Privacy Policy
How Smartware Holdings, Inc., doing business as Tasirio, handles personal information — in our product, on this website, and in the messages we send.
Last updated 26 August 2026. Smartware Holdings, Inc. (doing business as Tasirio), 4637 Indian Rock Dr, Fort Worth, TX 76244, United States. Smartware Holdings, Inc. is the legal entity responsible for the personal information described here; “Tasirio” is the name of the product and the brand. Questions, requests or complaints: privacy@tasirio.com.
The short version
- We read configuration, not content. Tasirio's connectors read metadata from the systems a customer connects — who has access to what, how sharing is configured, which roles exist. We do not read the files, emails, records or messages inside those systems.
- We are read-only. Our connectors issue read calls only. The single exception is writing a credential into a key vault (ours, or the customer's own), so it never sits in a database.
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
- This website runs no analytics or advertising trackers — no Google Analytics, no advertising pixels, no third-party session recording.
Who this covers
Two different groups, with different data:
- Visitors and prospects — people who use this website, book a demo, use the chat, or are added to our CRM as a sales contact.
- Customer users — people who sign in to the Tasirio application because their employer is a customer. For that data, the customer is the controller and Tasirio is the processor: we act on their instructions, and their agreement with us governs.
What we collect, and why
| What | Why |
|---|---|
| Name, work email, company, phone, and anything you type into a form or the chat | To answer you, book a demo, and run our sales process |
| Account details for people who sign in: name, work email, role, sign-in and 2FA records | To authenticate you, enforce permissions, and keep an access record |
| Configuration metadata from a customer's connected systems — user and group names, work email addresses, roles, permissions, sharing settings, device and application inventory | This is the product. It is how we can tell a customer who and what can reach their data |
| Notification recipients a customer adds: name, work email, optional mobile number | To send the operational alerts that customer asked us to send |
| Server and audit logs, including IP address and actions taken in the app | Security, abuse prevention, and a tamper-evident record of what we read |
| Billing contact and invoice records | To bill for the service and meet tax obligations |
We do not intentionally collect special-category data (health, biometrics, precise geolocation, and similar), and our connectors are not designed to retrieve it. Because we read configuration from systems our customers control, a customer could in principle name a person in a field we read; we treat anything so collected under this policy and delete it on request.
Text messages (SMS)
Tasirio sends SMS only when a customer sets it up, and only for operational alerts about that customer's own systems — for example a scheduled security scan that did not run. We never send marketing texts.
- An administrator of the customer's account adds the recipient's number, confirming that person agreed to receive alerts.
- We then text a 6-digit verification code to that number, and send nothing else until it is entered. Changing the number clears the verification.
- Message frequency may vary. Standard message and data rates may apply. Reply STOP to opt out. Reply HELP for assistance.
- Your mobile information will not be sold or shared with third parties for promotional or marketing purposes. Phone numbers and consent are shared only with our messaging provider in order to deliver the message you asked for.
Who we share it with
We use a small number of service providers. They act on our instructions and may not use the data for their own purposes.
| Provider | What it handles |
|---|---|
| Microsoft Azure | All hosting, databases, key vaults and storage. United States (East US 2) — the only region we operate. |
| Brevo | Transactional email and SMS delivery |
| Intuit QuickBooks | Invoicing and billing records |
| hCaptcha | Bot protection on public forms |
| Microsoft Azure OpenAI | Optional AI features (the in-app assistant and remediation help). This runs on our own Azure OpenAI resource in East US 2, inside the same Azure subscription as the rest of Tasirio — not a separate AI vendor. Microsoft does not use content submitted to Azure OpenAI to train its models. |
We also disclose information if the law requires it, to protect our rights or someone's safety, or to a buyer in a merger or acquisition — in which case this policy continues to apply until you are told otherwise. We do not sell personal information.
Where it lives, and how it is protected
- Data is hosted in the United States (Azure East US 2). That is the only region we operate and there is no EU, UK or Canadian hosting option.
- Every customer is isolated at the database, by row-level security the database enforces — not by application code alone.
- Encrypted in transit and at rest. Governance findings are additionally encrypted with a per-customer key, and customers on supported plans may supply their own key.
- Credentials are never stored in our database. They go to a key vault and are referenced.
- What we read is written to a tamper-evident audit log the customer can review.
- Staff access is least-privilege and requires two-factor authentication.
No system is perfectly secure, and we do not claim otherwise. Security questions and suspected vulnerabilities: security@tasirio.com.
How long we keep it
- Customer data — for the life of the agreement. On termination we delete or return it within 30 days, except where law requires us to keep it.
- Prospect and CRM records — up to 24 months after our last contact with you.
- Audit and security logs — up to 12 months.
- Billing records — as long as tax and accounting law requires, normally 7 years.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict how we use it, and to withdraw consent. Californians may additionally request disclosure of what we collect and opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of, and we will not discriminate against you for asking.
Email privacy@tasirio.com and we will respond within 30 days. If your data is in Tasirio because your employer is a customer, we will refer you to them, since they decide what is collected and we act on their instructions.
Cookies
This marketing website sets no analytics or advertising cookies. The Tasirio application uses only the storage strictly necessary to keep you signed in and to remember interface preferences. We do not run third-party trackers on either.
Children
Tasirio is a business product and is not directed to anyone under 18. We do not knowingly collect information from children.
International transfers
We are based in the United States and our infrastructure is in the United States — not "by default" but exclusively. If you are outside the US, using Tasirio means your information is transferred there. Where required, we rely on Standard Contractual Clauses. We do not offer regional hosting today, so if data must stay in a particular region, raise it before signing rather than after: it is a scoping conversation and the answer today is no.
Changes
We will update the date at the top when this changes, and will tell customers directly about any change that materially affects them.
See how Tasirio protects your data →
Related: Privacy Policy · Terms of Service · Data Processing Addendum · Sub-processors · Security & Trust