Skip to main content

Legal and privacy

Privacy notice

How Deacova handles personal information across our website, booking software, mobile experiences, and related services.

Effective and last updated: 18 August 2026

Jump to a section

The important distinction

Deacova controls information used for our own website and service administration. A business using Deacova normally controls the information it collects from its customers, participants, and visitors, and its own privacy notice applies.

1. Who we are and our role

Deacova provides software for bookings, events, services, resources, customers, participants, payments, websites, and communications. We are based in Leicestershire, United Kingdom. Privacy questions and rights requests can be sent to contact@deacova.co.uk.

Deacova as controller

We decide how to use information for our corporate website, enquiries, product updates, direct business relationships, billing, security, legal compliance, support, and service administration.

Deacova as processor

A business using Deacova normally decides what customer, participant, staff, booking, payment, or form information it needs. We generally handle that information on the business’s instructions.

Contact the relevant business first about a booking, participant profile, payment, form, or message handled for it. We support that business with rights requests where our contract and data-protection law require it.

2. Information we use

The information involved depends on how you interact with Deacova and which features the relevant business enables.

Contact and account details

Names, business and contact details, credentials, verification details, roles, permissions, support correspondence, and account activity.

Bookings and participation

Events or services, dates, participants, profiles, dates of birth, attendance, notes, configured answers, communications, and uploaded files.

Payments and commerce

Prices, fees, billing contacts, purchases, subscriptions, cancellations, refunds, and payment-provider identifiers. Deacova does not store full card numbers.

Device, location, and service use

IP address, browser or device details, session and push tokens, page or screen activity, address or place searches, coordinates, error reports, security logs, and aggregate visit counts.

Enquiries and updates

Contact details, business requirements, enquiry intent, source page, signup status, consent version, and unsubscribe history.

Support and AI content

Messages, files, screenshots, page context, prompts, responses, tool results, citations, action drafts, and support history.

Community content and safety

Blog comments, author and post details, edits and deletions, rule acceptances, reports and their source snapshots, moderation outcomes, commenting restrictions, and personal block or hide choices.

Information comes from you, the relevant business or another authorised person, your browser or device, and integrations you choose to use. Required fields are identified in the service; without them, we or the business may be unable to answer an enquiry, secure an account, complete a booking or payment, or provide the requested feature.

3. Why we use information

When Deacova is the controller, we use information for these purposes and lawful bases:

Contract
To provide and administer the service, support a direct customer relationship, and take requested steps before a contract, including enquiries and demos.
Legitimate interests
To secure and improve Deacova, prevent misuse, filter prohibited or repetitive community content, investigate reports, maintain moderation and audit trails, support users, and manage genuine business relationships, where those interests are not overridden by individual rights.
Legal obligations
To keep required tax, accounting, security, and legal records and respond to lawful requests.
Consent
To send product updates you requested and to use non-essential device storage or access where consent is required. You can withdraw consent at any time.

When we act as a processor, the relevant business chooses its purposes, lawful bases, and any special-category conditions, and we follow its documented instructions.

4. Cookies and external content

Essential session and XSRF cookies keep the service working and protect submissions. On the marketing site, their browser lifetime is normally up to two hours. Browser or mobile storage may also hold authentication, preferences, booking-cart details, and in-progress checkout or participant information until expiry, sign-out, completion, or removal.

Public forms may load Google reCAPTCHA to detect automated misuse. Embedded OpenStreetMap maps, YouTube videos, Vimeo videos, and Unsplash image previews can send the provider network, device, and request information when they load.

Deacova does not currently use advertising or behavioural-analytics cookies. If that changes, we will update this notice and use any consent controls required by law. Blocking essential storage can prevent parts of the service from working.

5. AI features

If a workspace enables the AI assistant, Deacova stores its conversations, page context, citations, tool output, proposed actions, and any documents provided for retrieval. Information needed to answer a request is sent to the OpenAI API. OpenAI states that API data is not used to train its models by default unless an organisation opts in. See OpenAI API data controls.

Users should avoid unnecessary sensitive information in prompts or documents. Record-changing actions require human approval, and Deacova does not use the assistant to make solely automated decisions about people with legal or similarly significant effects.

6. Community content and safety

A business can enable Blog or News comments for its workspace. That business normally controls its members’ comments and moderation decisions, and Deacova processes the information on its instructions. Deacova also uses the minimum records needed for platform security, abuse prevention, legal compliance, and reliable service administration.

Comments can show the author name and publication time to everyone allowed to read the post, including anonymous visitors when the post is public. A comment report records the reporter and reported member, report type, reason, optional details, and an immutable snapshot of the source comment and author at the time of reporting. It also records review status, decisions, notes, the reviewing administrator, and any commenting restriction.

Before commenting or editing, a user must accept the current version of Deacova’s community rules and any workspace addendum. We record the rule versions, acceptance time, workspace, user, and whether acceptance occurred on web or app. Comment text is automatically checked for platform and workspace prohibited terms, excessive links, repeated patterns, and rapid duplicate content. A failed check returns a general rules message; automated filtering does not impose a commenting restriction by itself.

Reporting is separate from hiding or blocking. Personal hide and block records are used only to tailor what the person sees and can reply to in that workspace. A blocked person is not notified. The person who created a block or hide can reverse it from Comment safety in their profile. Only authorised workspace comment moderators can access the report queue or impose and restore commenting restrictions; reports do not generate email, push, or inbox alerts.

7. Who receives information

We do not sell personal information. We disclose it only to provide the service, follow a customer’s instructions, protect legal rights, or comply with law. Providers are used only where the relevant feature is enabled.

