This Privacy Policy explains how KMPS Global Corporation, an Ohio corporation doing business as Tejdux (“we”, “us”, or “our”), handles personal data in connection with the TejDux platform at www.tejdux.com (the “Service”). It should be read alongside our Terms of Service.
TejDux is used by brands and agencies to manage relationships with content creators. Much of the personal data in the Service is data about creators, uploaded by a brand — often imported in bulk from a spreadsheet the brand already maintained.
For that data, the brand is the controller and we are only the processor. We hold it on the brand's behalf and act on their instructions. If you are a creator asking why a brand holds your details, Section 8 explains what to do — and we will help — but the brand, not us, decides what is collected and why.
Which role we play depends on whose data it is. This distinction determines who you should approach about it.
| Data | Our role | Who decides how it is used |
|---|---|---|
| Account and login details of brand or agency users | Controller | Us — this policy applies in full |
| Creator Portal account details, where a creator registers directly with us | Controller | Us — this policy applies in full |
| Creator Records held inside a brand's workspace, including imported spreadsheets | Processor | The brand or agency that uploaded them |
| Campaign, content, and performance records inside a workspace | Processor | The brand or agency |
| Website visits to www.tejdux.com | Controller | Us |
Where we act as a processor, we process personal data only on the documented instructions of the brand, and not for our own purposes. Our obligations to those brands are set out in our Data Processing Addendum.
This applies to people who sign up to use the Service on behalf of a brand or agency.
This applies to creators who register a Creator Portal account directly with us.
Creating a Creator Portal account does not, by itself, give a brand any new information about you, and does not require you to have any existing relationship with a brand on the Service.
This section describes data we hold as a processor, on behalf of a brand. We did not choose to collect it and we do not decide what it is used for.
A brand may import or manually enter records about creators they work with or wish to approach. These typically include name, social handle and platform, email address, campaign participation, fees and payment status, discount codes and affiliate links, notes and correspondence logs, and content the creator produced for that brand.
Under our Terms of Service, every brand must represent that it has a valid legal basis for the data it uploads, that it obtained the data lawfully, and that it has given any notices and obtained any consents its own jurisdiction requires. Brands are also required not to upload special categories of personal data, and not to upload data relating to minors.
We store it, make it available to the authorised users of that brand's workspace, and process it to provide features the brand uses — such as organising it into campaigns, mapping spreadsheet columns during import, and recording attribution. We do not sell it, we do not use it to build profiles for our own purposes, and we do not use it to train machine learning models.
When a brand imports a spreadsheet, the Service can suggest how each column maps to a field. To do this it sends the column headings and the target field names to our AI provider, Anthropic, which returns suggested mappings.
Only the header text — for example “Instagram Handle”, “Fee Paid”, “Email” — leaves our systems for this feature. The creator records underneath those headings are not transmitted to the AI provider. Suggestions are advisory, and the person importing must review and confirm the mapping before any records are created.
Separately from the import feature above, the Service can sort a creator into a content category — “fitness”, “beauty” and so on — and raise brand-safety flags for a brand to review. To do this it sends to our AI provider, Anthropic, the creator’s public social handle, public display name, public follower count, and the text of up to twelve of their recent public posts. The provider returns category labels only.
What is sent is information the creator already publishes on their public social profile. What is not sent: email addresses, phone numbers or any other contact detail; private messages; and anything a brand recorded privately, such as a fee, a rate or a private note. The model is asked only to apply a label — it is never asked to produce a follower count, engagement rate or any other figure, because a plausible invented number is worse than no number. Classification is advisory: a brand can change any label, and a creator record is never rejected on the strength of one.
Where a brand asks the Service to draft landing-page copy for a campaign, it sends the campaign brief that brand wrote — its goal, audience description and offer — together with the named creator’s public social handle and platform name, to our AI provider Anthropic. No follower count, post content, email address or contact detail is sent. The draft is a starting point that the brand edits and must publish deliberately; nothing is published automatically.
Where we act as a controller, we use personal data to:
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
Where the UK GDPR, EU GDPR, or similar law applies, we rely on the following bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service under our Terms | Performance of a contract |
| Billing and collecting payment | Performance of a contract |
| Security, fraud prevention, product improvement | Legitimate interests |
| Service and security notifications | Legitimate interests / legal obligation |
| Marketing emails, where sent | Consent, or soft opt-in where permitted |
| Retaining records for tax and accounting | Legal obligation |
Where we act as a processor for Creator Records, the legal basis is determined by the brand acting as controller, not by us.
