Privacy Policy

This Privacy Policy explains how Tectura and its affiliated companies, branches, and related entities (“Tectura”, “we”, “us”, or “our”) collect, use, store, share, transfer, and protect personal data when you interact with us, use our websites, subscribe to our communications, attend our events, contact our teams, apply for employment, or engage with us as a customer, supplier, partner, or business contact.

Tectura operates across multiple jurisdictions. We process personal data in accordance with applicable data protection and privacy laws, which may include, where applicable, the EU General Data Protection Regulation (“GDPR”), UK data protection laws, Taiwan Personal Data Protection Act, Hong Kong Personal Data (Privacy) Ordinance, Mainland China Personal Information Protection Law, Japan Act on the Protection of Personal Information, Singapore Personal Data Protection Act, Malaysia Personal Data Protection Act, India Digital Personal Data Protection Act, and other relevant local privacy laws.

This Privacy Policy is intended to provide a general explanation of our data processing practices. Where local law requires additional disclosures, consent, procedures, or rights, we will comply with those local requirements.

1. Who is responsible for your personal data?

The Tectura entity that determines the purpose and method of processing your personal data will generally be the data controller, personal information handler, data user, data fiduciary, or equivalent responsible party under applicable law.

Depending on your location and relationship with us, the responsible Tectura entity may be the local Tectura company or affiliate with which you interact. For privacy-related inquiries, you may contact us using the contact information provided at the end of this Policy.

2. What personal data do we collect?

We may collect and process the following categories of personal data:

  • Contact information, such as your name, business email address, phone number, company name, job title, department, and business address.
  • Business relationship information, such as your company, industry, business needs, communication history, event participation, meeting records, and service interests.
  • Account and service information, such as login credentials, user account details, service requests, support tickets, project records, billing information, and contract-related information.
  • Marketing and communication information, such as newsletter subscriptions, email engagement, event registrations, webinar participation, content downloads, survey responses, and communication preferences.
  • Website and technical information, such as IP address, browser type, device type, operating system, pages viewed, referring pages, downloaded resources, cookies, tracking pixels, log files, and similar online identifiers.
  • Recruitment information, such as your resume, employment history, education, qualifications, references, interview notes, and information submitted during the recruitment process.
  • Supplier and partner information, such as contact details, payment-related information, contract information, and service delivery records.
  • Other information you voluntarily provide to us through forms, emails, phone calls, meetings, events, surveys, or other interactions.

We generally do not seek to collect sensitive personal data unless it is necessary for a specific lawful purpose, required by law, or provided by you voluntarily. Sensitive personal data may include information relating to health, biometric data, precise location, religious or political beliefs, criminal records, or other categories protected under applicable law. Where required, we will obtain your explicit consent or rely on another lawful basis permitted by local law.

3. How do we collect personal data?

We may collect personal data directly from you when you:

  • Submit a form on our website.
  • Subscribe to newsletters or marketing communications.
  • Register for webinars, workshops, or events.
  • Download white papers, reports, product information, or other resources.
  • Contact us by email, phone, website form, social media, or other channels.
  • Enter into a contract or business relationship with us.
  • Apply for a job.
  • Visit our website or interact with our digital content.

We may also collect personal data from other sources, including:

  • Tectura affiliates and related entities.
  • Public websites, company websites, public registries, and professional directories.
  • Social media platforms, such as LinkedIn, where the information is publicly available or provided by you.
  • Business partners, vendors, service providers, event organizers, and data providers.
  • Existing customers, suppliers, employees, contractors, or other business contacts.
  • Public authorities or other sources where permitted by law.

4. Why do we use personal data?

We may use your personal data for the following purposes:

  • To respond to your inquiries and provide requested information.
  • To deliver products, services, consulting, support, implementation, and project-related communications.
  • To manage customer, supplier, partner, and business relationships.
  • To process contracts, proposals, quotations, invoices, payments, and service records.
  • To organize webinars, workshops, campaigns, events, and follow-up communications.
  • To send newsletters, marketing emails, event invitations, product updates, and business communications, where permitted by law.
  • To manage our CRM database and understand customer interests, engagement, and business needs.
  • To personalize website experience and improve our website, content, campaigns, and services.
  • To conduct analytics, reporting, market research, surveys, and campaign performance measurement.
  • To process job applications and manage recruitment activities.
  • To maintain information security, prevent fraud, monitor system performance, and protect our legal rights.
  • To comply with legal, regulatory, accounting, audit, tax, contractual, and compliance obligations.
  • To support business transactions, such as mergers, acquisitions, restructuring, or transfer of assets.
  • For other purposes disclosed to you at the time of collection or otherwise permitted by applicable law.

