Privacy notice
Version 2.4, in force from 2 October 2026. Version 2.4 adds two things we keep to section 9: the field names of layouts you have sent before, and your decisions about whether two names are the same supplier or customer. Version 2.3 recorded that some advertising measurement is now reported from our own server as well as from your browser, and that this can include a scrambled (one-way hashed) copy of your email address and your IP address. It still only happens if you agree, and section 12 sets out exactly what is sent.
1. Who we are
2. We act in two different roles, and the difference matters
Most privacy pages blur this. It is the first thing a compliance team asks, so here it is plainly.
- Your documents: we are the processor. When you upload an invoice, a payslip or a bank statement, the people described in it are not our customers, they are yours. You decide what is collected and why, and we act only on your instructions. The terms governing that are in the data processing agreement, which forms part of your contract automatically. You do not have to request it or sign anything.
- Your own account, and people we contact: we are the controller. Your email address, your billing record, and the contact details of anyone we approach about Datanem are ours to answer for. This notice covers those.
3. What we hold about you, and the lawful basis for it
- Account details, meaning your email address, authentication credentials and team membership. Held to provide the service you asked for, under Article 6(1)(b), performance of a contract.
- Billing records, meaning your plan, payment status and invoices. Held partly to perform the contract and partly because UK tax law requires company records to be kept, under Article 6(1)(c), legal obligation.
- Operational records, meaning rate limit counters, security logs and the record that a batch ran. Held under Article 6(1)(f), legitimate interests, specifically keeping the service available and not paying for someone else's abuse of it.
- Contact details of prospective customers. Covered separately in section 4, because if we found you rather than the other way round, the law says you are owed more.
We do not sell personal data, and we do not build profiles of anyone. We would like to share a limited signal with the advertising networks that carry our adverts, so we can tell which ones work, and we ask before we do: nothing of theirs loads unless you agree. That signal is sent both from your browser and from our own server, and can include a scrambled copy of your email address. Section 12 sets out exactly what that involves, what they are told, and how to change your mind.
4. If we contacted you about Datanem and you never signed up
This is the notice required by Article 14, which applies when a company holds someone's details without having obtained them from that person. If you received an email from us out of the blue, this section is for you.
- What we hold: your name, your work email address, your employer and your role. Nothing else. We hold nothing about your personal life.
- Where we got it: publicly available business sources. In practice, your employer's own website, Companies House, professional directories and public professional profiles. We do not buy marketing lists and we do not scrape personal social media.
- Why: to tell you once about a product that reads documents into spreadsheets, because your role suggests it may be relevant to your work. The lawful basis is Article 6(1)(f), legitimate interests. We have weighed our interest in finding customers against your interest in not being bothered, and concluded that a small number of individually written emails to named people at limited companies, each with a one-line way out, is proportionate. You are entitled to disagree, which is what the next point is for.
- Your absolute right to object: if you tell us to stop, we stop. There is no balancing test for direct marketing; your objection wins automatically under Article 21(2). Reply to the email, write to hello@datanem.com, or use datanem.com/unsubscribe if you would rather not correspond with us at all. The form needs no account and no reason, takes effect immediately, and can remove your whole organisation as well as you.
- What stopping means in practice, and why we keep one thing: we keep your email address on a suppression list so we can recognise it and never contact you again. Deleting it outright would mean finding you from the same public source in six months and starting over, which is precisely what you asked us not to do. That list holds the address and the date, nothing else. If you would rather we erased it completely, say so and we will.
- How long: if you do not reply, we delete your details within six months. If you object, the suppression entry stays until you tell us otherwise, for the reason just given.
- Sharing: nobody. Prospect details are not passed to any third party.
5. Where your documents are processed
Storage and processing are different questions, and most policies answer only the first. Both are answered here.
- Storage is in the EU. Uploaded files sit in an EU-only object storage bucket. The database recording your jobs is constrained to the EU. Neither leaves.
- Reading the document is done by Mistral AI, a French company. Mistral store data in the EU by default. We call their standard endpoint, for which Mistral do not commit to a specific inference location, so an individual request may be processed outside the EEA. We would rather say that than imply a guarantee we have not bought.
- If Mistral is unavailable, a fallback model runs on Cloudflare Workers AI. This happens only when the primary provider fails. Cloudflare run inference across their global network and it cannot be restricted to a region, so that fallback may process a document outside the UK and EEA. Cloudflare confirm in their published terms that they do not train models on it and do not make it available to other customers.
If EU-only processing is a hard requirement for your firm, tell us before you sign up and we will say honestly whether we can meet it today, rather than after you have paid.
