Privacy Policy
This policy explains what Eclypsion does with personal data when you use an Eclypsion ID account, a workspace, or this website. It is written for the person whose data it is, not for a compliance file, so it says what is stored, where it goes, and what is not yet finished.
1. Who we are
Eclypsion is a trading name of ECLYPSION LTD, a company registered in England and Wales under number 17469998, whose registered office is at 128 City Road, London, EC1V 2NX, United Kingdom. That is a service address rather than premises we occupy, but post sent there reaches us.
Unresolved
an email address that reaches us. Regulation 6 of the Electronic Commerce (EC Directive) Regulations 2002 and Article 13(1)(a) each require one, and the address filed at Companies House is a personal mailbox we will not publish here. A mailbox on our own domain is the outstanding piece.Unresolved
ICO registration number. The data protection fee is payable before processing starts and has not yet been paid. Incorporation did not change that: the fee is owed by whoever processes the data, and it falls due before the first account exists rather than after it.We are the controller for the processing this policy describes. Where a customer uses a product to work with data about their own people, they are the controller and we are their processor — section 2 sets out that line.
2. What this policy does not cover
When a customer uses Eclypsion CRM or Eclypsion Bots to work with data about their own contacts, employees or end-users, that customer decides what is collected and why. They are the controller; we act on their instructions as their processor. Ask them for their privacy notice, not us.
This policy covers your relationship with us: your account, your workspace, and this website.
3. What we collect, why, and for how long
| Data | Why | Lawful basis | Kept |
|---|---|---|---|
| Username and email address | To create the account, sign you in, and send you service messages | Contract | Until the account is erased |
| Company name, if you give one | To address you correctly | Contract | Until the account is erased |
| Password | To sign you in. Stored only as an Argon2id hash with a secret pepper, never as text | Contract | Until the account is erased |
| The country you are in, as you declare it | Sanctions screening — see section 4 | Legal obligation | Until the account is erased |
| Passkeys, authenticator secret, recovery codes | The sign-in methods you chose to add | Contract | Until you remove them, or the account is erased |
| Sessions: when issued, when last seen, a SHA-256 fingerprint of the token, your browser's User-Agent string, and a one-way keyed index of your IP address | To keep you signed in and to let you end a session you do not recognise | Contract | 30 days, then deleted automatically |
| Sign-in journal: the event, its time, the app involved, the User-Agent string, and the same one-way index of the IP address | To detect unauthorised access and to answer, within 72 hours of an incident, who got in and when | Legitimate interests | 180 days, then deleted automatically |
| Permissions you grant to an application: which app, which scopes, when granted, when withdrawn | To show you what you allowed and to prove the permission existed | Contract | Until the account is erased |
| Your Google account identifier, held only as a one-way index, if you sign in with Google | To recognise you on the next Google sign-in | Contract | Until you unlink Google, or the account is erased |
| Workspace membership, and the workspace journal of who was invited, joined, changed role or was removed | To run the workspace and let its administrator see who has access | Legitimate interests | The journal outlives the account; the person named in it is anonymised |
| Ledger entries, transactions and usage records | To account for money | Legal obligation | Six years. Once we are a company, paragraph 21 of Schedule 18 to the Finance Act 1998 requires records kept until the sixth anniversary of the end of the period a tax return may be required for; until then section 12B of the Taxes Management Act 1970 does the same work |
| Your settings: theme, type size, language, time zone, notifications | To apply your preferences in every product | Contract | Until the account is erased |
| The email address of someone you invite to a workspace | To deliver the invitation | Legitimate interests | The invitation expires after 7 days |
Email addresses, usernames, company names, the authenticator secret and the contents of a data export are encrypted in our database with AES-256-GCM. Email addresses are additionally searchable only through a one-way keyed index.
**What you have to give us.** An email address, a way to sign in, and the country you are in are required to enter into the contract — section 4 explains why the last one is not a formality. The company name is not. Nothing else is asked.
**When someone else gives us your address.** An invitation reaches you because a workspace administrator typed your address, not because you gave it to us. The invitation names them, names the workspace and links here, which is the notice Article 14 requires; the address goes when the invitation expires after 7 days.
