About this policy
This policy explains how Terrafa Limited handles personal data — information that identifies a living individual, or could when combined with something else we hold.
It covers you if you visit this website, contact us about Continuum, work for one of our customers, suppliers or partners, attend an event we run, or apply for a job with us.
Terrafa acts in two distinct roles, and the difference matters:
- As a controller. For the personal data we decide to collect and use for our own purposes — enquiries, contracts, marketing, recruitment, running the business. That is what most of this policy is about.
- As a processor. For personal data that happens to sit inside a customer's operational data when Continuum connects to their systems. There, the customer decides what happens and we act on their instructions. Section 6 explains that arrangement.
Where we say "personal data", we mean it in the sense used by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who we are
Terrafa Limited is an independent company registered in England and Wales under company number 16997385. Where this policy describes us as a controller, Terrafa Limited is the controller.
Registered in England & Wales, No. 16997385
Registered office: 1 Coldbath Square, London EC1R 5HL, England
Email: info@terrafa.uk
We are not required to appoint a Data Protection Officer, and have not appointed one. Privacy questions are handled directly by the Terrafa team at the address above.
What we collect
We collect as little as we can, and almost all of it comes from a business conversation rather than from tracking you. Depending on your relationship with us, we may hold:
Identity and contact data
- Name, job title, employer, and the business email address, phone number and postal address you give us.
Relationship and correspondence data
- What you asked us, what we discussed, meeting notes, and the record of emails and calls between us.
- Your role in an evaluation, pilot or contract, and the preferences you tell us about.
Contract and financial data
- Contracting and billing contacts, purchase order references, bank details for payment, and invoicing records. We do not store payment card numbers.
Platform account data
- For named users of Continuum: username, work email, role and permissions, authentication events, and a record of actions taken in the platform. The audit record exists so that a number can always be traced to who entered, approved or overrode it.
Technical data
- IP address, browser and device type, and request timing, where our infrastructure or a supplier's records it.
Marketing data
- Whether you have asked to hear from us, or asked us to stop, and the record of that choice.
Recruitment data
- CV, work history, qualifications, right-to-work confirmation, interview notes and references.
Special category data
We do not seek out special category data — health, ethnicity, religion, trade union membership, biometrics and the rest. The realistic exception is an accessibility or dietary requirement you volunteer for a meeting or event, which we use only to make the arrangement and then delete.
How we obtain it
- Directly from you — when you email us, meet us, ask for a Continuum account through the sign-up page on this site, complete a pilot, agree a contract, or apply for a role.
- From your colleagues — when someone at your organisation introduces you or names you as the right contact for a topic.
- From public and professional sources — company websites, Companies House, industry registers, conference delegate lists and professional networks, where we are researching organisations that our platform is built for.
- Automatically — technical data generated when you use Continuum, or recorded by the infrastructure serving this website.
- From service providers — for example our email provider passing us delivery and reply information.
Why we use it, and our legal basis
We only use personal data where the law gives us a basis to. In most cases that is our legitimate interest in running and growing a business-to-business software company, or the performance of a contract.
| Purpose | Data used | Legal basis |
|---|---|---|
| Responding to your enquiry and arranging a walkthrough | Identity, contact, correspondence | Legitimate interests — replying to someone who contacted us |
| Creating the Continuum account you asked for and sending you the invitation to sign in | Identity, contact, platform account | Steps at your request before entering a contract; legitimate interests |
| Delivering Continuum and supporting its users | Identity, contact, platform account, technical | Performance of a contract; legitimate interests where the contract is with your employer rather than you |
| Managing the customer, supplier and partner relationship | Identity, contact, relationship, contract | Performance of a contract; legitimate interests |
| Invoicing, payment and credit control | Contract and financial | Performance of a contract; legal obligation |
| Keeping the platform and our systems secure, investigating misuse | Technical, platform account | Legitimate interests — protecting our systems and our customers' data; legal obligation |
| Maintaining the audit record that lets a value be traced to its source and its approver | Platform account | Legitimate interests — the auditability our customers rely on; legal obligation where the record supports the customer's own compliance |
| Improving the platform and this website | Technical, relationship | Legitimate interests — understanding what works |
| Marketing to business contacts about Continuum | Identity, contact, marketing | Legitimate interests; consent where the law requires it |
| Recruitment | Recruitment, identity, contact | Steps at your request before entering a contract; legitimate interests |
| Meeting our legal obligations, and establishing or defending legal claims | Any of the above, as relevant | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have weighed our interest against your rights and satisfied ourselves that our use is proportionate and would not surprise you. You can ask us for that assessment, and you can object.
Where we rely on consent, you can withdraw it at any time. Withdrawing consent does not undo processing we carried out before you withdrew it.
Personal data inside customer data
Continuum connects to a customer's existing systems — historian, laboratory, terminal management, trading and risk, and file-based sources. Records in those systems often carry personal data incidentally: the analyst who ran a test, the operator who signed a movement, the trader who approved a position.
For that data the customer is the controller and Terrafa is a processor. We process it only on the customer's documented instructions, under a written agreement containing the terms required by Article 28 of the UK GDPR, including obligations of confidentiality, security, sub-processor control, assistance with individual rights, and deletion or return at the end of the contract.
If you are an employee or contractor of one of our customers and want to exercise your rights over that data, please approach your own organisation first — as controller, it decides. We will support them in responding.
