Effective and last updated: August 12, 2026
1. Who is responsible
NXO Group Private Limited (“NXO”, “Tez”, “we”, “us”, or “our”) operates Tez from 2nd Floor, Core 1, PACIFICA TECH PARK, Rajiv Gandhi Salai, Navalur, Chennai, Tamil Nadu 600130, India.
We act as the data controller or data fiduciary for information used to operate our website, accounts, subscriptions, security, support, and business. For Customer Content placed in a Tez workspace, the customer organization generally decides why and how that information is used, and we process it on the organization’s instructions as its processor or service provider.
2. Scope
This Policy applies when you visit tezworks.com, create or use a Tez account, join a workspace, contact us, receive communications, connect an integration, or interact with billing and support. It does not govern a third-party service or a customer organization’s independent handling of personal information.
3. Information we collect
Depending on how Tez is used, we may collect:
- Account and profile information: name, business email, password hash, optional phone number, profile details, company, workspace membership, role, and permissions.
- Customer Content: projects, tasks, requests, approvals, chat messages, comments, notes, goals, forms, files, attachments, custom fields, and related activity.
- Billing information: plan, paid-seat quantity, subscription status, transaction and invoice references, billing contact, tax identifiers, and payment status supplied by Paddle. We do not receive or store full payment-card numbers.
- Device, usage, and security information: IP address, browser and device type, operating system, pages and features used, dates and times, session information, audit events, error records, and security signals.
- Support and communications: messages, requests, feedback, and information included when you contact sales, support, billing, legal, or privacy teams.
- Integration information: identifiers, configuration, and content made available when an authorized administrator connects a third-party service.
4. Where information comes from
We receive information directly from you; from your organization and other authorized workspace users; automatically from your browser or device; from integrations you choose to connect; and from service providers such as Paddle that support billing and account administration.
5. How and why we use information
We use personal information to:
- create accounts and provide projects, tasks, requests, approvals, chat, notes, goals, reporting, files, and related workspace functions;
- authenticate users, maintain roles and permissions, prevent abuse, investigate incidents, and secure Tez;
- administer plans, paid seats, subscriptions, invoices, renewals, cancellations, and refunds;
- send service, account, security, billing, invitation, and notification messages;
- provide support, diagnose errors, maintain reliability, and improve usability and performance;
- comply with legal obligations, enforce agreements, establish or defend claims, and protect rights and safety; and
- send marketing communications where permitted, with an unsubscribe option.
6. Legal grounds
Depending on your location and our role, we process information because it is necessary to perform a contract or take requested steps before a contract; for legitimate interests such as operating, securing, supporting, and improving Tez; to comply with law; with consent where required; or to establish, exercise, or defend legal claims.
Where a customer organization controls Customer Content, that organization is responsible for its legal basis, notices, and instructions. If we rely on consent, you may withdraw it without affecting earlier lawful processing.
7. Cookies and device storage
Tez uses essential cookies and similar browser storage for sign-in, session security, active-workspace selection, appearance and interface preferences, and recently used functions. These are necessary to provide the requested service.
We do not use personal information for third-party behavioural advertising and do not sell personal information. If we introduce optional analytics or advertising cookies, we will update this Policy and request consent where required.
8. How we share information
We may share information only as reasonably necessary with:
- authorized members and administrators of the relevant company or workspace;
- service providers supporting cloud hosting, databases, file storage, email delivery, security, monitoring, customer support, and business operations;
- Paddle for checkout, subscription administration, tax, invoicing, fraud prevention, cancellation, and refunds;
- third-party services that an authorized user chooses to connect;
- professional advisers, auditors, insurers, and financing parties under appropriate confidentiality duties;
- government authorities, courts, or others when required by law or necessary to protect rights, safety, and security; and
- a buyer, investor, successor, or affiliate in a merger, financing, reorganization, or sale, subject to appropriate safeguards.
We do not sell Customer Content or personal information.
9. International transfers
Tez and its service providers may process information in India and other countries where they operate. Those countries may have different data-protection laws. Where required, we use appropriate safeguards such as contractual protections, transfer assessments, approved standard contractual clauses, or another lawful transfer mechanism.
10. Retention and deletion
We keep account information and Customer Content while the relevant account or workspace is active and for a reasonable period afterward to support authorized export, recovery, security, dispute resolution, and account closure. Security, audit, support, billing, tax, and transaction records may be kept longer where needed for legitimate business records or required by law.
When information is no longer required, we delete it, anonymize it, or isolate it until deletion is possible. Backup copies are removed through normal backup rotation. Legal holds, fraud prevention, unresolved disputes, and mandatory recordkeeping may delay deletion. Retention criteria include the nature of the data, account status, customer instructions, security needs, limitation periods, and applicable tax and legal requirements.
11. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, tenant and workspace permissions, encryption in transit, credential protection, logging, backups, and incident-response practices. No system can guarantee absolute security. Customers must use appropriate permissions, protect credentials, and promptly report suspected incidents to support@tezworks.com.
12. Your choices and rights
Subject to applicable law, you may have rights to obtain information about processing; access, correct, update, complete, delete, or receive a copy of personal information; restrict or object to processing; withdraw consent; opt out of marketing; and raise a grievance or complaint with a regulator.
For Customer Content controlled by your organization, submit the request to the organization’s administrator first. We will assist the organization where required. For information controlled by NXO, email privacy@tezworks.com. We may verify identity and authority before acting and may retain information where an exception or legal obligation applies.
13. India privacy rights and grievances
Individuals covered by India’s Digital Personal Data Protection framework may request information about processing, correction, completion, updating, or erasure of personal data, withdraw consent where applicable, nominate another person as permitted by law, and use our grievance process.
Send a grievance to our Privacy and Grievance Officer at privacy@tezworks.com. Please describe the concern and the account or organization involved without sending passwords, card details, or authentication codes. We will acknowledge and address the request within the period required by applicable law. You may approach the Data Protection Board of India after using our grievance process where the law permits.
14. Other regional rights
People in the EEA, United Kingdom, and other jurisdictions may have additional rights, including data portability, objection to legitimate-interest processing, restriction, and complaint to a local data-protection authority. Residents of jurisdictions with applicable US state privacy laws may also have rights to know, correct, delete, or receive personal information and to appeal certain decisions. We will not discriminate against anyone for exercising a legal privacy right.
15. Children
Tez is a workplace service intended for adults and organizations. It is not directed to children, and users must be at least 18 years old. If you believe a child has provided personal information, contact privacy@tezworks.com.
16. Updates to this Policy
We may update this Policy to reflect changes to Tez, our practices, or the law. We will post the revised date and give reasonable notice of a material change through Tez, email, or our website where required.
17. Contact
Privacy questions, rights requests, and grievances may be sent to privacy@tezworks.com or by post to: Privacy and Grievance Officer, NXO Group Private Limited, 2nd Floor, Core 1, PACIFICA TECH PARK, Rajiv Gandhi Salai, Navalur, Chennai, Tamil Nadu 600130, India.
