Skip to content

Privacy notice

Version 2.4, in force from 2 October 2026. Version 2.4 adds two things we keep to section 9: the field names of layouts you have sent before, and your decisions about whether two names are the same supplier or customer. Version 2.3 recorded that some advertising measurement is now reported from our own server as well as from your browser, and that this can include a scrambled (one-way hashed) copy of your email address and your IP address. It still only happens if you agree, and section 12 sets out exactly what is sent.

1. Who we are

DATANEM LIMITED is the company behind Datanem, registered in England and Wales under number 16870006, with its registered office at 8 Court View, Clowne, Chesterfield, England, S43 4BU. We are registered with the Information Commissioner's Office as a data controller under reference ZC053711, which you can check against the ICO's public register. For anything in this notice, including any request to exercise a right, write to hello@datanem.com. A person reads that inbox.

2. We act in two different roles, and the difference matters

Most privacy pages blur this. It is the first thing a compliance team asks, so here it is plainly.

  • Your documents: we are the processor. When you upload an invoice, a payslip or a bank statement, the people described in it are not our customers, they are yours. You decide what is collected and why, and we act only on your instructions. The terms governing that are in the data processing agreement, which forms part of your contract automatically. You do not have to request it or sign anything.
  • Your own account, and people we contact: we are the controller. Your email address, your billing record, and the contact details of anyone we approach about Datanem are ours to answer for. This notice covers those.

3. What we hold about you, and the lawful basis for it

  • Account details, meaning your email address, authentication credentials and team membership. Held to provide the service you asked for, under Article 6(1)(b), performance of a contract.
  • Billing records, meaning your plan, payment status and invoices. Held partly to perform the contract and partly because UK tax law requires company records to be kept, under Article 6(1)(c), legal obligation.
  • Operational records, meaning rate limit counters, security logs and the record that a batch ran. Held under Article 6(1)(f), legitimate interests, specifically keeping the service available and not paying for someone else's abuse of it.
  • Contact details of prospective customers. Covered separately in section 4, because if we found you rather than the other way round, the law says you are owed more.

We do not sell personal data, and we do not build profiles of anyone. We would like to share a limited signal with the advertising networks that carry our adverts, so we can tell which ones work, and we ask before we do: nothing of theirs loads unless you agree. That signal is sent both from your browser and from our own server, and can include a scrambled copy of your email address. Section 12 sets out exactly what that involves, what they are told, and how to change your mind.

4. If we contacted you about Datanem and you never signed up

This is the notice required by Article 14, which applies when a company holds someone's details without having obtained them from that person. If you received an email from us out of the blue, this section is for you.

  • What we hold: your name, your work email address, your employer and your role. Nothing else. We hold nothing about your personal life.
  • Where we got it: publicly available business sources. In practice, your employer's own website, Companies House, professional directories and public professional profiles. We do not buy marketing lists and we do not scrape personal social media.
  • Why: to tell you once about a product that reads documents into spreadsheets, because your role suggests it may be relevant to your work. The lawful basis is Article 6(1)(f), legitimate interests. We have weighed our interest in finding customers against your interest in not being bothered, and concluded that a small number of individually written emails to named people at limited companies, each with a one-line way out, is proportionate. You are entitled to disagree, which is what the next point is for.
  • Your absolute right to object: if you tell us to stop, we stop. There is no balancing test for direct marketing; your objection wins automatically under Article 21(2). Reply to the email, write to hello@datanem.com, or use datanem.com/unsubscribe if you would rather not correspond with us at all. The form needs no account and no reason, takes effect immediately, and can remove your whole organisation as well as you.
  • What stopping means in practice, and why we keep one thing: we keep your email address on a suppression list so we can recognise it and never contact you again. Deleting it outright would mean finding you from the same public source in six months and starting over, which is precisely what you asked us not to do. That list holds the address and the date, nothing else. If you would rather we erased it completely, say so and we will.
  • How long: if you do not reply, we delete your details within six months. If you object, the suppression entry stays until you tell us otherwise, for the reason just given.
  • Sharing: nobody. Prospect details are not passed to any third party.

5. Where your documents are processed

Storage and processing are different questions, and most policies answer only the first. Both are answered here.

  • Storage is in the EU. Uploaded files sit in an EU-only object storage bucket. The database recording your jobs is constrained to the EU. Neither leaves.
  • Reading the document is done by Mistral AI, a French company. Mistral store data in the EU by default. We call their standard endpoint, for which Mistral do not commit to a specific inference location, so an individual request may be processed outside the EEA. We would rather say that than imply a guarantee we have not bought.
  • If Mistral is unavailable, a fallback model runs on Cloudflare Workers AI. This happens only when the primary provider fails. Cloudflare run inference across their global network and it cannot be restricted to a region, so that fallback may process a document outside the UK and EEA. Cloudflare confirm in their published terms that they do not train models on it and do not make it available to other customers.

