Legal

Data protection

How we meet UK GDPR when we handle your organisation's data: the data processing terms, our sub-processors, transfers and security.

Last updated 4 October 2026

Who is responsible for what

UK data protection law (the UK GDPR and the Data Protection Act 2018) splits responsibility between a controller, who decides why and how personal data is used, and a processor, who handles it for them.

  • Your organisation's content. You're the controller of the personal data you put into 53°, such as your contacts and the people you send proposals to. We're your processor. The terms below apply.
  • Your account and our own records. We're the controller of the data we use to run our business: your account, billing, support and analytics. The privacy policy covers that.
Company
53 Degrees App LTD
Company number
16727854
ICO registration
ZC077341
Email
support@53degrees.app

Data processing terms

These terms are part of our terms of service. They apply whenever we process personal data for your organisation, and they're the contract the UK GDPR requires between a controller and its processor. You don't need to sign anything separately.

What we process

AspectDetails
Subject matterStoring and processing your organisation's content so that you can use 53°.
DurationFor as long as your organisation exists in the app, then until its content is deleted.
Nature and purposeHosting, organising, displaying, sending and deleting content as you and your members direct through the app.
Types of personal dataNames, contact details, job roles, notes and messages, files, deal and proposal details, signatures, and whatever else you choose to add.
Whose dataYour contacts, customers and suppliers, the people you send proposals to, and your members and guests.

The app isn't built for special category data, such as health records, or for data about criminal convictions. Please don't add it.

What we commit to

We will:

  • process your data only on your documented instructions, which are these terms and what you and your members do in the app, unless UK law requires otherwise, in which case we'll tell you first if we're allowed to
  • tell you if we think an instruction breaks data protection law
  • make sure everyone we let handle your data is bound to keep it confidential
  • keep the security measures described on this page in place
  • use sub-processors only as described below, under contracts that protect your data to the same standard, and stay responsible for what they do
  • help you answer requests from individuals exercising their rights
  • help you with security, breach notification, impact assessments and consulting the regulator, as far as they relate to our processing
  • delete or return your data when the service ends, as described below
  • give you the information you need to show these terms are being met, and allow an audit, as described below

If you need to audit us, we'll first answer your questions in writing and share what evidence we have. If that isn't enough, you can audit our processing once a year, with 30 days' notice, in working hours, at your own cost and under a confidentiality agreement.

What you commit to

  • You have a lawful basis for the personal data you add, and you've told the people it's about what they need to know.
  • Your instructions to us are lawful.
  • You'll choose who joins your organisation with care and keep their roles up to date.

Sub-processors

You agree to us using the providers below to help run the app. Each is bound by a contract that protects your data.

ProviderWhat it doesData involvedWhere
ConvexHosts the app's database and server codeAccounts, organisations and all the content you addUnited States
VercelHosts and delivers the web appIP addresses and request logsUnited States, with servers worldwide
UploadThingStores uploaded filesFiles, profile pictures and logosUnited States
StripeTakes payments and issues invoicesBilling contact, billing address, tax ID and payment cardIreland and United States
ResendSends the app's emailNames, email addresses, message content, and whether an email was delivered, opened or clickedUnited States
PostHogProduct analytics, session replay, error reports and logsUsage events, device details and, with consent, your name and emailEuropean Union
ProductlaneHelp centre, support messages and feedbackName, email address and what you send usEuropean Union
LinearOur record of customer organisations, for support and planningOrganisation name and planUnited States
incident.ioAlerts us to faults and runs the status pageTechnical fault details, and your email address if you subscribe to status updatesUnited Kingdom and United States

Before we add or replace a sub-processor, we'll update this page and email your organisation's owner at least 14 days ahead. If you object on reasonable data protection grounds and we can't resolve it, you can cancel and we'll refund any fees paid for time after you leave.

These services only receive data when you or a member choose to use them. They act under their own terms, not as our sub-processors.

ProviderWhat it doesData involvedWhere
GoogleSign-in, Calendar, Drive and Contacts, when you connect themYour Google profile, and the calendar events, files or contacts the connection coversUnited States, with servers worldwide
LinkedInSign-in, when you choose itYour LinkedIn name, email address and profile pictureUnited States
GiphyGIF search in chatWhat you search for, and your IP address when a GIF loadsUnited States

International transfers

Several of our sub-processors store data outside the UK. We only transfer personal data where the law allows it:

  • to countries the UK has found adequate, which includes the European Union
  • to US companies certified under the UK-US data bridge
  • otherwise under the International Data Transfer Agreement, or the UK Addendum to the EU's standard contractual clauses, after assessing the risk

Security

These are the measures we keep in place.

  • Encryption. Data is encrypted in transit with TLS, and at rest by our hosting providers.
  • Sign-in. Every password sign-in needs a second step, by emailed code or authenticator app. Passkeys are supported, new accounts must verify their email address, and sign-in attempts are rate limited.
  • Sessions. Members can see every device they're signed in on and revoke any of them.
  • Access by role. Each member's role decides what they can see and change, and the app checks it on every request.
  • Separation. Each organisation's data is kept apart from every other's.
  • Files. Private files are served through signed links that expire.
  • Our staff. Access to customer data is limited by staff role, and what staff do is recorded in an audit log.
  • Analytics. Session replays never show what anyone types.
  • Monitoring. Automated checks watch the app and alert us to faults.

Requests from individuals

If someone asks to see, correct or delete the data you hold about them, you can do most of it in the app: find the contact, edit or delete it, or export your contacts to a file. If you need more, email us and we'll help.

If someone contacts us directly about data in your organisation, we'll pass the request to you and won't answer it ourselves unless the law requires us to.

Data breaches

If we become aware of a breach affecting your organisation's personal data, we'll tell the organisation's owner without undue delay, with what we know about what happened, what data is involved and what we're doing about it, so you can meet your own duty to report it.

Deleting and returning data

  • You can export your contacts, and download your files, at any time.
  • Deleting something in the app removes it from the app. Deleting the organisation removes all of its content, and the clear-out finishes in the background.
  • An organisation that goes a year without a plan is deleted, after we email the owner and wait 14 days.
  • Copies in our providers' backups are overwritten on their normal cycle.
  • We keep invoices and payment records for as long as tax law requires.

Contact us

We aren't required to appoint a data protection officer. Data protection questions go to support@53degrees.app.

Copyright 2026 53 Degrees App LTD. Company number: 16727854. All rights reserved. Made with ♥ in Yorkshire 53.8008°N, 1.5491°W