[ Legal · Privacy ]
Privacy Policy
What we collect, why we collect it, how long we keep it, and what you can ask us to do with it. Written to be read rather than to be survived.
Last updated: 26 August 2026
01Who we are
DormData is a technology company. We design, build and operate our own platforms, we publish our own consumer applications through our studio, we build and run products jointly with partner companies, and we deliver software engineering, infrastructure, automation and growth services for other organisations.
This policy explains what personal data we collect, why we collect it, how long we keep it and what you can ask us to do with it. It covers this website, our marketing communications, our own platforms and applications, and the personal data we handle on behalf of clients. Where a client engages us to process data on their behalf, that client is the data controller and we act as a processor under a separate written agreement; this policy then describes our own practices rather than theirs.
For anything in this policy, you can reach us at hello@dormdata.com.
02The data we collect
We collect only what a specific purpose requires, and we separate the categories so that one does not quietly become another. The categories below are the complete set.
- Information you give us directly: your name, email address, telephone number, company, and anything you write in an enquiry, proposal request or job application.
- Account data for our platforms and applications: the identifiers needed to create and secure an account, authenticate you, and restore access if you lose it.
- Product usage data: the actions taken inside a product, such as features used, progress recorded, content created and settings chosen, so the product can function and so we can see what is genuinely working.
- Technical data: IP address, device and browser type, operating system, referring page, and timestamps, collected automatically in server logs and used for security, abuse prevention and diagnostics.
- Communications: correspondence with our team, support conversations, and the delivery and engagement status of emails we send you.
- Recruitment data: your CV, work history, portfolio links and interview notes, if you apply to work with us.
- Client and partner data: contract, billing and contact details relating to the organisations we work with, and any data made accessible to us in the course of an engagement under the terms of that engagement.
03How we use it
Every use of personal data at DormData maps to a purpose we can state plainly. We do not sell personal data, we do not trade it, and we do not use the personal data we process for clients to train models for anyone else.
- To provide, secure and maintain our websites, platforms and applications, including authentication, backup and fraud prevention.
- To respond to your enquiries, prepare proposals, and manage the commercial relationship if you become a client or partner.
- To improve our products, using aggregated and, wherever it is possible to do so, anonymised or pseudonymised data.
- To send service messages you cannot opt out of while you hold an account, such as security notices, billing information and material changes to terms.
- To send marketing communications where you have asked for them or where we have a legitimate interest in contacting you in a business capacity, always with a working unsubscribe link.
- To meet legal, accounting and regulatory obligations, and to establish, exercise or defend legal claims.
04Legal bases for processing
Where the UK GDPR, the EU GDPR or an equivalent regime applies, we rely on one of the following legal bases for each processing activity, and we can tell you which one applies to any specific use if you ask.
- Performance of a contract: providing the products and services you or your organisation have asked us for.
- Legitimate interests: running, securing and improving our business, provided your rights and freedoms do not override those interests. We document this assessment.
- Consent: optional analytics, marketing where consent is required, and any use of data outside the purposes described here. You can withdraw consent at any time.
- Legal obligation: tax, accounting, employment and other statutory requirements.
07International transfers
We operate internationally, so personal data may be processed in a country other than the one you are in. Where data leaves the UK or the European Economic Area, we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses or the UK International Data Transfer Addendum, together with technical measures such as encryption in transit and at rest.
We assess each transfer before it begins, and we will not move data to a jurisdiction where we cannot maintain a standard of protection substantially equivalent to the one it had before.
08How long we keep it
We keep personal data for as long as the purpose that justified collecting it still exists, and then we delete it or irreversibly anonymise it. In practice that means: enquiry correspondence for up to twenty four months from our last exchange; account and product data for the life of the account and up to ninety days afterwards to allow for recovery and dispute resolution; contract, billing and tax records for the period our accounting and statutory obligations require, typically seven years; unsuccessful job applications for twelve months unless you ask us to keep them longer; and server and security logs for up to twelve months.
Where we act as a processor for a client, retention follows the client's instructions and the engagement agreement, and data is returned or destroyed at the end of the engagement.
09How we protect it
Security is engineering work, not a policy statement. We run least-privilege access controls with individual named accounts and mandatory multi-factor authentication, encrypt data in transit and at rest, isolate production environments from development, keep audit logs of administrative access, patch dependencies on a schedule and review our infrastructure regularly.
Access to production data is limited to the smallest number of engineers who need it, is logged, and is removed the day it is no longer required. Backups are encrypted and restoration is tested rather than assumed.
No system is beyond compromise. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within seventy two hours of becoming aware of it, and we will notify affected individuals directly where the risk is high.
10Your rights
Depending on where you live, you have some or all of the following rights over your personal data. We do not charge for exercising them, and we will respond within one month, extending only where a request is genuinely complex and telling you if we do.
- Access: obtain confirmation of whether we hold data about you, and a copy of it.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: have your data deleted where we no longer have grounds to keep it.
- Restriction: limit how we use your data while an issue is being resolved.
- Portability: receive the data you provided in a structured, machine-readable format, or have it sent to another provider.
- Objection: object to processing based on legitimate interests, and to direct marketing at any time and without qualification.
- Withdrawal of consent: withdraw consent for any processing that relies on it, without affecting processing that already took place.
- Non-discrimination: where the CCPA or a comparable regime applies, we will not degrade the service you receive because you exercised a right.
11Children and education settings
Some of our platforms are used in education, which means students may be under the age of majority in their country. Where a school, college or other institution deploys one of our products, that institution is the data controller and is responsible for obtaining any consent the law requires; we act on its documented instructions.
We do not knowingly collect personal data directly from a child under 13 without appropriate consent, we do not use student data for advertising or profiling, and we do not sell it. If you believe a child's data has reached us without a lawful basis, contact us and we will investigate and delete it promptly.
12Changes to this policy
We update this policy when our practices change or when the law does. The date at the top always reflects the current version. If a change materially affects how we handle personal data we already hold, we will tell you directly rather than relying on you noticing the date.
13Contact and complaints
Write to hello@dormdata.com and address your message to the privacy team. Tell us what you want to know or what you want changed, and we will confirm receipt.
If you are not satisfied with our response, you have the right to complain to your local data protection authority. In the United Kingdom that is the Information Commissioner's Office; in the European Economic Area it is the supervisory authority in your country of residence, place of work, or the place where the issue arose. We would rather you came to us first, and we take that route seriously.