We share personal data only as described here:
| Recipient | Purpose | Data involved |
|---|---|---|
| Amazon Web Services | Hosting and storage | All data held in the Service |
| Stripe | Subscription payments | Billing contact and payment details |
| Anthropic | Suggesting spreadsheet column mappings; classifying a creator into a content category; drafting campaign brief and landing-page copy | For mapping: column headings and field names only — not row data (Section 4.4). For classification: a creator's public handle, public display name, public follower count and the text of up to twelve recent public posts (Section 4.5). For drafting: the campaign brief, plus the named creator's public handle and platform (Section 4.6) |
| Google, Facebook | Social sign-in, where you choose it | Identity details returned by the provider |
| Social and commerce platforms | Integrations a brand connects — metrics, discount codes, sales attribution | Data within the scope the brand authorises |
| Sending service and support email | Email address and message content |
We may also disclose personal data where required by law or valid legal process, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets — in which case we will give notice before your data becomes subject to a different privacy policy.
Requests from law enforcement and other public authorities are handled under our Government Request Policy, which sets out how we check that a request is lawful, when we challenge one, why we disclose only the minimum the request compels, and when we tell you that we received it.
A current list of sub-processors is published at tejdux.com/subprocessors, and is also available on request from privacy@tejdux.com.
Depending on where you live, you may have the right to:
To exercise any of these, contact us at privacy@tejdux.com. We will respond within the period required by applicable law — generally one month under the GDPR. We do not charge for this, and we will not treat you differently for asking.
Important: if your request concerns data a brand holds about you, please read Section 9 first — the route is slightly different.
You may be in our systems without ever having signed up, because a brand added you to their workspace or imported a spreadsheet containing your details. This section is for you.
Typically from the brand itself — a spreadsheet they already kept, details you gave them directly, a form you filled in, or a public social profile. We did not collect it from you, and we do not buy creator lists.
Because the brand is the controller of that data, they are best placed to answer why they hold it, correct it, or delete it. If you know which brand it is, contact them first.
If you do not know which brand holds your data, or a brand does not respond, contact us at privacy@tejdux.com. We will identify the relevant brand or brands and forward your request, and we will assist them in responding. Where we are legally permitted to act directly, we will.
If you register a Creator Portal account, you can claim a brand's record of you. Once the brand approves the claim, you can see the collaborations and campaign participation associated with you in that workspace.
Claim approval is a product feature that controls what you can see in the portal. It is not a gate on your data protection rights. If a brand rejects your claim, you may still exercise every right in Section 8 in respect of data held about you, and both we and the brand remain obliged to honour those rights. Our Terms require brands to handle claims in good faith and prohibit rejecting a legitimate claim in order to frustrate a rights request.
If you do not want a brand to hold your details at all, you can object. Tell the brand directly, or tell us and we will pass it on. Where a brand relies on legitimate interests, a valid objection generally requires them to stop unless they can show overriding grounds.
| Data | Retention |
|---|---|
| Account data | For the life of the account, then 30 days after closure |
| Workspace content, including Creator Records | Until deleted by the brand, or 30 days after the account closes |
| Deleted import batches | Removed on deletion; may persist in encrypted automated backups for up to 30 days, and in manual disaster-recovery snapshots until they are deleted |
| Billing and tax records | As required by law, typically 6–7 years |
| Security and access logs | 30 days |
| Support correspondence | 24 months |
Deleting an import batch unlinks and removes the records it created. Deletion may take a commercially reasonable period to propagate through backups and logs.
We use technical and organisational measures appropriate to the risk, including:
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data and the law requires it, we will notify you and the relevant supervisory authority within the required timeframes. Where we act as a processor, we will notify the affected brand without undue delay so they can meet their own obligations.
To report a vulnerability or suspected incident, contact security@tejdux.com.
We and our service providers may process personal data in countries other than your own, including the United States. Where we transfer personal data out of the UK, EEA, or another region with transfer restrictions, we rely on an appropriate safeguard — such as an adequacy decision, Standard Contractual Clauses, or the UK International Data Transfer Addendum.
We use only what the Service needs to function. Strictly necessary cookies and equivalent browser storage keep you signed in, maintain your session, and protect against cross-site request forgery. These cannot be disabled without breaking sign-in.
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. Brands are prohibited from uploading data relating to minors. If you believe we hold a child's data, contact us and we will delete it.
We may update this policy. For material changes we will give notice by email or in the product before they take effect. The “Last updated” date above always reflects the current version, and the current version is always available at this URL.
For any privacy question, or to exercise your rights:
KMPS Global Corporation (d/b/a Tejdux)
4912 Sanctuary Drive, Westerville, OH 43082, United States
privacy@tejdux.com