Effective date: 2026-08-04
Infracto is the data controller for the personal data described in this policy — the organisation that decides why and how it is used. Our ICO data protection registration number is [ICO REGISTRATION NUMBER — TBD, registration not yet filed]. You can contact us about anything in this policy at accounts@infracto.co.uk.
We collect three kinds of personal data:
We keep account and usage data for as long as your account is active, and for a limited period afterwards in case you wish to reactivate it or as required to resolve a billing dispute. Payment metadata is kept for as long as UK accounting law requires records to be retained.
We use a small number of processors to run the service. None of them use your data for their own purposes beyond providing their service to us.
| Processor | Role | Region |
|---|---|---|
| Supabase | Auth, database, and realtime sync | eu-west-2 (London) |
| Render | Application hosting | Frankfurt |
| Stripe Payments UK Ltd | Payment processing | UK |
| Brevo | Transactional email (account and billing notices) | EU (France) |
Every processor listed above is based in the UK or the EU. We do not currently transfer personal data outside the UK/EEA, so no additional safeguard (such as Standard Contractual Clauses or a UK International Data Transfer Agreement) is currently needed. We will update this section if that changes — for example, if we introduce a processor based elsewhere.
Under UK GDPR, you have the right to:
To exercise any of these rights, email accounts@infracto.co.uk. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data properly.
Tamora is a professional event-production tool and is not directed at, or intended for use by, children. We do not knowingly collect personal data from anyone under 18.
If we make a material change to this policy, we will update the effective date above and, where the change is significant, notify account holders by email.