Privacy
notice.
What personal data we collect, why, who sees it, how long we keep it, and what you can ask of us. Version 1.0, effective 8 October 2026.
1. What this notice covers
1.1 This notice explains how we handle personal data when you visit ardaform.net, send us a message through one of its forms, or use the ArdaForm portal, HTTP API, device control plane and related services (the "Services", as defined in our terms and conditions). It is written under the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 ("PECR").
1.2 ArdaForm is a business-to-business platform. The people whose data we handle as controller are mostly people acting for a business: website visitors, people who contact us, the users and owners of customer accounts, billing contacts, and people who are invited into an account.
2. Data on customers' devices and apps — the customer is in charge
2.1 Our customers use ArdaForm to run their own applications on their own devices — tills, kiosks, signage, terminals. Anything those applications, devices, datasets, files, settings, logs and webhooks contain ("Customer Data") belongs to the customer. For personal data in Customer Data, the customer is the controller and we are its processor: we handle it only on the customer's instructions, under clause 8.2 and Schedule 1 of our terms.
2.2 So if you used a device, screen or app that runs on ArdaForm — for example you checked in at a gym, paid at a till or appear in a record a business keeps — this notice does not describe what happens to that data. Please contact the business that runs the device. It decides what is collected and why, and it is the one that must answer your request. If you contact us about such data, we will pass your request to that customer where we can identify it, and help it to respond.
3. The personal data we collect, and why
3.1 The table below lists what we collect as controller, where it comes from, what we use it for, and the lawful basis under Article 6 of the UK GDPR. Where the basis is legitimate interests, the interest is stated; you can object to processing on that basis (section 9).
| Who / what | Data | Why we use it | Lawful basis |
|---|---|---|---|
| Website visitors | Our web server's access log records the time, the page requested, the response, the referring page and your browser's user-agent string. Because every request reaches us through Cloudflare (section 6), the address in that log is Cloudflare's, not yours. Cloudflare itself sees your IP address and approximate location. | Serving the site, keeping it working, and detecting and stopping abuse. | Legitimate interests — running a secure, working website. |
| People who use the contact form | Name, email address, topic, subject and message — plus your IP address, which is added to the message we receive. | Replying to you and dealing with what you asked. The IP address helps us spot automated abuse of the form. | Legitimate interests — answering enquiries and protecting the form. If you are writing about entering a contract with us, also steps at your request before a contract. |
| People who apply for early access | Name, email address, company (optional), what you are building, fleet size, a description of your project, and your IP address. | Deciding whether and when to offer you access, and contacting you about it. | Steps at your request before entering a contract; legitimate interests for the IP address, as above. |
| Form abuse protection | A hashed form of your IP address and the times you submitted a form. | Limiting each connection to three submissions an hour. | Legitimate interests — preventing spam and abuse. |
| Account holders and users | Name, username, email address, mobile number (optional), password (stored only as a salted scrypt hash — we cannot read it), the account and projects you belong to, your role and permissions, your preferences, and when you agreed to our terms and verified your email address. | Creating and running your account, signing you in, controlling what you can see and do, and telling you about the service. | Contract, where you are our customer or a sole trader. Otherwise legitimate interests — providing the service your organisation has contracted for, to the people it authorises. |
| Invited users | The email address an account member invites, who invited it, and when the invitation was sent, accepted, revoked or expired. The link itself is stored only as a hash. | Sending and honouring the invitation. | Legitimate interests — letting our customer add the people it chooses. |
| Billing contacts | Billing name, billing email address, postal address, country, VAT number, company registration number, your package and price, and records of invoices and payments. | Charging for the Services, issuing receipts, keeping accounting and tax records. | Contract; legal obligation (accounting and tax law). |
| Card payments | Paid packages are paid by card when you order, and renew automatically. Card details go straight to Stripe — we never see or store your full card number. We receive from Stripe the payment's status, amount, date, the card's brand, last four digits and expiry, and Stripe's own identifiers for you and the payment. | Taking payment, renewing your subscription, handling refunds and disputes. | Contract; legal obligation (accounting and tax law). |
| GitHub connections (only if you connect one) | The GitHub installation id, the GitHub account or organisation name and whether it is a personal account or an organisation, who linked it and when. For each connected branch, the latest commit's id, message, author name and time, and the same for each release we pack. While you connect, GitHub gives us a short-lived token to confirm which installations you can manage; we use it once and do not store it. | Reading your repository and deploying it to your devices, and showing you which commit is where. | Contract / legitimate interests, as for account holders. Commit authors' names: legitimate interests — showing our customer where each release came from. |