6. Your documents are not used to train AI models
This is the question we are asked most, so it gets a precise answer rather than a comforting one.
- DATANEM LIMITED does not train, fine-tune or evaluate any model on your documents or on the data extracted from them. We have no training pipeline.
- Mistral offer model training as an opt-out for API customers rather than excluding it by default. We have opted out, so content we send them is excluded from their training programmes.
- Cloudflare state in their published terms that content sent to Workers AI is not used to train any model, is not used to improve their services, and is not made available to other customers.
7. Who else touches your data
Three companies, named individually with what each receives, where it goes and the transfer mechanism, on the sub-processors page. That list last changed on 16 September 2026, and we tell customers before adding to it.
Where you configure a webhook, extracted data is also sent to whatever URL you nominate. You choose that destination and it is outside our control, so it is not a sub-processor of ours.
8. Transfers outside the UK
9. How long we keep things
- Uploaded files and extracted data: deleted automatically 30 days after the job is created on the free plan, and after 90, 180 or 365 days on Starter, Pro and Max. That clock does not move. A document is the sensitive thing, and nothing needs it once it has been read.
- Data in a saved database: kept until you delete it, but only where you have switched keeping on. That is an instruction you give us, recorded with the date you gave it, and you can withdraw it, empty the database or delete it at any time.
- The record that a batch ran: its date, how many documents it held and the columns it produced. This holds nothing from inside your documents and is kept until you delete the job or close your account.
- Remembered layouts: the field names of a document layout you have sent before, such as "Invoice number" and "Total", so that the next batch in the same layout does not need designing again. These are names, never the values filled in under them, and are deleted 180 days after the layout was last seen, or when you close your account.
- Your decisions about matching names: when you tell us two names in a database are the same supplier or customer, or that they are not, we keep that decision so your exports stay consistent. It is stored as a one-way fingerprint of each name rather than the name itself, and is deleted with the database design or your account.
- Billing records: six years after the end of the accounting period, because UK company and tax law requires it.
- Account details: deleted when you close your account.
10. What deleting actually does
A delete button that quietly leaves copies behind is worse than no delete button, so here is the mechanism.
- The stored file and any converted version of it are removed from object storage immediately.
- The extracted values are deleted from the database, unless you have asked for that database to be kept.
- The filename is overwritten, because documents are often named after the person they describe.
- The record that a job existed remains, holding its date and document count and nothing from inside the document, until you delete the job or close the account.
- Two honest caveats. Our database platform keeps a restorable history for up to 30 days as protection against accidental loss, and that cannot be switched off. Separately, Mistral retain API inputs and outputs for up to 30 days for abuse monitoring. So a deleted document is beyond your reach and ours straight away, but it is not gone from every backing system the same afternoon. Anyone who tells you otherwise about a system like this has not checked.
11. How it is kept safe
- Everything travels over TLS, and files and database contents are encrypted at rest by the storage platform.
- Documents are reachable only by the account that owns them. Intake addresses are random and unguessable.
- Sign-in is by emailed link, passkey or password, and there is no shared administrative password to leak.
- We do not log the contents of your documents or the values extracted from them. Operational logs record job identifiers, timings and errors. A small number of logs record an email address, for example when someone submits the contact form.
- Card details never reach us. Stripe handle them and we see only the result.
13. Documents you email to us
@in.datanem.com, we take the attachments and process them exactly as if you had uploaded them. The body of the message and its headers are read only to identify the sender and are not stored. Anyone who knows an intake address can send to it, so treat it as a secret and revoke it in the app if it is exposed.14. Shared accounts
15. Automated decision making
16. Your rights
You can ask us for a copy of what we hold about you, to correct it, to delete it, to restrict or object to how we use it, or to receive it in a portable form. Where we rely on legitimate interests, including any approach we made to you, you can object. For direct marketing that objection is absolute and we act on it without argument.
Write to hello@datanem.com. We answer within one month, and there is no charge.
If we get it wrong you can complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113. We would rather you told us first, but it is your right either way and you do not need our permission.
If a document you appear in was uploaded by one of our customers, they are the controller and the request goes to them. Tell us and we will help you work out who that is.
17. If something goes wrong
18. Changes to this notice
19. Related documents
- Data processing agreement, the Article 28 terms that apply when we handle documents for you.
- Sub-processors, the three companies involved and what each receives.
- Security and privacy in plain English, the short version for someone deciding whether to trust us.
- Terms and the licence.
Datanem is a product of DATANEM LIMITED, a company registered in England and Wales, number 16870006. Registered office: 8 Court View, Clowne, Chesterfield, England, S43 4BU. Registered with the Information Commissioner's Office, reference ZC053711.