Security
You own every account; we hold access only. Each person who works on your accounts is named, has read-only access wherever the platform allows it, and is removed the day the engagement ends. We hold no certification and claim none; this page states what we do so you can check it.
How we access your accounts
- Your accounts stay yours. Ad accounts, the Business Profile, social pages, the website, the domain and analytics belong to you or your company. We are added as users; we never hold ownership.
- Named users only. Access is given to named people, never a shared login. You can see every user on the platform's own access screen.
- Read-only where possible. Where a platform offers a read-only or reporting role, that is the role we ask for. Editing access is asked for only where the work needs it, and only for the named accountable director.
- Removed on exit. When a person leaves the work or the engagement ends, their access is removed and we confirm it to you in writing.
Where data lives
- Command, our own reporting software, runs on Cloudflare. It holds the figures we report to you, each with its source.
- Inquiries from this site go to Command. If Command cannot take one, a copy is held in a Cloudflare backup store for at most seven days, then removed.
- Email is on our company mailbox (growth@tessmonttechnologies.com); WhatsApp is on the Director's business number.
- The site's code and our file drive hold no inquiry or client personal data.
- The full list, with retention periods, is on the privacy page.
If something goes wrong
Every affected person is told without delay, in plain language: what happened, what it may mean for them, what we are doing and whom to contact. India's Data Protection Board is informed without delay and receives the full report within 72 hours. If your data is involved, you are told the same day, so you can meet your own duties. The procedure is owned by CA Mohammed Baaqar Shariff, with Tasneem Taksali, Director and Brand Director, as deputy. It covers Command, the backup store, our mailbox and email service logs, WhatsApp, the booking tool and backups.
How an engagement ends
- Your reports and the data behind them are exported to you in plain files.
- Our users are removed from every account, and we send you the list of what was removed.
- Your data in Command is deleted on request, and the deletion is confirmed in writing.
Healthcare: the data boundary
This rule is set before our first healthcare client; it is a rule, not a description of past work.
- For healthcare clients, Command holds counts and costs only: spend, inquiries, bookings and cost per inquiry, read from the ad platforms' and the Business Profile's reporting.
- It never holds patient names, phone numbers, message text, appointment details or review text.
- Our inbox, proof and review services are not offered on a patient-facing line.
- No Tessmont pixel, tag or beacon is placed on a patient-facing or signed-in page.
- Ad-account access is read-only where the platform allows it, and limited to the named accountable director.
- Every healthcare engagement letter carries this rule word for word, with a one-page record of what enters Command, who can see it and what is rejected or aggregated, reviewed by a Chartered Accountant (CA Mohammed Baaqar Shariff) before work starts.
- A US clinic that wants us to see appointment or patient records is declined unless a business associate agreement is signed first. None is planned.
Questions from your procurement or IT team
Send them to growth@tessmonttechnologies.com or on WhatsApp at +91 89041 67560, and the Director answers them in writing.