Privacy notice
What personal data Recellion holds, why we hold it, and the rights you have over it.
Last updated
1. Who we are
Recellion is operated by Delta Metrics Ltd, a company registered in England & Wales under company number 12690126, with its registered office at 71–75 Shelton Street, London WC2H 9JQ, United Kingdom. VAT registration number 445 4855 69. Director: Dr Malte Susen.
For any question about this notice or about how we handle personal data, contact ms@recellion.com. We have not appointed a statutory Data Protection Officer; data-protection enquiries are handled by the director.
2. When we are the controller, and when we are a processor
This distinction matters, because different parts of the platform work differently.
We are the controller for the data described in this notice: the accounts, identities, sessions, billing records and support correspondence of the people who use Recellion.
We are a processor for the operating data your organisation supplies or connects: meter readings, telemetry, contract envelopes, uploaded documents and the assets they describe. We process that data on your organisation’s documented instructions, under the terms set out on our data processing and sub-processors page. That material is overwhelmingly technical rather than personal, but where it does identify someone, such as a named signatory on a contract or an engineer in a maintenance log, your organisation decides what happens to it.
3. What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account and identity | Name, work email address, job title, phone number, avatar, password (stored only as a bcrypt hash). | You, when you register or are invited. |
| Organisation and access | Company and organisation membership, role, capability assignments, asset and portfolio scopes, invitation and verification status. | You and your organisation administrator. |
| Wallet identifiers | An on-chain signer address, and the timestamp of the signature challenge that proved you control it. Only set if you choose to link a wallet. | You, via the wallet-linking flow. |
| Session and security | Authentication tokens, sign-in and verification events, password-reset and invitation tokens (stored hashed), IP address and request metadata in server logs. | Automatically, when you use the platform. |
| Support and correspondence | Messages you send us, and the contents of support requests. | You. |
| Billing | Plan, subscription state and invoice records. Card details are handled by our payment processor and never reach our servers. | You and our payment processor. |
We do not collect special category data, and we do not buy personal data from third parties or build marketing profiles.
4. Why we process it, and our lawful basis
| Purpose | What this involves | Lawful basis |
|---|---|---|
| Providing the platform | Authenticating you, scoping access to your organisation’s assets, and producing the attestation records you ask for. | Performance of a contract. |
| Security and integrity | Detecting and investigating unauthorised access, rate limiting, and maintaining tamper-evident audit logs. | Legitimate interests: keeping an evidentiary platform trustworthy. |
| Service communications | Verification emails, invitations, password resets and material changes to the service. | Performance of a contract. |
| Billing and tax | Taking payment, issuing invoices and meeting statutory record-keeping duties. | Contract and legal obligation. |
| Support | Answering your questions and resolving faults. | Legitimate interests: supporting our customers. |
Where we rely on legitimate interests, we have considered the impact on you and concluded that the processing is proportionate to the purpose. You can object at any time; see section 9.
5. Cookies and local storage
Recellion sets no advertising, analytics or tracking cookies, and embeds no third-party tracking pixels. Every item below is strictly necessary to keep you signed in, to keep your requests safe, or to hold a choice you made yourself, which is why we do not present a consent banner: there would be nothing for you to consent to.
Opening a public page, whether the site, this notice or a passport someone shared with you, contacts no host other than ours. Fonts and styling are served from our own domain rather than a third-party CDN, so no one else learns your IP address from the fact that you visited. Inside the signed-in console, map tiles and our payment provider’s script are fetched from their own origins when you use those features; both are named on the sub-processor list.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| recellion_auth_token | Cookie | Keeps you signed in. Without it the platform cannot authenticate a request. | Session, or until the token expires. |
| recellion_csrf_token | Cookie | Paired with a matching request header to prove that a change you submit came from the platform and not from another site you had open. Set only when your browser calls our API. | Session. |
| Session keys in local storage | Local storage | Holds the active session token and the display name, email, organisation and user id used to render the console. | Until you sign out or clear site data. |
| Interface preferences | Local storage | Remembers choices you make in the interface, such as light or dark appearance, saved revenue assumptions and cached integration lists. Written when you make the choice, not before. | Until you clear site data. |
Clearing site data in your browser removes all of it, and signs you out.
6. Who we share it with
We do not sell personal data. We share it only with the service providers needed to run the platform: hosting and database, payment processing, transactional email, error monitoring, and the AI provider behind the assistant. Each is named, with its purpose and location, on the sub-processor list.
We may also disclose data where we are legally required to, or to establish or defend legal claims. If Delta Metrics Ltd is acquired or merged, data may transfer to the acquirer under this notice.
Attestation records are shared according to your instructions: with a counterparty you invite to co-sign, or a lender, adviser or insurer you grant reliance to. That sharing is initiated by your organisation, and recorded in the audit log.
7. International transfers
We prefer UK and EEA hosting regions. Where a provider processes data outside the UK, we rely on UK adequacy regulations, or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any additional safeguards the transfer requires. The sub-processor list states where each provider processes data.
8. How long we keep it
| Record type | Retention |
|---|---|
| Account records | For as long as your organisation holds an account, then deleted or anonymised within 90 days of closure. |
| Attestation records and audit logs | Retained for the evidentiary life of the record. These are the product; deleting them would destroy the assurance they exist to provide. See "Attestation records and the right to erasure" below. |
| Server and security logs | Up to 12 months. |
| Billing records | Six years, as required by UK tax law. |
| Support correspondence | Up to 24 months from the last message. |
9. Your rights
Under UK GDPR you have the right to:
- ask what personal data we hold about you, and get a copy of it;
- have inaccurate data corrected;
- have data erased, where we have no continuing basis to keep it;
- restrict or object to processing, including processing based on legitimate interests;
- receive data you gave us in a portable, machine-readable format;
- withdraw consent, where we relied on it, without affecting earlier processing.
Email ms@recellion.com to exercise any of these. We respond within one month. If we cannot act on a request we will explain why.
If you are not satisfied with our response you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you raised it with us first.
10. Attestation records, anchoring and the right to erasure
Recellion’s purpose is to produce records that cannot be quietly changed after the fact, and that has a consequence you should understand before you use it.
When a record is anchored, we publish a cryptographic hash of it to the Polygon public blockchain. A hash is a one-way fingerprint: it proves a specific record existed in a specific state at a specific time, and it cannot be reversed to recover the record. No personal data, no operating data and no document contents are ever written to the blockchain.
Public blockchain entries cannot be deleted by anyone, including us. This does not limit your erasure rights over personal data, because no personal data is published there. It does mean that the proof a record existed is permanent.
Separately, attestation records and audit logs held in our own systems may survive an erasure request where we need them to establish or defend legal claims, or where a counterparty or lender is relying on them under a contract. Where that applies we will tell you which records are affected and why.
11. How we protect it
Passwords are stored only as bcrypt hashes and are never recoverable. Sessions use signed tokens with environment-appropriate secure cookie settings. Traffic is served over TLS with hardened response headers, origin-restricted CORS and request rate limiting. Access inside the platform is role-scoped, and privileged actions are written to an audit log. Backups are taken on a schedule and access to production data is limited to those who need it.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the ICO within 72 hours and tell you without undue delay.
12. Changes to this notice
We update this notice when the platform changes. The date at the top always reflects the current version, and we will tell account holders directly before any change that materially affects them takes effect.
13. Contact
Delta Metrics Ltd, 71–75 Shelton Street, London WC2H 9JQ, United Kingdom. ms@recellion.com.
See also our terms of use and our data processing terms.