Legal / Privacy

Privacy policy

This policy explains what personal data tefer.io collects, why we collect it, who else sees it, how long we keep it, and what you can ask us to do with it. It covers the five forms on this site: the contact form, the call booking form, event registration, the future-events signup, and the newsletter opt-in.

Last updated: 30 July 2026

Who we are

tefer.io is operated by Tefer Consolidate PLC, which trades as Tefer. We are a software development and outsourcing studio. We decide what this site collects and why, which makes us the controller of the personal data described below.

Legal entity
Tefer Consolidate PLC
Trading name
Tefer, tefer.io
Registered address
Elsadol Building Suite 806, Mikeyleland Street, Addis Ababa, Ethiopia

Anything to do with your personal data goes to hello@tefer.io: access, correction, deletion, a complaint, or a question about a line in this document.

We have not appointed a separate data protection officer. Requests are handled by the small team that runs this site and the systems behind it, at the address above.

What we collect and when

We collect what you type into one of five forms, plus a small amount of technical data that arrives with every web request. There is nothing else. We do not buy data about you, we do not enrich what you give us from other sources, and we do not build profiles.

The contact form

Used when you send an enquiry from the contact section of the site. Stored in a database collection called leads.

  • Your name.
  • Your email address.
  • Your company, if you fill it in. This field is optional.
  • Which service you are interested in: product engineering, dedicated team, staff augmentation, MVP development, or not sure yet.
  • A budget range, if you pick one. This field is optional and includes a prefer-not-to-say option.
  • Your message.
  • Alongside those: the time of submission, the label tefer.io as the source, a status we use to track follow-up, the address of the page you submitted from, and the browser identification string (user-agent) your browser sends.

The call booking form

Used when you ask for an introductory call. Stored in a collection called bookings.

  • Your name.
  • Your email address.
  • Your phone number.
  • The date you asked for and the half-hour slot you picked.
  • The timezone your browser reports, for example Africa/Addis_Ababa, so that we propose a time in your own clock rather than ours.
  • Alongside those: the time of submission, the source, a status that starts at requested, the referring page address, and the user-agent string.

Event registration

Used when you register for one of our events. Stored in a collection called registrations. Read section 04 before you register: these are the only records we may share with other organisations.

  • Which event you are registering for.
  • Your name.
  • Your email address.
  • Your phone number.
  • Your company name.
  • Your company sector, picked from a list.
  • Whether you plan to attend in person or by livestream, or that you are on the waitlist because the room is full, and in that case whether you told us you would also join the livestream.
  • Whether the newsletter box was ticked when you submitted.
  • Alongside those: the time of submission, the source, a status that starts at registered, the referring page address, and the user-agent string.

The future-events signup

Shown in place of the registration form once a session is full, when you ask to hear about the next one. It creates a record in a collection called event-notifications. It holds your email address in lower case, your name, your company if you filled it in, which page you signed up from, whether you also ticked the newsletter box, your subscription status, and when the record was created and last updated. The record is keyed on your email address, so signing up twice updates one record instead of creating a duplicate.

The newsletter opt-in

Ticking the newsletter box on a form also creates a subscriber record in a collection called newsletter. It holds your email address in lower case, your name, your company, whether you are subscribed, where the opt-in came from, and when the record was last updated. The record is keyed on your email address, so opting in twice updates one record instead of creating a duplicate.

Technical data

  • Your IP address, read from the request headers when you submit a form. We use it to count submissions per address, at most five in any ten minutes, and the counter is held in the server's memory only. The IP address itself is not written to the database with your submission.
  • The referring page address and the browser user-agent string, stored with each submission. They help us tell a genuine enquiry from a scripted one and see which page a question came from.
  • Every form carries a hidden field that a person never sees. If it comes back filled in, we treat the submission as automated: it is discarded and nothing is stored.
  • Our hosting provider keeps ordinary server logs, which normally record IP addresses, requested pages and timestamps. Those logs belong to the provider and are kept on their schedule, not ours.
  • A decorative background video on the home page is served from a content delivery network, and the event page embeds a map. Loading either means your browser requests a file from that provider directly, so it sees your IP address. See section 11.

What we do not collect

We do not ask for identity documents, payment card details, or special category data such as health, religion, politics or biometrics, and we have no field for any of it. Please do not put that sort of information into a message box. If you do, we will delete it.

Why we collect it, and on what basis

Each thing we collect has one purpose, and we do not reuse it for another one without asking you.

