Data handling

What happens to your file.

This page will state, in plain words, where an uploaded file goes, what is kept, for how long, and who can see it. The current privacy notice and data processing agreement apply until the wording here is approved.

Structure only. Policy wording pending approval.

This page shows what the data-handling statement will cover and the requirements it must meet. It is not the policy itself. The current privacy notice, terms and data processing agreement on the app remain the documents that apply.

What it will cover

Where it runs
Hosting provider and region. Today the application runs on Fly.io in London, as the privacy notice states.
The file itself
Read in memory during processing and never written to disk. Whether that stays true when scanning is added, and how any temporary file is deleted.
What is stored
Contact points, evidence and states in your private workspace. Whether the original row is kept, and for how long.
Who can see it
You, through your account. Any operator access, when, why, what is visible, and how it is logged.
What leaves the service
Nothing from the file to any third party by default. Header labels only, only when column mapping fails, only if that feature is on, as the privacy notice describes.
Backups
What is backed up, where, encrypted or not, and for how long. Today: rolling copies for no longer than 30 days, not client-side encrypted, as the privacy notice states.
Logs
What is logged about an upload. No contact details in application logs.

Requirements before this becomes policy

  • In placeRegion and provider named and true of the live service.
  • In placeRetention numbers pinned to the code that enforces them.
  • PendingOperator-access procedure written and reviewed.
  • PendingTemporary-file handling for scanning defined and tested.
  • PendingDecision on keeping the original row after an audit is bought.
  • PendingWording reviewed by the named privacy reviewer.

Until then: privacy notice · data processing agreement.