Privacy Policy
Last updated: 1 July 2026
Plain-language summary
We collect only the data we need to run Depentra for you: your account details, your project data, billing information handled by Stripe, and limited usage analytics if you consent. We never sell your data. You can export or delete everything at any time, and you can email privacy@depentra.com with any question or request.
1. Who we are
Depentra Ltd ("Depentra", "we", "us") is the data controller for personal data processed through the Depentra application and website. Registered office: 1 Finsbury Avenue, London EC2M 2PF, United Kingdom. Company number 13892241.
2. Data we collect and why
- Account data (name, work email, organisation name, hashed password): to create and secure your account.
- Project data (tasks, dependencies, resources, risks, budgets, comments, attachments): to provide the service. This data belongs to your organisation.
- Billing data (plan, seat count, invoice history): to bill you. Card details are processed by Stripe and never touch our servers.
- Usage data (pages viewed, features used, device and browser type): to improve the product. Collected only if you accept analytics cookies.
- Support data (messages you send us): to help you.
3. Legal basis under GDPR
We process account, project, and billing data under contract performance (Article 6(1)(b)). We process usage analytics under consent (Article 6(1)(a)). We process security logs and fraud prevention data under legitimate interests (Article 6(1)(f)). We process tax and accounting records under legal obligation (Article 6(1)(c)).
4. Retention periods
- Account and project data: for the life of your subscription, then 30 days after cancellation before permanent deletion.
- Billing records: 7 years, as required by tax law.
- Audit logs: 12 months on Professional, unlimited on Enterprise per plan terms.
- Support correspondence: 24 months.
- Analytics data: 14 months, then aggregated or deleted.
5. Where data is stored and how it is protected
Data is stored in Supabase-managed PostgreSQL databases and object storage in the region closest to your organisation, encrypted at rest with AES-256 and in transit with TLS 1.2 or above. Access is restricted by row-level security, role-based access control, and audited administrative access. See our Security page for full details.
6. Third parties we share data with
- Supabase: database, authentication, and file storage.
- Cloudflare: hosting, content delivery, and DDoS protection.
- Stripe: payment processing (PCI DSS Level 1).
- Email delivery provider: transactional emails such as verification and notifications.
Each processor is bound by a data processing agreement. We never sell personal data and never share it with advertisers.
7. Your rights
Under GDPR you have the right to access, rectify, export, restrict, object to processing of, and erase your personal data, and the right to lodge a complaint with your supervisory authority (in the UK, the ICO).
8. How to exercise your rights
Email privacy@depentra.com from your account email address, or use the export and deletion tools in Account Settings. We respond within 30 days. Organisation Administrators can export all organisation data as JSON from the Administration Panel.
9. Cookies
We use essential cookies for login sessions and optional analytics cookies you can accept or reject at any time. Full details, including a table of every cookie we set, are in our Cookie Policy.
10. Data Protection Officer
Our DPO can be reached at dpo@depentra.comor by post at the registered office above, marked "Data Protection Officer".
11. Changes to this policy
Material changes will be notified by email and an in-app banner at least 14 days before they take effect, and will require acceptance before you continue using the service.