If EU-only processing is a hard requirement for your firm, tell us before you sign up and we will say honestly whether we can meet it today, rather than after you have paid.

6. Your documents are not used to train AI models

This is the question we are asked most, so it gets a precise answer rather than a comforting one.

  • DATANEM LIMITED does not train, fine-tune or evaluate any model on your documents or on the data extracted from them. We have no training pipeline.
  • Mistral offer model training as an opt-out for API customers rather than excluding it by default. We have opted out, so content we send them is excluded from their training programmes.
  • Cloudflare state in their published terms that content sent to Workers AI is not used to train any model, is not used to improve their services, and is not made available to other customers.

7. Who else touches your data

Three companies, named individually with what each receives, where it goes and the transfer mechanism, on the sub-processors page. That list last changed on 16 September 2026, and we tell customers before adding to it.

Where you configure a webhook, extracted data is also sent to whatever URL you nominate. You choose that destination and it is outside our control, so it is not a sub-processor of ours.

8. Transfers outside the UK

Where data leaves the UK it is covered by the UK International Data Transfer Addendum, the EU standard contractual clauses, or the UK-US Data Privacy Framework, depending on the provider. The specific mechanism for each is named on the sub-processors page rather than asserted generally here.

9. How long we keep things

  • Uploaded files and extracted data: deleted automatically 30 days after the job is created on the free plan, and after 90, 180 or 365 days on Starter, Pro and Max. That clock does not move. A document is the sensitive thing, and nothing needs it once it has been read.
  • Data in a saved database: kept until you delete it, but only where you have switched keeping on. That is an instruction you give us, recorded with the date you gave it, and you can withdraw it, empty the database or delete it at any time.
  • The record that a batch ran: its date, how many documents it held and the columns it produced. This holds nothing from inside your documents and is kept until you delete the job or close your account.
  • Remembered layouts: the field names of a document layout you have sent before, such as "Invoice number" and "Total", so that the next batch in the same layout does not need designing again. These are names, never the values filled in under them, and are deleted 180 days after the layout was last seen, or when you close your account.
  • Your decisions about matching names: when you tell us two names in a database are the same supplier or customer, or that they are not, we keep that decision so your exports stay consistent. It is stored as a one-way fingerprint of each name rather than the name itself, and is deleted with the database design or your account.
  • Billing records: six years after the end of the accounting period, because UK company and tax law requires it.
  • Account details: deleted when you close your account.

10. What deleting actually does

A delete button that quietly leaves copies behind is worse than no delete button, so here is the mechanism.

  • The stored file and any converted version of it are removed from object storage immediately.
  • The extracted values are deleted from the database, unless you have asked for that database to be kept.
  • The filename is overwritten, because documents are often named after the person they describe.
  • The record that a job existed remains, holding its date and document count and nothing from inside the document, until you delete the job or close the account.
  • Two honest caveats. Our database platform keeps a restorable history for up to 30 days as protection against accidental loss, and that cannot be switched off. Separately, Mistral retain API inputs and outputs for up to 30 days for abuse monitoring. So a deleted document is beyond your reach and ours straight away, but it is not gone from every backing system the same afternoon. Anyone who tells you otherwise about a system like this has not checked.

11. How it is kept safe

  • Everything travels over TLS, and files and database contents are encrypted at rest by the storage platform.
  • Documents are reachable only by the account that owns them. Intake addresses are random and unguessable.
  • Sign-in is by emailed link, passkey or password, and there is no shared administrative password to leak.
  • We do not log the contents of your documents or the values extracted from them. Operational logs record job identifiers, timings and errors. A small number of logs record an email address, for example when someone submits the contact form.
  • Card details never reach us. Stripe handle them and we see only the result.

12. Cookies

We set cookies to keep you signed in, to run a trial without an account, to remember an invite code so the free documents it carries reach the right account, and, if you arrive through a link we have shared, such as an offer or a directory listing, to remember which one sent you. Those are first party, readable only by our own server, and never shared with anyone else.

We also set a first party cookie that lets us count how far a visit got: whether somebody landed and left, uploaded a document, or reached the point of making an account. It holds a random identifier and nothing else. We do not store your IP address against it, we do not keep your browser's user agent string, only whether the device was a phone, a tablet or a computer, and it is never matched to your name, your address or anything you upload. Those records are deleted after 90 days. It exists so we can tell a page that is not working from an advert that is reaching the wrong people, which we could not otherwise do without watching individuals.

For traffic figures we also use Cloudflare Web Analytics, which sets no cookies and does not fingerprint visitors. When you enter a card we use Cloudflare Turnstile to check you are not a bot, and that receives your IP address.

