170TARV / LEGAL & PRIVACY
Privacy policy
How website enquiries and customer workspace information are handled, and how to raise a privacy request.
Document version · 2026-10-03
Scope and responsibilities
This policy describes the public website and the distinction between website enquiries and the contracted 170tarv service. For website enquiries, the operator determines how contact information is used. Within a customer workspace, the customer ordinarily determines the purposes of evidence processing and 170tarv processes that data under its customer agreement and data processing terms. Separate responsibilities may apply to account security, billing and legal obligations.
Website information
The demo form collects your name, work email, organisation, preferred plan and optional message. Submission also records a timestamp and your response consent. An email-derived keyed hash supports request rate limits. Do not send credentials, sensitive incident evidence, special-category data or customer records through this form.
The form is for responding to an enquiry. It does not subscribe you to marketing. The website has no user accounts and does not receive privileged customer or staff cookies. Infrastructure may process network and request information to deliver pages, detect abuse and diagnose faults; deployment-specific log retention must be confirmed before launch.
Purposes and legal bases
Enquiry information is used to respond, discuss a proposed service and manage follow-up that you requested. Consent is recorded for responding through the form. Pre-contract steps and legitimate interests may apply to business correspondence, service security and abuse prevention where legally appropriate. Billing records may also be retained to meet legal obligations. We do not treat permission to answer an enquiry as permission for unrelated marketing.
Customer evidence
Authorised integrations can collect identities, roles, assets, alerts, events, tickets, changes and source metadata. Evidence records distinguish source, observed, ingested and decision times and link decisions to human notes and obligations. Raw payloads are preserved unchanged; normalised records are stored separately. Customer access is tenant-scoped and role-restricted. Staff evidence access requires an explicit, reasoned, time-limited and audited grant.
Service providers and transfers
The architecture uses Hetzner-hosted PostgreSQL, Cloudflare R2 for raw evidence, Stripe for payment and billing records, and Resend for configured transactional communications. Integrations depend on customer-authorised source vendors. Actual processing locations, subprocessors, transfer safeguards and contractual terms must be documented in the customer data processing agreement before production onboarding. This policy does not claim that all providers or data are confined to one country.
Retention
Public enquiry records are scheduled for deletion after 90 days. Delivery retries are bounded. Any ongoing commercial correspondence or legal records have their own documented retention basis. Customer evidence retention is governed by the agreed plan, retention policy and legal obligations; this website does not set a universal evidence retention period. Backup expiry and lawful retention holds must be covered by the customer agreement.
Your choices and rights
You may request access, correction, deletion, restriction or portability where applicable, object to certain processing, or withdraw response consent. Withdrawal does not undo earlier lawful processing. Use the contact page to request a private follow-up for a privacy enquiry; include only your business contact details and the type of request. Identity may need to be verified before information is disclosed. Workspace requests should normally go through your organisation’s authorised administrator.
You may complain to the competent data protection regulator, including the UK Information Commissioner where applicable. No contract removes statutory rights.
Security and changes
Access controls, separate session audiences, tenant isolation and attributable audit trails protect the service. Hashes verify preservation after capture, not source truth. No system is guaranteed invulnerable. Material policy changes will be versioned and communicated where required. Browser storage is explained in the cookie notice.