Noetic is the trading name of [Insert Full Legal Name], a sole trader in
the United Kingdom, who is the data controller for personal data processed
through the Noetic platform. You can contact us about privacy at
[Insert Contact Email] or via the Support
form. We follow a privacy-first, data-minimisation approach: we collect
only what we need to run the service and your account.
3.2 The data we collect
Identity & contact: your name and email address.
Profile (optional): company, role, country, organisation size, industry and Salesforce clouds used.
Account & usage: your subscription tier, analysis run counts and daily limits, and the analysis results and run history we generate for you (see 3.4).
Marketing preferences: your opt-in/opt-out status and consent records.
Billing: where you buy a paid plan, billing is handled by our payment processor; we do not store your full card details.
Technical: IP address, basic device/browser information, and essential browser storage used to run the app and keep you signed in.
3.3 How and why we use your data (lawful bases)
To provide and manage the service and your account — performance of a contract.
To apply fair-use limits, secure the platform and prevent abuse — our legitimate interests.
To send marketing you have opted into — your consent (see 3.8).
To meet legal, accounting and tax obligations — legal obligation.
3.4 Salesforce data and analysis results
Credentials: We do not store your Salesforce login credentials or OAuth
tokens on our servers beyond what is needed for your active session. When
your session expires you will be asked to reconnect.
Your customers' data: We do not persist the raw metadata from your
Salesforce environment, nor the personal data of your own clients or
end-users held within it.
Analysis results: We do store the analysis results and summaries we
generate for you — for example issue counts, findings, trend history and
run snapshots — linked to your account, so they remain available across
sessions and devices. You can remove these at any time by closing your
account.
3.5 Service providers (processors)
We share personal data with trusted providers who process it on our behalf:
Google (Firebase Authentication, Firestore and hosting / Google Cloud) — sign-in, and storage of your account, profile and analysis data.
Loops, Inc. (United States) — marketing email delivery and contact management.
[Insert payment processor, e.g. Stripe] — payment processing for paid plans.
3.6 International transfers
As we trade internationally and use the providers above, your data may be
processed outside the United Kingdom, including in the United States. Where
it is, we rely on appropriate safeguards such as UK "adequacy" regulations,
the UK Extension to the EU-US Data Privacy Framework, and/or the UK
International Data Transfer Agreement / Standard Contractual Clauses.
3.7 Data retention
Account, profile and analysis data: kept while your account is active, and deleted or anonymised after you close your account (subject to the periods below).
Tax and accounting records: retained for 6 years to meet UK (HMRC) requirements.
Marketing consent records: retained as evidence of consent for as long as needed for accountability.
3.8 Marketing Communications
With your consent, we send marketing communications — product news, tips,
and updates about Noetic and the tools we offer now or in the future.
Lawful basis: Consent (UK GDPR Article 6(1)(a)). Marketing is always
optional. The opt-in is unticked by default and separate from accepting
our Terms.
Double opt-in: After you opt in, we email a confirmation link. You only
start receiving marketing once you click it. This confirms your consent
and protects against sign-ups you did not request.
Email service provider (processor): We use Loops (Loops, Inc., United
States) to store contact details and send these emails on our behalf. To
provide this, your email address, name, and basic profile details (such
as role and country, where supplied) are shared with Loops. This involves
a transfer outside the UK; it is safeguarded by appropriate measures
(Standard Contractual Clauses and/or the EU-US / UK Data Privacy
Framework).
Withdrawing consent: You can unsubscribe at any time from the
My Account page or via the unsubscribe link in
any marketing email. Opt-outs take effect immediately and are synced to
Loops.
Records of consent: We keep a record of your opt-in and opt-out events
(including timestamp and source) to evidence consent, as required by the
UK GDPR accountability principle.
3.9 Your rights
Under UK data protection law you have the right to:
access a copy of your personal data;
have inaccurate data corrected (rectification);
have your data erased;
restrict or object to certain processing;
data portability;
withdraw consent at any time for consent-based processing (such as marketing).
To exercise any of these, contact [Insert Contact Email] or use the
Support form. You also have the right to
complain to the UK Information Commissioner's Office (ICO) at ico.org.uk,
or to the data protection authority in your country of residence.
3.10 Cookies and local storage
We use essential cookies and browser local storage to sign you in and to
run the app — for example, caching your analysis so it loads quickly. These
are necessary for the service to function.
3.11 Children
Noetic is a professional tool and is not directed at children. We do not
knowingly collect personal data from anyone under 16.
Contact
For any privacy request or question, contact [Insert Contact Email] or use
the Support form.
This notice is provided for general information and must be completed with
Noetic's current details (shown in brackets) and kept up to date as
providers change. It is not legal advice; we recommend a qualified adviser
reviews it before publication.