Privacy Policy
How Smartware Holdings, Inc., doing business as Tasirio, handles personal information — in our product, on this website, and in the messages we send.
Last updated 10 October 2026. Smartware Holdings, Inc. (doing business as Tasirio), 4637 Indian Rock Dr, Fort Worth, TX 76244, United States. Smartware Holdings, Inc. is the legal entity responsible for the personal information described here; “Tasirio” is the name of the product and the brand. Questions, requests or complaints: privacy@tasirio.com.
The short version
- We read configuration, not content. Tasirio's connectors read metadata from the systems a customer connects — who has access to what, how sharing is configured, which roles exist. We do not read the files, emails or messages inside those systems. Three connectors read beyond metadata because the check cannot exist without it — Medius supplier bank identifiers (stored masked), Notion body text of pages you have Published to the web (only the derived labels are stored, never the text), and Softbase cardholder column names and row counts, never a value — and our DPA discloses all three.
- We are read-only. Our connectors issue read calls only. Tasirio writes only where you asked it to, and never to the configuration, permissions or records it reads: the connector credential you provide, stored in a key vault (ours, or your own under bring-your-own-key) with only a reference to it kept in our database — or, if you turn on the customer-key option, stored in our database encrypted under your key — and, only where you connect one, the tickets Tasirio opens in your ticketing system (Jira, ServiceNow, Zendesk or Syncro), including their status and comments; the findings it forwards to your SIEM or SOAR endpoint; and the alerts it posts to your webhook or Slack. Nothing is sent to any of them until you connect it. The access token you give us for a ticketing system or a SIEM is stored encrypted in our database, and a webhook address is stored there as you entered it.
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
- This website runs no analytics or advertising trackers — no Google Analytics, no advertising pixels, no third-party session recording.
Who this covers
Two different groups, with different data:
- Visitors and prospects — people who use this website, book a demo, use the chat, or are added to our CRM as a sales contact.
- Customer users — people who sign in to the Tasirio application because their employer is a customer. For that data, the customer is the controller and Tasirio is the processor: we act on their instructions, and their agreement with us governs.
What we collect, and why
| What | Why |
|---|---|
| Name, work email, company, phone, and anything you type into a form or the chat | To answer you, book a demo, and run our sales process |
| Account details for people who sign in: name, work email, role, sign-in and 2FA records | To authenticate you, enforce permissions, and keep an access record |
| Configuration metadata from a customer's connected systems — user and group names, work email addresses, roles, permissions, sharing settings, device and application inventory | This is the product. It is how we can tell a customer who and what can reach their data |
| Notification recipients a customer adds: name, work email, optional mobile number | To send the operational alerts that customer asked us to send |
| Server and audit logs, including IP address and actions taken in the app | Security, abuse prevention, and a tamper-evident record of what we read |
| Billing contact and invoice records | To bill for the service and meet tax obligations |
We do not intentionally collect special-category data (health, biometrics, precise geolocation, and similar), and our connectors are not designed to retrieve it. Because we read configuration from systems our customers control, a customer could in principle name a person in a field we read; we treat anything so collected under this policy and delete it on request.
Text messages (SMS)
Tasirio sends SMS only when a customer sets it up, and only for operational alerts about that customer's own systems — for example a scheduled security scan that did not run. We never send marketing texts.
- An administrator of the customer's account adds the recipient's number, confirming that person agreed to receive alerts.
- We then text a 6-digit verification code to that number, and send nothing else until it is entered. Changing the number clears the verification.
- Message frequency may vary. Standard message and data rates may apply. Reply STOP to opt out. Reply HELP for assistance.
- Your mobile information will not be sold or shared with third parties for promotional or marketing purposes. Phone numbers and consent are shared only with our messaging provider in order to deliver the message you asked for.
