How Sumvero uses personal data
This draft notice explains how Optimus Tech intends to operate Sumvero, what personal data the service can handle and the choices available to affected people. It must be completed with the production operator and vendor details before launch.
Version 2026-08-23
Who is responsible
The production operator will normally be the controller for account registration, subscription billing, service security, support and its own product communications. Each customer company will normally be the controller for the customer, contact, invoice and payment information it enters; the production operator will process that workspace data on the company’s documented instructions.
Information we handle
- Account and organisation details, including names, work email addresses, roles and company profile information.
- Workspace content, including customers, invoice line items, payment records, notes, logos and documents uploaded by authorised users.
- Subscription records and payment-provider identifiers. Where hosted Stripe checkout is enabled, card details are entered into Stripe’s interface rather than this application.
- Security and technical data, such as sign-in events, device sessions, IP addresses, browser/app information, audit records and diagnostic logs.
- Support correspondence, data-rights requests and service preferences.
Why we use it
| Purpose | Typical UK GDPR basis |
|---|---|
| Provide accounts, invoicing features, support and subscription administration | Contract and steps requested before a contract, subject to production legal review |
| Protect workspaces, investigate misuse and keep proportionate audit records | Legitimate interests and, where applicable, legal obligations |
| Measure authenticated feature and page usage, show near-real-time operational activity to the platform owner, and improve the service | Legitimate interests in operating, securing and improving the service; no advertising profile or third-party tracking is used |
| Keep records the operator is legally required to retain | Legal obligation, once the relevant obligation and retention period have been documented |
| Send optional product marketing | Consent where required, or another basis confirmed for the recipient and jurisdiction before sending |
Customer companies must choose their own lawful basis and give appropriate notices for information they add to a workspace.
Sharing and international transfers
Information may need to be disclosed to contracted hosting, database, payment, email-delivery, monitoring, support and professional-service providers, or where law requires it. The actual production providers, purposes and locations have not yet been completed in this draft.
Before live customer data is processed, the operator must publish the completed subprocessor schedule and document any international transfer mechanism and transfer-risk assessment required for each data flow. The service is not intended to sell customer workspace data.
Retention
The production retention schedule is not yet complete. Before launch, it must state a period or clear deletion criterion for each category, including accounts, workspace records, uploaded assets, support messages, audit/security events, payment metadata, backups and data-rights evidence. It must also explain the deletion workflow and any legally required exceptions. Until that schedule is completed, this draft must not be presented as a final retention promise.
Customer companies remain responsible for deciding how long their invoice and customer records must be kept and for making required exports before closing a workspace.
First-party page-usage events contain the workspace user identifier, company identifier, normalised page path and UTC time. Query strings and page content are excluded. Raw usage events are automatically deleted after 400 days so daily, weekly, monthly and yearly comparisons remain available.
Security
The application includes tenant-scoped authorization, password hashing, anti-forgery protection, rate limiting, protected session mechanisms and signed webhook verification where Stripe is configured. Those application controls do not by themselves establish that a deployment is secure. Before production, the operator must verify HTTPS, secrets and key management, least-privilege access, patching, backups and restore testing, logging, monitoring, incident response and supplier controls. No internet service can promise absolute security.
Your rights and complaints
Depending on the circumstances, individuals can ask for access, correction, deletion, restriction, portability or an objection to processing. Where consent is used, it can be withdrawn. Requests concerning data entered by a customer company may need to be handled by that company as controller.
Use the data rights and complaints route or email info@optimustech.co.uk. You may also complain to the UK Information Commissioner’s Office at ico.org.uk.
Automated decisions and children
The current service is not designed to make solely automated decisions about people that produce legal or similarly significant effects. It is a business service and is not directed to children. The production operator must reassess both statements if features or audiences change.
Changes
Material changes will be dated here and, where appropriate, communicated in the service or by email.
Cookies and electronic communications
Our current cookie and device-storage use is described in the cookie policy. Optional direct marketing will be sent only where the operator has a valid UK GDPR and PECR basis, will identify the sender, and will provide a straightforward way to opt out.