Legal / Privacy Policy
Privacy Policy
01Who we are (controller)
The controller of personal data described in this policy is TRESONANT.AI LTD, a company registered in Northern Ireland under company number NI739783, with its registered office at 3 Moat Street, Donaghadee, Northern Ireland, BT21 0DA ("Tresonant", "we", "us").
For all privacy matters, contact us at sales@tresonant.co. We have not appointed a Data Protection Officer; the company's directors are responsible for data protection compliance.
02Scope of this policy
This policy covers personal data processed by Tresonant in connection with:
- the website tresonant.co and its subpages; and
- any mobile applications published by TRESONANT.AI LTD on the Apple App Store or Google Play (together, the "apps"), including any future enterprise companion or monitoring applications we may release.
Where a specific app has materially different data practices, we will provide an app-specific supplement inside that app and on this page; unless and until we do, this policy applies in full to every app we publish. It does not cover third-party services that link to us or that we link to.
Personal data we process on behalf of business clients under an engineering services agreement is governed by that agreement (in which we normally act as processor), not by this policy.
03Data we process on the website
3.1 Email correspondence
The website contains no contact forms. If you email us (for example at sales@tresonant.co), we process your email address, name, and the content of your message in order to respond. This correspondence is stored in our business email system.
3.2 Server and security logs
The website is served through Cloudflare. Cloudflare processes technical data (IP address, user-agent, requested URL, timestamps) in server and security logs to deliver the site and protect it from abuse. We access such logs only in aggregate or for security investigation.
3.3 No analytics, no advertising
We do not use analytics tools, advertising networks, tracking pixels, social-media embeds or fingerprinting on this website. The only cookies that may be set are strictly-necessary security cookies set by Cloudflare — see our Cookie Policy.
04Data we process in our apps
This section describes the categories of data our apps may process. Each app collects only the subset it actually needs; the in-app disclosures and store listings for each app identify which categories apply to it.
4.1 Account information
If an app offers accounts: email address, display name, hashed authentication credentials, and organisation/workspace membership (for enterprise apps). We do not require more identity data than the app's function needs.
4.2 User content
Content you create or upload in an app (for example notes, configurations, monitoring dashboards or annotations) is stored on infrastructure operated by our hosting providers listed in section 6, in the United Kingdom or European Economic Area wherever the provider makes that option available. User content remains yours (see our Terms) and is processed only to provide the app's functionality.
4.3 Device and technical data
Device model, operating system version, app version, language and time-zone settings, and non-persistent technical identifiers needed for push notifications or session management.
4.4 Usage analytics
Where an app includes usage analytics, they are aggregated and privacy-preserving: feature-usage counts and performance measurements without advertising identifiers, without cross-app identifiers, and without profiling individuals.
4.5 Crash diagnostics
Crash reports (stack traces, device model, OS and app version, and system state at the moment of failure) may be collected to fix defects. Crash reports are not used for any other purpose.
4.6 App permissions
Our apps request only the permissions their features require. Every permission is optional at the operating-system level and can be revoked at any time in iOS Settings or Android Settings without losing unrelated functionality. The permissions any of our apps may request, and their sole purposes, are:
- Notifications — to deliver alerts you have configured (for example system-monitoring alerts). Revocable in system settings; the app continues to work without it.
- Camera — only if a feature involves capturing an image or scanning a code, and only while you use that feature. Never for background capture.
- Photo library / files — only to let you attach or export files you choose. We access only the items you select.
- Biometric authentication (Face ID / fingerprint) — only to unlock the app locally. Biometric data never leaves your device and is never accessible to us.
- Local network / Bluetooth — only if a feature connects to systems you administer, and only after you enable that feature.
4.7 What we do not do
Across all our apps, we do not:
- sell personal data, or share it for behavioural advertising;
- embed advertising SDKs or ad networks;
- track you across apps or websites owned by other companies;
- collect precise location data.
05Purposes and lawful bases
Under UK GDPR, each processing purpose has a lawful basis:
| Purpose | Data categories | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Responding to enquiries and correspondence | Email correspondence (3.1) | Legitimate interests — responding to people who contact us |
| Serving and securing the website | Server and security logs (3.2) | Legitimate interests — operating and defending our infrastructure |
| Providing app functionality | Account information, user content, device data (4.1–4.3) | Contract — performing our agreement with you |
| Improving app reliability and performance | Aggregated usage analytics (4.4) | Legitimate interests — improving our products without profiling individuals |
| Diagnosing and fixing defects | Crash diagnostics (4.5) | Legitimate interests — maintaining safe, working software |
| Contract negotiation and delivery with business clients | Business contact details | Contract, or legitimate interests for prospective clients |
| Compliance with legal obligations | Records we are required to keep (tax, accounting, legal claims) | Legal obligation |
| Any future optional feature requiring consent | As described at the point of collection | Consent — requested first, withdrawable at any time |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms; you may object at any time (section 9).