Analytics and advertising. We would like to know how this site is used and which adverts bring people here. Measuring that means letting a third party set its own cookies and, in the case of an advertising network, read an identifier it has already placed in your browser, and it means sending them a report from our own server when something happens. The advertising part of that is cross-site tracking and we are not going to describe it as anything else.

So we ask first. Nothing belonging to an analytics or advertising network loads until you have said yes to the banner. If you say no, or if you close the page without answering, no such script is loaded, no request is made to one, no cookie of theirs is set, and our server reports nothing about you either. There is no version of this where refusing costs you anything: every part of the product behaves identically either way.

If you do agree, the three recipients are TikTok, through its advertising pixel, Google Ads, through its conversion tag, and Google Analytics, through Google's measurement tag. All are named on the banner itself.

Google Analytics is told one thing: which page of this site you are looking at, each time you open or move to one. It is told this for every page, not only the marketing ones, and it sets its own cookies in our name so that a series of pages is recognised as one visit. It is not sent any of the events below and is not told when you pay for anything.

The advertising networks are told seven things and no more: that a marketing page was viewed, that a document was uploaded and reading began, that a document was successfully read, that someone asked for their spreadsheet by email, that an account was created, that a payment was started, and that a plan began or a payment completed. The last of those also carries its amount. Not every network is told all seven, because each only accepts the events its own system has a name for.

Some of those seven are reported from our own server rather than from your browser, because ad blockers and browser privacy settings stop a large share of the browser reports from arriving, which makes the measurement wrong rather than absent. This applies to the advertising networks only; nothing is ever sent to Google Analytics from our server. The events are the same ones listed above, and each carries a single random identifier so that the two reports of one event are recognised as one and not counted twice. This only happens if you agreed; your answer is not readable by our server, so the browser simply does not ask it to send anything when the answer was no.

Those server-side reports can include three further things: your IP address, your browser's user-agent string, and, if you gave us an email address to send a spreadsheet to, a scrambled copy of that address. The scrambling is a one-way hash (SHA-256): TikTok can check it against an address they already hold, which is the point of sending it, but they cannot read it or recover the address from it. We do not send the address itself, and we send nothing at all about anyone who declined.

We never send your name, the contents of a document you upload, or anything extracted from one. No analytics or advertising network receives your documents or the data extracted from them, and none of them is involved in processing a document at any point. For whatever they do with what they are sent, they act as an independent controller under their own privacy policies.

Your answer is stored in your own browser, not on our server, and is not sent with any request. You can change it at any time, and doing so is one click:

A tracker blocker, an ad blocker or blocking third-party cookies outright will also stop any of this, and none of it affects anything on this site.

Everything else we set remains first party and stays on our own server, as described above.

13. Documents you email to us

If you use an intake address, meaning one ending @in.datanem.com, we take the attachments and process them exactly as if you had uploaded them. The body of the message and its headers are read only to identify the sender and are not stored. Anyone who knows an intake address can send to it, so treat it as a secret and revoke it in the app if it is exposed.

14. Shared accounts

An account owner on a plan with more than one seat can invite colleagues. Everyone on a team works inside the same account, so each of them can see, download and delete every document that account holds, whoever uploaded it. Leaving a team does not take any documents with you: they belong to the account. If you are uploading material about other people, the account owner is the controller of it and is responsible for who they let in.

15. Automated decision making

Datanem transcribes and structures what is already written in your documents. It does not score, rank or decide anything about the people described in them, so it does not make decisions producing legal or similarly significant effects under Article 22. The output is a draft for a person to check, and the terms require exactly that.

16. Your rights

You can ask us for a copy of what we hold about you, to correct it, to delete it, to restrict or object to how we use it, or to receive it in a portable form. Where we rely on legitimate interests, including any approach we made to you, you can object. For direct marketing that objection is absolute and we act on it without argument.

Write to hello@datanem.com. We answer within one month, and there is no charge.

If we get it wrong you can complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113. We would rather you told us first, but it is your right either way and you do not need our permission.

If a document you appear in was uploaded by one of our customers, they are the controller and the request goes to them. Tell us and we will help you work out who that is.

17. If something goes wrong

We keep a record of security incidents. Where we act as your processor and a breach affects your data, we tell you without undue delay so you can meet your own reporting duty. Where we are the controller and a breach is reportable, we notify the Information Commissioner's Office within 72 hours of becoming aware of it.

18. Changes to this notice

The version and date at the top change whenever this does. Where a change materially affects you, for example a new sub-processor, we tell account holders before it takes effect rather than relying on you to re-read the page.

19. Related documents

Datanem is a product of DATANEM LIMITED, a company registered in England and Wales, number 16870006. Registered office: 8 Court View, Clowne, Chesterfield, England, S43 4BU. Registered with the Information Commissioner's Office, reference ZC053711.