement to have occurred. Where applicable, you may contact the UK Information Commissioner’s Office or Switzerland’s Federal Data Protection and Information Commissioner.

16. Children and sensitive information

Tierora is intended for business use and is not directed at children. Do not submit children’s data, health information, payment-card details, government identifiers or other specially protected information through the public forms.

Customers should keep workflow descriptions, ticket content and evidence proportionate to the change being managed. Processing special-category data or other regulated datasets requires a prior written agreement and appropriate safeguards; it is not included simply because a field accepts free text. If you believe such information has been submitted in error, contact us so we can assess and address it.

17. Changes to this notice

We will update this notice when our data handling changes and show the revision date above. For material changes, we will provide additional notice appropriate to the circumstances. Where a new purpose requires consent, an update to this page does not replace obtaining that consent.

Questions about this notice or how it applies to your organisation can be sent to privacy@tierora.com.

PRIVACY PREFERENCES

Necessary storage

Always active

After you save, we remember this choice on your device for 180 days. It contains no personal identifier and isn't sent to an analytics service.

Google Analytics

Optional. Helps us measure page visits and successful form requests. Google receives browser/device information and pseudonymous cookie identifiers. We exclude form contents, query strings and confirmation pages. Analytics cookies last up to 180 days.

How Google uses this information ↗

Advertising

Not used

We don't use advertising cookies, Google Signals or personalised advertising.

Reopen these settings anytime using “Cookie preferences” in the footer.