Privacy Policy
How Tantreak Design LLC handles information across our website, assessments, client administration, tenant-isolated CRM workspaces and client-controlled Meta and WhatsApp connections.

Policy details
Read how Tantreak Design handles this policy area and contact us if you need clarification.
Scope and who we are
Tantreak Design LLC operates tantreakdesign.com and provides business software that may be made available through product domains including doc.tantreakdesign.com and arch.tantreakdesign.com. This policy covers our public website, assessments, enquiries, client administration and the Tantreak CRM messaging platform. It was last updated on 24 September 2026.
Our role and the client’s role
For Tantreak’s own website, account, security, billing and service-administration data, Tantreak decides why and how information is used and acts as the responsible business or data controller. For customer, patient, prospect, appointment, project and conversation data placed in a client workspace, the clinic, architecture practice or other client normally decides the purpose and means of processing. Tantreak processes that workspace data to provide the service under the client’s instructions. Each client must give its own users and contacts any notice required for its activities.
Information we collect
Website and account information may include your name, business contact details, company, country, enquiry content, assessment answers, booking details, consent choices, device and browser information, page activity, referral source, campaign parameters and advertising identifiers. CRM platform information may include workspace and staff records, customer contact details, appointments, enquiries, projects, tasks, notes, communication preferences and audit events.
Meta and WhatsApp platform data
When an authorised client administrator uses Meta Embedded Signup, we receive the business portfolio, WhatsApp Business Account, phone-number and configuration identifiers selected by that administrator, together with connection status, display-number details, approved templates, messages and delivery events needed to provide the service. Authorisation credentials are kept in server-side systems and are not displayed to other clients. We do not ask clients to send us their Meta password.
How and why we use information
We use information to provide requested services, authenticate users, create and isolate workspaces, connect client-owned communication channels, deliver and receive authorised messages, manage enquiries and operational workflows, respond to requests, prevent fraud and abuse, maintain logs, meet legal obligations and improve reliability. Where applicable, the legal basis may include consent, steps requested before a contract, performance of a contract, compliance with law and legitimate interests that do not override individual rights.
Dental and other sensitive information
A dental workspace may contain appointment details or information a person chooses to provide about a concern. Clients must collect only information necessary for their service and apply any health, professional-confidentiality or special-category-data rules that apply to them. Unless a written agreement and configuration expressly state otherwise, the platform is not an electronic medical-record system, must not be used for emergency care and should not contain detailed clinical records, payment-card data, government identifiers or other unnecessary sensitive information.
Messaging, templates and marketing
Clients control their recipients, message purpose, templates and campaigns. They are responsible for having an appropriate legal basis or consent, respecting opt-outs, using the correct WhatsApp message category and following applicable marketing, telecom and consumer-protection rules. Tantreak may suppress further marketing messages after an opt-out while retaining a limited suppression record so the preference continues to be honoured.
Analytics and advertising providers
Subject to your choices, we use Google Tag Manager and Google Analytics 4 for measurement, Google Ads, Meta and LinkedIn for advertising and conversion measurement, Microsoft Clarity for aggregated behaviour and session insights, and a server-side country lookup service for regional reporting. These providers may receive online identifiers, device data, page activity, campaign data, conversion events, or a transient IP address where needed for country resolution. Server-side measurement may send the same limited event data directly to a provider to improve reliability and deduplication.
Service providers and international processing
We use providers such as cloud hosting, authentication, storage, communication, email, analytics, security and support services. Meta processes WhatsApp data under its own terms and policies. Providers may process information in the United States, United Kingdom, European Economic Area, India or other locations. Where required, the relevant business is responsible for using an approved transfer mechanism and contractual safeguards.
Sale, sharing and advertising choices
We do not sell CRM workspace content or Meta Platform Data. Subject to consent and applicable law, disclosure of public-site activity or online identifiers to advertising providers may be treated as sale, sharing or targeted advertising in some jurisdictions. You can change optional tracking through Your Privacy Choices and supported Global Privacy Control signals.
Retention, disconnection and deletion
We retain information for the period needed to provide the service, secure accounts, honour suppression requests, maintain required business records, resolve disputes and meet legal obligations. A client administrator can disconnect a WhatsApp number, but disconnection does not automatically erase records the client must retain. Verified deletion requests are handled through our Data Deletion page. Deletion may be delayed or limited where retention is required for security, legal claims, financial records, backups or another lawful obligation.
Security and tenant separation
The platform uses tenant-scoped workspaces, role-based access, server-only integration credentials, phone-number routing and audit records intended to prevent one client from accessing another client’s data. We apply reasonable technical and organisational safeguards, but no internet service can promise absolute security. Clients must protect administrator accounts, use authorised staff access and promptly report suspected misuse.
Regional privacy rights
Depending on where you live and whether a law applies, you may have rights to receive notice, access or know about information, correct it, request deletion, restrict or object to processing, obtain portability, withdraw consent, opt out of sale or sharing, limit certain sensitive-data uses, and avoid discrimination for exercising a right. These rights may be subject to verification and lawful exceptions. This section is intended to support rights recognised by regimes including India’s Digital Personal Data Protection framework, the EU GDPR, UK data-protection law and applicable United States state privacy laws.
Children
Tantreak’s business services are not directed to children. A client that handles information about a child must establish the appropriate authority, notices and safeguards required by applicable law and professional obligations.
Contact and complaints
Email info@tantreakdesign.com with “Privacy Request” in the subject line or use the Data Deletion page. We may need to verify identity and authority before acting. If the request concerns a clinic or studio workspace, contact that business first because it usually controls the record. You may also complain to the privacy or data-protection regulator available in your jurisdiction.
Ready to turn attention into a lead-ready growth system?
Tell us where your business is stuck. We will help you choose the right next step across brand, website, content, or Brand4ward.
