Skip to content
Self-hosted or hosted: Compare the two

Legal

Privacy notice

Last updated 26 September 2026

Draft for review. This document has not yet been reviewed by a solicitor and may change before Tenvara is generally available.

This notice explains how Tenvara collects and uses personal data when you visit www.tenvara.io or kb.tenvara.io, create an account, buy a subscription or get in touch with us. It does not cover data inside a customer's Tenvara instance: where we host Tenvara, we process that data on the customer's behalf under our data processing agreement, and where a customer self-hosts, we do not process it at all.

Who we are

The controller of your personal data is [Company legal name, company number and registered office to be confirmed] ("Tenvara", "we", "us"). We are based in the United Kingdom and handle personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and under the EU General Data Protection Regulation (EU GDPR) where it applies to people in the European Economic Area.

For anything about privacy, email privacy@tenvara.io. [EU representative under Article 27 EU GDPR, if required, to be confirmed.]

What we collect

Information you give us

Category Examples When
Account details Name, work email address, company name, password (stored only as a hash), two-factor settings When you create an account
Order and billing details Billing contact, billing address, VAT or tax number, plan, quantities, currency, order and invoice history When you buy or change a subscription
Payment details Card or bank details Collected and held by Stripe, not by us. We see only the card brand, last four digits and expiry date
Enquiries and demo requests Name, email, company, phone number if given, number of technicians or endpoints, your message When you use the contact or demo form
Support correspondence Emails and messages you send us and our replies When you contact us

Information we collect automatically

Category Examples Why
Server logs IP address, date and time, page requested, browser user agent, response code To run the website securely and investigate faults and abuse
Session and security cookies A session identifier and a CSRF token To keep you signed in and protect forms. See our cookie policy
Knowledge base feedback Whether an article was helpful, the article, any comment you add, and a one-way hash of your IP address combined with a secret key To improve articles and stop the same visitor voting repeatedly. We cannot turn the hash back into your IP address
Display preference Light or dark theme, stored in your browser only So the site remembers your choice. It is never sent to us

We do not use analytics, advertising or tracking cookies, and we do not build profiles of visitors.

Self-hosted licence check-ins

A self-hosted Tenvara instance checks its licence with us once a day. The check-in contains the licence key, an instance identifier, the software version and usage counts (such as the number of technicians and endpoints). It contains no customer data and no personal data about your staff or clients. We link it to your account to manage your licence and billing.

Why we use it and our lawful bases

Purpose Lawful basis
Creating and running your account, providing the subscription you ordered, licence management, taking payment and sending invoices Contract (to perform our agreement with your organisation, or take steps at your request before entering into it) and, for individuals acting for an organisation, our legitimate interests in dealing with our customers
Answering enquiries and demo requests Legitimate interests in responding to people who contact us about Tenvara
Service emails, such as receipts, security notices, planned maintenance and changes to our terms Contract and legitimate interests
Occasional product news to existing customers, with an unsubscribe link in every email Legitimate interests and, where required, the soft opt-in under the Privacy and Electronic Communications Regulations 2003
Keeping the website and our systems secure, preventing fraud and abuse Legitimate interests
Improving the knowledge base and website Legitimate interests
Keeping accounting and tax records Legal obligation
Establishing, exercising or defending legal claims Legitimate interests

Where we rely on legitimate interests, we have balanced them against your rights and you can object at any time (see Your rights). We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

How long we keep it

Data Retention
Account details For as long as your account is open, then 12 months after it closes, unless needed longer for the reasons below
Orders, invoices and billing records Six years from the end of the financial year they relate to, as required for UK tax and company records
Enquiries and demo requests that do not lead to a subscription 24 months from our last contact
Support correspondence Three years from the end of the conversation
Server logs 30 days, longer only where needed to investigate a specific security incident
Knowledge base feedback 24 months
Licence check-in records For the life of the subscription plus 12 months

Who we share it with

We do not sell personal data. We share it only with service providers who handle it for us under contract, and where the law requires.

Recipient What they do Location
Stripe Payment processing, subscriptions, invoicing and tax calculation (Stripe Tax) United States, Ireland and other locations
Microsoft Email (Microsoft 365), including sending account and service emails United Kingdom, European Economic Area and United States
[Hosting provider to be confirmed] Hosting the website and our systems [Location to be confirmed]
Cloudflare DNS, content delivery and protection against attacks. Traffic to our sites passes through Cloudflare Global network

We may also share information with professional advisers (such as accountants and lawyers), with authorities where the law requires it, or with a buyer or successor if our business is sold or reorganised, in which case this notice will continue to apply to your data.

International transfers

Some of the providers above process data outside the UK and the European Economic Area, including in the United States. Where that happens, we rely on:

  • adequacy regulations or decisions, including the UK Extension to the EU-US Data Privacy Framework and the EU-US Data Privacy Framework where the recipient is certified; or
  • the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum, or the UK International Data Transfer Agreement, together with any supplementary measures needed.

You can ask us for a copy of the relevant safeguards at privacy@tenvara.io.

Security

We protect personal data with encryption in transit (TLS), encryption of stored secrets, access controls with two-factor authentication for our staff, and logging of administrative access. Passwords are stored only as salted hashes. No system is completely secure, but we work to keep your data safe and will tell you and the regulator about a personal data breach where the law requires.

Your rights

Under UK GDPR and EU GDPR you have the right to:

  • access the personal data we hold about you and get a copy;
  • rectification of inaccurate or incomplete data;
  • erasure of your data in certain circumstances;
  • restriction of processing in certain circumstances;
  • object to processing based on legitimate interests, and to direct marketing at any time;
  • data portability, to receive data you gave us in a structured, machine-readable format where processing is based on contract or consent; and
  • withdraw consent at any time where we rely on consent.

To use any of these rights, email privacy@tenvara.io. We will reply within one month, which may be extended by two further months for complex requests, in which case we will tell you why. We may need to confirm your identity first. There is normally no fee.

If your request is about data inside an MSP's Tenvara instance (for example, you are a client of an MSP that uses Tenvara), please contact that MSP directly, as they control that data. If you contact us, we will pass your request on to them.

Complaints

If you are unhappy with how we have handled your personal data, please contact us first at privacy@tenvara.io so we can try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority:

  • website: ico.org.uk/make-a-complaint
  • phone: 0303 123 1113
  • post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

If you are in the European Economic Area, you can also complain to the data protection authority in the country where you live or work.

Changes to this notice

We may update this notice from time to time. The date at the top shows when it was last changed. If we make significant changes, we will tell account holders by email before they take effect.