Legal
Privacy Policy
Version 2026-09-16 · Last updated 16 September 2026
PRIVACY POLICY#
Enodo Tech Ltd
Last updated: [16/09/2026]
Enodo Tech Ltd (“Enodo”, “we”, “us”, or “our, a company registered in England and Wales (company number 17200793) with its registered office at 61 Bridge Street, Kington, United Kingdom, HR5 3DJ, is committed to protecting the privacy of individuals whose personal data we handle. This Privacy Policy explains what personal data we collect, why, how we use it, and what rights you have.
This Privacy Policy applies to: (a) visitors to our website at enodotech.io; (b) prospective and current customer contacts, including individuals who sign up for a trial, register an account, or otherwise engage with us commercially; and (c) other individuals who contact us directly. It does not cover personal data that Enodo processes on behalf of a customer as part of the contract risk analysis Service itself (for example, personal data contained within documents a customer uploads for analysis) — that processing is governed by the Data Processing Agreement between Enodo and the relevant customer, not by this Privacy Policy. If you are an employee, contractor, or counterparty whose data appears in a document uploaded to the Service by one of our customers, please refer to that customer’s own privacy notice, as they are the controller of that data.
1. Who We Are#
1.1For the purposes described in this Privacy Policy, Enodo Tech Ltd is the data controller of your personal data.
1.2If you have any questions about this Privacy Policy or how we handle personal data, you can contact us at info@enodotech.io
2. Personal Data We Collect#
2.1We collect personal data in the following ways:
(a)Information you provide directly. Name, job title, work email address, phone number, company name, and any other information you provide when you register for an account, request a demo, sign up for a trial, contact our support team, subscribe to marketing communications, or otherwise communicate with us.
(b)Account and usage data. Login credentials, account settings, and information about how you use the Service (e.g. features accessed, pages viewed, timestamps of activity), collected to operate, secure, and improve the Service.
(c)Technical data. IP address, browser type and version, device information, operating system, and general location (derived from IP address), collected automatically when you visit our website or use the Service.
(d)Billing data. Where you purchase a paid subscription, billing name, address, and payment details, processed on our behalf by our payment processor, Stripe (see Section 4).
(e)Cookies and similar technologies. See Section 5 (Cookies) below.
(f)Information from third parties. We may receive limited information about you from business contact data providers, publicly available sources (e.g. LinkedIn, Companies House), or from a colleague who invites you to join their Enodo account.
2.2Providing certain personal data (such as your name and work email address) is necessary to create an account and enter into a contract with us for the Service; if you do not provide it, we may be unable to register your account or provide the Service to you. Provision of other personal data described in this Section 2 (for example, marketing preferences) is optional.
3. How We Use Personal Data and Our Legal Basis#
3.1We use personal data for the following purposes, relying on the legal bases indicated:
-
To provide, operate, and maintain the Service to our customers, and to process payment for paid subscriptions — necessary for the performance of a contract, or to take steps at your request prior to entering into a contract.
-
To manage your account, provide customer support, and respond to enquiries — performance of a contract, or our legitimate interest in providing a responsive service.
-
To send you marketing communications about Enodo’s products and services — with your consent, or on the basis of our legitimate interest in promoting our business to existing business contacts, where permitted by applicable law and always with an option to opt out.
-
To monitor, analyse, and improve the Service, our website, and our marketing, including using aggregated or de-identified usage data — our legitimate interest in developing and improving our business.
-
To maintain the security and integrity of the Service, including detecting and preventing fraud, abuse, or unauthorised access — our legitimate interest in protecting our systems and our customers, and compliance with legal obligations.
-
To comply with applicable law, respond to lawful requests from public authorities, and establish, exercise, or defend legal claims — compliance with a legal obligation, or our legitimate interest in protecting our legal position.
3.2Where we rely on legitimate interests, we have considered that our processing does not override your interests or fundamental rights and freedoms. You may ask us for more detail about this balancing assessment by contacting us using the details in Section 1.2.
3.3You have an unconditional right to object to your personal data being used for direct marketing purposes, including any related profiling, at any time and free of charge, by contacting us using the details in Section 1.2. This right is separate from, and broader than, the general right to object described in Section 8.