5. What legal bases do we rely on?

Depending on the applicable law and the purpose of processing, we may rely on one or more of the following legal bases:

  • Your consent, where required by law or where you have voluntarily agreed to the processing.
  • Performance of a contract, such as providing services, support, or responding to a request before entering into a contract.
  • Compliance with legal obligations, such as tax, accounting, regulatory, employment, or audit requirements.
  • Legitimate interests, such as B2B relationship management, service improvement, information security, direct business communications, and marketing to relevant business contacts, provided that such interests are not overridden by your rights and interests.
  • Protection of vital interests, such as emergency situations.
  • Other legal bases permitted under applicable local laws.

Where we rely on consent, you may withdraw your consent at any time. Withdrawal of consent will not affect processing that occurred before the withdrawal.

Where local law requires separate or explicit consent, such as for certain marketing activities, sensitive personal data, cookies, data sharing, or cross-border transfer, we will seek such consent where applicable.

6. How do we use personal data for marketing?

Tectura is a B2B technology and consulting service provider. Most personal data used for marketing relates to employees, representatives, or business contacts of customers, prospects, partners, suppliers, and other organizations.

We may use personal data to:

  • Send newsletters, event invitations, webinar follow-ups, product updates, thought leadership content, and service-related marketing communications.
  • Manage leads and customer relationships in our CRM systems.
  • Understand your business interests based on website visits, email engagement, event participation, content downloads, or previous interactions with Tectura.
  • Measure and improve marketing campaign performance.
  • Build audience segments for relevant B2B communications, where permitted by law.

Our marketing emails may include tracking technologies that help us understand whether an email was opened, whether links were clicked, and which content may be relevant to you. You may opt out of marketing emails at any time by using the unsubscribe link in our emails or by contacting us.

If you opt out, we may retain limited information necessary to record your preference and ensure that we do not send further marketing communications to you.

7. How do we use cookies and similar technologies?

Our websites may use cookies, pixels, tags, scripts, log files, analytics tools, advertising technologies, and similar tracking technologies to:

  • Enable necessary website functions.
  • Remember your preferences.
  • Analyze website performance and user behavior.
  • Understand content engagement and campaign performance.
  • Support marketing, remarketing, and advertising activities.
  • Improve website usability, security, and relevance.

Depending on your location, we may request your consent before placing non-essential cookies on your device. You may manage your cookie preferences through our cookie banner, browser settings, or other available preference tools.

For more details, please refer to our Cookie Policy, where available.

8. Do we share personal data with third parties?

We may share personal data with the following categories of recipients where necessary and permitted by law:

  • Tectura affiliates, branches, and related entities.
  • IT, cloud hosting, CRM, marketing automation, analytics, email delivery, event management, and support service providers.
  • Professional advisors, such as auditors, lawyers, accountants, consultants, and insurers.
  • Business partners, subcontractors, implementation partners, and technology vendors involved in service delivery.
  • Payment, billing, finance, and administrative service providers.
  • Public authorities, regulators, courts, law enforcement agencies, or government bodies where required by law.
  • Third parties involved in a potential or actual merger, acquisition, restructuring, sale of assets, or similar business transaction.
  • Other parties where you have provided consent or where disclosure is otherwise permitted by applicable law.

We require service providers and business partners that process personal data on our behalf to use appropriate security and confidentiality measures and to process personal data only for authorized purposes.

9. International data transfers

Because Tectura operates across multiple countries and uses global technology systems, your personal data may be transferred to, stored in, accessed from, or processed in countries or regions outside your location.

Where we transfer personal data internationally, we will take appropriate steps to protect your data in accordance with applicable law. These measures may include:

  • Intra-group data protection arrangements.
  • Data processing agreements.
  • Standard contractual clauses or equivalent transfer mechanisms.
  • Security assessments, certifications, or standard contracts where required.
  • Technical and organizational security measures, such as access controls, encryption, logging, and data minimization.
  • Additional consent or notification where required by local law.

For personal data originating from the European Economic Area, United Kingdom, or Switzerland, we will use appropriate safeguards where required, such as adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms.

For personal information originating from Mainland China, Japan, Taiwan, Singapore, Malaysia, India, Hong Kong, or other jurisdictions with cross-border transfer requirements, we will follow applicable local requirements, which may include notification, consent, contractual safeguards, security assessments, or transfer restrictions.

10. How do we protect personal data?

We apply appropriate technical and organizational measures designed to protect personal data against unauthorized access, unlawful processing, accidental loss, destruction, alteration, disclosure, or damage.

These measures may include:

  • Access control and role-based permissions.
  • Encryption or secure transmission where appropriate.
  • System monitoring, logging, and security testing.
  • Data backup and recovery procedures.
  • Vendor security review and contractual controls.
  • Employee confidentiality obligations and training.
  • Internal policies for data handling, retention, and incident response.
  • Measures to prevent unauthorized alteration, loss, leakage, or misuse of personal data.

No system can be guaranteed to be completely secure. However, we take reasonable steps to protect personal data according to the nature of the data, processing risks, and applicable legal requirements.

11. How long do we keep personal data?

We retain personal data only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.