4. The country you declare
UK sanctions law prohibits providing customer relationship management software and project management software to a person connected with Russia. That prohibition covers software delivered as a service, which is what we deliver, so the check runs in the product rather than in a sales policy.
The prohibition is Chapter 4N of the Russia (Sanctions) (EU Exit) Regulations 2019, in force since 24 April 2025, over the software named in Schedule 3IA.
We therefore ask which country you are in, and we compare it with the country Cloudflare reports for your connection. If either indicates a restricted country, registration is refused. We store the declaration because it will be compared with the country of your payment instrument when billing exists.
**This refusal is automated.** Nobody looks at it: the signals are compared and the registration refused in the same request, before any account exists. We do not say which signal fired, because that would be instructions for getting round a sanctions control. It has a legal effect on you, so Article 22C gives you the right to contest it and to have a person look at it.
Unresolved
no route to contest a location refusal exists, and no record of one is kept. Article 22C requires the first; a control we cannot evidence is one we cannot rely on, which is the second.5. What we do not collect
- No analytics, advertising or measurement trackers, on this website or in the product. There are none to turn off.
- No raw IP address is written anywhere — not to the journal, not to the rate limiters, not to cache keys. Only a one-way keyed index of it.
- No device fingerprinting.
- No real name, no job title.
- No profile picture on our servers. If you set one, it stays in your browser.
- No third-party captcha. The check on the sign-up form is a proof-of-work puzzle your own browser solves; nothing is sent to anyone else.
- When you sign in with Google we ask Google for two things only: that you are signed in, and your email address. Not your name, not your picture.
What we do store on your device is what signing in requires: the token that keeps you signed in — in session storage, or in local storage if you asked to be remembered — your display settings, the product you arrived from, and a cookie saying a session exists. Regulation 6 of the Privacy and Electronic Communications Regulations covers storage of this kind, and all of it is strictly necessary for a service you asked for, which is the exemption that regulation gives. There is nothing here to consent to, because nothing here measures you.
6. The tick box on the sign-up form
Ticking "I accept the terms of use and the privacy policy" is how you enter into a contract with us. It is not consent under Article 6(1)(a), and nothing in this policy relies on consent as a lawful basis — so withdrawing it is not the mechanism you want. Section 8 lists the mechanisms you do want.
We record the date and time you accepted.
Unresolved
we do not record which version of these documents you accepted. Until we do, we cannot show a regulator what you actually agreed to.7. How long we keep things
Most retention periods are in the table in section 3. Three things need saying in their own words.
**Sessions.** A session lasts 30 days and is not extended. Expired sessions, unused verification codes, password reset links, abandoned email change requests and expired invitations are deleted by a job that runs every hour.
**Your account.** You can ask us to erase it from your account settings. The request gives you 30 days to change your mind, during which the account keeps working. After that a worker hands over or disposes of your workspaces and then deletes the account row. Sessions, passkeys, permissions, settings and linked sign-in providers go with it. Accounting records stay for the six years the Companies Act requires, and journal entries stay with your name removed.
**The sign-in journal.** A row lives 180 days and is then deleted by the same hourly job. The period comes from what the journal is for: it has to outlive the things it explains — a session, a refresh token and a deferred account deletion all last 30 days — and it has to leave room for a strange sign-in to be noticed, for a reason to look, and for the history around the event. Past that a row stops being something anyone can check and becomes only a record about a person.
8. Your rights
| Right | How it works today |
|---|---|
| Access (Article 15) | By request. There is no self-service copy of the full record yet — see the note below |
| Rectification | In your account settings |
| Erasure (Article 17) | In your account settings. 30 days to cancel, then permanent |
| Portability (Article 20) | In your account settings. We build an encrypted file and keep it available for 72 hours |
| Restriction and objection | By request |
| Withdrawing an application's access | In your account settings, at any time |
| Complaining to us (section 164A, Data Protection Act 2018) | By request. We acknowledge a complaint within 30 days and respond to it |
We answer a request within one calendar month of receiving it, as Article 12(3) requires. Where a request is complex, or where you have made several, we may take up to two months more — and if we do, we will tell you inside the first month and say why.