Replying to an enquiry
You asked us to. Sending a reply is the step you requested, and we have a clear interest in answering people who contact us.
Scheduling a call
To confirm a time that works in your timezone and to send you the details. Your phone number is there in case the email bounces or the call drops.
Running an event
To check you in, count seats against venue capacity, send joining links for the livestream, and follow up with materials and the recording.
Sending the newsletter
Your consent, given by leaving the newsletter box ticked when you submit a form. You can withdraw it at any time and we stop.
Blocking automated submissions
Our interest in keeping the forms usable and the database free of junk. This is the rate-limit counter and the hidden field described above.

As a company registered in Ethiopia, Ethiopian data protection rules apply to us. Where a law with a formal list of legal bases applies to you, for example if you are in the European Economic Area or the United Kingdom, read the right-hand column above as our statement of the basis we rely on: consent for the newsletter, and the performance of a step you requested or our legitimate interest for everything else.

Event registration and event partners

The important part

If you register for a Tefer event that we organise or host with partners, we may pass your registration details to those partners so that the event can actually run. This applies to event registrations only, never to contact form enquiries or call bookings. If you would rather we did not, email hello@tefer.io before the event and we will keep you off the shared list. Your seat is not affected and you can still attend.

Who the partners can be

  • Co-hosts and programme partners who run the session with us.
  • Sponsors of that specific event.
  • The venue operator or building management, where they need an attendance list for access or safety.
  • Livestream, webinar and registration platform providers we use to deliver the session.

What we share

Only the registration details, and only these: your name, email address, phone number, company name, company sector, and attendance mode (in person or livestream). Nothing else from your registration goes to a partner.

Contact form enquiries and call bookings are separate records and are never shared with event partners. That means your message, your budget range and your call details stay with us.

Why we share it

  • Attendee check-in at the door.
  • Capacity and venue management: seat counts, access lists, catering numbers, safety requirements.
  • Provisioning livestream or webinar access and sending you the joining link.
  • Event-related follow-up: session materials, the recording, and a note about what comes next.

The limits we put on partners

  • They may use the details only for that event and the follow-up listed above.
  • They may not add you to their own unrelated marketing lists.
  • They may not pass your details on to anyone else.
  • We share the shortest list that does the job, and only with partners involved in the event you registered for.

How to object

Email hello@tefer.io before the event, tell us which event, and say you do not want your details passed to partners. We will keep you off the shared list and confirm it. If a list has already gone out, we will tell you which partner has your details and ask them to delete your entry.

Events may also be recorded, streamed and photographed, and attendees can appear in that material. That is set out in section 04 of the terms and conditions.

Newsletter and marketing

The only route onto our list is the newsletter checkbox on a form. We do not add people because they sent an enquiry, booked a call or walked into an event.

Worth knowing: on the event registration form that box starts ticked. Untick it before you submit if you do not want the newsletter, or unsubscribe later from any email we send.

What we send: occasional notes on what we are building, invitations to our own events, and the odd write-up of a session. We do not carry other companies' advertising, and we do not sell, rent or swap the list.

How to unsubscribe

  • Use the unsubscribe link at the bottom of any newsletter email.
  • Or email hello@tefer.io with the word unsubscribe. A person will take you off the list by hand.

When you unsubscribe we mark the record as unsubscribed rather than deleting it, so that a later form submission does not quietly add you back. Ask us to delete it outright and we will.

Replies to your enquiry, call confirmations and event logistics emails are not marketing. Unsubscribing from the newsletter does not stop us answering a question you asked us.

Who else sees your data

Google
Every record described in section 02 is stored in Google Cloud Firestore. Google acts as our sub-processor: it holds the data on our instructions and its own terms govern how it runs the service.
Our hosting provider
Serves the pages, runs the code that handles form submissions, and keeps ordinary server logs.
Our email provider
Carries our replies to you, event emails and the newsletter, which means it processes your email address and the contents of those messages.
Event organising partners
Event registration details only, on the terms set out in section 04.
Advisers and authorities
Only where the law requires it, or where we need to establish or defend a legal claim.

We do not sell personal data, and we do not share it with anyone for advertising.

Where the data sits

Firestore, our hosting and our email are all run by companies based outside Ethiopia, on servers outside Ethiopia. Submitting a form on this site means your data will be stored and processed outside Ethiopia, and outside your own country if you are somewhere else again. We use established providers and rely on the transfer terms they publish for their services.

