Privacy policy

Last updated 2 August 2026

Draft — not yet in force. This document is a template. Anything shown as [ENTITY], [JURISDICTION] or [ADDRESS] has not been decided, and until it is, this page states an intention rather than a binding agreement.

This policy explains what [ENTITY] ("we") collects when you use cmykcloud, why we collect it, how long we keep it, and what you can ask us to do with it. We do collect personal data, we store it, and we use it to run the service. We do not sell it.

What we collect

  • Account details — your email address, your name if you give one, your password (stored only as a hash), and any second factor or passkey you register.
  • Sign-in activity — sessions, the applications you sign in to, and the approximate time and IP address of sign-in attempts. IP addresses are also used to rate limit sign-in attempts, which is how we defend the login page.
  • Organisation membership — the organisations you belong to and your role in each.
  • Content you create — whatever you enter into the applications you use, including contacts, messages and files.
  • An activity trail — a record of significant actions taken in your organisation: who did what, and when. See "The audit trail" below, because it behaves differently from everything else here.
  • Things you send us — the contents of the contact form and of an organisation request.

What we use it for

  • Operating the service, and letting you sign in to it.
  • Security: detecting and slowing down attacks on accounts, and investigating incidents.
  • Sending you messages the service exists to send, and replying when you contact us.
  • Diagnosing faults and understanding whether the service is working.

We do not sell personal data, and we do not use it to build advertising profiles. Access is limited to people who need it to operate the service.

How long we keep it

Account and content data is kept while your account exists. When an account is deleted it enters a short grace period, after which the personal data attached to it is removed or anonymised. Backups are kept for a limited period and are also encrypted, so deleted data may persist in a backup until that backup expires.

The audit trail, and why deletion works differently there

The activity trail is append-only and tamper-evident by design: entries are cryptographically chained, so an entry cannot be edited or removed without the chain reporting it. That is the entire point of an audit log — it is the record you consult when you suspect something was changed. It means we cannot quietly delete individual entries on request. Where we can, we remove or anonymise the personal details inside an entry rather than the entry itself.

Who else sees it

  • Your organisation. Owners and administrators of an organisation you belong to can see your membership, your role, and your activity within that organisation.
  • Service providers we use to run the service — hosting, object storage, and email delivery. They process data on our instructions.
  • Nobody else, unless we are legally required to disclose it.

Where it is stored

Data is stored on servers operated for us, and may be processed in a country other than the one you live in. Data in transit is encrypted, and credentials and other sensitive values are encrypted at rest.

Your choices

You can ask us for a copy of your data, ask us to correct it, or ask us to delete your account. Some of these rights depend on where you live; where they apply as legal rights, we honour them, and where they do not, we will still try to help. Requests that conflict with the audit trail are handled as described above. Contact us through the contact page, or at [ADDRESS].

Changes

If we change this policy in a way that materially affects you, we will say so on this page and update the date at the top. This policy is governed by the law of [JURISDICTION].