| API keys | The key's name, who created it, when it was created, last used and revoked, its scopes, and its first eight characters. The key itself is stored only as a hash. | Authenticating calls to the API and letting you manage keys. | Contract / legitimate interests, as for account holders. |
| Support access | When our staff ask to look into your account, the request (who asked, why, who it was sent to) and your answer, including the time and the IP address it came from; and for each support session, who opened it, when it started and ended, and from which IP address. | Making sure we only enter an account with its owner's agreement, and keeping a record of when we did. | Legitimate interests — accountable, consent-based support access. |
| Security and operational logs | The portal, API and control plane log each request or connection with its time, the IP address it came from, and what was asked for. Each action on a device — a restart, a screenshot, a console command, a shell, a wipe — is recorded with the user who did it, the time and their IP address. Repeated failed sign-ins are counted by IP address. | Keeping the Services secure, investigating faults and misuse, blocking password guessing, and giving customers a trail of who did what to their devices. | Legitimate interests — the security and reliability of the Services and of our customers' devices. |
| Device records | For each enrolled device: its name, notes and location as typed by the customer; its hardware identifier, model, operating system, runtime version and diagnostic readings; when it was last seen; the IP address it connects from; and an approximate location (country, and region and town where available) taken from Cloudflare's view of that address. Devices are usually business equipment, but this can relate to a person — for example a sole trader's premises. | Enrolling, managing, updating and securing devices, and showing their health and approximate whereabouts to the customer. | Legitimate interests — operating the device management service our customers contract for. |
3.2 We do not ask for, and you should not send us, special category data (such as health information) or criminal offence data. We do not buy personal data or combine it with data from data brokers. We do not use any of it for advertising.
3.3 Where data comes from someone other than you — an account owner who invites you, Stripe, GitHub, or Cloudflare — it is the data listed above and nothing more.
3.4 We do not currently send marketing email. If that changes, we will do it only as PECR allows, and every message will tell you how to opt out.
3.5 You do not have to give us any of this data, but without the items marked as needed in a form or screen we cannot answer you, open an account, or take payment.
4. Cookies and similar technologies
4.1 This website sets no cookies and stores nothing in your browser. It runs no analytics, no advertising and no tracking, and it loads nothing from any other domain — no fonts, scripts or images from third parties. You can check the page source.
4.2 Cloudflare, which protects the site, may set a short-lived security cookie (for example __cf_bm or cf_clearance) if it decides a request might be automated and needs checking. It is used only to tell people from bots.
4.3 The portal uses only what it needs to work:
| Name | Type | Purpose | Lasts |
|---|---|---|---|
__Host-ardasid | Cookie (HttpOnly, Secure, SameSite) | A random identifier for your session. It carries no personal data itself. | Until you close the browser. The session behind it ends after inactivity. |
| Tab session id | Browser session storage | Keeps each browser tab's sign-in separate. | Until the tab is closed. |
| Captured device log lines | Browser session storage | Keeps log lines you are watching on a device screen while you move around the portal. | Until the tab is closed. |
4.4 All of these are strictly necessary to provide a service you have asked for, so under regulation 6(4) of PECR they do not need your consent and we do not show a cookie banner. If we ever add anything that is not strictly necessary, we will ask first.
5. Who we share personal data with
5.1 We do not sell personal data. We share it only with the service providers we need to run ArdaForm, who act as our processors under written terms unless stated otherwise:
- Hosting — IONOS, which provides the servers that run the website, portal, API, control plane, database and our mail server, in the United Kingdom.
- Network protection and object storage — Cloudflare, Inc. All traffic to ardaform.net and its subdomains passes through Cloudflare's network, and files stored in the Services are held in Cloudflare R2 object storage.
- Payments — Stripe. Stripe processes payment data on our behalf to take and refund payments. For some purposes — such as preventing fraud, meeting its own legal and regulatory obligations, and improving its services — Stripe acts as an independent controller, and its own privacy policy applies to that processing.
- Source code hosting — GitHub, Inc., only if you connect a GitHub account. We request what is needed to read the repositories you choose; GitHub's own privacy statement covers your account with it.
- Email — our own mail server, hosted in the UK, and the delivery service it uses to relay messages to outside addresses.
5.2 Account data is visible to the other members of the same customer account, according to the permissions the account owner sets.
5.3 We may also disclose personal data to professional advisers (lawyers, accountants, insurers) under a duty of confidentiality; to the police, regulators, courts or HMRC when the law requires it or to establish, exercise or defend legal claims; and to a buyer or successor if our business, or part of it, is sold or reorganised, who would have to use it in line with this notice.
