Privacy Policy
Effective 10 September 2026 · Updated 11 September 2026
This Policy explains how Tarlara Digital Ltd uses personal data when people visit our websites, create or use an account, communicate with us or use our services.
1. Who we are
- Company
- Tarlara Digital Ltd
- Company number
- 17390332
- Registered office
- 52 Stancliffe Avenue, Marford, Wrexham, LL12 8LW
- Privacy enquiries
- privacy@tarlaradigital.com
Tarlara is the Controller for personal data used to manage accounts, subscriptions, security, support and our own business. A business customer is normally the Controller for personal data it places in the Service, and Tarlara normally acts as its Processor under the Data Processing Agreement.
2. Personal data we collect
Depending on the interaction, we may collect:
- account information, including name, email address, organisation, role, account identifier, status and permissions;
- subscription and transaction information, including plan, billing status, invoices, transaction references and limited billing details;
- communications, support requests, feedback and incident reports;
- technical and security information, including IP address, browser or device information, authentication events, timestamps, audit events and diagnostic information; and
- personal data contained in information or documents that a Customer chooses to enter or upload.
When production payments are enabled, card details will be handled by the payment provider and are not intended to be stored by Tarlara.
3. Where the data comes from
We obtain personal data directly from individuals, their employer or organisation, account administrators, use of the Service, communications with us, operational and security systems, payment and service providers, and public sources where appropriate.
4. How and why we use personal data
| Purpose | Lawful basis |
|---|---|
| Provide and administer a subscription purchased by an individual, including a sole trader | Contract, or steps requested before entering a contract |
| Manage organisational accounts, authorised users and support | Legitimate interests in providing and supporting the Service |
| Process billing and maintain transaction records | Contract where applicable; legal obligation for required accounting records |
| Protect accounts, prevent fraud, investigate faults and maintain reliability | Legitimate interests in operating a secure and reliable Service |
| Improve the Service using proportionate usage and diagnostic information | Legitimate interests in understanding and improving our products |
| Send marketing about Tarlara products and services | Consent where required; otherwise legitimate interests where lawful |
| Meet legal duties and respond to lawful requests | Legal obligation |
| Establish, exercise or defend legal claims | Legitimate interests in protecting our legal rights |
Where we rely on legitimate interests, we consider the effect on individuals and balance those interests against their rights. Where we rely on consent, it can be withdrawn at any time without affecting earlier lawful processing.
Where we process Customer Data for a Customer, we act on that Customer’s instructions. The Customer determines the purpose and lawful basis for that processing.
5. Artificial intelligence
Some features use the OpenAI API to generate summaries, classifications, suggestions or other requested output. We limit information sent for this purpose where reasonably practicable.
Tarlara does not opt in to provider model training and does not use Customer Data to train general-purpose AI models. AI provider and transfer information is summarised in the Supplier and Subprocessor Schedule.
Tarlara does not intend AI features to make decisions based solely on automated processing that produce legal or similarly significant effects about individuals.
6. Sharing personal data
We share personal data with service providers where necessary to operate, secure and support Tarlara, including providers of hosting, databases, storage, artificial intelligence, payments, communications, security and backups. Relevant providers are listed in the Supplier and Subprocessor Schedule.
We may also disclose personal data where required by law, to regulators or competent authorities, to protect legal rights or security, or in connection with a business sale or reorganisation subject to appropriate safeguards. We do not sell personal data.
7. International transfers
Some providers may process personal data outside the United Kingdom. Where a restricted transfer occurs, we use a lawful transfer mechanism. Depending on the recipient, this may be UK adequacy regulations or contractual protections based on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
The Supplier and Subprocessor Schedule gives the current known transfer position. Copies of, or further information about, applicable safeguards can be requested from privacy@tarlaradigital.com.
8. Retention
We retain personal data only for as long as necessary for the relevant purpose and for legal, accounting, security and dispute-resolution requirements.
- organisation deletion remains pending for 30 days before finalisation;
- independent production backups rotate within an operational window of up to 90 days;
- application notifications are retained for up to 180 days;
- AI usage records containing user identifiers are retained for up to 12 months; and
- billing, security, audit and legal records are retained for the period reasonably required by applicable law, security needs or potential claims.
Protected residual copies may remain in backups until normal rotation. They are not used for ordinary business processing after deletion from the live Service.
9. Cookies and similar technologies
Tarlara uses cookies or similar technologies where necessary for security, authentication, session management and essential functionality. If we introduce non-essential analytics, advertising or similar technologies, we will provide information and obtain consent where required.
10. Marketing
We may send relevant information about Tarlara products or services where permitted by law. We obtain consent where required and provide a clear way to unsubscribe. Service, security and billing messages are not marketing.
11. Security
We use appropriate technical and organisational measures designed to protect personal data, including access controls, organisation separation, authentication, private storage, encryption in transit, logging, backups and incident procedures. No internet-connected service can guarantee absolute security.
12. Your rights
Depending on the circumstances, you may have rights to access, correct or erase personal data; restrict processing; receive portable data; withdraw consent; and exercise rights relating to certain automated decisions. Legal conditions and exemptions may apply.
13. Your right to object
You may object to processing based on legitimate interests. You have an absolute right to object to the use of your personal data for direct marketing. Contact privacy@tarlaradigital.com or use the unsubscribe method in a marketing message.
Where Tarlara processes information only for a Customer, we may refer the request to that Customer as Controller. We normally respond to valid requests within one month, subject to extensions permitted by law.
14. Complaints
Please contact privacy@tarlaradigital.com if you have concerns. You may also complain to the Information Commissioner’s Office through ico.org.uk or by telephone on 0303 123 1113.
15. Children
The Service is intended for business and professional use and is not directed at children. We do not knowingly offer accounts directly to children.
16. Changes and contact
We may update this Policy when our Service, providers, processing or legal obligations change. The current version and effective date will be published through our website or Service, with appropriate notice of material changes where required.
For privacy questions or rights requests, contact privacy@tarlaradigital.com or write to Tarlara Digital Ltd at the registered office shown above.