We can't find the internet
Attempting to reconnect
Privacy Policy
Last updated: June 12, 2026
This Privacy Policy explains how Rigular Ltd ("Company", "We", "Us", "Our") collects, uses, shares, and protects Personal Data when You use Our software-as-a-service platform and related services (the "Service"). It also describes Your rights under applicable data protection laws.
This Privacy Policy applies to Personal Data We process as a controller — i.e., data We collect directly from You (such as account registration, website visits, and communications). For Personal Data We process as a processor on behalf of Our customers (Customer Data uploaded to the Service), the customer's own privacy policy applies, and Our processing is governed by the Data Processing Agreement (DPA) annexed to Our Terms and Conditions.
We are committed to protecting Your privacy and processing Your data lawfully, fairly, and transparently. Please read this Privacy Policy carefully.
1. Who We Are
Data Controller:
Rigular Ltd
Registered address:
128 City Road, London, EC1V 2NX, United Kingdom
Company registration:
England and Wales, number 14027363
Data Protection contact:
dpo@rigular.com
EU/EEA Representative (Article 27 EU GDPR):
Rigular SARL, 60 rue François 1er, 75008 Paris, France
For the purposes of the UK General Data Protection Regulation ("UK GDPR") and the EU General Data Protection Regulation ("EU GDPR"), We are the data controller for the Personal Data described in this Privacy Policy. Where We process the Personal Data of individuals in the EU/EEA, We have designated Rigular SARL (Paris, France) as Our representative in the Union under Article 27 of the EU GDPR, who may be contacted on matters relating to the EU GDPR.
2. Personal Data We Collect
2.1 Data You Provide to Us
| Category | Examples | When Collected |
|---|---|---|
| Account Data | Full name, business email address, company name, job title, phone number, password (hashed) | When You register for an account or are invited as an Authorised User |
| Billing Data | Billing name, billing address, VAT number, payment method details | When You subscribe to a paid plan or update billing information |
| Communication Data | Content of emails, support tickets, chat messages, feedback, and survey responses | When You contact Us or respond to Our communications |
| Identity Verification Data | Date of birth, national ID or passport number (where required by payment regulations) | When required for payment verification under applicable regulations |
2.2 Data We Collect Automatically
| Category | Examples | Purpose |
|---|---|---|
| Usage Data | Pages visited, features used, actions taken within the Service, session duration, frequency of use | To understand how the Service is used and to improve it |
| Device and Technical Data | IP address, browser type and version, operating system, device type, screen resolution, language preference | To ensure compatibility and diagnose technical issues |
| Log Data | Server logs, error reports, access timestamps, referring URLs | For security monitoring, debugging, and performance analysis |
2.3 Data from Third Parties
We may receive Personal Data about You from:
- Your employer or the subscribing organisation — when they create Your Authorised User account on the Service;
- Payment processors — transaction confirmation and fraud prevention data;
- Analytics providers — aggregated or pseudonymised usage insights;
- Public sources — business contact information from public company registers or professional networks, where We have a legitimate interest in doing so.
3. Cookies and Tracking Technologies
We use cookies and similar technologies on Our Website and Service. Under the Privacy and Electronic Communications Regulations 2003 ("PECR") and the ePrivacy Directive, We require Your consent for non-essential cookies.
3.1 Types of Cookies We Use
| Cookie Type | Duration | Purpose | Consent Required? |
|---|---|---|---|
| Strictly Necessary | Session | Authentication, security, load balancing. The Service cannot function without these. | No (exempt under PECR) |
| Functional | Persistent (up to 12 months) | Remembering Your language preference, display settings, and login state. | Yes |
| Analytics | Persistent (up to 24 months) | Understanding how visitors interact with the Website and Service (e.g., page views, feature usage). | Yes |
3.2 Managing Cookies
When You first visit Our Website, a cookie banner will allow You to accept or reject non-essential cookies. You can change Your preferences at any time via Our cookie settings . You can also configure Your browser to refuse cookies, but this may affect the functionality of the Service.
3.3 Other Tracking Technologies
We may use web beacons (pixel tags) in emails to determine whether messages have been opened and links clicked. You can prevent this by disabling image loading in Your email client.
