Privacy Policy
What personal data Drentova Group Ltd collects, why, on what lawful basis, and what you can do about it.
- Version
- 1.0
- Effective
- 26 July 2026
- Applies to
- Drentova Group Ltd
- History
- 1 version
Who is responsible for your data
We decide how your data is used when you deal with us directly. When another company uses our software to serve you, they decide and we act on their instructions.
Drentova Group Ltd is the controller of the personal data described in this policy. We are registered with the Information Commissioner’s Office under number PLACEHOLDER — ICO registration. Questions about this policy, or about how we handle personal data, go to [email protected].
Where you use one of our products as a customer of one of our customers — for example where an organisation uses our software to serve you — that organisation is the controller and we act as its processor. In that case, ask them first; we will help them respond.
What we collect and why
We collect only what we need, and we collect it for the reasons below.
Information you give us
- Account details — your name, email address and, for paid plans, billing details. We need these to provide the service and to take payment.
- Correspondence — what you send us when you contact us, so we can respond and keep a record of the exchange.
- Content — whatever you put into the service. We process it to provide the service and for no other purpose.
Information we collect automatically
- Technical data — IP address, browser and device information, and request logs. We need these to operate the service, to keep it secure, and to diagnose faults.
- Usage data — which features are used and when. Where this is not necessary to run the service, we collect it only with your consent through analytics.
Information from others
- Payment status from our payment provider, so we know whether a subscription is active. We do not receive or store your full card details.
Our lawful bases
Under the UK GDPR we must have a lawful basis for each purpose. Ours are:
- Contract — to provide the service you have asked for, to manage your account and to take payment.
- Legitimate interests — to keep the service secure, to prevent abuse, to improve what we build, and to respond to enquiries. We have assessed in each case that this does not override your rights, and you may object at any time.
- Consent — for analytics and marketing cookies, and for marketing email. You may withdraw consent at any time, as easily as you gave it.
- Legal obligation — to keep accounting records and to respond to lawful requests.
How long we keep it
We keep personal data only as long as we need it, and we delete or anonymise it after that.
- Account and content — for as long as your account is open, and for 30 days after you close it so an accidental closure can be undone.
- Correspondence — for two years from the last message, so we have context if you come back to us.
- Billing and accounting records — for six years, as UK tax law requires.
- Server and security logs — for 90 days.
- Cookie consent records — for as long as the consent cookie lasts, so we can show what you chose.
Who we share it with
We do not sell personal data, and we do not share it for anyone else’s marketing. We use a small number of providers to run the service; each processes personal data only on our instructions, under written terms meeting Article 28 of the UK GDPR. They are listed in the subprocessor table below.
We may also disclose personal data where the law requires it, to establish or defend legal claims, or to a buyer if the business is sold — in which case we will tell you first.
Subprocessors
| Subprocessor | Purpose | Location | Transfer safeguard | Data |
|---|---|---|---|---|
| Resend | Transactional email delivery | United States | UK Addendum to the EU SCCs | Recipient email address and message content |
| Supabase | Managed PostgreSQL database hosting | United Kingdom | No transfer — processed in the UK | All application data, including account details and submitted content |
| Vercel | Application hosting, content delivery and file storage | United States | UK Addendum to the EU SCCs | IP address, request metadata and server logs; uploaded media stored in Vercel Blob |
International transfers
We are based in the United Kingdom and process personal data here wherever we can. Some of the providers we rely on operate outside the UK.
Where personal data is transferred outside the UK, we rely on one of the safeguards permitted by Chapter V of the UK GDPR: UK adequacy regulations, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. The safeguard applying to each provider is named in the subprocessor table, and we carry out a transfer risk assessment before relying on any of them.
You can ask us for a copy of the safeguards in place for a particular transfer by writing to [email protected].
Your rights
You have the following rights over the personal data we hold about you. Exercising any of them is free, and we respond within one month.
- Access my dataArticle 15
- Get a copy of the personal data we hold about you, and an explanation of how we use it.
- Correct my dataArticle 16
- Have inaccurate personal data corrected, or incomplete data completed.
- Delete my dataArticle 17
- Have your personal data erased. We may need to keep some records where the law requires it — we will tell you if so.
- Restrict processingArticle 18
- Ask us to stop using your data while a dispute about it is resolved.
- Export my dataArticle 20
- Receive the data you gave us in a structured, machine-readable format, or have it sent to another provider.
- Object to processingArticle 21
- Object to processing based on our legitimate interests, or to direct marketing — which we stop on request, always.
- Human review of an automated decisionArticle 22
- Ask a person to review a decision made about you by automated means, and contest the outcome.
- Withdraw consentArticle 7(3)
- Withdraw consent you previously gave. Withdrawal is as easy as giving it and does not affect processing before it.
Exercise any of these through the data rights request centre. You can also complain to the Information Commissioner’s Office (ICO) at any time, and you do not have to raise it with us first.
Cookies
We use a small number of cookies. Necessary ones are always on; analytics and marketing cookies are set only if you agree. Our Cookie Policy lists every one, and you can change your choice at any time using “Cookie preferences” in the footer of any page.
Automated decisions
We do not make decisions producing legal or similarly significant effects about you by automated means alone. Where a product uses AI to assist a decision, our AI Policy explains what it does and how to ask for a person to review it.
Children
Our services are not directed at children and we do not knowingly collect personal data from anyone under 13. If you believe a child has given us personal data, tell us at [email protected] and we will delete it.
How to contact us
- Privacy and data protection
- [email protected]
- General enquiries
- [email protected]
Change log
- v1.0 · 26 July 2026First published version.