Skip to content

Privacy notice

You are reading the current version — v1.0, effective 27 August 2026. All versionsPermanent link

This notice explains what personal data Ferrith collects, why, where it is stored, how long we keep it, and your rights. Your workspace's content belongs to your organisation, everything stays on UK infrastructure we operate, we never use it to train AI models.

Ferrith is operated by Ferrith Ltd, company number 16623234, registered at 11 Laura Place, Bath, United Kingdom, BA2 4BL (ICO registration ZC228586). Contact: support@ferrith.ai.

1. Two roles: your organisation's data, and ours

Ferrith is used by organisations leading to data of two kinds, with different rules:

  • Workspace content, where Ferrith is the processor. For conversations, documents, AI agents, workflows and analysis grids, your organisation decides what goes into its workspace and who can see it. Ferrith processes that content on the organisation's instructions, under the Data Processing Agreement. If you are a member of an organisation's workspace and want to know how it uses your data, you should contact your organisations Ferrith admins as the controllers of the workspace.
  • Account and billing data, where Ferrith is the controller. The data required to run accounts and take payment: who you are, how you sign in, what your organisation has bought. The rest of this notice is about this data.

2. What Ferrith collects, and why

Data What it is Why (lawful basis)
Account details Your name and email address, held in our sign-in system To operate your account (contract)
Sign-in records When and how accounts sign in, security events (for example failed attempts) To keep accounts secure (legitimate interest)
Billing data Your organisation, subscription, invoices; payment is collected by Stripe and card details never reach Ferrith To charge for the service and keep required records (contract; legal obligation)
Workspace administration records Who was invited, role changes, and similar administrative events in a workspace The workspace's own accountability record (legitimate interest; processed for the organisation)
Service records Which account used which feature and when i.e. model, time, size of a request. Never the content of a message or document To meter fair use, keep the service secure, and investigate faults (legitimate interest)
Support correspondence Emails you send to support@ferrith.ai To help you (legitimate interest)

Three things we deliberately do not do:

  • We do not use your content, or your usage, to train AI models.
  • We do not write message or document content into logs. Our operational records are metadata only.
  • We run no advertising and no third-party analytics. No tracking pixels, no data brokers. This documentation site sets no cookies.

3. Where your data lives

The service runs on UK cloud infrastructure (Civo, London) that Ferrith operates. Workspace content, AI inference, encryption keys and the sign-in system all stay on that UK infrastructure. Inference runs in this custom environment, and prompts are never sent to a third-party AI provider.

Two suppliers sit outside that boundary:

  • Stripe processes payments. Stripe receives the buyer's billing details and handles bank cards entirely itself; it never sees workspace content. Stripe may process data outside the UK under its own published safeguards.
  • Microsoft (Azure Communication Services) relays our sign-in emails and verification links, invitations, password resets. It only sees the recipient's email address and the link, never workspace content.

The current supplier list, with a change log you can subscribe to, is published at Sub-processors.

Workspace content is encrypted at rest with a key unique to each workspace, which can be the customer's own (the bring-your-own-key option). Ferrith runs the service, so our systems decrypt content to answer requests, and our operators' access to the infrastructure is controlled and logged. The Trust page describes the security model in plain terms.

4. How long we keep things

Data Kept for
An abandoned sign-up (email verified, but no workspace created) 30 days from last activity, then the account is deleted
Workspace content The life of the subscription, plus a 15-day recovery window after it ends, at which point the workspace is permanently deleted and its encryption keys destroyed, which makes the content unreadable everywhere, backups included
Workspace administration records The life of the workspace. This is the workspace's own audit trail, exported with it and deleted with it
Workflow run records (inputs, outputs, review decisions) The life of the workspace, unless a workspace admin manually deletes the run sooner. These are the workspace's own record of what the AI did, exported with the workspace and deleted with it
In-app notifications 30 days
Service records (API and automation activity) 90 days
Our own administrative audit (operator actions) 12 months
Billing records (invoices, transactions) 6 years, as required for tax and accounting law
Sign-in system records The life of the sign-in account; the identity system additionally keeps its own internal event history for the life of the system
Server logs Days. Short, rotating windows

5. Your rights

You have the rights UK GDPR gives you: access, rectification, erasure, restriction, portability, and objection.

  • If you are a member of an organisation's workspace, direct requests about workspace content should be raised with your organisation as it is the controller. Workspace admins can permanently erase a member and their personal data from the workspace, and the Owner can export the workspace's data.
  • For your account data with us, email support@ferrith.ai. We answer within one business day (Monday to Friday, UK) and act within the statutory time.
  • You can complain to the Information Commissioner's Office (ico.org.uk). You should contact support@ferrith.ai for the chance to put it right first.

6. Cookies

The product uses essential cookies only: the cookie that keeps you signed in, and the security token that protects forms. Stripe sets its own cookies during checkout on its pages. There are no advertising or analytics cookies, and this documentation site sets none.

7. Changes to this notice

We publish changes here, with each version's effective date and a change log. This page always shows the current version, and every past version keeps its own address.

Versions

VersionEffectiveStatusWhat changed
v1.0 27 Aug 2026 Current Initial version.