4. How We Use Your Personal Data
| Purpose | Personal Data Used | Lawful Basis (Art. 6 UK/EU GDPR) |
|---|---|---|
| Providing the Service — managing Your account, delivering core functionality, processing transactions | Account Data, Billing Data, Usage Data | Performance of a contract (Art. 6(1)(b)) — necessary to perform Our obligations under the Terms and Conditions |
| Customer support — responding to queries, resolving issues, managing requests | Account Data, Communication Data, Usage Data | Performance of a contract (Art. 6(1)(b)) and Legitimate interest (Art. 6(1)(f)) — providing effective support |
| Service improvement — analysing usage patterns, identifying trends, developing new features | Usage Data, Device and Technical Data, Log Data | Legitimate interest (Art. 6(1)(f)) — improving and developing the Service |
| Security and fraud prevention — monitoring for threats, preventing unauthorised access, investigating incidents | Log Data, Device and Technical Data, Account Data | Legitimate interest (Art. 6(1)(f)) — protecting the Service and Our users |
| Billing and payments — processing payments, issuing invoices, managing subscriptions | Billing Data, Identity Verification Data | Performance of a contract (Art. 6(1)(b)) and Legal obligation (Art. 6(1)(c)) — tax and accounting requirements |
| Service communications — sending transactional emails (e.g., payment confirmations, security alerts, service updates) | Account Data | Performance of a contract (Art. 6(1)(b)) — necessary operational communications |
| Marketing communications — sending newsletters, product announcements, event invitations | Account Data (name, email) | Consent (Art. 6(1)(a)) — You may withdraw consent at any time via the unsubscribe link in each email or by contacting Us |
| Legal compliance — responding to lawful requests, enforcing Our terms, defending legal claims | Any relevant data | Legal obligation (Art. 6(1)(c)) and Legitimate interest (Art. 6(1)(f)) — establishing, exercising, or defending legal claims |
| Business transfers — evaluating or conducting a merger, acquisition, or sale of assets | Any relevant data | Legitimate interest (Art. 6(1)(f)) — pursuing legitimate business restructuring |
We do not use Your Personal Data for automated decision-making, including profiling, that produces legal effects or similarly significant effects on You.
5. Who We Share Your Personal Data With
We do not sell Your Personal Data. We share Personal Data only as described below:
| Recipient Category | Purpose | Safeguards |
|---|---|---|
|
Hosting and infrastructure providers
(OVHcloud) |
Hosting the Service, data storage, computing | DPA in place; data processed within the EEA (OVHcloud, France); ISO 27001-certified data centres |
|
Payment processors
(e.g., Revolut) |
Processing subscription payments | PCI-DSS compliant; DPA in place; their own privacy policy applies to card details |
| Analytics providers | Not applicable | We do not use third-party analytics providers |
|
Email and communication providers
(SMTP2GO) |
Sending transactional and marketing emails | DPA in place; SCCs for transfers outside UK/EEA |
|
Customer support tools
(GitLab — self-hosted) |
Managing support requests | Self-hosted on Our infrastructure (OVHcloud, EEA); no transfer to a third party |
| Affiliates | Internal administration, shared services | Bound by this Privacy Policy and internal data sharing agreements |
| Professional advisors | Legal, accounting, and audit services | Bound by professional confidentiality obligations |
| Law enforcement or regulatory authorities | Where required by applicable law, court order, or regulatory request | We disclose only what is legally required and notify You where permitted |
| Acquirers in a business transfer | In connection with a merger, acquisition, or sale of assets | We notify You before Your data is transferred; the acquirer must honour equivalent protections |
A full list of Our current sub-processors is set out in Annex 3 of Our Data Processing Agreement and is maintained in accordance with Section 5 of that Agreement.
6. International Data Transfers
Your Personal Data may be transferred to, and processed in, countries outside the United Kingdom and the European Economic Area. When such transfers occur, We ensure that appropriate safeguards are in place in accordance with the UK GDPR and EU GDPR, including:
- Adequacy decisions: We transfer data to countries that the UK Secretary of State or the European Commission has recognised as providing an adequate level of data protection (e.g., the EU-UK adequacy decision).
- Standard Contractual Clauses (SCCs): For transfers to countries without an adequacy decision, We use the European Commission's Standard Contractual Clauses (Decision 2021/914) and, where applicable, the UK International Data Transfer Addendum issued by the ICO.
- Additional safeguards: Where necessary, We implement supplementary measures (e.g., encryption, pseudonymisation, access controls) following a transfer impact assessment.
You may request a copy of the safeguards We use for international transfers by contacting Us at dpo@rigular.com.
7. Data Retention
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account Data | Duration of the account plus 12 months after account closure or contract termination | To allow for reactivation and to resolve any post-termination queries |
| Billing and Financial Data | 7 years from the date of the transaction | UK tax and accounting obligations (Companies Act 2006, HMRC requirements) |
| Communication Data | Duration of the business relationship plus 24 months | To improve support quality and resolve disputes |
| Usage Data and Log Data | Up to 12 months from collection | Service improvement, security monitoring, and debugging |
| Identity Verification Data | Duration of the business relationship plus 5 years | Anti-money laundering and know-your-customer obligations where applicable |
| Marketing preferences | Until You withdraw consent or 36 months of inactivity | To honour Your communication preferences |
| Cookie data | As specified in Section 3 (varies by cookie type, up to 24 months) | As required for the stated purpose |
After the applicable retention period, Personal Data is securely deleted or anonymised. Where Personal Data is retained for legal compliance, access is restricted to authorised personnel on a need-to-know basis.
8. Data Security
We take the security of Your Personal Data seriously and implement appropriate technical and organisational measures, including:
- Encryption: Personal Data is encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
- Access controls: Role-based access controls, multi-factor authentication for administrative access, and the principle of least privilege.
