Privacy notice

Draft for review

This document is a working draft prepared in-house. It has not been reviewed or approved by a solicitor and it is not yet in force. Anything in [square brackets] is a placeholder for a fact still to be confirmed. Do not rely on it, and do not treat it as legal advice. Questions to hello@restorable.cloud.

Version: draft. Effective date: [effective date]. Last updated: [effective date].

1. Who we are

Brindleford Technologies Ltd, a company registered in England and Wales with company number [company number], registered office [registered office address], operates Restorable. For the personal data described in section 3 we are the controller. Our registration with the Information Commissioner's Office is [ICO registration number]. Privacy questions go to [DPO or privacy contact] or hello@restorable.cloud.

2. The two roles, and why the distinction matters

Restorable sits in a chain. Reading this notice is easier if you keep the two roles apart.

We are the controller of your account data
The personal data of the people at the managed service provider who use Restorable: their names, work email addresses, roles, sign-in records and billing contact details. This notice covers that data, and section 3 sets it out.
We are a processor, or a sub-processor, of backup data
The Microsoft 365 content and metadata belonging to the MSP's own clients. The MSP decides what is backed up, for how long and to where. Depending on the MSP's own arrangements the MSP is either the controller of that data or itself a processor for its client, in which case we are a sub-processor. We act on the MSP's instructions and do not use that data for our own purposes. The data processing agreement governs it.

If you are an end user whose mailbox or files have been backed up, we are not your point of contact and we cannot lawfully act on your request directly. Please contact the organisation that manages your Microsoft 365, or its IT provider. They can reach us and we will help them.

3. What we hold as controller, and why

Personal data we process as controller, with the purpose and lawful basis under UK GDPR Article 6.
DataPurposeLawful basis
Name, work email address, role, password hash, second-factor secret and recovery codesCreating and securing accounts, signing people in, sending service emailPerformance of a contract
Company name, billing contact, billing address, VAT number, payment method type and the last four digits held by our payment processorInvoicing, taking payment, tax recordsPerformance of a contract, and legal obligation for tax records
Sign-in records, session and device information, IP addressesSecurity, abuse prevention, investigating incidentsLegitimate interests in keeping the service secure
Audit log entries naming the user who took an action, including searches with a term, restores, exports and key operationsAccountability inside the customer's own team, and our own security investigationsPerformance of a contract, and legitimate interests
Application and server logs, which may incidentally include identifiersDiagnosing faults and monitoring the serviceLegitimate interests in running a working service
Emails you send us, and our repliesSupport and correspondencePerformance of a contract, and legitimate interests
Business contact details you give us in an enquiryReplying to youLegitimate interests

We do not run advertising, we do not profile you, and we take no automated decision that has a legal or similarly significant effect on anyone. We do not sell personal data, and we do not send marketing email to your users unless they have asked for it.

4. What we process on an MSP's behalf

Where we act as processor or sub-processor, two things are worth stating plainly because they are easy to get wrong.

  • Backup content (the messages, attachments and files themselves) is encrypted and stored in the MSP's own S3-compatible bucket, with a provider the MSP chooses and pays. We do not hold a copy. The encryption keys are wrapped both under a key we hold, so that unattended backups can run, and under a passphrase only the MSP knows.
  • Backup metadata is held in our database and is not encrypted at the field level: message subjects, sender and recipient addresses and display names, folder paths, file and folder names, sizes, dates and hashes. This is what makes search work. Message bodies and file contents are never indexed.

Categories of data subject, categories of personal data and the security measures we apply are set out in the annexes to the data processing agreement.

5. This website

This website sets no cookies, runs no analytics, and loads nothing from any third party. Requests to it are recorded in ordinary web server logs, which include your IP address, the page requested, the time and your user agent, kept for [web log retention period] for security and diagnostics. See the cookies page. The console at app.restorable.cloud sets a session cookie when you sign in, which is strictly necessary for it to work.

6. Who else sees it

We share personal data with the processors listed on the sub-processors page: our hosting provider, our transactional email provider, our payment processor and our DNS and download provider. Each is bound by a contract that limits them to processing on our instructions.

We also disclose personal data where the law requires it, to our professional advisers under duty of confidence, and to a buyer or successor if the business is sold, in which case you would be told.

7. International transfers

The service is hosted in the European Union (France). Some of our processors are established outside the United Kingdom and the European Economic Area, principally in the United States. Where personal data is transferred there we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on the EU Standard Contractual Clauses, together with the additional measures described on the sub-processors page: [confirm the transfer mechanism relied on for each processor].

Backup data goes to the storage provider and region the MSP chooses. That choice, and any transfer it involves, is the MSP's decision and its responsibility.

8. How long we keep it

  • Account data: for as long as the account is open, then [account data retention period] after it closes.
  • Billing and tax records: six years from the end of the accounting period, as UK tax law requires.
  • Audit log: [audit log retention period].
  • Server and application logs: [log retention period].
  • Backup metadata and index: as long as the MSP's policy and instructions require, then removed by the purge process. Deletion is deliberate, explicit and audited rather than automatic, so that a deleted user's backup is not lost by accident.
  • Backup content: in the MSP's bucket, under the MSP's control, subject to the MSP's retention policy and its provider's own lifecycle rules.

9. Security

Encryption in transit and at rest, per-client encryption keys, role-based access control, second-factor authentication, tenant scoping enforced in the data layer, an audit log, and a documented offline recovery path. The security page describes all of it, including what we can and cannot decrypt.

10. Your rights

Where we are the controller you have the right to be informed, to access your data, to have inaccurate data corrected, to erasure, to restrict or object to processing, and to data portability, in each case subject to the conditions in UK GDPR. To exercise a right, write to [DPO or privacy contact] or hello@restorable.cloud. We will respond within one month and will tell you if we need longer. We may ask you to confirm who you are.

Where we act as processor, we pass requests we receive to the MSP and assist them in answering, as the data processing agreement requires. We do not answer them ourselves.

If you are unhappy with how we have handled your data, please tell us first. You can also complain to the Information Commissioner's Office at ico.org.uk, by telephone on 0303 123 1113, or at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

11. Changes to this notice

We will update this notice when what we do changes, and we will email account owners about a change that materially affects them. The effective date at the top says when the current version took effect.