Sign in

Privacy Policy

Draft — pending legal-counsel review. Not yet for publication. See README.md. Entity facts: COMPANY.md.

  • Controller: byRazLabs Ltd (trading as "Dena")
  • Version: 1.1 (draft)
  • Effective: [TODO: date on publication] — drafted 2026-06-05, updated 2026-07-08
  • Applies to: denainfra.com, the Dena web application, the Dena iOS/Android apps, and related services (the "Service")

1. Who we are

byRazLabs Ltd (trading as "Dena") ("Dena", "we", "us", "our") is a company registered in England & Wales (company number [TODO], registered office [TODO]). We provide an AI-powered inspection-and-repair platform for river-frontage assets, used by engineering consultancies and asset owners.

This policy explains how we handle personal data — information about identifiable living people. It is written for two audiences:

  • Visitors and direct users — people who use our website or hold a Dena account

(for this data we are the controller); and

  • People whose data appears in our customers' content — e.g. an inspector named in a

report, or an individual incidentally captured in a site photograph (for this data we are typically a processor acting on our customer's instructions; see §10 and the Data Processing Agreement).

We are registered with the UK Information Commissioner's Office (ICO), registration [TODO].

2. The personal data we process (as controller)

CategoryExamplesSource
Account & identityName, work email, organisation, role, password/auth credentials (managed by our identity provider, Clerk), profile settingsYou / your organisation admin
Authentication & securityLogin timestamps, IP address, device/session info, multi-factor settings, audit-log eventsAutomatically, on use
Usage & diagnosticsPages/features used, API requests, performance and error telemetry, request tracesAutomatically, on use
CommunicationsEmails and support messages you send us, and our repliesYou
WebsiteCookie identifiers and similar (see the Cookie Policy)Automatically, on the website

We do not seek to collect special-category data (health, biometrics, etc.) about account holders. We do not knowingly process data of anyone under 18; the Service is a business tool not directed at children.

3. Why we process it, and our lawful basis (UK/EU GDPR Art. 6)

PurposeLawful basis
Create and administer your account; provide the ServiceContract (Art. 6(1)(b)) — performance of our agreement with you/your organisation
Authenticate you, secure accounts, prevent abuse, keep audit logsLegitimate interests (Art. 6(1)(f)) — securing our Service; and legal obligation where logs are required
Operate, maintain, debug, and improve the ServiceLegitimate interests — running a reliable, secure product (see our LIA)
Respond to your enquiries and provide supportContract / legitimate interests
Send service/administrative messages (not marketing)Contract / legitimate interests
Send marketing emails (where applicable)Consent (Art. 6(1)(a)) — opt-in, withdrawable any time
Comply with legal, tax, and regulatory dutiesLegal obligation (Art. 6(1)(c))
Establish, exercise, or defend legal claimsLegitimate interests

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms; you can object (see §8).

4. AI processing

The Service uses AI to analyse inspection content (largely photographs of physical structures and structured engineering data). Account-holder personal data is not the subject of the AI analysis — the AI analyses asset and defect imagery, not people. Inspection content is processed by our AI sub-processor (Anthropic, for Claude model inference) under contract, solely to provide the Service. We do not use customer content or personal data to train third-party foundation models, and our AI provider is contractually bound not to train on data submitted via its API. See the sub-processor list and §10.

5. Who we share it with

We share personal data only with:

  • Sub-processors who help us run the Service (hosting, identity, AI inference,

communications), under written contracts that bind them to confidentiality and security. The current list — including Google Cloud (hosting/storage), Clerk (identity), and Anthropic (AI inference) — is at sub-processors.md.

  • Your organisation — your account activity may be visible to your organisation's

administrators.

  • Professional advisers, auditors, and authorities — where necessary for legal,

accounting, audit, or regulatory reasons.

  • A successor — in a merger, acquisition, or asset sale, subject to this policy.

We do not sell personal data.

