Privacy Policy
Tolair, Inc., a Delaware corporation · Kansas City, MO
1. About this policy
Tolair, Inc. (“Tolair,” “we,” “us”) provides governance and operating intelligence software to organizations in healthcare, gaming, hospitality, sports, and dental markets. This policy explains how we handle personal information.
Tolair sells to organizations, not to consumers. We have no consumer product and no self-serve consumer signup. That shapes everything below.
2. Two kinds of data, two different roles
This is the most important section of this policy, because our obligations differ depending on which kind of data is involved.
Data we control. Information about visitors to tolair.org, people who request a demo, and the individuals who administer a customer account with us. We decide how this information is used, and this policy governs it in full.
Data we process for customers. Information our customers connect to the Tolair platform from their own systems. We process this only on the customer’s documented instructions, under our agreement with that customer. We do not decide what it contains or what it is used for.
If your organization uses Tolair and you have a question about data your employer connected to our platform, that organization is the right place to direct it. Their privacy notice governs, and we will support them in responding. Section 9 covers this more fully.
3. Information we collect
Demo requests. Our demo form collects your name, job title, organization, industry, and work email address, plus optionally a phone number and whatever you write about the systems you run today. This information is sent directly to our team by email. It is not written to a database, and it is not added to any advertising or data-broker system.
Account setup and verification. Where a customer organization signs up for an eligible service, we collect a work email address, the organization’s name and identifier (for healthcare organizations, the CMS Certification Number), and the IP address the request came from. We use this to confirm the request is legitimate and that the person is authorized to act for that organization. Verification tokens are short-lived and expire automatically.
Correspondence. If you email us or otherwise contact us, we keep that correspondence so we can respond and maintain a record of it.
Server logs. Our servers record standard technical information: IP address, request time, pages requested, browser and device type, and referring page. We use this to operate the site, diagnose faults, and investigate abuse.
Abuse prevention. We record IP addresses associated with abusive or automated traffic, along with the reason and an expiry time, so we can rate-limit or block them. These records expire automatically.
4. What we do not collect
We want to be specific rather than merely reassuring:
- No third-party analytics or advertising trackers on tolair.org. No Google Analytics, no Google Tag Manager, no advertising pixels, no session-replay tools, no data-broker enrichment.
- No sale of personal information, and no sharing of it for advertising or cross-context behavioral advertising.
- No payment card details. Payments are handled by Stripe. Card numbers go to Stripe directly and never reach Tolair systems.
- No training of machine-learning models on customer data.
5. How we use information
We use the information described above to:
- respond to demo requests and sales enquiries;
- create, verify, and administer customer accounts;
- provide, maintain, secure, and improve our services;
- process payments and manage subscriptions;
- send service and administrative messages;
- detect, investigate, and prevent abuse, fraud, and security incidents; and
- comply with legal obligations.
We do not use information you give us through this website for advertising, and we do not build behavioral profiles.
8. Data retention
We keep information for as long as we need it for the purpose it was collected, and then delete it.
| Data | Retention |
|---|---|
| Demo requests and correspondence | Kept in our business email while there is an active relationship or prospect, then deleted |
| Account and verification records | For the life of the account. Verification tokens expire automatically and are short-lived |
| Abuse-prevention records | Until their expiry timestamp, then deleted automatically |
| Billing records | As required by tax and accounting law |
| Customer platform data | Per the customer agreement. See section 9 |
| Application audit logs | 365 days |
When we delete information it is removed from live systems immediately. Encrypted infrastructure backups persist for a bounded period after that, and we do not surgically edit backups. Deleted information is fully expunged once those backups rotate out.
9. Data our customers connect to the platform
Where a customer organization connects data to Tolair, we act on that organization’s instructions and under our agreement with them, which sets out what we may do with it, how long we keep it, and what happens on termination.
Our architecture reflects that. Some specifics that hold across our platform:
- We access customer systems only through credentials or permissions the customer explicitly grants, and only within limits the customer sets.
- Where we integrate with a customer mailbox, we retrieve message metadata such as sender, recipient, subject, timestamp, and the short preview line the mail provider generates. We do not retrieve message bodies or attachments. This is enforced by how the integration is built rather than by filtering after the fact. Note that a provider-generated preview line is drawn from the start of a message and can contain a fragment of its text.
- Access to customer data is restricted to authenticated, authorized users on a per-user allowlist. There is no anonymous access and no public sign-up.
- Administrative actions and sensitive reads are recorded in an audit trail.
- Customer data is stored and processed in the United States.
Health information. Where our services are used to process health information, that processing is governed by our agreement with the customer organization, including a business associate agreement where one is required. Individuals should direct requests about their health information to their provider.
Requests about customer data. If you believe an organization using Tolair holds information about you, contact that organization directly. If you contact us instead, we will refer you to them and assist them in responding.
10. Your privacy rights
Depending on where you live, you may have the right to:
- know and access the personal information we hold about you;
- correct inaccurate personal information;
- delete personal information;
- opt out of the sale or sharing of personal information for targeted advertising — note that we do not sell or share personal information for advertising, so there is nothing to opt out of;
- limit the use of sensitive personal information; and
- not be discriminated against for exercising any of these rights.
To make a request, email [email protected]. We will verify your identity before acting, which usually means confirming control of the email address associated with the information. You may use an authorized agent.
We do not use personal information collected through this website to make automated decisions that produce legal or similarly significant effects.
If your request concerns data your employer connected to our platform, see section 9. We will route it to the right organization rather than acting unilaterally on their data.
11. Security
Security measures we maintain include:
- encryption of data in transit and at rest;
- no public network path to our application backends;
- authentication required for all access to customer environments, with role-based authorization;
- no long-lived deployment credentials — our deployment pipeline authenticates using short-lived federated credentials scoped to a single repository and branch;
- secrets held in a managed secrets service, never in source control;
- audit logging of administrative actions; and
- separation of customer data by environment and by tenant.
No system is perfectly secure, and we do not claim otherwise. Tolair does not currently hold a SOC 2 or ISO 27001 certification.
12. International users
Tolair operates in the United States and our services are hosted here. If you access the site from outside the United States, your information will be transferred to and processed in the United States, where data protection law may differ from your own.
13. Children
Our services are sold to organizations and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.
14. Links to other sites
Our site links to third-party sites we do not control. This policy does not apply to them, and we are not responsible for their content or privacy practices.
15. Changes to this policy
We may update this policy. When we make material changes we will update the effective date above and, where the change materially affects customers, notify them directly rather than relying on a silent page update.
16. Contact
Tolair, Inc.
Kansas City, MO
[email protected]