06Recipients of data
We share personal data only with service providers acting on our documented instructions, and only as needed:
- Cloudflare, Inc. — content delivery, DNS and security for tresonant.co (server/security logs).
- Apple Inc. — distribution of iOS apps, and app-store services such as crash reporting where you have enabled sharing with developers.
- Google LLC — distribution of Android apps via Google Play, and equivalent app-store services.
If we engage additional processors (for example a hosting provider for app back-ends or a business email provider), they will be bound by data-processing terms, and we commit to keeping this section current so it always names the categories and principal providers in use. We may also disclose data where required by law, or in a corporate transaction under equivalent protections. We never disclose personal data for third-party marketing.
07International transfers
Some providers listed in section 6 are headquartered in the United States or operate globally. Where personal data is transferred outside the United Kingdom, we rely on one or more of the following safeguards:
- a UK adequacy decision covering the destination (including the UK–US Data Bridge where the recipient is certified);
- the UK International Data Transfer Agreement (IDTA); or
- the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum.
Copies of the relevant safeguard for a given transfer are available on request via sales@tresonant.co.
08Retention periods
- Email correspondence — up to 24 months after the correspondence closes, unless it forms part of a contract file.
- Contract and client records — 6 years after the end of the relationship (limitation periods and tax law).
- Cloudflare security logs — retained by Cloudflare for its standard short operational periods; we do not extend them.
- App account data — for the life of the account, then deleted within 30 days of account deletion (section 12).
- User content — for the life of the account or until you delete it in-app; backups purge within 30 additional days.
- Aggregated usage analytics — indefinitely, because they do not identify individuals.
- Crash diagnostics — up to 12 months, then deleted or fully anonymised.
Where a legal obligation or active legal claim requires longer retention of a specific record, we keep only that record, only for as long as required.
09Your rights
Under UK GDPR you have the right to:
- be informed — this policy;
- access your personal data (a "subject access request");
- rectification of inaccurate or incomplete data;
- erasure ("right to be forgotten"), where applicable;
- restriction of processing in certain circumstances;
- data portability — a machine-readable copy of data you provided under contract or consent;
- object — including to any processing based on legitimate interests; and
- not be subject to solely automated decisions with legal or similarly significant effects — we make no such decisions about you.
How to exercise them: email sales@tresonant.co with the subject "Privacy request". We may need to verify your identity. We will respond within one month of receiving your request; if a request is complex we may extend by up to two further months and will tell you within the first month. Exercising your rights is free of charge.
10Complaints to the ICO
If you are unhappy with how we handle your data, please contact us first — we take it seriously. You also have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
11Children
Our website and apps are designed for business and professional users and are not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us personal data, contact sales@tresonant.co and we will delete it promptly.
12Account and data deletion
You can delete your account and associated data for any of our apps by either route:
- In-app — once our apps ship, each app with accounts will include: Settings → Account → Delete account. This deletes the account and associated personal data.
- By email — send a request to sales@tresonant.co with the subject "Account deletion request" from the email address linked to the account (or with sufficient information for us to verify ownership).
Deletion is completed within 30 days of a verified request, including removal from active systems and expiry from routine backups. We may retain a minimal record where the law requires it (for example transaction records for tax purposes, or data needed to establish or defend legal claims) — limited strictly to that purpose and its statutory period.
13iOS App Tracking Transparency
Our apps do not track you as defined by Apple's App Tracking Transparency framework: we do not link user or device data with third-party data for advertising, and we do not share user data with data brokers. Accordingly, our apps do not display the ATT permission prompt — there is no tracking for it to authorise.
If any future feature ever required tracking as Apple defines it, we would ask for your consent through the ATT prompt before any tracking occurred, and update this policy first. Consent-first is our standing commitment.
14Google Play Data Safety
For each Android app we publish, the Data Safety section of its Google Play listing is completed to be consistent with this policy: the data types declared as collected or shared, the purposes given, and the security practices described will match sections 4–8 above. If a Play listing and this policy ever appear to conflict, this policy states our actual practice and we will correct the listing.
15Security measures
We apply the same engineering discipline to our own systems that we sell. Measures include:
- encryption in transit (TLS) for all website and app traffic, and encryption at rest for stored personal data;
- least-privilege access controls — personal data is accessible only to those who need it for a stated purpose;
- multi-factor authentication on administrative and infrastructure accounts;
- segregated environments and audit logging of administrative access;
- vendor due diligence and data-processing agreements with all processors;
- a documented incident-response process; where a breach is likely to result in a risk to your rights, we will notify the ICO within 72 hours and affected individuals without undue delay.
16Changes to this policy
We may update this policy as our products, providers or the law change. The effective date at the top will always reflect the current version. For material changes affecting app users, we will provide notice in-app or by email before the change takes effect. Superseded versions are available on request.
17Contact
Questions, requests and complaints about this policy or your personal data:
TRESONANT.AI LTD
3 Moat Street, Donaghadee, Northern Ireland, BT21 0DA
Company No. NI739783
sales@tresonant.co