Privacy Policy
Last updated: February 2026
About Us
Wardstone is a trading name of JRL Software LTD, a company registered in England and Wales (Company Number: 15511536). Our registered office is at 450 Oldfield Lane North, Greenford, UB6 0GF, United Kingdom.
We are registered with the UK Information Commissioner's Office (ICO) under registration reference ZB839131.
For data protection enquiries, contact us at Contact form (jack [at] wardstone.ai).
Introduction
JRL Software LTD ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI security services, website, and API, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Information We Collect
Information You Provide
- Account information (name, email, company name) when you sign up
- Contact information when you reach out to us or request enterprise access
- Payment information processed securely through Stripe
- Communications you send to us
Information Collected Automatically
- Usage data and analytics (via PostHog)
- Device and browser information
- IP address and approximate location
- Cookies and similar tracking technologies
API Data Processing
When you use our API, we process the text content you submit for security analysis. This data is processed in real-time and is not stored beyond the duration necessary to provide the service, unless you have explicitly enabled logging features in your account settings.
We do not use content submitted to our API to train, improve, or develop our machine learning models. Your data is used solely to provide the detection service you requested.
Legal Basis for Processing
We process your personal data on the following legal bases under UK GDPR:
- Contract: To provide our services to you and fulfil our contractual obligations
- Legitimate interests: To improve our services, ensure security, and communicate with you about our products
- Consent: Where you have given explicit consent for specific processing activities (e.g., marketing emails)
- Legal obligation: To comply with applicable laws and regulations
How We Use Your Information
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send technical notices, updates, and support messages
- Respond to your comments, questions, and requests
- Monitor and analyse trends, usage, and activities
- Detect, investigate, and prevent security incidents
- Comply with legal obligations
Where We Store Your Data
Your data is processed and stored on servers located in Finland (European Union), operated by Hetzner Online GmbH. Finland is an EU member state and provides an adequate level of data protection under UK GDPR.
Some of our third-party service providers may process data outside the UK or EU. In such cases, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.
Third-Party Services
We use the following third-party services that may process your personal data:
- Hetzner Online GmbH (Germany/Finland): Infrastructure and hosting
- PostHog Inc (US): Product analytics and usage tracking
- Stripe Inc (US): Payment processing
- Resend Inc (US): Email communications
Each of these providers has their own privacy policies and data processing agreements. Where data is transferred to the US, we rely on Standard Contractual Clauses or equivalent safeguards.
Cookies
We use cookies and similar technologies to:
- Keep you signed in to your account
- Remember your preferences
- Understand how you use our services (analytics)
- Improve our website and services
You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of our services.
Data Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. This includes encryption in transit (TLS) and at rest, access controls, and regular security assessments.
Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.
- Account data: Retained while your account is active, then deleted within 30 days of account closure
- API request data: Not retained unless you explicitly enable logging
- Analytics data: Retained for up to 24 months
- Financial records: Retained for 7 years as required by UK law
Your Rights
Under UK GDPR and the Data Protection Act 2018, you have the following rights:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data in certain circumstances
- Right to restriction: Request we restrict processing of your data
- Right to data portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests or for direct marketing
- Rights related to automated decision-making: Not be subject to decisions based solely on automated processing
To exercise these rights, please contact us at Contact form (jack [at] wardstone.ai). We will respond within one month as required by law.
If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information, please contact us and we will take steps to delete such information.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes affecting how we use your data, we will provide notice via email where possible.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Email: Contact form (jack [at] wardstone.ai)
- Website: wardstone.ai
- Post: JRL Software LTD, 450 Oldfield Lane North, Greenford, UB6 0GF, United Kingdom