Privacy Policy
Last updated: July 2026
1. Introduction
Tizo Mega Concepts (“Tizo,” “we,” “our,” or “us”) respects the privacy of every visitor, client, partner, and prospective client who interacts with our websites, applications, products, and professional services. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard personal and technical information, and the rights you have with respect to that information. It applies to all Tizo properties, including our marketing website, customer portals, contact forms, hosted applications built on our behalf, and any digital experience where this policy is referenced or linked.
We have written this policy to be readable by non-lawyers while remaining accurate and complete. If any provision is unclear, we encourage you to contact us at the address in Section 18 before providing personal information. By using our services, you acknowledge that you have read and understood this policy and consent to the practices described within it, to the extent permitted by applicable law.
This policy is intended to comply with applicable global privacy regimes, including the European Union General Data Protection Regulation (GDPR), the United Kingdom Data Protection Act, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Personal Information Protection and Electronic Documents Act (PIPEDA), and other equivalent frameworks. Where a specific jurisdiction requires additional disclosures or offers additional rights, those are described in Section 11.
2. Information We Collect
We collect information in three broad categories: information you provide to us directly, information collected automatically through your use of our services, and information received from trusted third parties. We collect only what we need to deliver, secure, improve, and market our services, and we do not sell personal information.
2.1 Personal Information
Personal information is information that identifies, relates to, or can reasonably be linked to an identified or identifiable individual. We may collect the following categories when you interact with us:
- Identity data such as your first and last name, professional title, company name, and, where you choose to provide it, a photograph or avatar.
- Contact data such as email address, phone number, postal address, and preferred communication method.
- Commercial data such as project inquiries, budget ranges, service preferences, engagement history, and invoices we issue to you or your organization.
- Content data such as messages, files, and materials you submit through our forms, email, workspace tools, or during the delivery of professional services.
- Marketing and communications preferences, including opt-in status for newsletters and event invitations.
2.2 Technical Information
When you visit our websites or use our applications, we automatically receive technical information from your browser, device, and network. This includes IP address (which we truncate where feasible), user-agent string, device type, operating system, referring and exit pages, timestamps, session identifiers, and interaction events such as clicks, scrolls, and form submissions. This information is used to operate and secure our services, diagnose issues, prevent abuse, and understand aggregate usage patterns.
2.3 Cookies and Similar Technologies
We use a small number of cookies and equivalent technologies (local storage, session storage, and pixel tags) to keep our services functional, remember your preferences, understand aggregate traffic patterns, and — with your consent where required — measure the performance of our marketing campaigns. You can control cookies through your browser settings and, where applicable, our on-site consent banner. Blocking essential cookies may impair the functionality of certain areas of our site.
2.4 Analytics
We use privacy-respecting analytics tools to understand how visitors discover and use our services. These tools may collect aggregated information such as page views, session duration, geographic region, and device category. Where required by law, analytics is loaded only after you consent through our on-site controls. We do not use analytics data to build advertising profiles about you across other websites.
2.5 Third Party Sources
We may receive limited information from trusted partners such as business enrichment providers, referral partners, event co-hosts, and public professional networks. This information is used only to contextualize inquiries you initiate, or to verify eligibility for services that require it. We do not knowingly acquire personal information from data brokers for advertising purposes.
3. How We Use Information
We use collected information to operate our business, deliver contracted services, communicate with you, protect our infrastructure, and comply with legal obligations. Specifically, we use information to:
- Respond to inquiries and provide requested proposals, quotations, or consultations.
- Deliver and administer professional services engagements, including project management, invoicing, and support.
- Operate, maintain, secure, and improve our websites, applications, and internal tools.
- Prevent, detect, and investigate fraudulent, malicious, or unauthorized activity.
- Send transactional communications such as engagement updates, security notices, and administrative messages.
- With your consent where required, share marketing communications, event invitations, and thought leadership content.
- Meet legal, regulatory, tax, and audit obligations, and enforce our contractual rights.
4. Third Party Services
We rely on carefully selected third-party service providers to help us operate. These include cloud infrastructure providers (for compute, storage, and delivery), email and calendar systems, customer relationship management platforms, invoicing and payment processors, analytics providers, and communications tools. Each provider is bound by contractual data processing terms and is chosen based on security posture, regulatory compliance, and operational reliability. A current list of subprocessors is available on request.