- Infrastructure security: Network firewalls, intrusion detection systems, and DDoS mitigation.
- Monitoring: Centralised security logging, regular vulnerability scanning, and annual independent penetration testing.
- Personnel: All staff with access to Personal Data are bound by confidentiality obligations and receive regular data protection and security training.
- Assurance: Our security programme is aligned with the UK GDPR and recognised security frameworks and is subject to annual independent penetration testing. Rigular does not currently hold ISO 27001 or SOC 2 certification; the Service is hosted in ISO 27001-certified data centres (OVHcloud).
No system is completely secure. If We become aware of a security incident affecting Your Personal Data, We will notify You and any applicable regulator in accordance with Our obligations under UK GDPR Article 33 and 34.
9. Your Rights
Under the UK GDPR and EU GDPR, You have the following rights in relation to Your Personal Data:
| Right | Description | GDPR Article |
|---|---|---|
| Access | Request a copy of the Personal Data We hold about You, together with information about how We process it. | Art. 15 |
| Rectification | Request correction of inaccurate or incomplete Personal Data. | Art. 16 |
| Erasure | Request deletion of Your Personal Data where there is no compelling reason for its continued processing. | Art. 17 |
| Restriction | Request that We restrict the processing of Your Personal Data in certain circumstances (e.g., while We verify accuracy or assess an objection). | Art. 18 |
| Data portability | Receive Your Personal Data in a structured, commonly used, machine-readable format and transmit it to another controller. | Art. 20 |
| Objection | Object to processing based on legitimate interest or for direct marketing purposes. Where You object to direct marketing, We will stop immediately. | Art. 21 |
| Withdraw consent | Where processing is based on consent, withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. | Art. 7(3) |
| Automated decision-making | Not be subject to decisions based solely on automated processing, including profiling, which produce legal effects or similarly significant effects. (We do not currently use such automated decision-making.) | Art. 22 |
| Lodge a complaint | Lodge a complaint with a supervisory authority if You believe Your rights have been violated. | Art. 77 |
9.1 How to Exercise Your Rights
To exercise any of these rights, please contact Us at dpo@rigular.com. We will respond within one (1) month of receiving Your request. This period may be extended by a further two (2) months where necessary, taking into account the complexity and number of requests. We will inform You of any such extension within the first month.
We may ask You to verify Your identity before processing Your request. We will not charge a fee for exercising Your rights, except where requests are manifestly unfounded or excessive, in which case We may charge a reasonable fee or refuse to act.
9.2 Right to Lodge a Complaint
If You are dissatisfied with how We handle Your Personal Data or a request, You have the right to lodge a complaint with:
- UK: Information Commissioner's Office (ICO) — ico.org.uk/make-a-complaint | Tel: 0303 123 1113
- EU: The data protection authority in the EU Member State where You reside or work, or where the alleged infringement occurred. A list of EU DPAs is available at edpb.europa.eu .
10. Customer Data (Processor Role)
When You use the Service to process data about Your own customers, employees, or other third parties ("Customer Data"), We act as a processor under Article 28 of the UK GDPR / EU GDPR. In this capacity:
- We process Customer Data only on Your documented instructions, as described in the Agreement and the DPA.
- You are the controller of Customer Data and are responsible for ensuring that You have a valid legal basis to collect and process it, and that appropriate privacy notices have been provided to the relevant Data Subjects.
- The rights of Data Subjects whose Personal Data is contained in Customer Data should be exercised by contacting You (the controller) directly. If We receive such a request, We will redirect the Data Subject to You and notify You within five (5) business days.
- Our processing of Customer Data is governed by the Data Processing Agreement (DPA) annexed to the Terms and Conditions, which sets out Our obligations regarding security, sub-processing, international transfers, data breach notification, and data return/deletion.
This Privacy Policy does not apply to Customer Data except to the extent required by applicable law.
11. Children's Privacy
The Service is designed for business use and is not directed at individuals under the age of 18. We do not knowingly collect Personal Data from anyone under 18. If We become aware that We have inadvertently collected data from a minor, We will take prompt steps to delete it. If You believe a minor has provided Us with Personal Data, please contact Us at dpo@rigular.com.
12. Links to Third-Party Websites
The Service may contain links to third-party websites or services not operated by Us. We are not responsible for the privacy practices of such third parties. We encourage You to review the privacy policies of any third-party website You visit.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in Our practices, the Service, or applicable law. For material changes, We will:
- Post the updated Privacy Policy on this page with a revised "Last updated" date;
- Notify You by email and/or a prominent notice within the Service at least thirty (30) days before the changes take effect.
We encourage You to review this Privacy Policy periodically. Your continued use of the Service after the updated Privacy Policy takes effect constitutes Your acknowledgment of the changes.
14. Contact Us
If You have any questions about this Privacy Policy or wish to exercise Your rights, please contact Us:
- Data Protection contact: dpo@rigular.com
- General enquiries: contact@rigular.com
- Post: Rigular Ltd, 128 City Road, London, EC1V 2NX, United Kingdom
- Website: https://www.rigular.com/en/contact