Privacy Policy

Last updated: 8 August 2026

Heimdell Tech Ai Ltd (company number 16478408, registered office at Croft, Preston, PR1 9DJ, ICO registration ZC079121) is committed to protecting your privacy. This policy explains what personal data we collect through RoundFlow (the "Service"), why, and how it is handled under UK GDPR and the Data Protection Act 2018.

1. Two roles: controller and processor

When a business signs up to RoundFlow (an "Account Holder"), Heimdell Tech Ai Ltd is the data controller for the Account Holder's own account details (e.g. business owner/staff name, login email, phone number).

Account Holders use RoundFlow to store and manage information about their own customers ("End Clients") — names, addresses, contact details, service history, access notes, and payment status. For that End Client data, the Account Holder is the data controller and Heimdell Tech Ai Ltd acts only as a data processor, processing it solely on the Account Holder's instructions to provide the Service. If you are an End Client with a question about your own data, please contact the business that provides your window cleaning/gardening service directly in the first instance.

2. What we collect

  • Account details: name, email, phone, password (stored hashed), role.
  • Customer and property records entered by Account Holders: names, addresses, postcodes, phone numbers, email addresses, access/hazard notes, and approximate map coordinates derived from the address for route planning.
  • Service and job records: schedules, prices, job status, before/after photos, worker notes.
  • Payment-related data: preferred payment method, and tokenised references to a Stripe customer/payment method or GoCardless mandate. We do not store full card numbers or bank account numbers — these are held directly by Stripe/GoCardless.
  • Usage data: login times, and technical data such as IP address and browser type, for security and diagnostics.
  • If you install RoundFlow's admin app and enable notifications, a push-notification token (an opaque identifier from your browser/device, not readable by us as personal content) so we can deliver that notification.

3. How we use it

To provide the Service (scheduling, route mapping, payment collection, client self-service portal, notifications), to maintain security and prevent misuse, to provide support, and to meet legal obligations. We do not sell personal data, and we do not use Customer Data for our own marketing purposes.

4. Who we share it with

We use the following third-party processors to operate the Service, each of whom processes data only as needed to provide their part of it:

  • Stripe — card payment processing.
  • GoCardless — Direct Debit payment processing.
  • Twilio — SMS notifications.
  • Resend — email notifications.
  • Netlify — application hosting.
  • Neon — database hosting (PostgreSQL, EU/UK region where available).
  • OpenStreetMap / Nominatim — address geocoding for the route map (address text only, no other personal data is sent).

We do not use any advertising or analytics trackers on the Service.

5. Retention

Account Holders control retention of their Customer Data and can delete customer records from within the Service, which removes the associated jobs, notes, and payment history. See section 6 below for what happens, and what is retained, when an account or an entire organisation is deleted.

6. Account deletion

You can request deletion of your RoundFlow account in two ways:

  • From inside the app — Settings → Your account (to delete just your own login) or Settings → Danger zone (for an organisation administrator to delete the whole organisation).
  • Without signing in — via our public account deletion page, which explains the process in full and verifies your identity by email before anything is actioned.

We process deletion requests without undue delay, and always within one calendar month of verification.

6.1 What is normally deleted

For an individual account: your name, email address, phone number, and password are permanently removed and your login is deactivated immediately. Where you were assigned to jobs within an organisation that keeps operating, those historical records are kept for the organisation's own operational purposes but show "Former user" in place of your name — no personal information about you remains attached to them.

For a whole organisation: all of that organisation's data is deleted — staff accounts, customers, properties, jobs, photographs, notifications, routes, and any Stripe/GoCardless credentials connected to the organisation's own account.

We do not retain a business's customer records, job photographs, addresses, or contact details merely because that business may have its own separate accounting or record-keeping obligations. It is the Account Holder's own responsibility to export anything they are legally required to keep before requesting deletion — our deletion flow warns you of this before you confirm.

6.2 What may be retained, and why

Only two things are ever retained after a deletion request is processed:

  • Heimdell's own platform billing records — the fact that an organisation subscribed to RoundFlow, for how long, and a reference to the corresponding Stripe invoice/payment record (which Stripe itself separately retains). This never includes that organisation's own customers' personal data. We keep this until six years after the end of Heimdell's financial year (Heimdell Tech Ai Ltd's financial year ends 31 May) in which the billing record falls, in line with UK accounting and tax record-keeping obligations (Companies Act 2006 / HMRC guidance). Records may exceptionally be kept longer where required by an open HMRC compliance check, a late-filed tax return, or another documented legal hold.
  • A minimal deletion audit record — the fact that a request was made and processed, its dates, and a short summary of what was deleted. This exists purely to prove the request was handled correctly, and is deliberately designed to hold no more personal data than necessary.

We may also retain a strictly limited, minimised, and anonymised record where genuinely necessary for security, fraud prevention, or to establish, exercise, or defend legal claims — for example, evidence of abuse of the Service. Where this applies we document the specific lawful basis and a retention expiry at the time.

6.3 Third-party processors

Where applicable, we also action deletion requests with the processors listed in section 4 (in particular Stripe, GoCardless, Twilio, and Resend) in line with their own data-deletion processes for data they hold on our behalf.

6.4 Abuse protection on the public deletion-request page

To stop the public, unauthenticated account deletion page being abused (for example, to flood the system with fake requests or guess verification links), we keep short-lived request counters keyed to your IP address and the email address you submit. Your IP address is never stored as-is — it is passed through a keyed cryptographic hash (HMAC-SHA256) before being saved, so the stored value cannot be reversed back into your IP address. These counters hold no other personal data, are not linked to your account, and each one automatically expires — within an hour for IP-based counters, and within 24 hours for email-based counters. This is retained solely for security/abuse prevention under our legitimate interest in keeping the Service available and trustworthy.

7. Your rights

Under UK GDPR you have the right to:

  • access the personal data we (or, for End Client data, the relevant Account Holder) hold about you;
  • have inaccurate data corrected;
  • have data erased in certain circumstances (see section 6 above);
  • object to or restrict certain processing;
  • receive your data in a portable format;
  • complain to the Information Commissioner's Office (ico.org.uk) if you believe your data has been mishandled.

To exercise these rights over data we control directly, email admin@heimdell-tech-ai.co.uk.

8. Data Protection Registration

Heimdell Tech AI Ltd is registered with the UK Information Commissioner's Office (ICO) under registration number ZC079121.

9. Security

We use industry-standard measures including encrypted connections (HTTPS), hashed passwords, and access controls scoped per Organisation, so one Account Holder cannot see another's data.

10. Children

The Service is intended for business use and is not directed at children.

11. Changes to this policy

We may update this policy from time to time; material changes will be reflected by the "Last updated" date above.

12. Contact

Heimdell Tech Ai Ltd, Croft, Preston, PR1 9DJ — admin@heimdell-tech-ai.co.uk.