Legal

Privacy policy

Last updated 2026-08-13

Who we are

Tessio is operated by Triple Down AB, a Swedish company (org. no. 559333-6091, VAT no. SE559333609101, registered address Skeppargatan 55, 114 59 Stockholm). We are the data controller for the processing described on this page. You can reach us at hello@tessio.eu.

This policy covers tessio.eu, labs.tessio.eu and the Tessio.Cloud dashboard and API at cloud.tessio.eu and api.tessio.eu.

The short version

The product is built so that identity data never reaches us. An age check returns a yes or no proved from the EU Digital Identity Wallet, and the credential involved carries no name, no date of birth, no document number and no portrait. What remains is ordinary operational data: your account email, our correspondence and aggregate website statistics.

Website visitors

Our websites use self hosted, cookieless analytics (Umami, running on our own EU infrastructure). It records aggregate page statistics and does not build visitor profiles, use cookies or share data with third parties. Legal basis: our legitimate interest in understanding how the sites are used.

If you email us, we keep the correspondence for as long as the conversation is relevant. Legal basis: legitimate interest.

Tessio.Cloud accounts

If you have a dashboard account we process your email address and password (stored as an Argon2id hash; we never see the plaintext), plus an audit log of administrative actions in your organisation. Legal basis: performance of the contract with you or your employer. We keep this data for as long as the account exists.

People who complete an age check

If you proved your age to one of our customers through Tessio: we received no name, no date of birth, no document number and no photo. The credential your wallet presented contains age booleans and nothing else, and you approved exactly what was disclosed on your own device.

What we hold afterwards is the outcome (a yes or no), a reference chosen by the customer and timestamps. We process this on the customer’s behalf as their processor, under a data processing agreement. For questions about a specific check, the customer you verified with is the controller and your first point of contact.

Where data lives, and who else touches it

Everything runs on servers in Helsinki, Finland (Hetzner), inside the EU, over TLS. We list the few external services we use, and the conditions, on the subprocessors page. We do not sell or share personal data with anyone for their own purposes.

How long we keep things

Account data lives as long as the account. Check outcomes belong to the customer and follow their account. Backup copies expire within 14 days. If you ask us to delete your data, we do, and the deletion reaches backups as they expire.

Your rights

Under the GDPR you can ask for access, correction, deletion, restriction and portability, and you can object to processing based on legitimate interest. Write to hello@tessio.eu and we will answer within a month. You can also complain to the Swedish supervisory authority, Integritetsskyddsmyndigheten (imy.se), or to your local authority.

We do not use automated decision making or profiling in our own processing. An age check itself is automated, but it happens on the instructions of the customer you verified with, and its only output is the yes or no you approved in your wallet.

Related: cookies · subprocessors · security · terms · questions to hello@tessio.eu