Retention periods may depend on:

  • The duration of our relationship with you or your organization.
  • The period required to provide services, support, or account access.
  • Legal, tax, accounting, audit, contractual, or regulatory requirements.
  • The need to resolve disputes or enforce agreements.
  • Your marketing preferences and unsubscribe records.
  • Security, fraud prevention, or compliance needs.

When personal data is no longer needed, we will delete, anonymize, or securely retain it in accordance with applicable retention procedures.

12. Your privacy rights

Depending on your location and applicable law, you may have the right to:

  • Request access to your personal data.
  • Request a copy of your personal data.
  • Request correction of inaccurate or incomplete personal data.
  • Request deletion of your personal data.
  • Request restriction of processing.
  • Object to certain processing activities.
  • Withdraw consent where processing is based on consent.
  • Request data portability.
  • Opt out of marketing communications.
  • Object to or limit certain automated decision-making or profiling, where applicable.
  • Lodge a complaint with a relevant data protection authority.

These rights may be subject to legal limitations, exceptions, identity verification, and local procedures. To exercise your rights, please contact us using the contact information below.

13. Region-specific privacy notes

13.1 European Economic Area, United Kingdom, and Switzerland

If GDPR, UK GDPR, or similar laws apply, we will process your personal data according to applicable data protection principles, including lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.

You may have rights to access, rectify, erase, restrict, object to processing, request data portability, withdraw consent, and lodge a complaint with a supervisory authority.

Where personal data is transferred outside the EEA, UK, or Switzerland, we will use appropriate safeguards where required.

13.2 Taiwan

Where Taiwan law applies, we will collect, process, and use personal data for specific purposes and within the necessary scope. We will provide required notices, including the name of the collecting entity, purpose of collection, categories of personal data, period, area, recipients, method of use, data subject rights, and the impact of not providing data where required.

You may have rights to inquire, review, request a copy, supplement or correct, request cessation of collection, processing or use, and request deletion of your personal data, subject to applicable exceptions.

13.3 Hong Kong

Where Hong Kong law applies, we will handle personal data in accordance with the Personal Data (Privacy) Ordinance and its Data Protection Principles, including requirements relating to collection, accuracy, retention, use, security, openness, access, and correction.

Where direct marketing rules apply, we will provide required notices and opt-out mechanisms.

13.4 Mainland China

Where Mainland China law applies, we will process personal information in accordance with applicable requirements, including principles of legality, legitimacy, necessity, good faith, transparency, purpose limitation, data minimization, security, and accountability.

Where required, we will provide specific notices, obtain consent or separate consent, conduct personal information protection impact assessments, implement cross-border transfer mechanisms, and comply with requirements for sensitive personal information, minors’ personal information, and overseas transfers.

13.5 Japan

Where Japan law applies, we will handle personal information in accordance with the Act on the Protection of Personal Information and applicable guidelines. We will specify purposes of use, manage personal data securely, respond to applicable data subject requests, and follow requirements for third-party provision and cross-border transfer where applicable.

13.6 Singapore

Where Singapore law applies, we will comply with applicable obligations under the Personal Data Protection Act, including consent, purpose limitation, notification, access and correction, accuracy, protection, retention limitation, transfer limitation, and accountability obligations.

13.7 Malaysia

Where Malaysia law applies, we will comply with applicable requirements under the Personal Data Protection Act 2010, including the personal data protection principles relating to notice and choice, disclosure, security, retention, data integrity, access, and transfer.

13.8 India

Where India law applies, we will process digital personal data in accordance with applicable requirements under the Digital Personal Data Protection Act and related rules, including notice, consent or permitted use, data principal rights, grievance handling, security safeguards, breach notification, and cross-border transfer requirements where applicable.

14. Third-party websites and services

Our websites may contain links to third-party websites, platforms, applications, plug-ins, or services. These third parties may collect or process personal data according to their own privacy policies.

We are not responsible for the privacy practices, security, or content of third-party websites or services. We encourage you to review their privacy policies before providing personal data or using their services.

15. Children’s personal data

Our websites, services, and marketing activities are generally intended for business users and are not directed to children. We do not knowingly collect personal data from children unless permitted by law and necessary for a specific service or activity. Where local law requires parental or guardian consent for children’s personal data, we will obtain such consent where applicable.

16. Automated decision-making and profiling

We may use analytics, CRM segmentation, marketing automation, and similar tools to better understand business interests and improve communications. These activities are generally used for B2B marketing and service improvement.

We do not use personal data to make decisions that produce legal or similarly significant effects on individuals solely by automated means, unless clearly disclosed and permitted by applicable law.

17. Updates to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our business, legal requirements, technology, or data processing practices. The updated version will be posted on our website with a revised “Last updated” date.

18. Contact us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or want to opt out of marketing communications, please contact us at:

Tectura Email: in.information@tectura.com

If required by applicable law, we will respond to your request within the legally required timeframe.