Privacy

What we do with data.

Written plainly, and only about things that are actually true of the product today.

Draft โ€” not yet legal advice

This is a working draft written by the team that built the product, so that the facts are right before a lawyer makes it binding. It has not been reviewed by counsel and it is not yet a privacy notice you can rely on. Sections marked “to be completed by counsel” are deliberately blank.

001 / Who we are

The controller

Legal entity name, registered address, company number, the jurisdiction it is established in, and (where required) an EU/UK representative and a data-protection contact. None of this is stated anywhere on this site yet.

002 / What we process

Five kinds of data

  • Account data. Your name, email address, and either a password stored as a hash or a link to your Google account if you sign in that way. Plus which organisation and workspaces you belong to, and your role in each.
  • The content you put in a workspace. Documents, pages, uploaded media, content models, and anything your own editors write. We store and serve it; we do not mine it.
  • Form submissions. If you build a form with Contentive, whatever a visitor types into it is stored in your workspace. You decide what that form asks for, so you decide what is collected.
  • Site analytics. If analytics is switched on for a site, we count page views. It is cookieless: no cookie is set, no identifier follows a visitor between sites or between days. A visitor is counted using a salted hash that is rotated daily, and the IP address is used only to derive a country and is then discarded. Because of that there is no consent banner.
  • Operational logs. Request logs, error reports and audit records of who changed what in a workspace — the things needed to keep the service running and to answer “who published this?”.
003 / Our role

Controller and processor

For your account data we decide the purposes, so we act as the controller. For the content you and your clients put into a workspace we act on your instructions, so you are the controller and we are the processor.

Confirm that characterisation, and supply the data-processing terms it requires (a DPA, the standard contractual clauses where relevant, and the sub-processor notification commitment below).

004 / Cookies

One cookie, and it signs you in

The Studio sets a session cookie so that you stay signed in. There are no advertising cookies, no third-party trackers, and — as above — the analytics are cookieless.

Confirm whether that single functional cookie needs a cookie notice in each market we operate in, and the exact wording if so.

005 / Sub-processors

Who else touches it

Contentive is built on third-party infrastructure. The categories below are the ones the product depends on today; each named supplier, its purpose and its location must be confirmed and then kept current, because a published sub-processor list is a commitment.

  • Application and database hosting.
  • Object storage for uploaded media and built sites.
  • CDN, DNS and TLS for published sites.
  • Transactional email delivery.
  • Payment processing, once billing is live.

The named list — supplier, purpose, processing location — plus the notice period we commit to before adding or changing one.

006 / How long we keep it

Retention

Content, media and form submissions are kept for as long as the workspace exists, because that is the point of a CMS. Delete a workspace and its content is deleted with it, after a grace period intended to make an accidental deletion recoverable.

The actual numbers, none of which are settled: the deletion grace period, how long encrypted backups persist beyond it, how long raw analytics events are kept before only aggregates remain (still an open question in our analytics spec), and how long operational logs are retained.

007 / Your rights

Access, export, deletion

You can export a workspace — content and schema together — at any time; portability is a product feature, not a favour. You can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it.

Requests go through our contact page.

The statutory response window we commit to, how we verify who is asking, the escalation and complaint route, and the supervisory authority to name.

008 / Security

What we actually do

  • Traffic is encrypted in transit; stored data is encrypted at rest.
  • Every workspace’s data is isolated in the database itself using PostgreSQL row-level security, so isolation does not depend on application code being bug-free.
  • Passwords are stored only as hashes. Media is served over signed or public URLs, never shared credentials.
  • We are not certified against SOC 2 or ISO 27001, and we do not claim to be. A SOC 2 path is planned; a plan is not a certificate.

Breach-notification commitments and timelines, and whatever security statements we are prepared to stand behind contractually.

009 / Where it lives

International transfers

The regions data is stored and processed in, the transfer mechanism relied on for any cross-border processing, and whether region choice is offered to customers.

010 / Changes & contact

If this changes

We will date this page when it changes, and tell account owners by email when a change is material.

The notice address for privacy correspondence, and how much notice a material change gets.