Privacy policy
Last updated 1 September 2026 · Effective On publication, following legal review · Version 1.0-draft
Draft — not yet reviewed by counsel.
This document is published so it can be read and corrected. It has not been through legal review and it does not yet bind anyone. If you are evaluating Rutba and need agreed terms, ask us and we will tell you where the review stands.
The short version
1. Two different roles, and why it matters
Almost every complaint about a SaaS privacy policy comes from these two being run together, so this policy separates them and says which section applies to which.
Where we are the controller. Personal data about our customers and visitors: who signed up, who is billed, who raised a ticket, who read which page. We decide why and how it is processed. That is what the rest of this document is about.
Where we are the processor. Personal data your organization puts into the products — your customers, your staff, your suppliers, your correspondence. You decide why and how; we act on your instructions and nothing else. The data processing agreement is the contract for that, and the sub-processor list names everyone involved.
Rutba of Registered address available on request is the controller for the first, and the processor for the second.
2. What we collect
- Account data — your name, work email, the organization you belong to, your role in it, and your authentication data. Passwords are stored only as a hash; nobody here can read one.
- Subscription and billing data — what you subscribed to, invoices, payment status, and your billing address and VAT number. Card details are handled by our payment processor and never reach our systems.
- Enquiry data — what you told us when you asked for a quote or a demo: what you run today, how many people, what you are trying to change.
- Support and feedback data — the tickets you raise, the feedback you post, and our replies.
- Usage and technical data — IP address, browser and device, pages visited, and the security logs a platform has to keep. Administrative actions and support access are recorded in an audit trail.
We do not ask for special category data about you, and you should not send us any. If you do, we will delete it.
3. Why, and on what legal basis
| What for | Basis |
|---|---|
| Creating and running your account and organization | Performance of the contract |
| Billing you, and collecting what is owed | Performance of the contract; legal obligation for tax records |
| Answering enquiries and quoting | Steps taken at your request before entering a contract |
| Support, and telling you about changes that affect your service | Performance of the contract |
| Keeping the platform secure, and investigating abuse | Legitimate interests — running a service other customers can rely on |
| Understanding which pages get read, in aggregate | Consent, given through the cookie banner and withdrawable at any time |
| Telling you about products related to what you bought | Legitimate interests, with an unsubscribe link in every message |
We do not sell personal data, and we do not use it for advertising. We do not use it to train machine-learning models.
6. Where it is processed
Primarily in the United Kingdom and the European Economic Area. Where a processor is outside those, the transfer relies on UK adequacy regulations, the International Data Transfer Agreement, or the EU Standard Contractual Clauses with a transfer risk assessment.
The sub-processor list names the processing location for each entry, and says plainly where a location is still being confirmed rather than implying it is settled.
7. How long we keep it
| What | How long |
|---|---|
| Account data | While the organization is live, then 30 days |
| Invoices and tax records | Six years after the financial year they fall in, because the law requires it |
| Enquiries that did not become customers | 24 months |
| Support tickets and feedback | Three years |
| Security and audit logs | 12 months |
| Backups | 35 days, after which deleted data ages out of them |
Deletion means deletion. The 35-day backup window is why a deletion request is completed rather than instantaneous, and we say so rather than claiming otherwise.
8. How it is protected
TLS 1.3 in transit and AES-256 at rest. Single sign-on with multi-factor authentication. Access follows organization roles, so revoking a person is one action rather than one per product. Administrative actions and support access are written to an audit trail you can export.
The trust centre has the fuller picture, including our compliance position stated honestly — what we are engineered against, and what we are certified against, which are not the same thing.
If a breach affects your personal data and is likely to result in a risk to you, we will notify the Information Commissioner’s Office within 72 hours of becoming aware, and tell you without undue delay where the risk is high.
9. Your rights
Under UK and EU GDPR you can ask us to:
- tell you what we hold about you, and give you a copy
- correct it if it is wrong
- delete it, where we have no overriding reason to keep it
- restrict or object to how we use it, including profiling
- send it to you or another provider in a portable format
- withdraw consent, where consent is what we relied on
Write to privacy@rutba.io. We respond within one month and we do not charge. If your request concerns data your employer put into Rutba, we will point you to them — under section 1 they decide, not us — and we will help them answer you.
10. Children
Rutba is business software and is not directed at children. We do not knowingly collect personal data from anyone under 16 in the course of our own processing. If you believe we have, tell us and we will delete it.
11. Changes to this policy
Every version carries a version number and a date. Where a change materially affects you we will tell you before it takes effect rather than relying on you noticing the date.
12. Contact and complaints
Rutba, Registered address available on request. Privacy questions and rights requests: privacy@rutba.io.
If you are not satisfied with our answer you can complain to the Information Commissioner’s Office in the UK, or to your local supervisory authority in the EEA. We would rather you came to us first, and we would rather you did both than neither.