Marketing
We may send business contacts occasional email about Continuum — what it does, what has changed, and what we are learning about commodity operations. We market to organisations and to people in a professional capacity, not to consumers.
Every marketing email carries a one-click unsubscribe, and you can also ask us to stop by emailing info@terrafa.uk. We will act on it promptly and keep a minimal record of your objection so that we do not contact you again by mistake.
Opting out of marketing does not stop service messages we need to send you — a contract notice, a security advisory, a change to this policy.
We do not sell, rent or trade contact details, and we do not share them with third parties for their own marketing.
International transfers
Our infrastructure runs in Amazon Web Services' eu-north-1 region, in Stockholm, Sweden — inside the European Economic Area. Deployments are designed so that a customer's operational data stays in the region agreed with them.
Transfers from the United Kingdom to the EEA are covered by UK adequacy regulations, so our primary hosting arrangement needs no further safeguard.
Some of our suppliers are based outside the UK and the EEA, or support us from outside them. Where personal data leaves the UK, we rely on one of the following:
- UK adequacy regulations, where the destination country has been recognised as offering an equivalent standard of protection;
- the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum; or
- another safeguard permitted by the UK GDPR.
Where we rely on contractual safeguards, we assess the destination's laws and practices and apply additional technical measures — encryption in transit and at rest, and minimisation of what is transferred — where that assessment calls for them.
One transfer applies to every visitor to this website: content is served from the content delivery network's edge locations across North America, Europe and the Middle East, so the request that returns this page may be handled outside the UK.
You can ask us for details of the safeguards applying to a particular transfer.
How long we keep it
We keep personal data for as long as we need it for the purpose we collected it for, and then delete it or anonymise it. Where the law sets a minimum, we keep it for that period.
| Record | Retention |
|---|---|
| Enquiries and prospect contacts | 24 months from our last meaningful contact |
| Continuum sign-up requests, and the account created from one | 24 months from your last use of the platform |
| A Continuum account nobody has signed into | 24 months from the date it was created, then deleted |
| Customer, supplier and partner contract records | The life of the contract, then 7 years |
| Accounting and tax records | 7 years, as required by the Companies Act 2006 and HMRC |
| Platform account and audit records | The life of the customer contract, then as agreed with the customer in the deletion or return terms |
| Marketing preferences and objections | Indefinitely — an objection has to outlive the record it relates to |
| Unsuccessful job applications | 6 months, or 12 months if you agree to us keeping you on file |
| Security and infrastructure logs | 90 days, longer where an investigation requires it |
Where a period expires but we still need part of a record — an unresolved dispute, a live legal claim, an ongoing regulatory obligation — we keep only what that purpose requires and delete the rest.
How we protect it
We apply technical and organisational measures appropriate to the sensitivity of what we hold: encryption in transit and at rest, least-privilege access to production systems, authentication handled by a managed identity service rather than built in-house, separation of production from development, and infrastructure defined as reviewed code.
Our Security overview describes the approach in more detail.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware, and tell affected individuals directly where the risk to them is high.
You have a part in this too. Keep platform credentials to yourself, use a unique password, and tell us at once if you think an account has been compromised.
Third-party websites
This site and our communications may link to organisations we do not control. Following such a link takes you outside this policy, and we are not responsible for how those sites handle your data. Read their privacy notices before giving them anything.
Your rights
Under the UK GDPR you have the right to:
- Be informed about how we use your personal data — which is what this document is for.
- Access a copy of the personal data we hold about you.
- Rectification of data that is inaccurate or incomplete.
- Erasure of your data where we no longer have a good reason to hold it.
- Restrict processing while an accuracy dispute or an objection is resolved.
- Data portability — receive data you gave us in a structured, commonly used, machine-readable form, or have it sent to another controller, where processing is based on consent or a contract and carried out by automated means.
- Object to processing based on our legitimate interests. Where you object to direct marketing, we will stop — there is no balancing test on that one.
- Withdraw consent at any time, where consent is what we relied on.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects for you. We do not make such decisions about individuals.
To exercise any of these, email info@terrafa.uk. Exercising them is free. We will respond within one month, and will tell you if a request is complex enough to need up to two months more.
We may ask for enough information to confirm who you are, so that we do not disclose your data to someone else. If a request is manifestly unfounded or excessive we may charge a reasonable fee or decline it, and we will explain why if we do.
If you are in the EEA
Where we process the personal data of individuals in the European Economic Area, the EU GDPR applies alongside the UK GDPR, and the rights described above apply in materially the same form. You may complain to the supervisory authority in the country where you live or work, or where you believe the problem occurred.
We have not appointed a representative in the EEA under Article 27 of the EU GDPR. Until we do, contact us directly on any matter relating to our processing of personal data, at info@terrafa.uk. We answer requests from the EEA on the same terms as those from the UK.
Complaints
If you are unhappy with how we have handled your personal data, tell us first — we would rather fix it. Email info@terrafa.uk and we will investigate and respond.
You also have the right to complain to the UK's supervisory authority at any point:
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk
Changes to this policy
We will update this policy when what we do changes — new tooling, a new processing activity, a change in the law. The version number and date at the top of this page always reflect the current text.
Where a change materially affects how we use data you have already given us, we will tell affected contacts directly rather than relying on you to notice.
Contact us
Questions about this policy, or about anything else we do with personal data:
Registered in England & Wales, No. 16997385
Registered office: 1 Coldbath Square, London EC1R 5HL, England
Email: info@terrafa.uk