Privacy Policy
Effective 15 July 2026. This policy describes how TUCE MSP ("TUCE," "we") handles information on msp.tuce.app and related managed-IT services. For security posture and enterprise trust signals, see our Trust Center.
1. Who we are
TUCE MSP provides business network assessments, modernization projects, and fully managed IT retainers. Active contact mailboxes (IONOS): privacy@tuce.app · security@tuce.app · compliance@tuce.app.
2. Information we collect
Hard rule - no client content data. Automation and agents collect log-level operational signals only (errors, health thresholds, heal actions, debugging metadata). We do not collect or upload customer files, documents, emails, database rows, share paths, or PHI.
- Registration & billing: company contact fields you enter, payment status (Stripe processes cards - we do not store full card numbers).
- Ops telemetry (assessment / RMM): hostname/OS class, disk free %, service up/down, health warn codes, counts - for error, heal, and debug automation only (
data_scope=ops_logs_only). - Local encrypted storage (endpoint): agent config and topology cache stay on the customer host as
agent_config.enc/topology.enc(Windows DPAPI or openssl AES). Plaintext config is removed after first run. - Portal & ops: role accounts, MFA status, change-control / terms acknowledgments, remote-session metadata (not desktop content).
- Platform logs: IP, user-agent, timestamps, TLS metadata for security and abuse prevention.
3. How we use information
To quote infrastructure work, detect failures, run heal/debug automation, secure the platform, and meet legal obligations. We do not sell personal information. We do not use customer content for training or marketing analytics.
4. HIPAA & healthcare customers
If you are a Covered Entity or Business Associate under HIPAA and TUCE will create, receive, maintain, or transmit Protected Health Information (PHI) on your behalf, we will execute a Business Associate Agreement (BAA) before PHI is intentionally processed.
- msp.tuce.app marketing pages and the standard $999 assessment are designed for IT infrastructure inventory, not for uploading ePHI.
- Do not paste patient identifiers, clinical notes, or medical images into registration fields, network notes, or tickets.
- TUCE does not claim "HIPAA certification," HITRUST certification, or SOC 2 Type II attestation on this website alone. Compliance readiness and BAA-backed services are contracted separately - see /trust and /security.
- Request a BAA: compliance@tuce.app.
5. Sharing
We share data with processors needed to run the service (e.g. hosting, TLS certificates, payment processors, email) under contracts that require appropriate safeguards. We may disclose information if required by law or to protect rights and safety.
6. Retention
Project, quote, acknowledgment, and inventory records are retained for the engagement and as required for legal, tax, and security purposes, then deleted or archived per schedule. Locked backup images under customer contracts follow the retention in that SOW.
7. Security
We use HTTPS/TLS, access controls, MFA on portal roles, change-control logging, and least-privilege engineer access. No method of transmission is 100% secure; report issues to security@tuce.app or see security.txt.
8. Cookies & similar tech
Essential cookies/session tokens may be used for auditor console login and portal continuity. We do not use third-party advertising trackers on msp.tuce.app. See Trust Center for third-party request posture.
9. Your rights
Contact privacy@tuce.app to access, correct, or request deletion of personal data we hold, subject to legal retention and contract needs. California/other state rights honored where applicable.
10. Children
Services are for business customers - not directed to children under 16.
11. Changes
We may update this policy; the effective date above will change. Material changes for retainers are communicated at renewal where required.