The important distinction
Deacova controls information used for our own website and service administration. A business using Deacova normally controls the information it collects from its customers, participants, and visitors, and its own privacy notice applies.
1. Who we are and our role
Deacova provides software for bookings, events, services, resources, customers, participants, payments, websites, and communications. We are based in Leicestershire, United Kingdom. Privacy questions and rights requests can be sent to contact@deacova.co.uk.
Deacova as controller
We decide how to use information for our corporate website, enquiries, product updates, direct business relationships, billing, security, legal compliance, support, and service administration.
Deacova as processor
A business using Deacova normally decides what customer, participant, staff, booking, payment, or form information it needs. We generally handle that information on the business’s instructions.
Contact the relevant business first about a booking, participant profile, payment, form, or message handled for it. We support that business with rights requests where our contract and data-protection law require it.
2. Information we use
The information involved depends on how you interact with Deacova and which features the relevant business enables.
Contact and account details
Names, business and contact details, credentials, verification details, roles, permissions, support correspondence, and account activity.
Bookings and participation
Events or services, dates, participants, profiles, dates of birth, attendance, notes, configured answers, communications, and uploaded files.
Payments and commerce
Prices, fees, billing contacts, purchases, subscriptions, cancellations, refunds, and payment-provider identifiers. Deacova does not store full card numbers.
Device, location, and service use
IP address, browser or device details, session and push tokens, page or screen activity, address or place searches, coordinates, error reports, security logs, and aggregate visit counts.
Enquiries and updates
Contact details, business requirements, enquiry intent, source page, signup status, consent version, and unsubscribe history.
Support and AI content
Messages, files, screenshots, page context, prompts, responses, tool results, citations, action drafts, and support history.
Community content and safety
Blog comments, author and post details, edits and deletions, rule acceptances, reports and their source snapshots, moderation outcomes, commenting restrictions, and personal block or hide choices.
Information comes from you, the relevant business or another authorised person, your browser or device, and integrations you choose to use. Required fields are identified in the service; without them, we or the business may be unable to answer an enquiry, secure an account, complete a booking or payment, or provide the requested feature.
3. Why we use information
When Deacova is the controller, we use information for these purposes and lawful bases:
- Contract
- To provide and administer the service, support a direct customer relationship, and take requested steps before a contract, including enquiries and demos.
- Legitimate interests
- To secure and improve Deacova, prevent misuse, filter prohibited or repetitive community content, investigate reports, maintain moderation and audit trails, support users, and manage genuine business relationships, where those interests are not overridden by individual rights.
- Legal obligations
- To keep required tax, accounting, security, and legal records and respond to lawful requests.
- Consent
- To send product updates you requested and to use non-essential device storage or access where consent is required. You can withdraw consent at any time.
When we act as a processor, the relevant business chooses its purposes, lawful bases, and any special-category conditions, and we follow its documented instructions.
5. AI features
If a workspace enables the AI assistant, Deacova stores its conversations, page context, citations, tool output, proposed actions, and any documents provided for retrieval. Information needed to answer a request is sent to the OpenAI API. OpenAI states that API data is not used to train its models by default unless an organisation opts in. See OpenAI API data controls.
Users should avoid unnecessary sensitive information in prompts or documents. Record-changing actions require human approval, and Deacova does not use the assistant to make solely automated decisions about people with legal or similarly significant effects.
6. Community content and safety
A business can enable Blog or News comments for its workspace. That business normally controls its members’ comments and moderation decisions, and Deacova processes the information on its instructions. Deacova also uses the minimum records needed for platform security, abuse prevention, legal compliance, and reliable service administration.
Comments can show the author name and publication time to everyone allowed to read the post, including anonymous visitors when the post is public. A comment report records the reporter and reported member, report type, reason, optional details, and an immutable snapshot of the source comment and author at the time of reporting. It also records review status, decisions, notes, the reviewing administrator, and any commenting restriction.
Before commenting or editing, a user must accept the current version of Deacova’s community rules and any workspace addendum. We record the rule versions, acceptance time, workspace, user, and whether acceptance occurred on web or app. Comment text is automatically checked for platform and workspace prohibited terms, excessive links, repeated patterns, and rapid duplicate content. A failed check returns a general rules message; automated filtering does not impose a commenting restriction by itself.
