Privacy Policy

Last updated: August 17, 2026

Introduction

Deltastring Ltd (“we”, “our”, or “us”) is committed to protecting your privacy. This privacy policy explains how we collect, use, and safeguard your personal information when you visit our website or use our services.

Data Controller: Deltastring Ltd, London, United Kingdom
Contact: hello@deltastring.com

Information We Collect

Information You Provide

  • Contact details when you reach out via email or phone
  • Business information during consultations and project work
  • Project requirements and technical specifications
  • Feedback and communications throughout our engagement

Information Automatically Collected

  • Technical information such as browser type, IP address, and visit duration, recorded in standard web-server logs
  • Performance data to improve our website functionality

How We Use Your Information

We use your personal information to:

  • Provide our services and respond to your inquiries
  • Communicate about projects, proposals, and business matters
  • Improve our services based on feedback and usage patterns
  • Comply with legal obligations and business requirements

Deltastring (our software product)

Deltastring is our Zendesk configuration-management product. If you use Deltastring, this section covers how we handle your data. It sits alongside the terms of service and data processing agreement available inside the Deltastring app.

Configuration only, never ticket content

Deltastring reads and stores your Zendesk configuration (triggers, automations, views, groups, fields, forms and the like). It does not read, store, or expose the content of your tickets or your customers’ personal data. The one exception is the change simulator, which processes tickets you choose to upload as dry-run inputs; those are used only to produce the simulation and are not kept as part of your configuration history.

What we hold for a Deltastring account

  • Account and billing details for the person or organisation that signs up
  • Configuration snapshots captured from the Zendesk instances you connect
  • An audit log of every change planned, approved, applied, or rolled back
  • API tokens you mint for the agent (MCP) interface, revocable at any time

Security

Configuration snapshots are encrypted at rest and in transit and scoped to your account. Access to a connection follows Deltastring’s own permission model, and production changes require a named human other than the requester to approve them.

Retention

We keep Deltastring data only as long as we need it:

  • Configuration snapshots: the most recent 50 per connection
  • Audit and change log: 7 years
  • Webhook delivery logs: 30 days
  • Product analytics events: 90 days
  • Pending (unapplied) changes: 7 days

Deleting your account

You can delete your Deltastring account from the app. Deletion revokes your API keys and hard-deletes your connections and any linked Git repositories immediately. Personal data then enters a 60-day cooling-off period and is scrubbed automatically. You can request immediate erasure (UK GDPR Article 17) from your account settings.

Training

We do not use your configuration data to train AI models, and we do not sell it. When you use Deltastring’s agent interface, it runs on your own AI assistant’s model under your account, not ours.

Under GDPR, we process your personal data based on:

  • Legitimate interests for business communications and service delivery
  • Contractual necessity when providing agreed services
  • Consent for marketing communications (where applicable)

Data Sharing and Disclosure

We do not sell your personal information. We may share data with:

  • Trusted service providers (hosting, email, analytics) under strict data processing agreements
  • Legal authorities if required by law or to protect our rights
  • Business partners only with your explicit consent

Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Secure hosting with reputable providers
  • Encrypted communications for sensitive information
  • Access controls limiting data access to authorized personnel
  • Regular security assessments and updates

Your Rights

Under GDPR, you have the right to:

  • Access your personal data we hold
  • Rectify inaccurate or incomplete information
  • Erase your data (right to be forgotten)
  • Restrict processing in certain circumstances
  • Data portability in machine-readable format
  • Object to processing based on legitimate interests

To exercise these rights, contact us at hello@deltastring.com.

Data Retention

We retain personal data only as long as necessary for:

  • Active projects: Duration of engagement plus 6 years for business records
  • Inquiries: 2 years for potential future business opportunities

Cookies and Tracking

Our website does not use Google Analytics, advertising pixels, or any third-party analytics or tracking. We use only the essential cookies needed for the site to function. You can control cookies through your browser settings.

International Transfers

Your data may be processed outside the UK/EU by our service providers. We ensure adequate protection through:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions for countries with equivalent data protection laws
  • Appropriate safeguards as required by GDPR

Changes to This Policy

We may update this privacy policy to reflect changes in our practices or legal requirements. We will notify you of significant changes via email or website notice.

Contact Us

For privacy-related questions or concerns:

Email: hello@deltastring.com
Address: Deltastring Ltd, London, United Kingdom

Data Protection Officer: Nico B. Boyce (for data protection inquiries)


This policy complies with GDPR, UK Data Protection Act 2018, and Privacy and Electronic Communications Regulations (PECR).