Draft for review. This document has not yet been reviewed by a solicitor and may change before Tenvara is generally available.
This notice explains how Tenvara collects and uses personal data when you visit www.tenvara.io or kb.tenvara.io, create an account, buy a subscription or get in touch with us. It does not cover data inside a customer's Tenvara instance: where we host Tenvara, we process that data on the customer's behalf under our data processing agreement, and where a customer self-hosts, we do not process it at all.
Who we are
The controller of your personal data is [Company legal name, company number and registered office to be confirmed] ("Tenvara", "we", "us"). We are based in the United Kingdom and handle personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and under the EU General Data Protection Regulation (EU GDPR) where it applies to people in the European Economic Area.
For anything about privacy, email privacy@tenvara.io. [EU representative under Article 27 EU GDPR, if required, to be confirmed.]
What we collect
Information you give us
| Category | Examples | When |
|---|---|---|
| Account details | Name, work email address, company name, password (stored only as a hash), two-factor settings | When you create an account |
| Order and billing details | Billing contact, billing address, VAT or tax number, plan, quantities, currency, order and invoice history | When you buy or change a subscription |
| Payment details | Card or bank details | Collected and held by Stripe, not by us. We see only the card brand, last four digits and expiry date |
| Enquiries and demo requests | Name, email, company, phone number if given, number of technicians or endpoints, your message | When you use the contact or demo form |
| Support correspondence | Emails and messages you send us and our replies | When you contact us |
Information we collect automatically
| Category | Examples | Why |
|---|---|---|
| Server logs | IP address, date and time, page requested, browser user agent, response code | To run the website securely and investigate faults and abuse |
| Session and security cookies | A session identifier and a CSRF token | To keep you signed in and protect forms. See our cookie policy |
| Knowledge base feedback | Whether an article was helpful, the article, any comment you add, and a one-way hash of your IP address combined with a secret key | To improve articles and stop the same visitor voting repeatedly. We cannot turn the hash back into your IP address |
| Display preference | Light or dark theme, stored in your browser only | So the site remembers your choice. It is never sent to us |
We do not use analytics, advertising or tracking cookies, and we do not build profiles of visitors.
Self-hosted licence check-ins
A self-hosted Tenvara instance checks its licence with us once a day. The check-in contains the licence key, an instance identifier, the software version and usage counts (such as the number of technicians and endpoints). It contains no customer data and no personal data about your staff or clients. We link it to your account to manage your licence and billing.
Why we use it and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Creating and running your account, providing the subscription you ordered, licence management, taking payment and sending invoices | Contract (to perform our agreement with your organisation, or take steps at your request before entering into it) and, for individuals acting for an organisation, our legitimate interests in dealing with our customers |
| Answering enquiries and demo requests | Legitimate interests in responding to people who contact us about Tenvara |
| Service emails, such as receipts, security notices, planned maintenance and changes to our terms | Contract and legitimate interests |
| Occasional product news to existing customers, with an unsubscribe link in every email | Legitimate interests and, where required, the soft opt-in under the Privacy and Electronic Communications Regulations 2003 |
| Keeping the website and our systems secure, preventing fraud and abuse | Legitimate interests |
| Improving the knowledge base and website | Legitimate interests |
| Keeping accounting and tax records | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests |
Where we rely on legitimate interests, we have balanced them against your rights and you can object at any time (see Your rights). We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
How long we keep it
| Data | Retention |
|---|---|
| Account details | For as long as your account is open, then 12 months after it closes, unless needed longer for the reasons below |
| Orders, invoices and billing records | Six years from the end of the financial year they relate to, as required for UK tax and company records |
| Enquiries and demo requests that do not lead to a subscription | 24 months from our last contact |
| Support correspondence | Three years from the end of the conversation |
| Server logs | 30 days, longer only where needed to investigate a specific security incident |
| Knowledge base feedback | 24 months |
| Licence check-in records | For the life of the subscription plus 12 months |
Who we share it with
We do not sell personal data. We share it only with service providers who handle it for us under contract, and where the law requires.
| Recipient | What they do | Location |
|---|---|---|
| Stripe | Payment processing, subscriptions, invoicing and tax calculation (Stripe Tax) | United States, Ireland and other locations |
| Microsoft | Email (Microsoft 365), including sending account and service emails | United Kingdom, European Economic Area and United States |
| [Hosting provider to be confirmed] | Hosting the website and our systems | [Location to be confirmed] |
| Cloudflare | DNS, content delivery and protection against attacks. Traffic to our sites passes through Cloudflare | Global network |
We may also share information with professional advisers (such as accountants and lawyers), with authorities where the law requires it, or with a buyer or successor if our business is sold or reorganised, in which case this notice will continue to apply to your data.
International transfers
Some of the providers above process data outside the UK and the European Economic Area, including in the United States. Where that happens, we rely on:
- adequacy regulations or decisions, including the UK Extension to the EU-US Data Privacy Framework and the EU-US Data Privacy Framework where the recipient is certified; or
- the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum, or the UK International Data Transfer Agreement, together with any supplementary measures needed.
You can ask us for a copy of the relevant safeguards at privacy@tenvara.io.
Security
We protect personal data with encryption in transit (TLS), encryption of stored secrets, access controls with two-factor authentication for our staff, and logging of administrative access. Passwords are stored only as salted hashes. No system is completely secure, but we work to keep your data safe and will tell you and the regulator about a personal data breach where the law requires.
Your rights
Under UK GDPR and EU GDPR you have the right to:
- access the personal data we hold about you and get a copy;
- rectification of inaccurate or incomplete data;
- erasure of your data in certain circumstances;
- restriction of processing in certain circumstances;
- object to processing based on legitimate interests, and to direct marketing at any time;
- data portability, to receive data you gave us in a structured, machine-readable format where processing is based on contract or consent; and
- withdraw consent at any time where we rely on consent.
To use any of these rights, email privacy@tenvara.io. We will reply within one month, which may be extended by two further months for complex requests, in which case we will tell you why. We may need to confirm your identity first. There is normally no fee.
If your request is about data inside an MSP's Tenvara instance (for example, you are a client of an MSP that uses Tenvara), please contact that MSP directly, as they control that data. If you contact us, we will pass your request on to them.
Complaints
If you are unhappy with how we have handled your personal data, please contact us first at privacy@tenvara.io so we can try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority:
- website: ico.org.uk/make-a-complaint
- phone: 0303 123 1113
- post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
If you are in the European Economic Area, you can also complain to the data protection authority in the country where you live or work.
Changes to this notice
We may update this notice from time to time. The date at the top shows when it was last changed. If we make significant changes, we will tell account holders by email before they take effect.