Privacy policy DRAFT
Draft prepared 17 July 2026 — to be reviewed by legal counsel before public launch.
1. Who this policy covers
This policy is issued by Numiko Ltd (“Numiko”, “we”, “us”), a company registered in England and Wales, [TO BE COMPLETED — REGISTERED ADDRESS]. It covers Team Portal, our client-collaboration portal for agencies.
Team Portal involves two different relationships, and this policy is honest about which one applies where. For visitors to this marketing site and anyone requesting a trial or demo, Numiko is the data controller for the details you give us. Once an agency (“customer organisation”) is using the product with its own clients and staff, that customer organisation decides what goes into the portal and who can see it — Numiko processes that data on the customer's behalf and instructions, as a data processor. Where a section below applies to one role and not the other, it says so.
2. What we collect
Depending on how you use Team Portal, we collect:
- Account details — name, email address, job title and the organisation you belong to, for anyone with a login.
- Content — messages, uploaded files, tasks and comments that your organisation's users add to the portal.
- Usage and access logs — sign-ins, file downloads, IP address and browser/device information, kept for security monitoring and to support your own audit needs (see Retention, below).
- Billing details — the plan and billing contact for a paying organisation. Card numbers are handled entirely by Stripe, our payment processor; they never reach our own servers (see Sub-processors, below).
- A single session cookie — used only to keep you signed in. We do not run analytics, advertising or third-party tracking cookies on the portal or on this marketing site.
3. Why we process it (legal basis)
We rely on: performance of a contract, to provide the service an organisation has signed up for; legitimate interests, to keep the service secure, investigate misuse and maintain the access/audit logs described below; and consent, for optional features an organisation actively switches on, such as AI-drafted activity summaries (see Sub-processors).
Where a customer organisation's own clients or staff use the portal, that organisation is generally responsible for the lawful basis it relies on towards its own people; we process that data on its instructions as processor, not as a party who decides why it is collected.
4. Sub-processors and third parties
We use a small number of specialist providers to run the service. We never sell personal data, and third-party integrations (the last row below) are only ever contacted if and when your organisation chooses to connect them.
| Sub-processor | What it does | Where | Applies to |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage, session/cache storage, and sending/receiving portal email | Primary data in Western Europe; some operational tokens and caching on Cloudflare's global edge network (see §5) | All customers |
| Stripe, Inc. | Payment processing and subscription billing | Processes card details directly — they never touch our servers | Paying customers |
| Anthropic, PBC | Optional AI-drafted summaries of a week's portal activity | USA | Only organisations that switch this feature on; every draft is reviewed by someone on your team before a client sees it |
| Atlassian, Float, Slack (and similar tools you connect) | Read-only display, inside the portal, of your own data from tools you already use (e.g. Jira, Jira Service Management, Confluence, Float, Slack notifications) | Wherever that provider hosts your account | Only if and when your organisation chooses to connect that integration |
5. Where data is stored
Our primary databases and file storage run on Cloudflare in the Western Europe region. Some supporting infrastructure — session tokens, short-lived caches of connected-tool data, and content delivery — runs on Cloudflare's global edge network by design, so the service loads quickly wherever your users are. This edge layer holds operational tokens and temporary cached copies, not your organisation's primary records.
6. How long we keep it
We keep data for as long as your organisation's account is active, plus the following after that or after a specific item is removed:
- Deleted files — kept in backup for 30 days after deletion, then permanently removed.
- Database backups — nightly exports are retained for 84 days, giving a recovery window if something needs restoring.
- Access and security logs (sign-ins, downloads, admin actions) — kept on a rolling 400-day basis, to investigate suspicious activity and support your own audit requirements.
- Account and content data — retained for the life of your subscription. On cancellation, see “Data ownership, export and deletion” in our Terms of service: we provide an export on request and then delete your organisation's data.
Today, trimming these periods is a manual process carried out by our team rather than a fully automated job for every category — we are honest about that so it isn't mistaken for more than it is.
7. Your rights
Under UK GDPR, you have the right to ask for: access to the personal data we (or, where we are a processor, your organisation) hold about you; correction of inaccurate data; erasure; restriction of processing; a portable copy of your data; and to object to certain processing. If your organisation's admin manages your account, the fastest route is usually to ask them directly, since they control your access. You can also contact us (see “Contact”, below) and we will action or forward the request. This is currently a manual process on our side rather than a fully self-service one — we aim to respond within a reasonable time and will keep you informed.
If you are unhappy with how a request has been handled, you have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO).
8. Security measures
- Tenant isolation — every organisation's data is scoped at the database query level, so one organisation cannot see another's.
- Encrypted integration credentials — API keys and similar credentials you provide for connected tools are encrypted at rest using AES-256-GCM.
- Encryption in transit — all traffic to and from the portal uses TLS (HTTPS).
- Passwordless sign-in — accounts use one-time email magic links; we do not store passwords, because there isn't one to store.
- Access and audit logging — sign-ins, file downloads and administrative actions are logged, as described in §6.
To report a suspected security issue, contact us at the address in “Contact”, below.
9. International transfers
Our primary data stays in Western Europe. Two things involve a transfer outside the UK/EEA:
- Anthropic (AI summaries) is based in the USA. This only applies to organisations that have switched the feature on, and the transfer is safeguarded by UK International Data Transfer Addendum / EU Standard Contractual Clauses.
- Stripe (payments) may process billing information outside the UK/EEA as part of running global payment infrastructure, under its own standard contractual safeguards.
10. Changes to this policy
If we make a material change to this policy, we will update the date at the top of this page and, where the change is significant, notify customer organisations by email or an in-product notice before it takes effect.
11. Contact
For privacy questions or to make a data request, contact privacy@teamportal.site. By post: Numiko Ltd, [TO BE COMPLETED — REGISTERED ADDRESS].