Privacy Policy
Last updated: 2026-08-04
This policy explains how Details ("we", "us") collects and processes personal data. This is a template you should have reviewed by qualified counsel before relying on it in production. Placeholders are marked in [square brackets].
1. Who we are
Details is operated by [Company Name], [registered address]. We are the data controller for information about our customers (firm owners and staff who sign up to use Details).
For personal data your firm processes about its own clients using Details, your firm is the controller and we act as a processor. See our Data Processing Addendum for details.
2. What data we collect
- Account data: name, email, encrypted password (or Google sign-in identifier).
- Firm data: firm name, currency, plan tier, billing status.
- Usage data: pages visited, features used, error logs (used to keep the service running).
- Customer content: clients, tasks, workflows, time entries and invoices you enter into Details.
- Consent records: which version of these policies you accepted and when.
3. Lawful bases (UK/EU GDPR)
We rely on contract to provide the service you signed up for, legitimate interests to keep the service secure and improve it, and consent for any optional analytics cookies.
4. Sub-processors
To deliver the service we use the following sub-processors:
- Supabase / AWS — database, authentication and file storage (EU region).
- Cloudflare — hosting and CDN.
- [Email provider] — transactional email.
5. International transfers
Where personal data is transferred outside the UK or EEA, we rely on Standard Contractual Clauses and equivalent safeguards.
6. Retention
Account data is retained while your account is active and for up to 90 days after deletion for backup rotation. Customer content is deleted within 30 days of your written deletion request, subject to legal obligations.
7. Your rights
You have the right to access, rectify, erase, restrict, port and object to processing of your personal data. Signed-in users can export their data and delete their account at Settings → Privacy. To exercise other rights, email privacy@example.com.
8. Security
We use TLS in transit, encryption at rest, HIBP checks on new passwords, row-level security in the database, and audit logging of admin actions.
9. Contact
Data protection queries: privacy@example.com. You have the right to complain to the ICO (UK) or your local supervisory authority.