Data protection
How we meet UK GDPR when we handle your organisation's data: the data processing terms, our sub-processors, transfers and security.
Last updated 4 October 2026
Who is responsible for what
UK data protection law (the UK GDPR and the Data Protection Act 2018) splits responsibility between a controller, who decides why and how personal data is used, and a processor, who handles it for them.
- Your organisation's content. You're the controller of the personal data you put into 53°, such as your contacts and the people you send proposals to. We're your processor. The terms below apply.
- Your account and our own records. We're the controller of the data we use to run our business: your account, billing, support and analytics. The privacy policy covers that.
- Company
- 53 Degrees App LTD
- Company number
- 16727854
- ICO registration
- ZC077341
- support@53degrees.app
Data processing terms
These terms are part of our terms of service. They apply whenever we process personal data for your organisation, and they're the contract the UK GDPR requires between a controller and its processor. You don't need to sign anything separately.
What we process
| Aspect | Details |
|---|---|
| Subject matter | Storing and processing your organisation's content so that you can use 53°. |
| Duration | For as long as your organisation exists in the app, then until its content is deleted. |
| Nature and purpose | Hosting, organising, displaying, sending and deleting content as you and your members direct through the app. |
| Types of personal data | Names, contact details, job roles, notes and messages, files, deal and proposal details, signatures, and whatever else you choose to add. |
| Whose data | Your contacts, customers and suppliers, the people you send proposals to, and your members and guests. |
The app isn't built for special category data, such as health records, or for data about criminal convictions. Please don't add it.
What we commit to
We will:
- process your data only on your documented instructions, which are these terms and what you and your members do in the app, unless UK law requires otherwise, in which case we'll tell you first if we're allowed to
- tell you if we think an instruction breaks data protection law
- make sure everyone we let handle your data is bound to keep it confidential
- keep the security measures described on this page in place
- use sub-processors only as described below, under contracts that protect your data to the same standard, and stay responsible for what they do
- help you answer requests from individuals exercising their rights
- help you with security, breach notification, impact assessments and consulting the regulator, as far as they relate to our processing
- delete or return your data when the service ends, as described below
- give you the information you need to show these terms are being met, and allow an audit, as described below
If you need to audit us, we'll first answer your questions in writing and share what evidence we have. If that isn't enough, you can audit our processing once a year, with 30 days' notice, in working hours, at your own cost and under a confidentiality agreement.
What you commit to
- You have a lawful basis for the personal data you add, and you've told the people it's about what they need to know.
- Your instructions to us are lawful.
- You'll choose who joins your organisation with care and keep their roles up to date.
Sub-processors
You agree to us using the providers below to help run the app. Each is bound by a contract that protects your data.
| Provider | What it does | Data involved | Where |
|---|---|---|---|
| Convex | Hosts the app's database and server code | Accounts, organisations and all the content you add | United States |
| Vercel | Hosts and delivers the web app | IP addresses and request logs | United States, with servers worldwide |
| UploadThing | Stores uploaded files | Files, profile pictures and logos | United States |
| Stripe | Takes payments and issues invoices | Billing contact, billing address, tax ID and payment card | Ireland and United States |
| Resend | Sends the app's email | Names, email addresses, message content, and whether an email was delivered, opened or clicked | United States |
| PostHog | Product analytics, session replay, error reports and logs | Usage events, device details and, with consent, your name and email | European Union |
| Productlane | Help centre, support messages and feedback | Name, email address and what you send us | European Union |
| Linear | Our record of customer organisations, for support and planning | Organisation name and plan | United States |
| incident.io | Alerts us to faults and runs the status page | Technical fault details, and your email address if you subscribe to status updates | United Kingdom and United States |
Before we add or replace a sub-processor, we'll update this page and email your organisation's owner at least 14 days ahead. If you object on reasonable data protection grounds and we can't resolve it, you can cancel and we'll refund any fees paid for time after you leave.
These services only receive data when you or a member choose to use them. They act under their own terms, not as our sub-processors.
| Provider | What it does | Data involved | Where |
|---|---|---|---|
| Sign-in, Calendar, Drive and Contacts, when you connect them | Your Google profile, and the calendar events, files or contacts the connection covers | United States, with servers worldwide | |
| Sign-in, when you choose it | Your LinkedIn name, email address and profile picture | United States | |
| Giphy | GIF search in chat | What you search for, and your IP address when a GIF loads | United States |
International transfers
Several of our sub-processors store data outside the UK. We only transfer personal data where the law allows it:
- to countries the UK has found adequate, which includes the European Union
- to US companies certified under the UK-US data bridge
- otherwise under the International Data Transfer Agreement, or the UK Addendum to the EU's standard contractual clauses, after assessing the risk
Security
These are the measures we keep in place.
- Encryption. Data is encrypted in transit with TLS, and at rest by our hosting providers.
- Sign-in. Every password sign-in needs a second step, by emailed code or authenticator app. Passkeys are supported, new accounts must verify their email address, and sign-in attempts are rate limited.
- Sessions. Members can see every device they're signed in on and revoke any of them.
- Access by role. Each member's role decides what they can see and change, and the app checks it on every request.
- Separation. Each organisation's data is kept apart from every other's.
- Files. Private files are served through signed links that expire.
- Our staff. Access to customer data is limited by staff role, and what staff do is recorded in an audit log.
- Analytics. Session replays never show what anyone types.
- Monitoring. Automated checks watch the app and alert us to faults.
Requests from individuals
If someone asks to see, correct or delete the data you hold about them, you can do most of it in the app: find the contact, edit or delete it, or export your contacts to a file. If you need more, email us and we'll help.
If someone contacts us directly about data in your organisation, we'll pass the request to you and won't answer it ourselves unless the law requires us to.
Data breaches
If we become aware of a breach affecting your organisation's personal data, we'll tell the organisation's owner without undue delay, with what we know about what happened, what data is involved and what we're doing about it, so you can meet your own duty to report it.
Deleting and returning data
- You can export your contacts, and download your files, at any time.
- Deleting something in the app removes it from the app. Deleting the organisation removes all of its content, and the clear-out finishes in the background.
- An organisation that goes a year without a plan is deleted, after we email the owner and wait 14 days.
- Copies in our providers' backups are overwritten on their normal cycle.
- We keep invoices and payment records for as long as tax law requires.
Contact us
We aren't required to appoint a data protection officer. Data protection questions go to support@53degrees.app.