Privacy Notice for Tessa Cloud
Die deutsche Fassung ist massgebend / The German version is binding. Binding German version
This privacy notice explains which personal data we process when you use Tessa Cloud and which rights you have. It supplements the privacy notice of our website. For personal data in an organisation’s test artifacts that organisation is the controller; the Data Processing Agreement applies to it.
1. Controller
Ernst & Conte GmbH, Oberneuhofstrasse 8, 6340 Baar, Switzerland. Send data protection questions to [email protected].
2. Which data we process
2.1 Sign-in and account data. You sign in with Google or GitHub, or on Enterprise through your organisation’s identity provider (single sign-on). Through our identity broker we receive your name, e-mail address, profile picture, and the identifier at the provider. Added to this are your role in the organisation, your settings, and the times of your sign-ins. Which data Google, GitHub, or your identity provider process in doing so is governed by their privacy notices.
2.2 Organisation and billing data. Organisation name, billing address, VAT number, chosen plan, invoices, and payment status. Stripe handles payment; we neither see nor store card details. Stripe receives your e-mail address and the billing data for this.
2.3 Test artifacts and logs. Scenarios, test plans, schedules, reports, screenshots, recordings, application logs, App Map, and uploaded builds of your organisation. We process this data as a processor on behalf of your organisation. It may contain personal data, depending on what your application and your test data show.
2.4 Technical data. IP address, browser and device type, timestamps, and error messages in server logs, to secure operations and fix problems. At signup, Cloudflare Turnstile checks whether a request comes from a human; Cloudflare processes technical characteristics of your browser for this.
2.5 Data sent to your AI provider. To run tests, Tessa Cloud transmits scenario steps, screenshots, and screen contents of the application under test to the AI provider your organisation configured with its own API key. That provider is your organisation’s contractor.
2.6 Support and communication. E-mails you write to us, and feedback and bug reports you submit in the product, including the screenshots and context information you attach.
3. Purposes and legal bases
- Providing Tessa Cloud, managing your account and organisation, billing: performance of the contract with your organisation and, where you are not a party to it yourself, our legitimate interest and that of your organisation in providing the service to the invited persons.
- Security, abuse prevention, troubleshooting: our legitimate interest in secure operations.
- Bookkeeping and retention of invoices: legal obligation.
- Information about material changes to the contract documents or the subprocessors: performance of the contract.
We do not use the data from Tessa Cloud for advertising and pass it on only to the recipients named below. Information about the service itself (changes, security, billing) is part of performing the contract.
4. Recipients
Subprocessors according to the list of subprocessors: Hetzner for hosting in Germany and Finland (for Enterprise, per order form, also a data centre in Switzerland), Stripe for billing, Cloudflare for bot protection and delivery. The AI provider and the GitHub or GitLab integrations of your organisation receive data because your organisation engaged them. Authorities receive data only where we are legally obliged.
5. Processing abroad
We process your data in Switzerland and in the EU or EEA. Cloudflare and Stripe may process data in the USA; data processing agreements with the EU standard contractual clauses and the Swiss addendum are in place for this. Where data sent to your AI provider goes is determined by your organisation through its choice of provider and region.
6. Retention
- Account and organisation data and test artifacts: as long as your organisation exists, then following the schedule in the General Terms, section 8: deletion 90 days after the lock. Your organisation can request earlier deletion at any time.
- Invoices and accounting records: 10 years (Art. 958f Swiss Code of Obligations).
- Server logs with IP addresses: at most 90 days, unless they are needed to investigate a security incident.
- Support e-mails: as long as needed to handle and trace your request, at most three years after the last exchange.
7. Your rights
You have the right to access, rectification, deletion, restriction of processing, receipt of your data in a common format (data portability), and objection, to the extent the FADP or the GDPR provide for it. Write to [email protected]; we may ask for proof of identity. If your request concerns data in the test artifacts of an organisation, we forward it to that organisation because it is the controller. You can also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where the GDPR applies, with the supervisory authority of your country.
8. Cookies and tracking
Tessa Cloud uses only technically necessary cookies and browser storage for sign-in and your settings. There is no advertising tracking and no sharing with advertising networks.
9. Changes
This notice carries a version number in the form of a date. We publish changes as a new version; the changelog shows what changed.