Data Handling Policy
Effective date: 19 May 2026
Last updated: 19 May 2026
1. Scope of This Policy
This Data Handling Policy supplements our Privacy Policy and provides detailed information about how we handle data in our capacity as a data controller and, where applicable, data processor. It applies to all personal data processed in connection with our website, services, and client engagements.
This policy reflects our commitment to transparency and compliance with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018 (DPA 2018)
- Privacy and Electronic Communications Regulations (PECR)
- Information Commissioner's Office (ICO) guidance
2. Data We Handle
2.1 Client Data
When you engage us for services (consulting, hosting, development, support), we handle:
- Contact details (name, email, phone, company name, billing address)
- Communication content (emails, messages, project requirements)
- Service usage data (hosting metrics, support tickets, access logs)
- Payment information (processed by our payment providers, not stored directly)
2.2 Website Visitor Data
- Analytics data (anonymised IP addresses, pages visited, referrer URLs)
- Contact form submissions (name, email, message content)
- Forum registration data (username, email, profile information)
2.3 Hosted Service Data
When providing hosted services (n8n, Nextcloud, EspoCRM, Dolibarr, Invoice Ninja, osTicket), we process data stored within those platforms on behalf of our clients. This data is handled according to the terms of our service agreement with each client.
3. Purposes and Legal Basis
| Purpose | Legal Basis (UK GDPR) | Data Types |
|---|
| Responding to enquiries | Legitimate Interests | Name, email, message |
| Delivering contracted services | Contract | Contact, project, usage data |
| Account management | Contract | Contact, authentication |
| Marketing (where applicable) | Consent | Email address |
| Service improvement | Legitimate Interests | Usage analytics |
| Security and fraud prevention | Legitimate Interests | Access logs, IP addresses |
| Legal compliance | Legal Obligation | Financial records |
4. Data Processors and Sub-Processors
We use the following sub-processors for data handling:
Infrastructure
- Cloudron Surfer — website hosting
- Cloudflare — CDN and DDoS protection (may process technical data)
Communications
- PocketBase (self-hosted) — contact form processing, stored on our own infrastructure
- Email provider — transactional and marketing email delivery
Client Services
- Managed hosting providers — for n8n, Nextcloud, CRM, and other hosted services (data location specified in service agreements)
5. Data Storage and Security
We implement appropriate technical and organisational measures to protect personal data, including:
- TLS encryption for data in transit
- Encryption at rest for sensitive data
- Access controls on a least-privilege basis
- Regular security reviews and vulnerability scanning
- Access logging for systems containing personal data
- Staff training on data protection obligations
- Incident response procedures (see Section 8)
6. Data Retention Schedule
| Data Category | Retention Period | Disposal Method |
|---|
| Contact form submissions | 12 months | Secure deletion |
| Client service records | 7 years (UK tax law) | Secure deletion |
| Marketing subscriber list | Until unsubscribe | Secure deletion |
| Forum accounts (active) | Until deletion requested | Secure deletion |
| Forum accounts (dormant) | 2 years inactivity | Secure deletion |
| Access logs | 90 days | Automated purge |
| Support tickets | 2 years post-resolution | Secure deletion |
7. International Data Transfers
When we transfer personal data outside the UK or EEA, we ensure an adequate level of protection by:
- Using processors covered by UK adequacy decisions (EU/EEA countries, Canada, etc.)
- Entering into Standard Contractual Clauses (SCCs) approved by the ICO for transfers to other countries
- Conducting Transfer Impact Assessments (TIAs) where required
8. Data Breach Response
In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will:
- Notify the ICO within 72 hours of becoming aware of the breach (where required)
- Notify affected individuals without undue delay when the breach is likely to result in high risk
- Document the breach, its effects, and remedial actions taken
- Where applicable, notify our clients who are data controllers
To report a suspected breach, contact: security@openelara.org
9. Data Processing Agreements (DPAs)
For clients who engage us to process personal data on their behalf (e.g., hosting their CRM with customer data), we enter into formal Data Processing Agreements as required by UK GDPR Article 28. Contact us at privacy@openelara.org to request a DPA.
10. Your Rights
As a data subject, you have the following rights under UK GDPR:
- Right of Access — receive a copy of your personal data (Subject Access Request)
- Right to Rectification — have inaccurate personal data corrected
- Right to Erasure — request deletion of your data (subject to legal retention obligations)
- Right to Restriction — request we limit how we process your data
- Right to Portability — receive your data in a structured, machine-readable format
- Right to Object — object to processing based on legitimate interests
- Rights related to automated decision-making — not be subject to solely automated decisions with significant effects
To exercise any rights, email privacy@openelara.org. We will respond within 30 days. If you are unsatisfied with our response, you may complain to the ICO.
11. Changes to This Policy
We may update this policy periodically to reflect changes in our data handling practices, regulatory guidance, or legislation. Material changes will be communicated via our website and, where appropriate, by direct notification to affected individuals.
Contact Us: hello@openelara.org