Who we share it with
We use a small number of service providers, listed below and kept in step with our sub-processors page — Stripe handles billing and payment details. They act on our instructions and may not use the data for their own purposes.
| Provider | What it handles |
|---|---|
| Microsoft Azure | All hosting, databases, key vaults and storage. United States (East US 2) — the only region we operate. |
| Brevo | Transactional email and SMS delivery |
| Intuit QuickBooks | Invoicing and billing records |
| hCaptcha | Bot protection on public forms and when a website chat is started |
| Microsoft Azure OpenAI | Optional AI features (the in-app assistant and remediation help), and the assistant on our website chat: what you type into that chat is sent to this provider to produce a reply. This runs on our own Azure OpenAI resource in East US 2, inside the same Azure subscription as the rest of Tasirio — not a separate AI vendor. Microsoft does not use content submitted to Azure OpenAI to train its models. The AI provider is a single setting for the whole service, not chosen per customer; moving to a different provider would be a sub-processor change and would be notified as one. |
We also disclose information if the law requires it, to protect our rights or someone's safety, or to a buyer in a merger or acquisition — in which case this policy continues to apply until you are told otherwise. We do not sell personal information.
Where it lives, and how it is protected
- Data is hosted in the United States (Azure East US 2). That is the only region we operate and there is no EU, UK or Canadian hosting option.
- Findings and permission data are isolated at the database, by row-level security the database enforces. A further 23 platform tables — connections, users and the analytics event log among them — are isolated by application predicates instead, deliberately, and are reviewed as such.
- Encrypted in transit and at rest. Governance findings are additionally encrypted with a per-customer key. Separately, you can choose a key you control to encrypt your connector credentials; Tasirio keeps that key in its own vault so scheduled syncs can run.
- Connector credentials are held in a key vault, and our database stores only a reference. One exception: if you turn on the customer-key option, they are stored in our database encrypted with AES-256-GCM, and the key is held separately in the vault. Access tokens for a ticketing system or SIEM you connect are stored encrypted in our database.
- What we read is written to a tamper-evident audit log the customer can review.
- Staff access to production is by named account. We do not claim every Tasirio administrator holds a second factor — our own access review of 26 August 2026 found two of five that did not, and closing that is tracked as an open finding. Administrators who reset another person’s two-factor must prove their own first.
No system is perfectly secure, and we do not claim otherwise. Security questions and suspected vulnerabilities: security@tasirio.com.
How long we keep it
- Customer data — for the life of the agreement. On termination we delete or return it within 30 days, except where law requires us to keep it, or where you asked us to retain a specific artefact — a signed evidence pack keeps its stated retention so it stays verifiable.
- Website chat transcripts — up to 24 months after the last message in the conversation.
- Other prospect and CRM records (demo requests, sales contacts and notes) — kept for as long as we have a business relationship or an open sales conversation with you. We do not currently delete them on an automatic schedule; you can ask us to delete yours at any time (see “Your rights” below).
- The tenant activity log — the tamper-evident record of completed syncs and administrative actions is append-only for the life of the agreement and is deleted with your tenant record on termination. It is not trimmed to a fixed window: a hash-chained log with entries removed from the middle can no longer prove its own integrity, which is the only reason it exists.
- Evidence packs you asked us to keep — a 365-day write-once retention policy, so a pack stays verifiable for as long as it is cited.
- Our own operational and security logs (infrastructure telemetry, not your governance data) — retained on the platform's configured schedule.
- Billing records — as long as tax and accounting law requires, normally 7 years.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict how we use it, and to withdraw consent. Californians may additionally request disclosure of what we collect and opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of, and we will not discriminate against you for asking.
Email privacy@tasirio.com and we will respond within 30 days. If your data is in Tasirio because your employer is a customer, we will refer you to them, since they decide what is collected and we act on their instructions.
Cookies
This marketing website sets no analytics or advertising cookies. The Tasirio application uses only the storage strictly necessary to keep you signed in and to remember interface preferences. We do not run third-party trackers on either.
Children
Tasirio is a business product and is not directed to anyone under 18. We do not knowingly collect information from children.
International transfers
We are based in the United States and our infrastructure is in the United States — not "by default" but exclusively. If you are outside the US, using Tasirio means your information is transferred there. Where required, we rely on Standard Contractual Clauses. We do not offer regional hosting today, so if data must stay in a particular region, raise it before signing rather than after: it is a scoping conversation and the answer today is no.
Changes
We will update the date at the top when this changes, and will tell customers directly about any change that materially affects them.
See how Tasirio protects your data →
Related: Privacy Policy · Terms of Service · Data Processing Addendum · Sub-processors · Security & Trust