Privacy & Cookie Policy
This policy explains how Coltrane Ltd, trading as ColtraDataAi ("we", "us", "our"), collects, uses, and protects your personal information when you use our website and data analytics platform (the "Service"). We take your privacy seriously and are committed to handling your data responsibly and in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Coltrane Ltd is the data controller for personal information collected through this website and Service. Our registered office is Kemp House, 128 City Road, London EC1V 2NX.
For any privacy-related questions, contact us at support@coltradata.com.
2. What Data We Collect
We may collect the following categories of personal information:
- Account information: Your email address, used for authentication (one-time passcode) and licence delivery. We do not collect a username or password.
- Payment information: Billing and payment details are collected and processed by our payment provider, LemonSqueezy. We do not store payment card details.
- Subscription data: Your plan tier, subscription status, and licence key, stored in our database to enable plan activation.
- API authentication data: If you use the ColtraDataAi Enterprise API, we store a SHA-256 hash of your API key, your email address, and the key label. The raw API key is only shown to you once at the point of issuance and is not recoverable from our systems.
- API usage metadata: For Enterprise API customers, we log each API call: the domain category, number of rows processed, input format (CSV or JSON), and the timestamp. We do not log or retain the content of submitted data.
- Uploaded files: Excel and CSV files you upload for processing are processed in memory for the duration of your session and are not permanently stored on our servers.
- Exported report files: If you generate a report, it may be temporarily stored in our secure cloud storage (Supabase Storage, EU region) to produce a download link. These files are automatically deleted after one hour.
- Usage data: Pages visited, features used, session duration, and browser or device type, used to improve the Service.
- Support communications: Email messages or support requests you send to us.
3. How We Use Your Data
We use your personal information to:
- Authenticate you securely via one-time passcode (OTP).
- Provide, operate, and improve the ColtraDataAi Service.
- Process your subscription and manage your account.
- Deliver and validate API keys for Enterprise API customers.
- Monitor API usage to enforce plan limits and generate billing metadata.
- Respond to support requests and enquiries.
- Send service and billing notifications you need to manage your account.
- Analyse usage patterns to improve the platform (where you have given consent).
- Comply with our legal and regulatory obligations.
4. Legal Basis for Processing (UK GDPR)
We rely on the following legal bases for processing your personal data:
- Contract performance: To deliver the Service you have subscribed to, including authentication, licence activation, and API access.
- Legitimate interests: To improve the Service, maintain security, prevent fraud, and monitor API usage for platform integrity.
- Legal obligation: To comply with applicable laws and regulations.
- Consent: For optional analytics cookies, which you may withdraw at any time.
5. Your Uploaded Data
5a. Standard File Uploads
Files you upload are used solely to deliver the Service to you. We do not read, access, sell, or share the content of your files with any third party. Data is processed in memory during your session. You retain full ownership of all data you upload.
Important: The content of your uploaded files is never stored on our servers beyond the duration of your session. If your session ends, you must re-upload to process again.
5b. Accounting Software Data Exports (Xero, QuickBooks, Sage)
Many customers use ColtraDataAi to clean and validate data originally exported from accounting platforms such as Xero, QuickBooks, Sage, and similar software. When you export a CSV or Excel file from your accounting platform and upload it to ColtraDataAi:
- The file is processed using the same in-memory approach as all other uploads, it is not stored after your session ends.
- ColtraDataAi does not connect directly to Xero, QuickBooks, or Sage on your behalf. We do not request OAuth access to your accounting platform accounts.
- Any financial data within your export (transactions, invoices, ledger entries) is processed locally in our service and returned to you as cleaned output. We do not retain, analyse, or share this data.
- If a future direct integration with accounting platforms is introduced, this policy will be updated and you will be notified in advance.
5c. Enterprise Direct Database Connections
Enterprise plan customers may optionally configure ColtraDataAi to connect directly to their own databases (such as PostgreSQL, MySQL, Microsoft SQL Server, or similar) to extract data for cleaning. Where this feature is used:
- Database connection credentials (host, port, username, password) are provided by you at runtime and are used solely to establish the connection and retrieve the requested data.
- Connection credentials are not stored on our servers after the session ends.
- We do not retain any data extracted from your database beyond your active session.
- You are responsible for ensuring that the account credentials you provide have appropriate, least-privilege access to your database.
- This feature is only available to customers on the Enterprise £999/month plan.
5d. Enterprise API Submissions
Customers using the Enterprise API submit data to our API endpoint at https://coltradata-api.onrender.com. The following applies:
- The content of data submitted via the API is processed in memory and is not stored after the API response is returned.
- We log metadata only per call: domain category, number of rows processed, input format, and timestamp. This metadata is retained for billing and capacity planning (see Section 7).
- You are responsible for ensuring that any data you submit via the API is appropriately authorised for external processing.
