Tatta Bio Privacy Notice
Effective date: August 1, 2025
In this privacy notice (“Notice”) you can find information on how we process your personal data, which for the purposes of this Notice means information that directly identifies you or can be used to identify you (“Personal Data”). This Notice applies to Personal Data that Tatta Bio and its affiliates process as the data controller when you browse or otherwise engage with us through our websites (including but not limited to tatta.bio), applications, and services that refer to this Notice (“Services”).
1. Personal Data We Collect
Personal Data is collected from you directly and/or automatically from your device when you use our Services. Personal Data collected when you use the Services may vary depending on how you interact with us and the features you use.
Personal Data You Provide:
We may collect Personal Data that you provide to us when you engage or use our Services:
- Account Information: When you create an account with us, we will collect information associated with your account, including your name, contact information and professional association.
 - User Content: When you use our Services, we may collect Personal Data that is included in the input, file uploads, or feedback that you provide to our Services.
 - Communication Information: If you communicate with us, we may collect your name, contact information, and the contents of any messages you send.
 
Personal Data We Receive Automatically:
When you visit, use, and interact with the Services, we may collect the following information:
- Log Data: Information your browser automatically sends whenever you use our website.
 - Usage Data: Information about your use of the Services, such as the types of content that you view or engage with.
 - Device Information: Includes name of the device, operating system, and browser you are using.
 - Session Recordings: Capture information such as mouse movements, clicks, scrolling, and keystrokes for authenticated users.
 
2. Processing Purposes: How We Use Your Personal Data
Personal Data collected when you use the Services may be used for:
- Business Operations: Including billing, accounting, and internal reporting
 - Communication: To inform you about new Services, features, offers, and updates
 - Inference: To derive likely preferences or other characteristics
 - Legal Requirements: To comply with legal obligations and protect rights
 - Personalization: To customize the Service to your preferences
 - Providing our Services: To deliver and update our Services
 - Resolving Technical Issues: To identify and resolve technical problems
 - Safety and Security: To promote safety, integrity, and security across our Services
 
3. Sharing of Personal Data
We may share Personal Data with the following recipients:
- Affiliates: We may disclose Personal Data to our affiliates
 - Business Transfers: In connection with strategic transactions or reorganization
 - Competent Authorities: To authorized law enforcement or regulators
 - Partners and Resellers: With third parties that offer related services
 - Data Processors and Service Providers: To assist us in meeting business operations needs
 - Other Users and the Public: Information you share in public-facing areas
 
4. Lawful Basis for Processing Personal Data
Tatta processes Personal Data in compliance with the GDPR, ensuring a lawful basis for each processing activity:
- Contractual Necessity: To fulfill our contractual duties to you
 - Legal Obligation: To comply with applicable laws
 - Legitimate Interests: For purposes in our legitimate interests
 - Consent: When you have explicitly consented to processing
 
5. Your Privacy Rights
Depending on your residence location, you may have certain rights regarding your Personal Data:
- The right to access the data collected about you
 - The right to request detailed information about Personal Data collected
 - The right to rectify or update inaccurate or incomplete Personal Data
 - The right to erase or limit the processing of your Personal Data
 - The right to object to the processing of your Personal Data
 - The right to withdraw consent
 - The right to data portability
 
To exercise these rights, please send an email to legal@tatta.bio and follow the instructions provided.
5.1 US State Specific Information
This section provides additional information for residents of certain US states with distinct data protection laws.
Privacy Rights
- Right to Knowledge and Correction: Request details on Personal Information collected
 - Right to Know Data Recipients: Information about who we share data with
 - Right to Request Deletion: Request deletion of your Personal Information
 - Right to a Timely Response: Two free requests in any 12-month period
 - Non-Discrimination: We will not discriminate for exercising your rights
 
California
We make disclosures for compliance with California privacy law, including CCPA as amended by CPRA. We do not “sell” or “share” the personal information of known minors under 16 years of age.
Under the “Shine the Light” law, California residents may request information about disclosures for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
Colorado/Connecticut/Virginia
If you live in Colorado, Connecticut, or Virginia, you have the right to appeal if we deny your request. You also have the right to opt out of profiling in relation to decisions that produce legal or similarly significant effects.
Nevada
We do not sell your covered information, as defined under Chapter 603A of the Nevada Revised Statutes.
6. International Data Transfers and Security
Tatta, as a company located in the United States, stores and processes Personal Data in international locations, including the United States. We use appropriate administrative, technical, and physical security measures to protect your Personal Data.
7. Data Retention
We'll retain your Personal Data only as long as necessary and, if you have created an account with us, as long as your account is active. We may retain personal Data as needed to fulfill contractual obligations, comply with legal requirements, resolve disputes, and enforce agreements.
8. Third Party Access and Data Protection
When you use third-party extensions, integrations, or follow references and links within our Services, the privacy policies of these third parties apply to any Personal Data you provide or consent to share with them.
9. Information for Minors
Our Services are not intended for individuals under the age of 18. We do not intentionally gather Personal Data from such individuals. If you are under the age of 18, you are not allowed to use our Services.
10. Contact Us
Contact us by emailing us at legal@tatta.bio. Our address is:
CIC Cambridge1 Broadway
Tatta Bio, Floor 9
1 Broadway, Cambridge, MA 02142
11. Changes to this Notice
This Notice may be updated periodically for clarity or to reflect changes in law or our practices. We indicate at the top of this Notice when it was most recently updated. By continuing to use the Services, you agree to our updates.