Privacy Policy
Our Privacy Policy is currently being finalized and reviewed before publishing. Check back soon.
Terms of Service
Our Terms of Service is currently being finalized and reviewed before publishing. Check back soon.
Legal
Tervynex is an early-stage company, and this page reflects where we actually stand today, not where we intend to be. As our infrastructure and team grow, this page will be updated to reflect that.
All data in transit is encrypted using TLS. Data stored in our database is encrypted at rest using AES-256 encryption, provided by Neon, our database host, as a standard part of their infrastructure.
We back up our website and its associated pages on a regular schedule. Our database host and application host also each maintain their own independent backup systems as part of their standard infrastructure.
Internally, access to customer data is currently limited to Tervynex's two founders and our support staff. We do not have a large internal team, and we intend to keep access tightly scoped as we grow.
We do not build every part of Tervynex ourselves. We rely on established providers for the pieces that require serious infrastructure, and each one maintains its own independent security certifications:
Tervynex is built on infrastructure that already meets some of the highest independent security standards available, including SOC 2, ISO 27001, and PCI DSS, through the certified providers named above. Formal certification of Tervynex itself is a goal we are actively working toward as the company grows.
If you believe you have found a security vulnerability in a Tervynex product, please email us at security@tervynex.com. We take reports seriously and will respond as quickly as we can.
If we become aware of a security incident affecting your personal information, we will notify affected users without undue delay.
For Florida residents specifically, this commitment is not just a promise, it is a legal requirement. Under the Florida Information Protection Act (Fla. Stat. § 501.171), we are required to notify affected individuals within 30 days of determining that a breach has occurred, with a possible 15-day extension for documented good cause. If a breach affects 500 or more Florida residents, we are also required to notify the Florida Attorney General within that same 30-day window. Properly encrypted data that is exposed in a breach is generally exempt from these notification requirements, which is part of why encryption is not a formality for us, it is a real protection for you.