You can also complain to the Information Commissioner's Office, the UK supervisory authority, without asking us first.
Unresolved
the export covers portability, not access. It carries your data but not the purposes, the categories of recipient, the retention periods or the source, so it is not a subject access response. A written process and a contact route for Article 15 requests still have to exist.Unresolved
Article 12(3) gives us one calendar month to answer. Nothing in our systems measures that month.9. Who else sees your data
| Who | What they get | Why |
|---|---|---|
| Resend | Your email address and the text of the message | To deliver verification codes, password reset links and security notices |
| Only if you choose to sign in with Google: Google tells us your account identifier and your email address | To sign you in with an account you already have | |
| Cloudflare | Your request, including your IP address, before it reaches us. It passes us only a two-letter country code | To serve the site and to absorb attacks |
Our database, cache and backups run on a server rented from Hetzner Online GmbH, a German company, in its Helsinki facility in Finland. Backups are taken nightly on that same machine.
Those four are the whole list. Hetzner and Resend act on our instructions and are our processors; Cloudflare sits in front of every request. Google is not our processor but a separate controller you involve by choosing to sign in with it, so what it does with your Google account is governed by Google's policy, not this one.
Unresolved
an off-site backup destination has not been chosen. Until one exists, a nightly copy sitting on the disk it protects does not give the ability to restore data after a physical incident that Article 32(1)(c) requires, and this policy is not going to imply that it does.Unresolved
the notice we give before adding a processor. It belongs in the data processing agreement, which does not exist yet.10. Sending data outside the United Kingdom
Our server is in Finland, an EEA state, which Part 3 of Schedule 21 to the Data Protection Act 2018 specifies as adequate — so that is not a restricted transfer and needs no further safeguard.
Resend, Cloudflare and Google are in the United States. The Data Protection (Adequacy) (United States of America) Regulations 2023 make it adequate for a transfer to an organisation listed on the Data Privacy Framework List under the UK Extension to the EU–US Data Privacy Framework. All three are listed: Plus Five Five, Inc., trading as Resend; Cloudflare, Inc.; and Google LLC. We re-check each listing is still active rather than assuming it.
Unresolved
the written processor contract Article 28(3) requires with Hetzner, Resend and Cloudflare. Adequacy says where data may go, not on what terms it is held.11. How we protect it
- Passwords are hashed with Argon2id and a secret pepper. Nothing in the database can be used to sign in as you.
- Email addresses, usernames, company names, authenticator secrets, signing keys and data exports are encrypted at rest with AES-256-GCM under a versioned key ring. The keys are not in the database and not in the backups.
- Session tokens are stored only as a SHA-256 fingerprint.
- Sign-in is rate limited per account and per address, behind a proof-of-work barrier, and a wrong password is answered exactly like an unknown address so the form cannot be used to test whether an account exists.
- Every sign-in, refusal, session revocation and permission change is written to the journal described above.
Backups are the gap in this list, as section 9 says: taken nightly onto the machine they protect, they survive a mistake but not the loss of the machine.
If there is a breach that risks your rights, we must tell the Information Commissioner's Office within 72 hours of becoming aware of it, and tell you directly where the risk is high.
12. Children
You must be at least 16 to hold an Eclypsion account. That is a term of the contract rather than a data protection rule: nothing here relies on consent, so the Article 8 age does not come into it, and 16 sits deliberately above the floor.
We do not ask your date of birth and do not verify your age, so we knowingly hold no data about children. If we learn an account belongs to someone under 16 we close it and erase what it holds.
Unresolved
there is no way to tell us. That commitment needs the same missing address as section 14.13. Changes to this policy
We will not change this policy silently. A material change is published with the date it takes effect.
Unresolved
we have no way to notify account holders of a change. Until there is one, publication is the only notice we can actually give.14. Contact
Today the only contact route we operate is Telegram, linked from the company website.
Unresolved
a written contact address for privacy requests. A policy that offers no way to exercise a right offers no right.