Rutba

Legal

Privacy policy

Last updated 1 September 2026 · Effective On publication, following legal review · Version 1.0-draft

Draft — not yet reviewed by counsel.

This document is published so it can be read and corrected. It has not been through legal review and it does not yet bind anyone. If you are evaluating Rutba and need agreed terms, ask us and we will tell you where the review stands.

The short version

This policy covers personal data about you — the people who visit the site, sign up, get invoiced and ask for help. It is a short list: your name, your work contact details, what you bought, and how you use the site. We do not sell it, we do not use it to advertise, and we do not train models on it. The data your business puts into Rutba is a different thing under the law, and the data processing agreement governs it — there, you decide and we follow.

1. Two different roles, and why it matters

Almost every complaint about a SaaS privacy policy comes from these two being run together, so this policy separates them and says which section applies to which.

Where we are the controller. Personal data about our customers and visitors: who signed up, who is billed, who raised a ticket, who read which page. We decide why and how it is processed. That is what the rest of this document is about.

Where we are the processor. Personal data your organization puts into the products — your customers, your staff, your suppliers, your correspondence. You decide why and how; we act on your instructions and nothing else. The data processing agreement is the contract for that, and the sub-processor list names everyone involved.

Rutba of Registered address available on request is the controller for the first, and the processor for the second.

2. What we collect

  • Account data — your name, work email, the organization you belong to, your role in it, and your authentication data. Passwords are stored only as a hash; nobody here can read one.
  • Subscription and billing data — what you subscribed to, invoices, payment status, and your billing address and VAT number. Card details are handled by our payment processor and never reach our systems.
  • Enquiry data — what you told us when you asked for a quote or a demo: what you run today, how many people, what you are trying to change.
  • Support and feedback data — the tickets you raise, the feedback you post, and our replies.
  • Usage and technical data — IP address, browser and device, pages visited, and the security logs a platform has to keep. Administrative actions and support access are recorded in an audit trail.

We do not ask for special category data about you, and you should not send us any. If you do, we will delete it.

3. Why, and on what legal basis

What forBasis
Creating and running your account and organizationPerformance of the contract
Billing you, and collecting what is owedPerformance of the contract; legal obligation for tax records
Answering enquiries and quotingSteps taken at your request before entering a contract
Support, and telling you about changes that affect your servicePerformance of the contract
Keeping the platform secure, and investigating abuseLegitimate interests — running a service other customers can rely on
Understanding which pages get read, in aggregateConsent, given through the cookie banner and withdrawable at any time
Telling you about products related to what you boughtLegitimate interests, with an unsubscribe link in every message

We do not sell personal data, and we do not use it for advertising. We do not use it to train machine-learning models.

4. Cookies and analytics

This site sets nothing that follows you until you agree to it. If you decline, it stays that way, and the analytics tag is never loaded. The cookies page lists exactly what is set, by whom, and for how long — and if that table and the site ever disagree, the table is the bug.

5. Who we share it with

Only with the processors we need to run the business, each under a contract that limits them to our instructions. They are the same organisations named on the sub-processor list, which covers both roles in section 1 so there is one place to look rather than two.

We will also disclose data where the law requires it, and we will tell you when we are permitted to.

If the business is sold or reorganised, data moves with it — and you will be told before it does, in time to object or leave.

6. Where it is processed

Primarily in the United Kingdom and the European Economic Area. Where a processor is outside those, the transfer relies on UK adequacy regulations, the International Data Transfer Agreement, or the EU Standard Contractual Clauses with a transfer risk assessment.

The sub-processor list names the processing location for each entry, and says plainly where a location is still being confirmed rather than implying it is settled.

7. How long we keep it

WhatHow long
Account dataWhile the organization is live, then 30 days
Invoices and tax recordsSix years after the financial year they fall in, because the law requires it
Enquiries that did not become customers24 months
Support tickets and feedbackThree years
Security and audit logs12 months
Backups35 days, after which deleted data ages out of them

Deletion means deletion. The 35-day backup window is why a deletion request is completed rather than instantaneous, and we say so rather than claiming otherwise.

8. How it is protected

TLS 1.3 in transit and AES-256 at rest. Single sign-on with multi-factor authentication. Access follows organization roles, so revoking a person is one action rather than one per product. Administrative actions and support access are written to an audit trail you can export.

The trust centre has the fuller picture, including our compliance position stated honestly — what we are engineered against, and what we are certified against, which are not the same thing.

If a breach affects your personal data and is likely to result in a risk to you, we will notify the Information Commissioner’s Office within 72 hours of becoming aware, and tell you without undue delay where the risk is high.

9. Your rights

Under UK and EU GDPR you can ask us to:

  • tell you what we hold about you, and give you a copy
  • correct it if it is wrong
  • delete it, where we have no overriding reason to keep it
  • restrict or object to how we use it, including profiling
  • send it to you or another provider in a portable format
  • withdraw consent, where consent is what we relied on

Write to privacy@rutba.io. We respond within one month and we do not charge. If your request concerns data your employer put into Rutba, we will point you to them — under section 1 they decide, not us — and we will help them answer you.

10. Children

Rutba is business software and is not directed at children. We do not knowingly collect personal data from anyone under 16 in the course of our own processing. If you believe we have, tell us and we will delete it.

11. Changes to this policy

Every version carries a version number and a date. Where a change materially affects you we will tell you before it takes effect rather than relying on you noticing the date.

12. Contact and complaints

Rutba, Registered address available on request. Privacy questions and rights requests: privacy@rutba.io.

If you are not satisfied with our answer you can complain to the Information Commissioner’s Office in the UK, or to your local supervisory authority in the EEA. We would rather you came to us first, and we would rather you did both than neither.