NativeCMS Privacy Policy
Version 1.0 Effective 31 July 2026
1. Who we are
NativeCMS is operated by Sam Lewis, a sole trader trading as NativeCMS, at
Mortimer Court, Abbey Road, London, NW8 9AD ("NativeCMS", "we" or "us").
Contact privacy@nativecms.co.uk about privacy matters.
This notice explains how we use personal information when you visit nativecms.co.uk, create or use a NativeCMS workspace, receive support, or act as a customer contact. It does not replace a customer's privacy notice for the Drupal sites and apps that customer operates.
We will reassess the Information Commissioner's Office data-protection fee position immediately before inviting external beta customers. If registration is required, the reference will be added here without changing the substance of this notice.
2. Our roles
We normally act as a controller for NativeCMS account, security, contract, support and service-analytics information.
For personal information that a customer places in its managed Drupal sites, files, forms and Native app content, the customer normally determines why and how it is used. The customer is the controller and NativeCMS acts as its processor under the Data Processing Addendum. The facts determine each party's role in any particular case.
3. Information we collect
- Account and workspace details: name, organisation, email, role, invitations, authentication, legal acceptance and recovery status.
- Security and audit details: session identifiers, device or browser label, timestamps, IP address, approximate IP-derived location, MFA state, Git credential metadata and administrative actions. Passwords, recovery codes and tokens are stored in protected or hashed form where applicable.
- Service content and metadata: site names, domains, environment status, deployments, Git commits, backups, configuration, support diagnostics and usage against service limits.
- Communications: support requests, verification and invitation delivery, feedback and incident communications.
- Website and reliability information: essential cookies, request and security logs, performance and availability results.
- Customer-hosted information: content, accounts, form submissions, files and app interactions processed under the customer's instructions.
The invited beta does not collect payment-card information. If a paid service is introduced, this notice and the Subprocessor List will be updated before payment processing begins.
4. Why we use it
| Purpose | Typical UK GDPR basis |
|---|---|
| Provide accounts, workspaces, hosting, deployment, backups and support | Contract; steps requested before contract |
| Authenticate users, prevent abuse, investigate incidents and protect tenants | Legitimate interests; legal obligation where applicable |
| Keep contract and tax records if required | Contract; legal obligation |
| Send verification, invitation, security and operational messages | Contract; legitimate interests |
| Improve reliability and usability using proportionate service telemetry | Legitimate interests |
| Send optional marketing | Consent, or another basis where law permits; unsubscribe is always provided |
| Process customer-hosted personal information | Customer's documented instructions under the DPA |
Where we rely on legitimate interests, we balance the service or security benefit against people's rights and reasonable expectations. We do not use customer site content for unrelated advertising or to train general-purpose AI models.
5. Sharing and subprocessors
We share only what is necessary with providers that support hosting, email and service operations. Current providers are listed in Subprocessors. We may also disclose information when required by law, to protect people or the service, or during a business transfer subject to appropriate confidentiality.
Workspace Owners and authorised members can see information within their workspace according to their role. They cannot use NativeCMS to access another workspace.
6. International transfers
Primary customer workloads are hosted in the EU Azure region shown in the dashboard. A provider or support operation may process information elsewhere. Before a restricted transfer, we use an applicable adequacy regulation, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard, with a transfer-risk assessment where required.
7. Retention
| Information | Retention |
|---|---|
| Active account and workspace records | For the agreement |
| Deleted-site recovery copy | 30 days after deletion unless a legal hold applies |
| Routine backups | The schedule displayed for the environment |
| Security and audit logs | 12 months |
| Support records | 24 months after closure |
| Expired invitations and verification tokens | Token expiry plus up to 30 days of minimal audit evidence |
| Contract and tax records | Up to 6 years where required by law or to establish or defend claims |
We delete or anonymise information when it is no longer needed. Protected backup deletion may follow the backup cycle rather than immediate primary deletion.
8. