Legal

Privacy Policy

Terrafa asks operators to trust it with the inside of their operation. That trust has to start with being plain about what we do with personal data, and honest about the little we currently collect.

Last updated 7 August 2026 Version 1.2 Applies to terrafa.co.uk and Terrafa Limited

About this policy

This policy explains how Terrafa Limited handles personal data — information that identifies a living individual, or could when combined with something else we hold.

It covers you if you visit this website, contact us about Continuum, work for one of our customers, suppliers or partners, attend an event we run, or apply for a job with us.

Terrafa acts in two distinct roles, and the difference matters:

  • As a controller. For the personal data we decide to collect and use for our own purposes — enquiries, contracts, marketing, recruitment, running the business. That is what most of this policy is about.
  • As a processor. For personal data that happens to sit inside a customer's operational data when Continuum connects to their systems. There, the customer decides what happens and we act on their instructions. Section 6 explains that arrangement.

Where we say "personal data", we mean it in the sense used by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Who we are

Terrafa Limited is an independent company registered in England and Wales under company number 16997385. Where this policy describes us as a controller, Terrafa Limited is the controller.

Terrafa Limited
Registered in England & Wales, No. 16997385
Registered office: 1 Coldbath Square, London EC1R 5HL, England
Email: info@terrafa.uk

We are not required to appoint a Data Protection Officer, and have not appointed one. Privacy questions are handled directly by the Terrafa team at the address above.

What we collect

We collect as little as we can, and almost all of it comes from a business conversation rather than from tracking you. Depending on your relationship with us, we may hold:

Identity and contact data

  • Name, job title, employer, and the business email address, phone number and postal address you give us.

Relationship and correspondence data

  • What you asked us, what we discussed, meeting notes, and the record of emails and calls between us.
  • Your role in an evaluation, pilot or contract, and the preferences you tell us about.

Contract and financial data

  • Contracting and billing contacts, purchase order references, bank details for payment, and invoicing records. We do not store payment card numbers.

Platform account data

  • For named users of Continuum: username, work email, role and permissions, authentication events, and a record of actions taken in the platform. The audit record exists so that a number can always be traced to who entered, approved or overrode it.

Technical data

  • IP address, browser and device type, and request timing, where our infrastructure or a supplier's records it.
Plainly: this website is a set of static pages. It runs no analytics, sets no cookies, and we do not currently switch on access logging for it. It stores exactly one value on your device — a note that you have already seen the message about not using cookies, described in section 7 — and nothing else. It carries one form, the Continuum sign-up page, which sends the name, email address and organisation you type to our sign-up service and nowhere else. If that changes we will say so here before it does.

Marketing data

  • Whether you have asked to hear from us, or asked us to stop, and the record of that choice.

Recruitment data

  • CV, work history, qualifications, right-to-work confirmation, interview notes and references.

Special category data

We do not seek out special category data — health, ethnicity, religion, trade union membership, biometrics and the rest. The realistic exception is an accessibility or dietary requirement you volunteer for a meeting or event, which we use only to make the arrangement and then delete.

How we obtain it

  • Directly from you — when you email us, meet us, ask for a Continuum account through the sign-up page on this site, complete a pilot, agree a contract, or apply for a role.
  • From your colleagues — when someone at your organisation introduces you or names you as the right contact for a topic.
  • From public and professional sources — company websites, Companies House, industry registers, conference delegate lists and professional networks, where we are researching organisations that our platform is built for.
  • Automatically — technical data generated when you use Continuum, or recorded by the infrastructure serving this website.
  • From service providers — for example our email provider passing us delivery and reply information.

Why we use it, and our legal basis

We only use personal data where the law gives us a basis to. In most cases that is our legitimate interest in running and growing a business-to-business software company, or the performance of a contract.

PurposeData usedLegal basis
Responding to your enquiry and arranging a walkthroughIdentity, contact, correspondenceLegitimate interests — replying to someone who contacted us
Creating the Continuum account you asked for and sending you the invitation to sign inIdentity, contact, platform accountSteps at your request before entering a contract; legitimate interests
Delivering Continuum and supporting its usersIdentity, contact, platform account, technicalPerformance of a contract; legitimate interests where the contract is with your employer rather than you
Managing the customer, supplier and partner relationshipIdentity, contact, relationship, contractPerformance of a contract; legitimate interests
Invoicing, payment and credit controlContract and financialPerformance of a contract; legal obligation
Keeping the platform and our systems secure, investigating misuseTechnical, platform accountLegitimate interests — protecting our systems and our customers' data; legal obligation
Maintaining the audit record that lets a value be traced to its source and its approverPlatform accountLegitimate interests — the auditability our customers rely on; legal obligation where the record supports the customer's own compliance
Improving the platform and this websiteTechnical, relationshipLegitimate interests — understanding what works
Marketing to business contacts about ContinuumIdentity, contact, marketingLegitimate interests; consent where the law requires it
RecruitmentRecruitment, identity, contactSteps at your request before entering a contract; legitimate interests
Meeting our legal obligations, and establishing or defending legal claimsAny of the above, as relevantLegal obligation; legitimate interests

Where we rely on legitimate interests, we have weighed our interest against your rights and satisfied ourselves that our use is proportionate and would not surprise you. You can ask us for that assessment, and you can object.

Where we rely on consent, you can withdraw it at any time. Withdrawing consent does not undo processing we carried out before you withdrew it.

Personal data inside customer data

Continuum connects to a customer's existing systems — historian, laboratory, terminal management, trading and risk, and file-based sources. Records in those systems often carry personal data incidentally: the analyst who ran a test, the operator who signed a movement, the trader who approved a position.

For that data the customer is the controller and Terrafa is a processor. We process it only on the customer's documented instructions, under a written agreement containing the terms required by Article 28 of the UK GDPR, including obligations of confidentiality, security, sub-processor control, assistance with individual rights, and deletion or return at the end of the contract.

Our commitment on customer data, unchanged from the rest of this site: it is never shared, pooled or sold. We do not use one customer's operational data to serve another, and connection to a customer's systems is read-first.

If you are an employee or contractor of one of our customers and want to exercise your rights over that data, please approach your own organisation first — as controller, it decides. We will support them in responding.

Cookies and similar technologies

The one thing we store on your device: when you first open the home page, a short notice tells you the site does not use cookies. We write a single value to your browser's local storage to record that you have seen it, so it is not shown to you again. That value is the only thing this website stores on your device.

It holds no identifier and says nothing about you beyond the fact that the notice has been shown once. Nothing else reads it, and it never leaves your device — there is no request that could carry it to us or to anyone else. Clearing your browsing data removes it, and the only consequence is that you see the notice one more time.

Local storage is not a cookie, but it is storage on your device, and the law we care about here treats the two the same way. We are satisfied this value is strictly necessary for something you asked for: it exists only to stop us repeating a message you have already read. On that basis it does not require your consent. We would not use the same reasoning to store anything that identified you.

Beyond that one value, this website does not set cookies. It contains no analytics, no advertising pixels, no session tracking and no embedded third-party widgets.

There is one third-party request you should know about: the page loads its typefaces from Google Fonts. Making that request discloses your IP address and basic browser information to Google, which we do not receive or control. Google describes its handling of that data in its own privacy policy.

The site is delivered through Amazon CloudFront, a content delivery network. Amazon operates the edge servers that return the page to you.

If we later add analytics, embedded media or any cookie that is not strictly necessary, we will update this policy first and, where the Privacy and Electronic Communications Regulations require it, ask for your consent before setting anything.

The Continuum platform itself uses strictly necessary cookies to keep you signed in and to protect the session. These do not require consent, and are described in the platform's own documentation.

Marketing

We may send business contacts occasional email about Continuum — what it does, what has changed, and what we are learning about commodity operations. We market to organisations and to people in a professional capacity, not to consumers.

Every marketing email carries a one-click unsubscribe, and you can also ask us to stop by emailing info@terrafa.uk. We will act on it promptly and keep a minimal record of your objection so that we do not contact you again by mistake.

Opting out of marketing does not stop service messages we need to send you — a contract notice, a security advisory, a change to this policy.

We do not sell, rent or trade contact details, and we do not share them with third parties for their own marketing.

Who we share it with

We disclose personal data only where there is a reason to, and only to:

  • Service providers acting for us — Amazon Web Services, which provides all of our hosting, infrastructure and authentication, together with the email, collaboration and accounting tools we use to run the business. They act on our instructions under a written contract and may not use the data for their own purposes. We do not operate a customer relationship management system, so your contact details are not held in one.
  • Professional advisers — lawyers, accountants, auditors and insurers, where they need it to advise us.
  • Regulators, courts and law enforcement — where we are legally required to disclose, or where disclosure is necessary to establish or defend a legal claim. We will resist requests that appear overbroad or unlawful.
  • A buyer or investor — if we sell, restructure or raise against the business, subject to confidentiality, and to the same protections described here.

We do not sell personal data, and we have never done so.

A current list of the suppliers we use, and what each of them handles, is available on request.

International transfers

Our infrastructure runs in Amazon Web Services' eu-north-1 region, in Stockholm, Sweden — inside the European Economic Area. Deployments are designed so that a customer's operational data stays in the region agreed with them.

Transfers from the United Kingdom to the EEA are covered by UK adequacy regulations, so our primary hosting arrangement needs no further safeguard.

Some of our suppliers are based outside the UK and the EEA, or support us from outside them. Where personal data leaves the UK, we rely on one of the following:

  • UK adequacy regulations, where the destination country has been recognised as offering an equivalent standard of protection;
  • the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum; or
  • another safeguard permitted by the UK GDPR.

Where we rely on contractual safeguards, we assess the destination's laws and practices and apply additional technical measures — encryption in transit and at rest, and minimisation of what is transferred — where that assessment calls for them.

One transfer applies to every visitor to this website: content is served from the content delivery network's edge locations across North America, Europe and the Middle East, so the request that returns this page may be handled outside the UK.

You can ask us for details of the safeguards applying to a particular transfer.

How long we keep it

We keep personal data for as long as we need it for the purpose we collected it for, and then delete it or anonymise it. Where the law sets a minimum, we keep it for that period.

RecordRetention
Enquiries and prospect contacts24 months from our last meaningful contact
Continuum sign-up requests, and the account created from one24 months from your last use of the platform
A Continuum account nobody has signed into24 months from the date it was created, then deleted
Customer, supplier and partner contract recordsThe life of the contract, then 7 years
Accounting and tax records7 years, as required by the Companies Act 2006 and HMRC
Platform account and audit recordsThe life of the customer contract, then as agreed with the customer in the deletion or return terms
Marketing preferences and objectionsIndefinitely — an objection has to outlive the record it relates to
Unsuccessful job applications6 months, or 12 months if you agree to us keeping you on file
Security and infrastructure logs90 days, longer where an investigation requires it

Where a period expires but we still need part of a record — an unresolved dispute, a live legal claim, an ongoing regulatory obligation — we keep only what that purpose requires and delete the rest.

How we protect it

We apply technical and organisational measures appropriate to the sensitivity of what we hold: encryption in transit and at rest, least-privilege access to production systems, authentication handled by a managed identity service rather than built in-house, separation of production from development, and infrastructure defined as reviewed code.

Our Security overview describes the approach in more detail.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware, and tell affected individuals directly where the risk to them is high.

You have a part in this too. Keep platform credentials to yourself, use a unique password, and tell us at once if you think an account has been compromised.

Third-party websites

This site and our communications may link to organisations we do not control. Following such a link takes you outside this policy, and we are not responsible for how those sites handle your data. Read their privacy notices before giving them anything.

Your rights

Under the UK GDPR you have the right to:

  • Be informed about how we use your personal data — which is what this document is for.
  • Access a copy of the personal data we hold about you.
  • Rectification of data that is inaccurate or incomplete.
  • Erasure of your data where we no longer have a good reason to hold it.
  • Restrict processing while an accuracy dispute or an objection is resolved.
  • Data portability — receive data you gave us in a structured, commonly used, machine-readable form, or have it sent to another controller, where processing is based on consent or a contract and carried out by automated means.
  • Object to processing based on our legitimate interests. Where you object to direct marketing, we will stop — there is no balancing test on that one.
  • Withdraw consent at any time, where consent is what we relied on.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects for you. We do not make such decisions about individuals.

To exercise any of these, email info@terrafa.uk. Exercising them is free. We will respond within one month, and will tell you if a request is complex enough to need up to two months more.

We may ask for enough information to confirm who you are, so that we do not disclose your data to someone else. If a request is manifestly unfounded or excessive we may charge a reasonable fee or decline it, and we will explain why if we do.

If you are in the EEA

Where we process the personal data of individuals in the European Economic Area, the EU GDPR applies alongside the UK GDPR, and the rights described above apply in materially the same form. You may complain to the supervisory authority in the country where you live or work, or where you believe the problem occurred.

We have not appointed a representative in the EEA under Article 27 of the EU GDPR. Until we do, contact us directly on any matter relating to our processing of personal data, at info@terrafa.uk. We answer requests from the EEA on the same terms as those from the UK.

Complaints

If you are unhappy with how we have handled your personal data, tell us first — we would rather fix it. Email info@terrafa.uk and we will investigate and respond.

You also have the right to complain to the UK's supervisory authority at any point:

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk

Changes to this policy

We will update this policy when what we do changes — new tooling, a new processing activity, a change in the law. The version number and date at the top of this page always reflect the current text.

Where a change materially affects how we use data you have already given us, we will tell affected contacts directly rather than relying on you to notice.

Contact us

Questions about this policy, or about anything else we do with personal data:

Terrafa Limited
Registered in England & Wales, No. 16997385
Registered office: 1 Coldbath Square, London EC1R 5HL, England
Email: info@terrafa.uk