6. Third-Party Services
We use the following third-party services that may process some of your data as sub-processors:
- LemonSqueezy: Payment processing and subscription management. Processes your payment details and billing information. LemonSqueezy Privacy Policy
- Supabase (West EU, Ireland): Database and authentication infrastructure. Stores your email address, subscription record, API key hash, API usage metadata, and temporarily stores exported report files (deleted after 1 hour). Supabase is GDPR-compliant and hosted in the EU. Supabase Privacy Policy
- Render (Frankfurt, Germany, EU): Cloud hosting for the ColtraDataAi web application and the Enterprise API. Your session data and processed results are handled within Render's infrastructure during active processing. Render Privacy Policy
- Resend: Transactional email delivery. Used to send OTP authentication codes, licence keys, subscription confirmations, and support communications. Processes your email address. Resend Privacy Policy
- Anthropic: AI language model infrastructure. Used to generate AI-powered data insights for Business and Enterprise tier customers. Data submitted to the AI insights feature is processed via Anthropic's API. No personal identifiers from your account are sent, only the cleaned data summary and statistical observations. Anthropic Privacy Policy
- YouTube (Google LLC): Embedded demo video on our website. YouTube may set cookies when the video player loads. Google Privacy Policy
Each third party operates under its own privacy policy and is responsible for compliance with applicable data protection laws. We maintain Data Processing Agreements with our key sub-processors where required by UK GDPR.
7. Data Retention
We retain personal data only as long as necessary for the purpose it was collected:
- Uploaded files: Processed in-session only; not stored after your session ends.
- Exported reports (Supabase Storage): Temporarily stored and automatically deleted after 1 hour.
- Account and subscription data: Retained for the duration of your subscription, plus up to 6 years thereafter for legal and compliance purposes.
- API key hash and label: Retained for the lifetime of the subscription. Deactivated keys are retained for audit purposes for up to 3 years.
- API usage logs: Retained for up to 2 years for billing and capacity planning purposes, then deleted.
- Authentication OTP records: OTP codes expire within 10 minutes of issuance and are not retained thereafter.
- Support communications: Retained for up to 3 years.
- Analytics data: Retained in aggregated or anonymised form for up to 2 years.
8. Your Rights (UK GDPR)
Under UK GDPR, you have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct inaccurate or incomplete data.
- Erasure: Request deletion of your personal data (subject to legal obligations).
- Restriction: Ask us to restrict how we process your data.
- Portability: Receive your data in a structured, commonly used, machine-readable format.
- Objection: Object to processing based on our legitimate interests.
- Withdraw consent: Withdraw consent for optional processing (such as analytics cookies) at any time.
To exercise any of these rights, contact us at support@coltradata.com. We will respond within one calendar month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at any time.
9. Cookie Policy
Cookies are small text files stored on your device when you visit a website. We use cookies to keep the site running, remember your preferences, and (with your consent) understand how visitors use the site.
| Category | Purpose | Examples | Consent required? |
|---|---|---|---|
| Essential | Required for the site and Service to function. Cannot be switched off. | Session ID, Supabase authentication token, cookie consent preference | No |
| Analytics | Help us understand how visitors interact with the site so we can improve it. Data is aggregated and anonymised where possible. | Page views, session duration, feature usage | Yes |
| Third-party | Set by embedded third-party services when you interact with them (e.g. playing the YouTube demo video). | YouTube / Google cookies | Yes |
You can manage your preferences using the cookie consent banner displayed when you first visit the site. You can also control cookies through your browser settings. Withdrawing consent for analytics or third-party cookies will not affect your ability to use the Service.
10. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or misuse. These include:
- API keys are stored as SHA-256 hashes, the raw key cannot be recovered from our database.
- All data in transit is encrypted using TLS (HTTPS).
- Authentication uses time-limited, single-use one-time passcodes (OTP) rather than passwords.
- Our infrastructure is hosted in the EU (Ireland and Frankfurt) with security controls managed by Supabase and Render.
- Webhook events from LemonSqueezy are verified using HMAC-SHA256 signature validation before processing.
However, no method of data transmission or storage over the internet is completely secure, and we cannot guarantee absolute security.
11. International Transfers
Our primary infrastructure is hosted within the European Economic Area (EEA):
- Supabase: West EU region (Ireland), within the EEA.
- Render (application and API hosting): Frankfurt, Germany, within the EEA.
Some of our service providers may process data in the United States or other countries outside the UK or EEA (including LemonSqueezy, Resend, and Anthropic). Where such transfers occur, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or reliance on the UK's adequacy regulations, in accordance with UK GDPR requirements. A list of our sub-processors and the transfer mechanisms in place is available on request.
12. Children's Privacy
ColtraDataAi is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
13. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices, new features (such as direct accounting software integrations), or legal requirements. The "last updated" date at the top of this page will be revised accordingly. We will notify registered users of significant changes by email or in-app notification.
14. Contact Us
For any privacy-related queries, to exercise your data rights, to request a Data Processing Agreement, or to raise a concern, please contact:
Coltrane Ltd (trading as ColtraDataAi)
Kemp House, 128 City Road, London EC1V 2NX
Email: support@coltradata.com
We aim to acknowledge all privacy queries within 72 hours and resolve them within one calendar month.