Tejdux

Government Request Policy

Last updated 4 September 2026

This policy explains how KMPS Global Corporation, an Ohio corporation doing business as Tejdux (“we”, “us”, or “our”), handles requests from law enforcement, courts, regulators and other public authorities for the personal data of users of the TejDux platform. It supplements our Privacy Policy and, for our business customers, the Data Processing Addendum.

The short version We require valid legal process before disclosing user data. We review every request for legal validity, we challenge requests we believe to be unlawful or overbroad, we disclose only the minimum data the request actually compels, we log every request and our response, and we notify affected users unless the law forbids it.

Contents

  1. Scope
  2. Where to send a request
  3. Review of legality
  4. Challenging unlawful requests
  5. Data minimisation
  6. User notification
  7. Documentation and record-keeping
  8. Emergency requests
  9. Requests for customer-controlled data
  10. Transparency reporting
  11. Contact

1. Scope

This policy applies to any request, demand, order or process from a governmental or public authority — law enforcement, prosecutors, courts, regulators, tax authorities or national security bodies, in any jurisdiction — seeking personal data that we hold about a user of the Service. That includes data about brand users who hold an account with us, and data about creators whose information is held in a customer workspace.

It does not apply to requests from private parties in civil litigation, which we handle separately under the same requirement for valid legal process, nor to a data subject exercising their own rights under the Privacy Policy.

2. Where to send a request

Public authorities should direct requests to legal@tejdux.com, or by post to the address in section 11. We do not accept service of legal process through support channels, in-app messages, or the personal accounts of our staff. A request sent elsewhere may be delayed or missed; that is a reason to use the address above, not a basis for treating a request as served.

A request should identify the issuing authority and the officer responsible, cite the legal authority relied on, identify the account or data sought with particularity, and state the time period covered.

3. Review of legality

We review every request before we disclose anything. No user data is produced to a public authority on the strength of an informal approach, a phone call, or a request that merely asserts urgency.

The review asks, at minimum:

Where a request raises a question we cannot answer with confidence, we obtain outside legal advice before responding. We would rather be late than disclose data we were not obliged to disclose.

4. Challenging unlawful requests

Where our review concludes that a request is unlawful, defective, overbroad, or inconsistent with applicable data protection law, we do not comply with it as framed. Depending on the defect, we will:

We instruct outside counsel to conduct a challenge where the matter warrants it. The decision not to challenge a request is itself recorded, with the reasoning, under section 7.

5. Data minimisation

We disclose only the data that a valid request actually compels, for only the period it covers. We do not respond to a request about one account by producing an export of everything we hold, and we do not volunteer data outside the scope of the request.

Our systems are built so that this is practical rather than aspirational. Data is separated by context and by brand workspace, and access is scoped by role, so records for a single account or a single individual can be produced without extracting unrelated data. Where a request is satisfied by a narrower category — basic subscriber information rather than activity records, for example — we produce the narrower category.

Where a request is broader than the underlying legal authority supports, we treat that as a scope defect under section 4 and seek narrowing before disclosing.

6. User notification

Our policy is to notify the affected user before disclosing their data to a public authority, and to give them a reasonable opportunity to seek protection from disclosure, unless:

Where a non-disclosure obligation is time-limited, we notify the user when it expires. Where an authority asks us to delay notice without a legal basis for that request, we decline.

7. Documentation and record-keeping

We keep a record of every government request we receive. Each entry records:

These records are retained for the period required by applicable law and are available to our auditors, our regulators, and to counsel advising on a challenge. They are held securely and access is limited to those who need it.

8. Emergency requests

We may disclose data without the process described above where we have a good-faith belief that an emergency involving a risk of death or serious physical injury requires disclosure without delay. In that case we disclose only what is necessary to address the emergency.

An emergency request is documented under section 7 like any other, including the basis for the good-faith belief. We ask the requesting authority to follow up with formal process, and we notify the affected user once the emergency has passed unless we are prohibited from doing so.

9. Requests for customer-controlled data

For much of the data in the Service we act as a processor on behalf of a business customer, who is the controller. Where we receive a government request for data a customer controls, our policy is to redirect the requesting authority to that customer, so that they can respond as the controller.

Where we are legally compelled to respond directly and are permitted to tell the customer, we notify them promptly so that they may seek protection from disclosure. This commitment is also reflected in our Data Processing Addendum.

10. Transparency reporting

As of the date above, we have received no requests for user data from any public authority. Should that change, we intend to publish periodic aggregate figures on this page — the number of requests received, the number challenged, and the number resulting in disclosure — to the extent the law permits us to do so.

11. Contact

For legal process, or any question about this policy:

KMPS Global Corporation (d/b/a Tejdux)
4912 Sanctuary Drive, Westerville, OH 43082, United States
legal@tejdux.com