6. Where your data is stored and processed (international transfers)

Dena hosts the Service on Google Cloud Platform in the europe-west2 (London, UK) region. We aim to keep personal data in the UK/EEA. Where a sub-processor processes data outside the UK/EEA (for example, certain AI inference or support functions), we ensure an appropriate safeguard is in place — typically the UK International Data Transfer Addendum (IDTA) and/or the EU Standard Contractual Clauses, plus a transfer risk assessment. The sub-processor list notes each sub-processor's processing location and the safeguard relied on. You can request a copy of the relevant safeguard at privacy@denainfra.com.

7. How long we keep it

We keep personal data only as long as necessary for the purposes above:

  • Account data — for the life of your account, then deleted or anonymised within

90 days of account closure (longer only where law requires).

  • Security/audit logs — retained per the Logging & Monitoring Policy

(typically up to 400 days for security logs).

  • Backups — encrypted backups roll off on the schedule in our

Data Retention & Deletion Policy (production database: up to 30 daily backups).

  • Records we must keep by law (e.g. tax) — for the legally required period.

Full retention periods are in the Data Retention & Deletion Policy.

8. Your rights

Under UK/EU GDPR you have the right to: access your data; rectify inaccurate data; erase data ("right to be forgotten"); restrict or object to processing; data portability; and to withdraw consent at any time where we rely on it. You also have the right not to be subject to solely automated decisions producing legal or similarly significant effects — Dena does not make such decisions about account holders.

To exercise any right, email privacy@denainfra.com. We respond within one month (extendable by two further months for complex requests, with notice). There is normally no charge. We may need to verify your identity. Our handling process is the DSAR procedure.

Self-service. If you hold a Dena account, some rights can be exercised directly in the web app: from Settings → Privacy you can download a copy of your account data and opt out of usage analytics, and you can rectify your profile details from your account settings. Erasure requests are actioned by our team using our data-subject-rights tooling — Dena is a business service, so there is no self-serve account deletion. As noted in §7, data may persist in encrypted backups until they roll off.

If your personal data appears in a customer's inspection content, the customer is the controller for that content — we will refer your request to them and assist them as processor (see §10).

9. How we protect your data

We apply layered technical and organisational measures, including encryption in transit (TLS) and at rest, tenant isolation enforced at the database layer (PostgreSQL row-level security), least-privilege access, multi-factor authentication on administrative access, audit logging, and a documented incident-response process. Our measures are described in the Trust page and the DPA security annex, and governed by our internal security policies.

10. When we are a processor, not a controller

When our customers (engineering consultancies and asset owners) upload inspection content, that content can include personal data they control — for example, the names of inspectors or report authors, or an individual who happens to be visible in a site photograph. For that content the customer is the controller and Dena is the processor: we process it only on the customer's documented instructions, under the Data Processing Agreement. If you are such an individual and want to exercise your rights, please contact the relevant organisation (the controller); we will support them and can route your request to them.

11. Cookies

Our website uses cookies and similar technologies as described in the Cookie Policy. The web application uses only the cookies strictly necessary to keep you logged in and secure.

12. Changes to this policy

We may update this policy. Material changes will be notified (in-app or by email) before they take effect. The version and effective date at the top always reflect the current version; prior versions are available on request.

13. How to contact us & complain

  • Privacy enquiries / DSARs: privacy@denainfra.com
  • Data Protection Lead: dpo@denainfra.com
  • Post: byRazLabs Ltd, [TODO: registered office]

If you are unhappy with how we handle your data you can complain to the UK regulator, the Information Commissioner's Office (https://ico.org.uk; helpline 0303 123 1113), or your local EU supervisory authority. We would appreciate the chance to resolve it first.


Revision history

VersionDateChangeAuthor
1.0 (draft)2026-06-05Initial draftAI session — pending counsel review
1.1 (draft)2026-07-08Note in-product self-service (export account data + analytics opt-out, Settings → Privacy) and operator-actioned erasure tooling; backup-residual caveat retainedAI session — pending counsel review

© 2026 byRazLabs Ltd (trading as “Dena”). All rights reserved.

PrivacyTermsCookiesDPAAcceptable useSub-processorsSecurity