Privacy Policy
Effective 29 July 2026
1. Who we are and our role
Terra Tester (“we”) operates the TerraTester service. For personal data relating to your account and our business relationship with you, we act as a controller. For the laboratory data that a customer enters to run its laboratory, we act as a processor on that customer's behalf, and our Data Processing Addendum applies. You can reach us about privacy at hello@terratester.com.
2. Personal data we process
Account data — the name, email address and assigned roles of each user, and passwords stored only as bcrypt hashes (never in readable form).
Usage and security data — sign-in timestamps, an audit log of significant actions, and, to defend the sign-in form against brute-force attacks, recent failed-login records containing the email address attempted and the originating IP address.
Customer Data — the laboratory records our customers enter, which may contain personal data such as the contact details of their clients. We process this only on the relevant customer's instructions as controller.
3. How and why we use it
We use personal data to provide, secure and support the Service: to authenticate users, enforce access and seat limits, maintain an audit trail, throttle abusive sign-in attempts, send transactional email (such as password resets and invitations) and administer subscriptions.
4. Legal bases
Where data-protection law such as the UK/EU GDPR applies, we rely on: performance of a contract (to provide the Service); our legitimate interests (to secure the Service, prevent abuse and run our business); consent where we separately ask for it; and legal obligation where applicable. For Customer Data we process on the documented instructions of the customer as controller.
5. Cookies
We set a single strictly-necessary session cookie to keep you signed in. We do not use advertising or third-party tracking cookies.
6. Sharing and subprocessors
We do not sell personal data. We share it only with the service providers who help us run TerraTester:
- PerfGrid — Application hosting and backups (The Netherlands).
- Mailtrap — Transactional email delivery (EU / US).
- Stripe — payment processing.
We may also disclose data where required by law. A current list of subprocessors is maintained in our Data Processing Addendum.
7. Security
We protect personal data with technical and organisational measures including: encryption in transit (TLS); bcrypt password hashing; strict per-tenant data isolation with access checked on every request; CSRF protection and a strict content-security policy; login throttling; and an append-only audit log. Backups are taken by JetBackup. No system is perfectly secure, but we work to protect data appropriately to its sensitivity.
8. Retention
We keep account and Customer Data for the life of the account. After closure we retain data for up to 30 days to allow export, then delete or anonymise it unless the law requires us to keep it longer. Security logs (audit and failed-login records) are retained for 12 months and then pruned.
9. International transfers
Data is hosted in The Netherlands. Where personal data is transferred across borders, we rely on an appropriate safeguard such as the Standard Contractual Clauses.
10. Your rights
Subject to applicable law, you may request access to, or correction, deletion, restriction, portability of, or object to the processing of your personal data. Where the data is Customer Data, please direct the request to the laboratory that controls it; we will assist that customer as its processor. To exercise a right regarding data for which we are the controller, contact hello@terratester.com. You may also lodge a complaint with your local data-protection authority.
11. Changes
We may update this Policy and will post the revised version here with a new effective date.
12. Contact
Terra Tester. Privacy enquiries: hello@terratester.com.