Privacy Policy

How TietAI collects, uses, and protects personal data.

Last updated: April 2026

The data controller responsible for processing your data under this Privacy Policy is TIET AI, S.L. (hereinafter, TietAI).

TietAI, with Tax Identification Number (CIF) B26627893, registered office at Calle Fuenterrabía 9, Puerta 6, 28014 Madrid, Spain, and contact email privacy@tiet.ai, processes personal data to carry out some of its activities.

In this data processing, we comply at all times with the applicable legislation in force on the subject: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR) and Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).

We recommend reading this Policy together with our Cookie Policy and our Terms of Service.

1. Privacy Statement

TietAI is fully aware of the importance that the processing of personal data has for users. Therefore, we are committed to ensuring its protection, confidentiality, and security, in accordance with the principles of proactive accountability, transparency, and respect for individual rights.

This Privacy Policy aims to inform clearly and accessibly about what personal data we collect through the website tiet.ai/en, for what purpose we use it, on what legal basis we process it, and what rights data subjects may exercise.

We undertake to process only the personal data strictly necessary for the specified and legitimate purposes described in this policy, and to adopt all appropriate technical and organizational measures to prevent unauthorized access, loss, or misuse.

2. Scope of Application

This Policy applies to personal data that we process as data controllers through our website, contact forms, support, sales/marketing operations, account administration, and platform telemetry necessary to provide the service.

It does not replace your organization's privacy policy for patient or member data processed through integrations, in which context TietAI acts as a data processor. In the case of customer data processed in the framework of service provision (personal data processing that is not part of this policy or its scope of application), communications or disclosures of personal data will be made solely in accordance with the customer's documented instructions (for example, to infrastructure sub-processors identified in the corresponding Data Processing Agreement or DPA).

3. Categories of Personal Data

The categories of personal data that we may process, depending on the corresponding purpose, include:

  • Contact and account data: for example, name, professional email, job title, organization; credentials and administrator data.
  • Usage and device data: for example, basic device information, page views, referrer, general location by IP, event logs.
  • Support communications: for example, tickets, emails, call notes.
  • Billing and contract data: for example, plan, invoices, payment status (without access to full payment method information, which is managed by third-party payment service providers).
  • Recruitment process data: for example, data provided when applying for a job position.
  • Cookie and analytics data: as described in our Cookie Policy.

4. Purposes and Legal Bases for Processing

Personal data provided by users through the website will be processed by TietAI for the following purposes, only when a valid legal basis exists under the GDPR, depending on the services or features with which they interact:

  • Providing and ensuring service security / account administration (creating/managing accounts, authentication, support, troubleshooting, security/availability).
  • Legal basis: Performance of the contract with you and/or with your employer, and on the other hand, your employment contract, given that your activity through the account on our website corresponds to your job functions.
  • Product analysis and improvement (performance measurement, user experience improvement, abuse detection; methods that preserve privacy where possible).
  • Legal basis: Legitimate interest and/or performance of the contract with you and/or with your employer and, on the other hand, your employment contract, given that your activity through the account on our website corresponds to your job functions.
  • Sales and customer communications (responding to inquiries, service notices).
  • Legal basis: Legitimate interest and/or performance of the contract (or pre-contractual measures thereof) with you and/or with your employer and, on the other hand, your employment contract, given that your activity through the account on our website corresponds to your job functions.
  • Marketing (B2B) (only where applicable; you may unsubscribe at any time).
  • Legal basis: Consent or, in cases provided for by applicable regulations, legitimate interest.
  • Regulatory compliance and maintenance of records and preservation of evidence useful for defense against potential liabilities (legal, financial, and tax obligations; defense against legal claims).
  • Legal basis: Compliance with a legal obligation.

5. Personal Data Retention Periods

We retain personal data only for as long as necessary for the purposes indicated above and, once these purposes have been fulfilled, we proceed to erase or, when legally required, block the data in accordance with applicable regulations. The general criteria applicable after the relevant purpose ends are as follows:

If a longer legal or contractual retention period applies (for example, for tax or regulatory reasons, or for the preservation of evidence in the event of administrative or judicial proceedings), the data will remain duly blocked, being retained solely during said period and with access restricted to the absolute minimum necessary.

  • Account logs and support communications: for the duration of the account and for a limited period thereafter, being retained, where appropriate, duly blocked, when necessary for security, auditing, or defense against potential claims.
  • Web logs and security events: for the time strictly necessary for monitoring the security of the website and services, and as long as they may be necessary for the detection or investigation of incidents.
  • Marketing contacts: until the data subject objects to the processing or requests cancellation, or as long as an active relationship is maintained. Subsequently, the data will be deleted or anonymized.
  • Contracts, billing, and accounting: for the retention period required by applicable legal regulations.

