Last updated 10 September 2026
When you use IniDeck to work with your clients, you are the controller of their personal data and we are the processor. This sets out how we handle that.
Roles
You decide what client data goes into IniDeck and what we do with it. We process it only on your documented instructions, which include your use of the product.
What we process
Contact details, business records, documents and communications relating to your clients and the people you work with.
For the duration of your subscription, and the limited retention period afterwards described in our privacy policy.
Security measures
Encryption in transit and at rest. Access controls limiting who at IniDeck can reach production data, with the presumption being nobody.
Personal data is removed from any request sent to third-party language models and replaced with placeholders before it leaves our systems.
Logging and monitoring, with an incident response process and notification to you without undue delay.
Sub-processors
We use a small number of sub-processors for hosting, payments, messaging delivery and monitoring. A current list is available on request, and we will give notice before adding a new one.
International transfers
Where data moves between countries, we rely on recognised transfer mechanisms and require equivalent protection from every sub-processor.
Your rights as controller
You may audit our compliance on reasonable notice. We will help you respond to data subject requests and to regulators.
On termination, we will return or delete personal data at your direction, except where we must keep it by law.