T&T Compliance Shield Privacy Policy
Privacy, Data Handling, Retention, And Customer Requests
We keep guided reviews controlled.
Do not send sensitive applicant, employee, medical, payroll, Social Security numbers, bank/payment, government-ID, background-check, immigration, protected-class demographic, biometric, credential, production access, or confidential legal communications unless a separate written agreement authorizes that data before receipt.
Customer records require verified workspace access. Workspace-backed access requires user authentication, workspace permissions, active unexpired membership, signed scope where restricted business data is involved, and approved retention/deletion controls.
Expired or revoked users cannot view customer records. Restricted business documents require signed SOW/DPA scope, private storage, no-Tier-3 acknowledgment, and a written retention/deletion path before intake.
We do not use customer review files to train AI models. We do not sell, rent, or trade personal information.
1. Overview
This Privacy Policy explains how T&T Compliance Shield LTD collects, uses, stores, shares, and deletes information related to its website, AegisReview workflow, guided reviews, and customer communications.
AegisReview is designed to begin with company-level and tool-level information. Restricted business documents are accepted only under signed scope. Sensitive person-level data is outside the standard workflow. This Privacy Policy is part of, and subject to, the T&T Compliance Shield Terms of Service, including its disclaimers, limitations of liability, and dispute-resolution provisions.
2. Information Collected
Intake information: name, work email, phone if provided, company, website, role, Illinois hiring exposure, urgency, known HR or hiring tools, and message content.
Review information: company context, public scan findings, known tools, documentation gaps, customer-approved notes, Snapshot records, report templates, notice scaffolding, workflow status, assignments, and review dates.
Portal and workspace information: user account, workspace membership, permissions, activity events, file metadata, and review status where workspace-backed access is enabled.
Technical information: IP address, browser/device information, page visits, timestamps, form submission metadata, security logs, analytics, and diagnostic data.
3. Information Not To Submit Without Written Scope
Do not submit applicant resumes, employee files, Social Security numbers, driver's license numbers, government IDs, medical information, payroll records, bank/payment data, background-check reports, immigration documents, protected-class demographic data, biometric data, passwords, API keys, production credentials, or confidential legal communications unless a separate written agreement specifically authorizes that data before receipt. Submissions made in violation of this Section are the submitter's sole responsibility, as further stated in the Terms of Service and the Data Processing Addendum, and Provider may reject, quarantine, delete, or return such submissions without liability.
4. Data Tiers
Tier 1 includes standard company-level and tool-level review data.
Tier 2 includes restricted business documents such as vendor AI documentation, vendor contracts, internal HR process documents, vendor security materials, or non-public ATS screenshots. Tier 2 requires signed scope, named access, approved storage, and a 30-day maximum retention period by default.
Tier 3 includes sensitive or regulated applicant, employee, biometric, protected-class, privileged, credential, government ID, financial, medical, payroll, or raw HR dataset materials. Tier 3 is not accepted in the standard workflow. Provider does not request, collect, capture, analyze, derive, extract, purchase, receive through trade, or otherwise obtain biometric identifiers or biometric information, as defined in the Illinois Biometric Information Privacy Act (740 ILCS 14), in the standard workflow, including faceprints, voiceprints, hand or finger geometry, or biometric templates from interview recordings, video files, audio files, photographs, screenshots, or other media. Any file or media containing biometric identifiers, biometric information, interview recordings, voice recordings, facial images intended for recognition, or material from which such identifiers or information could be derived is Tier 3 data and is prohibited unless a separate attorney-approved Tier 3 agreement is executed before receipt. For all purposes, the Tier 1, Tier 2, and Tier 3 definitions in Section 2 of the Data Processing Addendum govern.
5. Use Of Information
Provider uses information to respond to inquiries, run guided reviews, organize hiring-tool facts, prepare review files, create reports and template scaffolding, maintain workflow status, operate and secure the service, communicate with customers, and improve product reliability.
Provider will not sell Customer data and will not use Customer data, Customer review files, submitted materials, or deliverables to train AI models unless Customer separately agrees in a signed writing. These restrictions do not limit the next sentence. Provider may create, retain, and use aggregated, anonymized, or de-identified information that does not identify any customer or individual, for any lawful business purpose, including service operation, improvement, benchmarking, and analytics. Provider will not intentionally re-identify aggregated, anonymized, or de-identified information, and will not authorize any third party to do so, except to test or verify de-identification controls or as required by law.
6. Sharing
Provider may share information with service providers that support hosting, forms, email, scheduling, storage, payments, support, analytics, security, or productivity tools.
Provider may share information with attorneys, HR consultants, or advisors only when requested or approved by Customer, or when necessary under an applicable agreement.
