Finchley
Draft for review by a solicitor before publication. Bracketed items are placeholders.
Last updated 7 September 2026

Privacy policy

Finchley is provided by Rendella Media, [company type and number], of [registered address]. This policy explains what personal data we handle, why, and what your rights are. It is written for two audiences: agencies who use the dashboard, and people who talk to an assistant on a client’s website.

Who is responsible

Dashboard accounts. For the people who sign in to Finchley (agency staff and invited client viewers), Rendella Media is the data controller.

Client knowledge and widget conversations. For documents an agency uploads and for conversations between an assistant and a website visitor, the agency (or its client, as agreed between them) is the controller and Rendella Media is the processor, acting on the agency’s instructions. Website visitors should contact the business whose site they were using.

What we collect

Why, and on what basis

To provide the Service you asked for (contract); to keep it secure and to prevent abuse (legitimate interests); to bill you (contract and legal obligation); and to email you about your account (contract). We do not sell personal data and we do not use anyone’s data to train models.

Who we share it with

ProviderWhat for
[Hosting provider, region]Servers, database and file storage
AnthropicGenerating answers, grading tests and reading scanned documents, under the agency’s own API key
OpenAITurning knowledge into searchable embeddings, under the agency’s own API key
NangoConnecting apps such as Shopify and HubSpot when an agency enables them
StripeSubscriptions and card payments
[Email provider]Transactional email such as invitations and handoff notifications
[Error monitoring provider]Error reports, with personal data minimised

Some providers are outside the UK. Where they are, transfers rely on the UK International Data Transfer Agreement or an adequacy decision.

How long we keep it

Your rights

Under UK GDPR you can ask for a copy of your data, ask us to correct or delete it, object to or restrict processing, and complain to the Information Commissioner’s Office. Agency owners can export everything the agency holds (as JSON plus the original files) and remove the agency from the dashboard under Your agency, Your data; anyone can change their details or delete their own account from their account page. Website visitors should ask the business whose site they used; we will help that business respond.

Cookies

The dashboard uses a session cookie, a security (CSRF) cookie and, when you sign in, a “remember me” cookie so you stay signed in; all three are needed for it to work. The widget stores a short-lived visitor token in the visitor’s browser so a conversation can continue; it identifies the conversation, not the person. We do not use advertising or analytics cookies.

Security

Data is encrypted in transit and at rest. API keys and access tokens are encrypted with a separate key. Access to production systems is limited to named staff with two-factor authentication. Tell us at once at [security@ email] if you think an account has been compromised.

Changes and contact

We will post changes here and email account owners about material ones. Questions: Rendella Media, [registered address], hello@rendella.media.