Skip to main content

Legal

Data handling & retention

Where your data lives, how we protect it, and exactly how long we keep each kind of thing. Security isn't a footnote here — it's part of the product.

Last updated .

A note on these dates. These policies were drafted before VOCABOTICS LTD was incorporated on 20 August 2026, and until 25 August 2026 they carried dates that predated the company they name as the contracting party and data controller. They were re-dated on that day, when the entity details on them were re-checked against the incorporation record. Nothing about the substance changed with the date; we are telling you because the old dates were not possible.

The short version

Your data lives on EU-based infrastructure we control. We encrypt it in transit and encrypt sensitive fields at rest, use short-lived signed links for anything gated, and keep data only as long as we genuinely need it. When it’s no longer needed, we delete or anonymise it. Below, each control says plainly whether it is in place today or planned — because a control you cannot demonstrate is not a control, and a security page that overstates is worse than one that is short.

Where data lives

Our primary database, queue, analytics and most application hosting are in the EU (Frankfurt region). A small number of trusted processors operate elsewhere for specific tasks; where any transfer outside the UK/EEA is involved it’s covered by appropriate safeguards (Standard Contractual Clauses or the UK International Data Transfer Addendum). The full list of who processes what, and where, is on our subprocessor page.

How we protect it

  • Encryption (in place) — TLS for everything in transit; encryption at rest, with additional encryption of sensitive fields.
  • Access control (in place) — least-privilege, role-based access. vocabotics currently has one sole director and no employees, so “staff access” today means one person’s access. We will say so here rather than imply a team we do not have.
  • Tamper-evident audit logs (planned, not yet built) — we intend security-relevant changes to be written to an append-only, hash-chained log so tampering is detectable. That log is designed and is not yet implemented. Until it is, do not rely on it, and we will not offer it as audit evidence.
  • Gated downloads (in place) — protected files are served via short-lived signed URLs, checked against your entitlements.
  • Backups & recovery (partly in place) — point-in-time backups are configured. We have not yet run and dated a restore drill, so we do not describe the restore process as tested. When we have run one, the date will appear here.
  • Network protection (in place) — a web application firewall, rate limiting and bot protection on sensitive endpoints (such as the quiz and lead forms), provided by the CDN and bot-protection processors named on our subprocessor page.

How long we keep it

We keep personal data only as long as we need it for the purpose it was collected, or as the law requires. As a guide:

  • Account data — for as long as your account is active, then deleted or anonymised within 90 days of closure (unless we must keep some of it for legal reasons).
  • Quiz, DIAGNOSE and plan data — kept while it’s useful to you and your account; deleted or anonymised on account closure or on request.
  • Billing and financial records — retained for up to 7 years, as tax and accounting law requires.
  • Email and newsletter contacts — kept until you unsubscribe or ask us to remove you; suppression records are kept so we don’t email you again by mistake.
  • Product analytics — pseudonymised event data retained for up to 14 months, and only captured with your consent.
  • Error and diagnostic logs — typically retained for up to 90 days.
  • Audit logs — retained longer for security and integrity; access is tightly controlled.

These are defaults; specific periods can vary where a legal obligation or a live dispute requires it. When a retention period ends, data is securely deleted or irreversibly anonymised.

Anonymisation

Where we keep data for longer-term insight — for example, to understand how SMEs adopt AI — we anonymise it first, so it can no longer be linked back to you. Anonymised, aggregated data is no longer personal data, but we still apply our Pledge: we only ever learn from consented inputs (see the AI-use disclosure).

Data breaches

We have a process to detect, contain and investigate security incidents. If a breach is likely to affect your rights, we’ll notify the relevant regulator within the legally required time and tell affected people without undue delay.

Your rights and contact

You can access, correct, export or delete your data at any time — see your privacy rights. For anything about how we handle or retain data, email privacy@vocabotics.com and a real person will answer.

Next step

Questions about any of this? We’d rather you ask than wonder.

    We use cookies.

    Data handling & retention · vocabotics