Privacy Policy

Last updated: June 18, 2026

Privacy is the reason Tirmira exists, so this policy is written to be read. It names every company that touches your data, where it lives, and for how long.

1. Who is responsible

The Service is operated by Slim Labbane Dit Kalti, sole proprietor ("we"). Contact for all privacy matters: hello@tirmira.com.

For the business documents you upload, you (or your company) remain the data controller and we act as a processor on your instructions, under our Data Processing Agreement — countersigned copy available on request.

2. What we collect

3. How your documents are processed — and by whom

Every processor we use, in full:

No US company processes your documents at any step.

4. What we never do

5. Retention and deletion

6. Legal bases (GDPR)

We process data to perform our contract with you (Art. 6(1)(b) GDPR), to comply with legal obligations (Art. 6(1)(c)), and for our legitimate interest in securing the Service (Art. 6(1)(f)).

7. Your rights

You may request access, correction, deletion, restriction, or portability of your personal data, and object to processing, by emailing hello@tirmira.com. We respond within 30 days. You may also lodge a complaint with your local data protection authority.

8. Security

All transfers are encrypted in transit (TLS). Analyses are encrypted at rest (AES-256-GCM) — honestly stated: this protects against theft of the database, not against a full compromise of the server itself. Documents are processed in isolation under unguessable identifiers and removed on schedule. Access to production systems is limited to the Operator. Passwords are hashed with argon2id and never stored in clear.

9. Cookies

The website sets no advertising or analytics cookies. Only functional cookies strictly necessary for checkout (Paddle) are used.

10. Changes

Material changes to this policy will be announced on this page and, for customers, by email at least 14 days in advance.