We have deliberately not named our hosting and email providers here, because a policy that names a supplier goes stale the day we change one. Email hello@tefer.io and we will tell you exactly which providers hold data at that point.

How long we keep it

Contact enquiries
24 months from our last contact with you, then deleted. If we are still talking, the clock restarts each time.
Call bookings
24 months from the call, or from our last contact about it.
Event registrations
12 months after the event, then deleted. What we keep for our own records after that is counts and totals, not your details.
Future-events signups
Until you ask us to stop. We then mark the record unsubscribed rather than deleting it, so you are not added back by a later signup, and we delete it outright if you ask us to.
Newsletter
Until you unsubscribe. After that we keep the email address marked as unsubscribed so we do not add you back, unless you ask us to delete it.
Rate-limit counters
Minutes. They live in the server's memory and disappear as the ten-minute window passes or when the server restarts.
Server logs
Kept by our hosting provider on their own schedule, normally weeks rather than years.

We may keep a record longer where we have to, for example an unresolved dispute or an accounting requirement. Ask us and we will tell you what we still hold and why.

How we protect it

  • Every submission is checked on the server against a strict schema before anything is written. Fields that are not in the schema are dropped, and lengths and formats are enforced.
  • Database credentials live in environment variables on the server. They are not in the code and not in the repository.
  • The dashboard where our team reads submissions is private, behind an email and password sign-in, and the session is carried by a signed token that expires after seven days.
  • Forms are rate limited per IP address and carry a hidden honeypot field, which together stop most automated submissions before they reach the database.
  • The site is served over HTTPS, so what you type is encrypted on its way to us.
  • Access to the stored records is limited to the people at Tefer who need it to reply to you or run an event.

No website can promise perfect security. If we find a breach that puts you at risk, we will tell the people affected and the relevant authority without unnecessary delay, and we will say plainly what happened.

Your rights

Whatever your country, you can ask us for all of the following. We do not make you prove a legal entitlement first.

Access
A copy of what we hold about you, and where it came from.
Correction
Fix anything wrong or out of date.
Deletion
Delete your records. We will do it unless we have to keep something, and then we will tell you what and why.
Objection
Object to a particular use, including the sharing of event registration details with event partners described in section 04.
Withdrawing consent
Withdraw your newsletter consent at any time. Withdrawing it does not undo emails already sent.
Portability
A copy in a common machine-readable format, such as JSON or CSV.

Send requests to hello@tefer.io. We answer within 30 days. If a request is complicated we will say so inside those 30 days and give you a date. We do not charge for any of this. We may ask you to write from the email address the data was submitted with, so that we do not hand your data to someone else.

If you are unhappy with how we handled a request, tell us and we will look at it again. You can also complain to the data protection authority in your country.

Children

This site is aimed at founders, operators and companies. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. Our events are for adults.

If you believe someone under 18 has submitted a form here, email hello@tefer.io and we will delete the record.

Cookies and tracking

This site sets one cookie, and only for our own staff.

tefer_admin_session
Strictly necessary. Set only when a member of the Tefer team signs in to the private admin dashboard. It carries a signed, expiring session token, is marked httpOnly so scripts cannot read it, and lasts seven days. An ordinary visitor never receives it.

That is the whole list. There are no advertising cookies, no analytics cookies, and no third-party tracking scripts on this site. Nothing follows you between sites, and no vendor gets a copy of your browsing for its own use. There is nothing for a cookie banner to ask you about, which is why you have not seen one.

Our web fonts are served from our own domain, so opening a page does not call a font provider.

Embedded and hosted content

Two parts of the site do reach out to other companies when they load, and those requests are covered by the provider's privacy policy rather than this one:

  • The event page embeds a Google map so you can find the venue. The map is loaded by Google, which sees the request and can set its own cookies or browser storage once it does.
  • The decorative background video on the home page is fetched from a content delivery network, which receives your IP address as part of serving the file.

If we ever add analytics or any other tracking, we will say so on this page before we turn it on, and we will ask for consent where consent is required.

Changes to this policy

If we change what we collect, why we collect it, or who else sees it, we will update this page and change the date at the top. The version on this page is the one that applies.

Where a change materially affects data you have already given us, and we have your email address, we will tell you by email rather than leave you to notice.

Your use of the site is also covered by our terms and conditions.

Contact

Tefer Consolidate PLC

Elsadol Building Suite 806, Mikeyleland Street, Addis Ababa, Ethiopia

Also read

Terms and conditions

The rules for using this site, our events, and what a form submission does and does not commit either of us to.

Read it