Data Handling Policy

Effective date: 19 May 2026

Last updated: 19 May 2026

1. Scope of This Policy

This Data Handling Policy supplements our Privacy Policy and provides detailed information about how we handle data in our capacity as a data controller and, where applicable, data processor. It applies to all personal data processed in connection with our website, services, and client engagements.

This policy reflects our commitment to transparency and compliance with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018 (DPA 2018)
  • Privacy and Electronic Communications Regulations (PECR)
  • Information Commissioner's Office (ICO) guidance

2. Data We Handle

2.1 Client Data

When you engage us for services (consulting, hosting, development, support), we handle:

  • Contact details (name, email, phone, company name, billing address)
  • Communication content (emails, messages, project requirements)
  • Service usage data (hosting metrics, support tickets, access logs)
  • Payment information (processed by our payment providers, not stored directly)

2.2 Website Visitor Data

  • Analytics data (anonymised IP addresses, pages visited, referrer URLs)
  • Contact form submissions (name, email, message content)
  • Forum registration data (username, email, profile information)

2.3 Hosted Service Data

When providing hosted services (n8n, Nextcloud, EspoCRM, Dolibarr, Invoice Ninja, osTicket), we process data stored within those platforms on behalf of our clients. This data is handled according to the terms of our service agreement with each client.

3. Purposes and Legal Basis

PurposeLegal Basis (UK GDPR)Data Types
Responding to enquiriesLegitimate InterestsName, email, message
Delivering contracted servicesContractContact, project, usage data
Account managementContractContact, authentication
Marketing (where applicable)ConsentEmail address
Service improvementLegitimate InterestsUsage analytics
Security and fraud preventionLegitimate InterestsAccess logs, IP addresses
Legal complianceLegal ObligationFinancial records

4. Data Processors and Sub-Processors

We use the following sub-processors for data handling:

Infrastructure

  • Cloudron Surfer — website hosting
  • Cloudflare — CDN and DDoS protection (may process technical data)

Communications

  • PocketBase (self-hosted) — contact form processing, stored on our own infrastructure
  • Email provider — transactional and marketing email delivery

Client Services

  • Managed hosting providers — for n8n, Nextcloud, CRM, and other hosted services (data location specified in service agreements)

5. Data Storage and Security

We implement appropriate technical and organisational measures to protect personal data, including:

  • TLS encryption for data in transit
  • Encryption at rest for sensitive data
  • Access controls on a least-privilege basis
  • Regular security reviews and vulnerability scanning
  • Access logging for systems containing personal data
  • Staff training on data protection obligations
  • Incident response procedures (see Section 8)

6. Data Retention Schedule

Data CategoryRetention PeriodDisposal Method
Contact form submissions12 monthsSecure deletion
Client service records7 years (UK tax law)Secure deletion
Marketing subscriber listUntil unsubscribeSecure deletion
Forum accounts (active)Until deletion requestedSecure deletion
Forum accounts (dormant)2 years inactivitySecure deletion
Access logs90 daysAutomated purge
Support tickets2 years post-resolutionSecure deletion

7. International Data Transfers

When we transfer personal data outside the UK or EEA, we ensure an adequate level of protection by:

  • Using processors covered by UK adequacy decisions (EU/EEA countries, Canada, etc.)
  • Entering into Standard Contractual Clauses (SCCs) approved by the ICO for transfers to other countries
  • Conducting Transfer Impact Assessments (TIAs) where required

8. Data Breach Response

In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will:

  • Notify the ICO within 72 hours of becoming aware of the breach (where required)
  • Notify affected individuals without undue delay when the breach is likely to result in high risk
  • Document the breach, its effects, and remedial actions taken
  • Where applicable, notify our clients who are data controllers

To report a suspected breach, contact: security@openelara.org

9. Data Processing Agreements (DPAs)

For clients who engage us to process personal data on their behalf (e.g., hosting their CRM with customer data), we enter into formal Data Processing Agreements as required by UK GDPR Article 28. Contact us at privacy@openelara.org to request a DPA.

10. Your Rights

As a data subject, you have the following rights under UK GDPR:

  • Right of Access — receive a copy of your personal data (Subject Access Request)
  • Right to Rectification — have inaccurate personal data corrected
  • Right to Erasure — request deletion of your data (subject to legal retention obligations)
  • Right to Restriction — request we limit how we process your data
  • Right to Portability — receive your data in a structured, machine-readable format
  • Right to Object — object to processing based on legitimate interests
  • Rights related to automated decision-making — not be subject to solely automated decisions with significant effects

To exercise any rights, email privacy@openelara.org. We will respond within 30 days. If you are unsatisfied with our response, you may complain to the ICO.

11. Changes to This Policy

We may update this policy periodically to reflect changes in our data handling practices, regulatory guidance, or legislation. Material changes will be communicated via our website and, where appropriate, by direct notification to affected individuals.

Contact Us: hello@openelara.org