DRAFT, FOR LEGAL REVIEW
This policy has not yet been reviewed by a solicitor. Placeholders in [square brackets] must be completed before publication.
Privacy Policy
Last updated: 16 July 2026 (draft)
1. Who we are
Retempla is operated by [COMPANY NAME], [REGISTERED ADDRESS] ("we", "us"). For your account and usage data we are the controller under UK GDPR. For the content of the documents you upload we act as a processor on your behalf: your documents are yours, and we process them only on your instructions, that is, to perform the conversions you request.
2. What we process
- Account data: your email address. That is the only personal detail an account requires (sign-in is passwordless).
- Your documents: the templates and documents you upload, and the converted files, reports and workbooks produced from them.
- Operational records: an append-only audit log of account activity (sign-in requests, sign-ins, uploads, conversions, downloads, deletions) including timestamps and IP addresses, kept for security and accountability.
- Error reports: technical error details sent to our monitoring service, configured to exclude request bodies, cookies and personal data.
We do not sell your data, and we do not use the contents of your documents for anything other than the conversion you asked for. Your documents are never used to train AI models.
3. Lawful bases (UK GDPR)
- Performance of a contract: providing the service: processing your documents, sending sign-in links and service emails such as job-completion notifications.
- Legitimate interests: keeping the service secure: rate limiting, audit logging, error monitoring and abuse prevention.
- Consent: where we ask for it explicitly; you can withdraw it at any time.
4. Subprocessors
We use a small number of service providers to run Retempla. Each one sees only what its role requires:
| Provider | Purpose | What it processes |
|---|---|---|
| Railway | Application hosting and database | All service data in transit and at rest during processing |
| Cloudflare R2 | File storage | Your uploaded and converted files (deleted after at most 30 days) |
| Anthropic | Optional AI formatting analysis | Document content, only when AI features are used for a conversion |
| Resend | Transactional email | Your email address and the content of service emails |
| Paddle | Payment processing (prospective: listed ahead of billing launch, not yet active) | Billing details, once self-serve billing launches |
| Google Analytics | Website visitor measurement, only with your consent | Public-site page visits, approximate location and device type; no document content and nothing from the signed-in application |
| Sentry | Error monitoring | Technical error details; no document content, request bodies or cookies |
We will update this list before adding or replacing a subprocessor that handles your data.
5. Retention
- Documents and converted results: deleted automatically after at most 30 days; every deletion is logged. You can delete files sooner at any time.
- Account data: kept until you delete your account, which removes your files and data immediately.
- Audit and security records: retained for as long as needed for security and legal accountability.
6. International transfers
Some subprocessors may process data outside the UK. Where they do, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. [FOR LEGAL REVIEW: confirm the transfer mechanism for each subprocessor and the hosting region.]
7. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict and port your personal data, and to object to processing based on legitimate interests. To exercise any of these, email [CONTACT EMAIL]. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
8. Security
How we protect your documents and account, including encryption, access controls, file isolation and automatic deletion, is described in detail on our security page.
9. Cookies
We use as few cookies as we can, and we ask before setting any that are not strictly necessary.
| Cookie | Purpose | Consent needed | Expires |
|---|---|---|---|
docubrand_session |
Keeps you signed in. Without it the service cannot work. | No, strictly necessary | When your session ends |
retempla_consent |
Remembers whether you accepted or declined analytics, so we stop asking. | No, strictly necessary | 6 months |
_ga, _ga_* |
Google Analytics. Counts visits and shows us which pages are read, so we can improve them. | Yes. Set only if you click Accept | Up to 2 years |
Analytics is genuinely optional. If you decline, or simply ignore the banner, no Google script is loaded and no analytics cookie is created. Declining costs you nothing: every part of the service works the same either way.
Analytics runs on our public website only. It is switched off once you are signed in, so the pages where your documents, batches and templates appear are never reported to Google.
To change your mind at any time, use the Cookie settings link at the bottom of any public page. You can also delete cookies in your browser settings, and browsers offer their own controls for blocking them.
10. Changes and contact
If we make material changes to this policy we will notify account holders by email. Questions and requests: [COMPANY NAME], [REGISTERED ADDRESS], [CONTACT EMAIL].