4. How We Share Personal Data#
4.1We do not sell personal data. We share personal data covered by this Privacy Policy (that is, our own business, marketing, account, and billing data — not Customer Personal Data processed via the Service, which is addressed in our Data Processing Agreements with customers) with the service providers listed below. Each provider processes personal data on our behalf solely in accordance with the data processing agreement we have in place with it:
-
Infomaniak — email hosting
-
Brevo — transactional email platform
-
Stripe — payment processing
4.2Stripe additionally acts as an independent controller, rather than solely as our processor, for certain purposes such as fraud prevention and regulatory compliance; see Stripe’s own privacy policy at stripe.com/privacy for that portion of processing.
4.3In connection with the purposes described in Section 4.2, Stripe may carry out automated decision-making (for example, automatically declining or flagging a payment) as part of its fraud prevention and compliance checks. Enodo does not itself carry out any processing described in this Privacy Policy that involves solely automated decision-making producing legal or similarly significant effects on you; if you have questions about a decision made by Stripe, please contact Stripe directly using the details in its privacy policy.
4.4We may also share personal data with:
-
Professional advisers, including lawyers, auditors, and insurers, where necessary in connection with the operation of our business;
-
A buyer or prospective buyer if we sell, merge, or otherwise transfer all or part of our business or assets, subject to appropriate safeguards;
-
Regulators, law enforcement, or other third parties where required by law or to protect our rights, property, or safety, or that of our customers or others.
4.5A current list of the service providers referred to in this Section 4 is detailed in clause 4.1. Please note that this list is separate from the Sub-processor list in our Data Processing Agreement with customers, which covers the different providers involved in delivering the Service itself — see Section 4.1 of our DPA for that list.
5. Cookies#
5.1Our website and Service use cookies and similar technologies to operate core functionality, remember your preferences, and (where you consent) understand how visitors use our site so we can improve it.
5.2You can control cookies through your browser settings and, where applicable, through the cookie preference tool on our website. Disabling certain cookies may affect the functionality of the website or Service. For more detail, see our Cookie Policy on our website.
6. International Transfers#
6.1Our service providers may store and process personal data outside the UK or European Economic Area. Where this occurs, we rely on a transfer mechanism recognised under UK data protection law — such as an applicable adequacy regulation, the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or a recognised certification framework — as set out in the relevant provider’s own data processing agreement. You may request further details of the specific safeguard that applies to a particular provider by contacting us using the details in Section 1.2.
7. Data Retention#
7.1We retain personal data for as long as necessary to fulfil the purposes described in this Privacy Policy, including to provide the Service, comply with our legal and regulatory obligations, resolve disputes, and enforce our agreements. Retention periods vary depending on the type of data and the purpose for which it is used; for example, account data is generally retained for the duration of the customer relationship plus a limited period afterwards to comply with legal and accounting obligations, while marketing contact data is retained until you unsubscribe or we no longer have a lawful basis to retain it.
8. Your Rights#
8.1Subject to applicable law, you may have the right to: request access to your personal data; request correction of inaccurate data; request erasure of your data; request restriction of, or object to, our processing of your data; request portability of your data; and withdraw consent at any time where we rely on consent.
8.2To exercise any of these rights, please contact us using the details in Section 1.2. We may need to verify your identity before responding, and there are circumstances in which we may not be able to fulfil a particular request (for example, where we are required to retain data to comply with a legal obligation).
8.3If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk, or with your local supervisory authority if you are located outside the UK.
9. Security#
9.1We maintain appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction, as further described in the Data Processing Agreement available to our customers. No system can be guaranteed completely secure, and we cannot guarantee the absolute security of your data.
10. Children’s Privacy#
10.1The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.
11. Changes to This Privacy Policy#
11.1We may update this Privacy Policy from time to time. We will post the updated version on our website with a revised “last updated” date, and where changes are material, we will provide additional notice (for example, by email).
12. Contact Us#
12.1If you have questions, concerns, or requests relating to this Privacy Policy or our handling of personal data, please contact us at info@enodotech.io.
Contact: [info@enodotech.io] | Enodo Tech Ltd