Legal & Data
TARMEH delivers real-time workforce visibility and safety solutions for high-risk industries. Our TESA system and BiB wearable devices provide advanced workforce tracking, and operational intelligence to protect workers and improve efficiency on sites.
1
Compliance
TARMEH is committed to helping companies meet regulatory and industry standards through transparent workforce digitization. The TESA system supports compliance with activity monitoring, location tracking, and operational oversight requirements in high-risk industries.
Key Compliance Areas
Safety and Operational Standards
-
Supports alignment with MSHA (Mine Safety and Health Administration) requirements for mining operations.
-
Aids compliance with OSHA and equivalent international construction and industrial safety regulations.
-
Facilitates documentation of worker activity, inactivity periods, zone adherence, and site presence for audit purposes.
-
Enables logging of sleeping-on-workplace incidents and unauthorized zone access.
Data Protection and Privacy Regulations
-
Designed to support GDPR, CCPA/CPRA, and other regional data protection laws.
-
Configurable data retention and access controls to match jurisdictional requirements.
-
Supports company-specific compliance policies through customizable reporting and audit logs.
Industry-Specific Standards
-
ISO 45001 (Occupational Health and Safety Management).
-
ISO 27001 (Information Security Management).
-
Sector-specific protocols for mining, construction, energy, and heavy industry.
Audit and Reporting Capabilities
-
Comprehensive, exportable logs of worker activity, location history, zone interactions, and detected events.
-
Timestamped records for regulatory inspections and internal audits.
-
Role-based access ensuring only authorized personnel can view compliance data.
Ongoing Commitment TARMEH regularly reviews system features against evolving regulations. Clients are encouraged to consult with their legal and compliance teams to ensure TESA configuration meets specific jurisdictional needs.
Compliance Resources
-
Downloadable audit report templates.
-
Integration guides for compliance management systems.
-
Dedicated compliance support during onboarding.
2
Data Security
Protecting your workforce data is foundational to the TESA platform. We provide robust, multi-layered security controls with flexible deployment options that prioritize company ownership.
Core Security Features
Encryption
-
End-to-end encryption for all data transmitted from BiB devices.
-
Data at rest encryption on servers (on-premises or pipeline).
-
Secure communication protocols (TLS 1.3+).
Access Controls
-
Role-based access control (RBAC) with granular permissions.
-
Multi-factor authentication (MFA) for dashboard and API access.
-
Detailed audit logs of all data access and modifications.
Deployment Options
-
Company-Owned Server: Full on-premises deployment with zero external data transmission. Complete data sovereignty for your organization.
-
TARMEH Pipeline: TARMEH acts solely as a secure, encrypted data routing and processing pipeline. Primary storage and control remain with your company servers.
-
Hybrid models available.
Threat Protection
-
Continuous monitoring for anomalies and potential breaches.
-
Regular security updates and vulnerability patching.
-
Device-level security features to prevent tampering or unauthorized access.
Data Handling Practices
-
Activity, inactivity, location, and event data (including sleeping detection) processed strictly for operational purposes.
-
Configurable data retention policies set by the customer.
-
Secure data deletion capabilities upon request.
Certifications and Testing
-
Alignment with ISO 27001 standards.
-
Regular third-party penetration testing and security audits.
-
Incident response protocols with client notification procedures.
Security Responsibilities Clients are responsible for proper device assignment, user training, and internal access policies. TARMEH provides tools and documentation to support these efforts.
3
Terms of Use
These Terms of Use govern your access to and use of the TARMEH TESA system, including BiB devices, platform, software, and related services.
1. Acceptance of Terms By deploying or using TESA, you agree to these Terms. If you represent a company, you warrant that you have authority to bind that entity.
2. Service Description TESA provides workforce digitization tools including activity/inactivity monitoring, real-time location tracking, zoning for site representation, and detection of specific events such as sleeping on the workplace. The system is intended for operational and compliance purposes in industrial environments.
3. User Responsibilities
-
Ensure BiB devices are properly assigned and maintained.
-
Configure zones accurately for your site (mines, construction areas, etc.).
-
Use the system in compliance with applicable laws and internal policies.
-
Maintain confidentiality of account credentials.
4. Prohibited Uses
-
Attempting to reverse engineer, tamper with, or circumvent device or system security.
-
Using TESA data for purposes other than authorized operational oversight.
-
Sharing access credentials with unauthorized parties.
5. Data Ownership You retain ownership of your workforce data. TARMEH processes data only as a pipeline or provides software/tools as specified in your deployment agreement.
6. Server Deployment You may choose full on-premises deployment or TARMEH pipeline services. In all cases, you control data retention and access policies.
7. Termination TARMEH may suspend or terminate access for violations of these Terms. Upon termination, you are responsible for data export from the system.
8. Limitation of Liability TARMEH provides the system "as is." We are not liable for indirect, incidental, or consequential damages arising from use of TESA.
9. Governing Law These Terms are governed by the laws of [Insert Jurisdiction].
10. Changes to Terms We may update these Terms. Continued use after changes constitutes acceptance.
For full legal agreements, refer to your signed contract with TARMEH. These Terms do not replace professional legal advice.
4
Privacy Policy
TARMEH respects the importance of data protection. This Privacy Policy explains how we handle data processed through the TESA system.
Data We Process When using TESA:
-
Device Data: Activity and inactivity patterns from BiB devices worn by personnel.
-
Location Data: Worker whereabouts and interactions with defined site zones.
-
Event Data: Detection of specific conditions such as sleeping on the workplace.
-
System Data: Usage logs, audit trails, and configuration settings.
How We Use Data
-
To provide real-time workforce visibility and digital site representation.
-
To generate alerts for inactivity, zone violations, or detected events.
-
To produce reports supporting operational oversight and compliance.
-
To improve system performance and security (aggregated/anonymized where possible).
Data Sharing
-
Data is not sold to third parties.
-
Shared only as required for service delivery (e.g., secure pipeline routing) or as instructed by the customer.
-
In on-premises deployments, data remains entirely within your infrastructure.
Data Storage and Retention
-
Retention periods are controlled by the deploying company.
-
On-premises: Data stored on your servers.
-
Pipeline: Temporary secure routing with customer-defined deletion policies.
Your Rights and Controls
-
Companies control access to their TESA data.
-
Workers should contact their employer regarding data subject rights.
-
Companies can export or delete data using platform tools.
Security We implement industry-standard technical and organizational measures to protect data. See our Data Security page for details.
International Transfers For pipeline services, data transfers comply with applicable laws (e.g., Standard Contractual Clauses where required).
This Policy applies to TARMEH's processing on behalf of customers. Employers using TESA are responsible for their own privacy notices to personnel.
Get in Touch
Contact Us For privacy inquiries: info@tarmeh.com