Legal

Legal & trust

Our commitments on privacy, terms of use, and how we keep your data secure.

Privacy policy

Last updated: May 1, 2026

TimFid, Inc. (“TimFid”, “we”) processes data on behalf of our customers as a data processor. This policy explains what we collect, why, and your choices.

Data we process

We process event data that customers send to our ingest API, account information for authorized users, and operational telemetry needed to run the service reliably.

How we use data

Customer event data is used solely to provide the service to that customer. We do not sell personal data, and we do not use customer event data to train third-party models.

Data retention

Retention is configured per plan and per dataset. Customers may request deletion of their data at any time, subject to legal retention obligations.

Terms of service

Last updated: May 1, 2026

These terms govern your access to and use of the TimFid platform. By accessing the service through a provisioned organization account, you agree to these terms on behalf of your organization.

Accounts

Access is granted to authorized users of approved organizations. You are responsible for safeguarding your credentials and for all activity under your account. Accounts are not available for self-service registration.

Acceptable use

You agree not to misuse the service, including attempting to probe, scan, or test the vulnerability of any system without authorization, or to access data that does not belong to your organization.

Availability

Enterprise plans include a 99.99% uptime SLA. Scheduled maintenance is announced in advance on our status page.

Security

Security is foundational to everything we build.

  • Compliance. SOC 2 Type II and ISO 27001. Reports available to Enterprise customers under NDA.
  • Encryption. TLS 1.2+ in transit; AES-256 at rest.
  • Access control. SSO/SAML, SCIM provisioning, and granular role-based access.
  • Isolation. Per-tenant data isolation with strict authorization checks on every request.
  • Disclosure. Report a vulnerability through our contact page; we respond within one business day.