DRAFT, FOR LEGAL REVIEW

This policy has not yet been reviewed by a solicitor. Placeholders in [square brackets] must be completed before publication.

Privacy Policy

Last updated: 16 July 2026 (draft)

1. Who we are

Retempla is operated by [COMPANY NAME], [REGISTERED ADDRESS] ("we", "us"). For your account and usage data we are the controller under UK GDPR. For the content of the documents you upload we act as a processor on your behalf: your documents are yours, and we process them only on your instructions, that is, to perform the conversions you request.

2. What we process

  • Account data: your email address. That is the only personal detail an account requires (sign-in is passwordless).
  • Your documents: the templates and documents you upload, and the converted files, reports and workbooks produced from them.
  • Operational records: an append-only audit log of account activity (sign-in requests, sign-ins, uploads, conversions, downloads, deletions) including timestamps and IP addresses, kept for security and accountability.
  • Error reports: technical error details sent to our monitoring service, configured to exclude request bodies, cookies and personal data.

We do not sell your data, and we do not use the contents of your documents for anything other than the conversion you asked for. Your documents are never used to train AI models.

3. Lawful bases (UK GDPR)

  • Performance of a contract: providing the service: processing your documents, sending sign-in links and service emails such as job-completion notifications.
  • Legitimate interests: keeping the service secure: rate limiting, audit logging, error monitoring and abuse prevention.
  • Consent: where we ask for it explicitly; you can withdraw it at any time.

4. Subprocessors

We use a small number of service providers to run Retempla. Each one sees only what its role requires:

Provider Purpose What it processes
Railway Application hosting and database All service data in transit and at rest during processing
Cloudflare R2 File storage Your uploaded and converted files (deleted after at most 30 days)
Anthropic Optional AI formatting analysis Document content, only when AI features are used for a conversion
Resend Transactional email Your email address and the content of service emails
Paddle Payment processing (prospective: listed ahead of billing launch, not yet active) Billing details, once self-serve billing launches
Google Analytics Website visitor measurement, only with your consent Public-site page visits, approximate location and device type; no document content and nothing from the signed-in application
Sentry Error monitoring Technical error details; no document content, request bodies or cookies

We will update this list before adding or replacing a subprocessor that handles your data.

5. Retention

  • Documents and converted results: deleted automatically after at most 30 days; every deletion is logged. You can delete files sooner at any time.
  • Account data: kept until you delete your account, which removes your files and data immediately.
  • Audit and security records: retained for as long as needed for security and legal accountability.

6. International transfers

Some subprocessors may process data outside the UK. Where they do, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. [FOR LEGAL REVIEW: confirm the transfer mechanism for each subprocessor and the hosting region.]

7. Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict and port your personal data, and to object to processing based on legitimate interests. To exercise any of these, email [CONTACT EMAIL]. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

8. Security

How we protect your documents and account, including encryption, access controls, file isolation and automatic deletion, is described in detail on our security page.

9. Cookies

We use as few cookies as we can, and we ask before setting any that are not strictly necessary.

Cookie Purpose Consent needed Expires
docubrand_session Keeps you signed in. Without it the service cannot work. No, strictly necessary When your session ends
retempla_consent Remembers whether you accepted or declined analytics, so we stop asking. No, strictly necessary 6 months
_ga, _ga_* Google Analytics. Counts visits and shows us which pages are read, so we can improve them. Yes. Set only if you click Accept Up to 2 years

Analytics is genuinely optional. If you decline, or simply ignore the banner, no Google script is loaded and no analytics cookie is created. Declining costs you nothing: every part of the service works the same either way.

Analytics runs on our public website only. It is switched off once you are signed in, so the pages where your documents, batches and templates appear are never reported to Google.

To change your mind at any time, use the Cookie settings link at the bottom of any public page. You can also delete cookies in your browser settings, and browsers offer their own controls for blocking them.

10. Changes and contact

If we make material changes to this policy we will notify account holders by email. Questions and requests: [COMPANY NAME], [REGISTERED ADDRESS], [CONTACT EMAIL].