← Back

Privacy Policy

Last updated: 29 August 2026

TactIQ ("the Platform") is operated by Tactigent Consultancy ("Tactigent," "we," "us") as a case-management system for immigration and business-formation consulting services. This policy explains what personal data we collect, why, and how it is protected.

1. Who this applies to

This policy covers Tactigent staff (consultants and administrators) and clients who use the Platform, whether through the staff dashboard or the client portal.

2. Information we collect

  • Account information: name, email address, and profile photo, obtained from Google Sign-In.
  • Case and business information: case details, status history, messages exchanged with your consultant, and documents you or your consultant upload.
  • Compliance/KYC information (for business clients): date of incorporation, Chamber of Commerce (KKF) number, tax identification (FIN) number, industry, phone and contact email, government ID number, a copy of a government-issued ID, and articles of incorporation. This category is treated as sensitive: access is restricted to the client themselves and the staff member(s) directly responsible for that client's case, every view or download is logged with who accessed it and when, and it is never displayed in full in list views (ID numbers are masked to their last four characters outside of restricted, individual views).
  • Google Workspace data (staff only, and only if a staff member chooses to connect it): read-only access to search and attach existing files from Google Drive, and access to create, update, and delete Google Calendar events that the staff member links to a case. We do not read, modify, or delete any Drive file content, and we do not access Gmail, Contacts, or any other Google service.

3. How we use this information

We use your information solely to provide the case-management service: tracking your case, communicating with you, generating documents, scheduling appointments, and — where you've connected it — searching your Drive for relevant files or managing calendar events tied to your case. We do not sell personal data, and we do not use it for advertising.

4. Data security

  • Google account connections use industry-standard OAuth 2.0; we never see or store your Google password.
  • Access tokens for connected Google services are encrypted at rest.
  • Sensitive compliance documents are served only through signed, time-limited links tied to an authenticated session — never through a public or permanently-accessible URL.
  • Access to case, client, and compliance data is restricted by role: consultants see only their assigned cases; clients see only their own; sensitive fields require a specific authorization check beyond a general staff login.
  • New staff and client accounts require administrator approval before they can access any case data.

5. Data retention and your rights

We retain case records for as long as needed to provide the service and to meet applicable legal and regulatory record-keeping obligations. You may request a copy of your data, a correction, or deletion (subject to our legal retention obligations) by contacting us at the address below.

6. Third parties

We use SendGrid to deliver transactional email (status updates, approval confirmations) and, optionally, Twilio to deliver WhatsApp messages a consultant chooses to send. We do not share your data with any other third party except where required by law.

7. Contact

Questions about this policy or your data can be sent to [email protected].


This is a draft policy prepared as part of the Platform's initial build. It should be reviewed by qualified legal counsel familiar with Suriname/regional data protection requirements before being relied upon in production, particularly given the sensitivity of the compliance/KYC data described above.