6. International transfers
6.1 Our servers are in the United Kingdom. Some of our providers — Cloudflare, Stripe and GitHub — are based in the United States or operate global networks, so personal data may be processed outside the UK. Cloudflare in particular serves each request from the data centre nearest the visitor, and object storage may be located outside the UK.
6.2 Where personal data leaves the UK, we rely on one of the safeguards UK law allows: the UK Extension to the EU-US Data Privacy Framework, for US recipients certified under it; adequacy regulations, for countries the UK recognises as adequate; or the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as incorporated in the provider's data processing terms. You can ask us for more detail through the contact form.
7. How long we keep it
| Data | Kept for |
|---|---|
| Website access logs | 14 days, then deleted. |
| Contact form and early-access messages | 24 months after our last exchange, unless they become part of a customer relationship, in which case they are kept as account correspondence. |
| Form abuse protection (hashed IP and times) | No more than 24 hours. |
| Failed sign-in counter and lockout | 30 minutes. |
| Portal session | Ends after an hour of inactivity at most, when you sign out, or when you close the browser. |
| Account, user, invitation, GitHub connection, API key and device records | While the account is open. When it closes, you have 30 days to export Customer Data (terms clause 15.2); we then delete account data from our active systems, except what we must keep for the reasons below. |
| A device that removed itself | Its record is deleted 7 days later. |
| Billing, invoices and payment records | Six years from the end of the financial year they relate to, as tax and company law require. |
| Application logs (portal, API, control plane) | 90 days. |
| Device action audit trail and support access records | 12 months, or until the account is deleted if that is sooner — unless needed for an ongoing investigation or legal claim. |
| Backups | Overwritten on a rolling cycle of no more than 30 days. |
7.1 We may keep data longer where the law requires it, or where it is needed to establish, exercise or defend a legal claim, and only for as long as that lasts.
8. How we protect it
8.1 Every connection to the Services is encrypted in transit. Account passwords, API keys and invitation links are stored only as hashes. The portal delivers its screens over an encrypted channel after sign-in, our servers accept web traffic only from Cloudflare, and access to production systems is limited to the people who need it. Our security page describes the measures in more detail, including how devices are protected.
8.2 No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will tell the Information Commissioner within 72 hours where the law requires, and tell you without undue delay where the risk is high.
9. Your rights
9.1 Under the UK GDPR you have the right to:
- access the personal data we hold about you, and get a copy of it;
- have inaccurate data corrected and incomplete data completed;
- have your data erased in some circumstances;
- restrict how we use your data in some circumstances;
- object to our use of your data where we rely on legitimate interests — we will then stop unless we have compelling grounds that override yours, or need it for a legal claim;
- data portability — receive data you gave us, under a contract or with consent, in a structured, machine-readable form, or have it sent to someone else; and
- withdraw consent at any time, where we rely on it.
9.2 Many of these you can do yourself in the portal — correcting your name, email or mobile, for example. For anything else, send a request through the contact form, saying it is a privacy request and what you want. We may need to confirm your identity first, for example by replying to the email address on your account.
9.3 We will respond within one month of receiving your request. If a request is complex, or you have made several, we may extend that by up to two further months; if so, we will tell you within the first month and explain why. We do not charge, unless a request is manifestly unfounded or excessive.
9.4 Some rights have limits. For example, we cannot erase billing records we must keep by law, and if you are a user on someone else's account, the account owner controls parts of your record. Where we cannot do what you ask, we will say why.
10. Complaints
10.1 If you are unhappy with how we have handled your data, please tell us first through the contact form — we will acknowledge your complaint and look into it without undue delay.
10.2 You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office, at any time: online at ico.org.uk, by phone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
11. Automated decisions
11.1 We do not make decisions about people based solely on automated processing that have legal or similarly significant effects, and we do not profile people. Automatic security controls — such as pausing sign-in from an address after repeated failed attempts, or limiting how often a form can be sent — are temporary and do not decide anything about you as a person.
12. Children
12.1 ArdaForm is a service for businesses and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, please tell us and we will delete it.
13. Changes to this notice
13.1 We will update this notice when what we do with personal data changes. The version and effective date at the top and bottom of this page show which version you are reading. If a change matters to account holders, we will also tell them in the portal or by email before it takes effect.
Tominko Ltd · Company no. 12089741 · Registered in England and Wales · Version 1.0 · Effective 8 October 2026