Reporting is separate from hiding or blocking. Personal hide and block records are used only to tailor what the person sees and can reply to in that workspace. A blocked person is not notified. The person who created a block or hide can reverse it from Comment safety in their profile. Only authorised workspace comment moderators can access the report queue or impose and restore commenting restrictions; reports do not generate email, push, or inbox alerts.
8. Transfers and retention
Some providers operate or provide support outside the United Kingdom. Depending on the provider and destination, we use UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, and any required transfer-risk assessment. You can ask us about the safeguard relevant to your information.
We keep information only for its purpose, the relevant customer’s documented instructions, security and recovery, and applicable legal, accounting, dispute, or regulatory requirements. In particular:
- enquiries are kept while we respond and for a reasonable follow-up or legal-claims period; product-update details remain until unsubscribe, with minimum consent and suppression records kept afterwards;
- accounts, contracts, billing, and finance records remain for the active relationship and the applicable contractual or statutory period;
- business-controlled bookings, profiles, files, forms, and messages follow that business’s instructions and contract with Deacova;
- comments follow the relevant business’s instructions and contract; resolved reports, immutable source snapshots, moderation decisions, and restrictions can be retained as safety and audit history for legal, dispute, and repeat-abuse purposes;
- personal blocks and hidden-comment choices remain until the user reverses them or the related account or workspace data is deleted; versioned community-rule acceptances are kept to demonstrate the rules accepted before a comment mutation;
- abandoned checkout records are scheduled for deletion after 30 days, temporary uploads after about 60 minutes, generated exports after 7 days, and export-history records 30 days after expiry;
- detailed service-visit buckets are removed after about one year; technical AI usage logs after 365 days; and AI failure logs and unexecuted draft or rejected action records after 90 days; and
- security and backend Sentry error records, provider-held service state, and restricted recovery copies follow the operational or contractual cycle needed to investigate, secure, and recover the service; and
- mobile Sentry crash reports are available only to authorised Deacova personnel responsible for reliability and security. Sentry alerts go only to those authorised recipients, events follow the configured Sentry project retention period, and source maps are uploaded solely to translate technical code locations without adding user content. Deacova can stop new mobile reporting by removing the production crash-reporting configuration and shipping a compatible update or release.
A legal hold, dispute, fraud investigation, or regulatory request can require longer retention. Irreversibly anonymised information may be kept because it no longer identifies anyone.
9. Children and sensitive information
Deacova’s corporate website and business administration service are not directed at children. A business may use Deacova for an activity involving a child and may collect a date of birth, guardian contact, or participation details. That business is responsible for its lawful basis, privacy information, and any required parental or guardian authority; Deacova normally acts as its processor.
Configurable fields and uploads can contain health, disability, allergy, safeguarding, or other sensitive information. The business must make sure collection is necessary, authorised, access-controlled, and retained appropriately. Users should not put unnecessary sensitive information into free-text fields, files, or AI prompts.
10. Your rights
Depending on the circumstances, UK data-protection law may let you access, correct, erase, restrict, or obtain a portable copy of your information, and withdraw consent. These rights are not absolute, and we may need to verify your identity.
Your right to object
You may object to processing based on legitimate interests. You may also object to direct marketing at any time. We will stop direct marketing and will stop other objected-to processing unless a lawful exception applies.
Contact the relevant business first for information it controls. For Deacova-controlled information, email contact@deacova.co.uk. Product-update emails also contain an unsubscribe link.
Comment safety in the web and mobile profile lets a user review and reverse their own member blocks and hidden-comment choices. Requests about comments, reports, moderation records, or restrictions controlled by a particular workspace should normally be directed to that business first.
You may complain to the UK Information Commissioner’s Office. We would appreciate the opportunity to help first, but this does not limit your right to use the ICO complaints service.
11. Security and contact
We use encrypted connections, authentication and role-based access, tenant separation, audit and security logging, controlled infrastructure access, monitoring, and other technical and organisational measures designed to protect personal information. No online service can guarantee absolute security.
You can also use our contact page for general enquiries. We may update this notice when our service, providers, or legal requirements change. We will revise the date above and take reasonable steps to highlight material changes.