Privacy Policy
Last updated October 2026
This policy describes how TerraSecure handles personal data through ServiQ (serviq.terrasecure.co), a service management platform offering service ticketing, an asset inventory, and a password vault to organizations (“Customers”) and their users. If your organization uses ServiQ, your employer is typically the data controller for your account and content, and TerraSecure processes it on their behalf to provide the service.
Information we collect
Account and profile information
Name, work email, and optionally phone number, job title, department, and location — provided when an administrator invites you or you complete signup.
Content you create
Tickets, comments, attachments, knowledge articles, change and problem records, and asset records. Password vault entries are content too, but are encrypted — see Security — and TerraSecure cannot read them.
Usage and log data
Sign-in activity, and an audit trail of security-relevant actions (role changes, sharing, permission changes) scoped to your organization.
Billing information
Subscription plan and status. Card and payment details are collected and processed directly by our payment processor, Stripe — ServiQ does not receive or store your card number.
How we use it
- To operate the service: authenticate you, enforce the access controls your administrator configures, and store and display your organization's content.
- To send transactional notifications you'd expect from a service desk — ticket updates, approval requests, SLA alerts — and account notices like email verification, security alerts, and billing status.
- To maintain security: audit logging, abuse prevention, and the password vault's breach-check against Have I Been Pwned (see Security for how that's done without exposing your password).
- To provide support when you contact us, or when your administrator asks TerraSecure staff to assist (logged as organization view — see Security).
We don't sell personal data, and we don't use your organization's content to train models.
Who we share it with
ServiQ relies on a small number of subprocessors to operate, each bound by their own data protection commitments:
- Stripe — payment processing and billing.
- Resend — delivery of transactional email (notifications, verification links, reminders).
- Railway — application hosting and database infrastructure.
- OpenAI — only if your organization uses optional AI-assisted features (e.g. response suggestions); ticket content relevant to that request is sent to generate the suggestion.
We don't share personal data with advertisers or data brokers, and we don't run third-party advertising or analytics trackers on ServiQ.
Data retention & deletion
Your organization's data is retained for as long as the subscription is active. If a subscription is canceled, the organization enters a 30-day recovery window — reactivating restores full access — after which data is permanently deleted. Administrators can export ticket and report data as CSV at any time from within the product. Deleting an individual account (rather than the organization) preserves the historical records — tickets, comments, audit entries — that reference it, consistent with the audit and support purposes described above.
Cookies
ServiQ sets one cookie that matters: a signed, httpOnly session cookie used to keep you signed in. We don't use third-party advertising or cross-site tracking cookies.
Your rights
If your organization's data protection framework (e.g. GDPR or CCPA) gives you rights to access, correct, export, or delete your personal data, start with your organization's administrator, who controls your account. If you're an administrator or need to reach us directly, email legalops@terrasecure.co.
Children
ServiQ is a business product. It isn't directed at, and we don't knowingly collect information from, children.
Changes to this policy
If we make a material change to how we handle personal data, we'll update the date at the top of this page and, where appropriate, notify organization administrators.
Contact
Questions about this policy: legalops@terrasecure.co.