Relevant business
Its authorised staff receive the bookings, participant details, payments, forms, messages, and community moderation information needed to provide and protect its services.
Community readers and moderators
People allowed to read a post can see its visible comments and displayed author names. Only authorised workspace moderators can see reports, reporter identity, immutable report snapshots, review history, and commenting restrictions.
Amazon Web Services
Hosting and infrastructure, configured file storage, transactional email through Amazon SES, and address or place search through Amazon Location Service.
Sentry
Error monitoring and diagnosis for the backend and mobile app. Backend reports can include limited account, user, workspace, and technical context; Deacova scrubs request content, breadcrumbs, and error messages before sending them. Mobile crash reports exclude user, workspace, account, and tenant-origin identifiers, request data, breadcrumbs, screenshots, view hierarchy, and original error-message content. They keep only coarse app environment and access state plus the technical crash context needed to diagnose reliability.
Stripe
Payment collection, subscriptions, refunds, billing, identity checks, and fraud controls. Stripe handles payment credentials through its secure interfaces.
Google
reCAPTCHA, optional Google sign-in, and Android push delivery, including identifiers and technical interaction or delivery information.
OpenAI
Assistant responses, tool use, and document retrieval where AI features are enabled.
Slack
Restricted operational alerts to Deacova, which can include a product-update subscriber email and technical submission details.
Address and maps
Geoapify receives address search terms for autocomplete. Postcodes.io receives postcode lookups. OpenStreetMap receives network and device requests when a map or map tile loads.
Website media
Unsplash receives website-builder search terms, image choices, download events, and requests for image previews. YouTube and Vimeo receive network and device requests when embedded videos load.
Mobile delivery
Expo, Apple, and Google may process device tokens and delivery information when mobile notifications are enabled.

We may also disclose information to advisers, insurers, auditors, regulators, courts, law-enforcement bodies, or a genuine buyer or successor where necessary and lawful.

8. Transfers and retention

Some providers operate or provide support outside the United Kingdom. Depending on the provider and destination, we use UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, and any required transfer-risk assessment. You can ask us about the safeguard relevant to your information.

We keep information only for its purpose, the relevant customer’s documented instructions, security and recovery, and applicable legal, accounting, dispute, or regulatory requirements. In particular:

  • enquiries are kept while we respond and for a reasonable follow-up or legal-claims period; product-update details remain until unsubscribe, with minimum consent and suppression records kept afterwards;
  • accounts, contracts, billing, and finance records remain for the active relationship and the applicable contractual or statutory period;
  • business-controlled bookings, profiles, files, forms, and messages follow that business’s instructions and contract with Deacova;
  • comments follow the relevant business’s instructions and contract; resolved reports, immutable source snapshots, moderation decisions, and restrictions can be retained as safety and audit history for legal, dispute, and repeat-abuse purposes;
  • personal blocks and hidden-comment choices remain until the user reverses them or the related account or workspace data is deleted; versioned community-rule acceptances are kept to demonstrate the rules accepted before a comment mutation;
  • abandoned checkout records are scheduled for deletion after 30 days, temporary uploads after about 60 minutes, generated exports after 7 days, and export-history records 30 days after expiry;
  • detailed service-visit buckets are removed after about one year; technical AI usage logs after 365 days; and AI failure logs and unexecuted draft or rejected action records after 90 days; and
  • security and backend Sentry error records, provider-held service state, and restricted recovery copies follow the operational or contractual cycle needed to investigate, secure, and recover the service; and
  • mobile Sentry crash reports are available only to authorised Deacova personnel responsible for reliability and security. Sentry alerts go only to those authorised recipients, events follow the configured Sentry project retention period, and source maps are uploaded solely to translate technical code locations without adding user content. Deacova can stop new mobile reporting by removing the production crash-reporting configuration and shipping a compatible update or release.

A legal hold, dispute, fraud investigation, or regulatory request can require longer retention. Irreversibly anonymised information may be kept because it no longer identifies anyone.

9. Children and sensitive information

Deacova’s corporate website and business administration service are not directed at children. A business may use Deacova for an activity involving a child and may collect a date of birth, guardian contact, or participation details. That business is responsible for its lawful basis, privacy information, and any required parental or guardian authority; Deacova normally acts as its processor.

Configurable fields and uploads can contain health, disability, allergy, safeguarding, or other sensitive information. The business must make sure collection is necessary, authorised, access-controlled, and retained appropriately. Users should not put unnecessary sensitive information into free-text fields, files, or AI prompts.

10. Your rights

Depending on the circumstances, UK data-protection law may let you access, correct, erase, restrict, or obtain a portable copy of your information, and withdraw consent. These rights are not absolute, and we may need to verify your identity.

Your right to object

You may object to processing based on legitimate interests. You may also object to direct marketing at any time. We will stop direct marketing and will stop other objected-to processing unless a lawful exception applies.

Contact the relevant business first for information it controls. For Deacova-controlled information, email contact@deacova.co.uk. Product-update emails also contain an unsubscribe link.

Comment safety in the web and mobile profile lets a user review and reverse their own member blocks and hidden-comment choices. Requests about comments, reports, moderation records, or restrictions controlled by a particular workspace should normally be directed to that business first.

You may complain to the UK Information Commissioner’s Office. We would appreciate the opportunity to help first, but this does not limit your right to use the ICO complaints service.

11. Security and contact

We use encrypted connections, authentication and role-based access, tenant separation, audit and security logging, controlled infrastructure access, monitoring, and other technical and organisational measures designed to protect personal information. No online service can guarantee absolute security.

Deacova

Leicestershire, United Kingdom

contact@deacova.co.uk

You can also use our contact page for general enquiries. We may update this notice when our service, providers, or legal requirements change. We will revise the date above and take reasonable steps to highlight material changes.