Provider may disclose information when required by law, subpoena, court order, or valid government request. Provider may also disclose information: (a) to enforce its agreements, protect its rights, property, or safety or that of others, and detect or prevent fraud or security issues; and (b) to an actual or prospective acquirer, successor, or assignee in connection with a merger, acquisition, financing, reorganization, or sale of all or part of Provider's business or assets, subject to this Privacy Policy.
7. Storage And Access
Workspace-backed records require authenticated access, approved workspace membership, active permissions, and access controls.
Restricted business documents require signed written scope and private storage before intake.
Trial or launch access may be time-bound, workspace-specific, and revocable.
8. Retention And Deletion
Provider retains information only as long as reasonably needed for requested services, business records, customer support, dispute prevention, legal obligations, security, or the applicable SOW.
Tier 2 restricted business documents are retained for no more than 30 days after receipt by default unless a different written scope is approved before receipt.
Customers may request deletion by emailing the contact address below. Provider may retain limited records where required for legal, payment, security, dispute, or business-record reasons. Provider may retain aggregated, anonymized, or de-identified information indefinitely.
9. Security
Provider uses reasonable administrative, technical, and organizational safeguards designed for the service scope, including workspace isolation, private storage for approved restricted documents, limited access, review boundaries, and security logging where available.
No internet service or electronic storage method is completely secure. Provider reduces risk by limiting requested data and blocking Tier 3 data from the standard workflow. This Section describes safeguards and is not a warranty or guarantee. Provider's security commitments are limited to those expressly stated in a signed agreement.
10. Customer Choices
Customers may request access, correction, export, or deletion of contact and review information, subject to legal, security, payment, dispute, and operational limits. Provider may require reasonable verification of the requester's identity and authority before acting on any request, may decline requests where retention is permitted or required, and will respond within the time required by applicable law. No default, nonpayment, retention exception, or export limitation permits Provider to refuse a legally mandatory return, deletion, access, or security action to the extent applicable law prohibits refusal.
Customers may opt out of marketing communications by replying unsubscribe or emailing the contact address below.
11. Cookies And Analytics
The website may use cookies, local storage, analytics, and similar technologies to operate forms, remember workspace state, understand site usage, and improve the product.
12. Changes
Provider may update this Privacy Policy as the product, law, vendors, or customer workflows change. The effective date will be updated when material changes are made. For material changes, Provider will post the updated Policy and, where an email address is on file, send notice at least thirty (30) days before the updated effective date; material changes apply prospectively only. Terms applicable solely to optional new functionality apply when Customer first uses that functionality. For website visitors or other persons for whom Provider has no email address on file, posting the updated Privacy Policy on the website is the only required notice. Continued use of the website or services after the updated effective date constitutes acceptance of the updated Privacy Policy.
13. Disputes
Any dispute arising from or related to this Privacy Policy is governed by Section 14 of the Terms of Service, including the certified-mail notice-of-default requirement, the thirty (30) day cure period (with limitations periods tolled as stated in the Terms of Service), non-binding mediation in Chicago, Illinois, final and binding AAA arbitration in Chicago before a single arbitrator if not resolved within forty-five (45) days after the mediation demand, the rule that, to the maximum extent permitted by law, each party bears its own attorneys' fees, expert fees, and costs and its share of arbitration fees as allocated under the applicable rules, the class-action, consolidated-arbitration, representative-action, and jury-trial waivers, the poison-pill severability rule for class or consolidated arbitration, and the one (1) year claim-notice bar. For avoidance of doubt, the fee-allocation carve-outs and savings language in Section 14.3 of the Terms of Service control here and are incorporated by reference. Total recovery is capped at the greater of one thousand U.S. dollars (US $1,000) or the amounts actually paid by Customer to Provider for the applicable service. For any claim arising in whole or in part from a trial, preview, launch, beta, experimental, or evaluation feature, the one hundred U.S. dollar (US $100) cap in Section 10 of the Terms of Service applies to the portion of the claim arising from that feature, supersedes any higher cap in this Privacy Policy for that portion, and does not stack with any other cap. Nothing in this Privacy Policy or the incorporated Terms of Service limits liability for a party's gross negligence, willful misconduct, or fraud, or any other liability that cannot be limited under applicable law.
14. Contact
Privacy requests may be sent to tony@ttcomplianceshield.com.
T&T Compliance Shield LTD. Website: ttcomplianceshield.com. Formal legal notices, including notices of default, must follow the notice provisions of the Terms of Service and be sent by certified mail, return receipt requested, to: T&T Compliance Shield LTD, Attn: Legal, [Provider notice address].