These providers process personal information only under our instructions and for the purposes described in this policy. We do not authorize them to use personal information for their own marketing or profiling activities.
5. Data Storage
Personal information is stored on infrastructure operated by reputable cloud providers with facilities located in the European Union, the United States, and other regions selected for regulatory alignment and operational resilience. Data is stored using industry-standard encryption at rest and is protected by strict access controls, audit logging, and least-privilege administration.
6. Data Protection
We apply a layered security program that combines administrative, technical, and physical safeguards. This includes role-based access control, multi-factor authentication for all administrative access, mandatory encryption in transit and at rest, network segmentation, vulnerability management, structured incident response, employee background checks where lawful, and mandatory security and privacy training. Despite our best efforts, no security program can guarantee absolute protection, and we encourage you to use strong, unique passwords and to keep your own devices up to date.
7. Legal Basis for Processing
Where the GDPR or an equivalent framework applies, we rely on one or more of the following legal bases to process personal information:
- Contract: to negotiate, enter into, and perform contracts with you or your organization.
- Legitimate interests: to run and improve our business, secure our systems, and understand aggregate usage, provided your interests and fundamental rights do not override ours.
- Consent: where you have opted in, such as for non-essential cookies and marketing communications.
- Legal obligation: to comply with applicable laws, tax obligations, and regulatory requests.
8. User Rights
Subject to applicable law, you have the right to request access to the personal information we hold about you, to request correction of inaccurate information, to request deletion where we no longer have a lawful basis to retain it, to restrict or object to certain processing, to receive a portable copy of information you provided to us, and to withdraw consent where processing is based on consent. You may exercise these rights by contacting us using the details in Section 18. We will respond within the timeframes required by applicable law and may need to verify your identity before acting on your request.
9. International Data Transfers
Because we operate globally, personal information may be transferred to and processed in countries outside your country of residence. When we transfer personal information outside the European Economic Area, the United Kingdom, or other regions with data transfer restrictions, we do so under approved safeguards such as Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms. We will only transfer information to countries or providers that offer an adequate level of protection.
10. Children's Privacy
Our services are directed at businesses and are not intended for children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will promptly delete the information from our records.
11. Regional Disclosures
If you are a California resident, you have specific rights under the CCPA/CPRA, including the right to know what personal information we have collected, to request deletion, to correct inaccurate information, and to opt out of the sale or sharing of personal information. We do not sell personal information and do not share it for cross-context behavioral advertising. If you are a resident of the European Economic Area or the United Kingdom, the rights described in Section 8 apply to you in full, and you have the right to lodge a complaint with your local supervisory authority.
12. Marketing Communications
We may send you occasional marketing emails about new services, case studies, and industry insights. Every marketing email includes an unsubscribe link that immediately removes you from future marketing sends. Transactional messages related to an active engagement, security notices, and other administrative communications are not affected by marketing unsubscribes.
13. Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this policy or as required by law. Contact information from prospective clients is generally retained for up to 36 months after the last meaningful interaction. Engagement records, invoices, and contract materials are retained for the duration required by applicable tax and commercial law, typically seven years. Backup copies may persist for a limited period before being securely overwritten.
14. Security Incident Notification
In the unlikely event of a security incident affecting your personal information, we will notify you and, where required, applicable regulators without undue delay, in accordance with the timelines and content requirements of applicable law. Our incident response process includes containment, investigation, remediation, and post-incident review.
15. Automated Decision Making
We do not use personal information to make decisions that produce legal or similarly significant effects on individuals solely through automated means, and we do not engage in profiling for such purposes.
16. Do Not Track
Some browsers offer a “Do Not Track” signal. Because there is no consensus on how such signals should be interpreted, we do not currently respond to them differently from other traffic. You can control cookies and similar technologies through your browser settings and, where applicable, our on-site consent banner.
17. Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, provide a more prominent notice on our website or by email. We encourage you to review this policy periodically.
18. Contact Information
If you have questions about this Privacy Policy, want to exercise a right described above, or need to report a privacy concern, please contact us at privacy@tizomegaconcepts.com. We will do our best to resolve your concern directly. Where you are entitled to do so, you may also contact your local data protection authority.
This document constitutes the full Privacy Policy of Tizo Mega Concepts as of the date shown at the top of this page. All previous versions are superseded and any conflicting statements made in marketing collateral or elsewhere are subordinate to this policy.