6. Prohibition of Sale or Third-Party Advertising Use

We do not sell personal data nor do we transfer it to unrelated third parties for their own advertising or profiling purposes.

When we use verified service providers (for example, web hosting, security, or email delivery), they access personal data solely to the extent necessary for the provision of the service, act under our instructions, and are subject to the corresponding confidentiality and data processing agreements, in accordance with applicable regulations.

7. Recipients of Personal Data

Personal data collected through the website may be communicated or made available, when necessary, to the following recipients:

  • Service providers and sub-processors (for example, cloud hosting, security, email, or CRM and support services): limited access to personal data strictly necessary for service delivery, acting under TietAI's instructions and subject to corresponding data processing agreements.
  • Professional advisors (for example, legal, accounting, or tax advisors): confidential access to personal data when necessary for the exercise of their professional functions.
  • Public authorities or competent bodies: when such access is required by applicable regulations or necessary for the protection of rights, security, and integrity.
  • Corporate or business operations (for example, mergers, acquisitions, or corporate reorganizations): with the application of guarantees and protection measures required by data protection legislation.

8. International Transfers

If, for the provision of the service or the use of certain providers, it is necessary to transfer personal data outside the European Economic Area (EEA), such transfers will only take place when there is a legal basis that permits it and in accordance with legally established mechanisms, including, where applicable, adequacy decisions of the European Commission or the execution of Standard Contractual Clauses (SCCs), together with the adoption of any supplementary measures necessary to ensure an adequate level of personal data protection.

9. Security Measures

TietAI declares that it has an information security management system certified under the ISO 27001 standard, committing to apply the measures derived therefrom in the processing operations carried out and updating cybersecurity measures to conform to the state of the art.

10. User Rights Regarding Personal Data Processing

Users have, for all purposes, the following rights regarding the processing of their personal data by TietAI. However, in certain cases, legal grounds provided for in applicable regulations may apply that limit the exercise of any of these rights. In such cases, TietAI will duly inform the data subject, stating the reasons for the corresponding response.

  • Right of access: You may request confirmation as to whether personal data concerning you is being processed and, if so, access it and obtain information about its processing.
  • Right to rectification: You have the right to request the modification of your data if it is inaccurate or incomplete.
  • Right to erasure: You may request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected.
  • Right to restriction of processing: In certain circumstances, you may request that the processing of your data be restricted.
  • Right to data portability: In certain cases, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller, or to request that it be transmitted directly to them, provided this is technically feasible.
  • Right to object: You may object at any time to the processing of your data for reasons related to your particular situation.
  • Right not to be subject to automated decision-making: You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects concerning you or significantly affect you.
  • Right to withdraw consent: In processing based on your consent, you have the right to withdraw it at any time. The withdrawal of consent shall not have retroactive effect, so it will not affect the lawfulness of processing carried out prior to withdrawal.

11. How to Exercise User Rights

Users can exercise their rights by sending an express request, accompanied by the necessary information to verify their identity, through any of the following channels:

TietAI will respond to requests within the legally established timeframes, in accordance with applicable data protection regulations.

In any case, if you consider that the processing of your personal data violates applicable data protection regulations, or if you have not obtained a satisfactory response in exercising your rights, you have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).

  • By email: privacy@tiet.ai.
  • By postal mail: Calle Fuenterrabía 9, Puerta 6, 28014 Madrid, Spain.

12. Minors

Our website and the services offered through it are not directed to persons under 16 years of age. We do not knowingly collect personal data from minors through the website. If you believe a minor has provided us with personal data, please contact privacy@tiet.ai.

13. Third-Party Links and Integrations

Our website may contain links to third-party websites or integrations with third-party services, as well as embedded content. Such services are provided by third parties and are governed by their own privacy policies. TietAI is not responsible for the privacy practices of such third-party websites or services. We recommend reviewing the privacy policies of each website you visit.

14. Changes to this Policy

We may update this Policy to reflect changes in technology, in our practices, or in applicable legislation. In the event of material modifications, we will publish the updated version on this website indicating the "Last updated" date and, where required by applicable regulations, we will request user consent again or provide additional notice.

15. Cookies and Similar Technologies

A cookie is a small file that is downloaded and stored on the user's computer when accessing a website. Cookies allow the website, among other things, to store and retrieve information about the browsing habits of the user or their equipment and, depending on the information they contain and how the equipment is used, can be used to recognize the user. Users have the option to configure or reject the use of non-essential cookies through the tools provided for this purpose or through their browser settings. Cookies strictly necessary for the operation of the website do not require user consent. You can obtain more detailed information about the use of cookies by consulting our Cookie Policy.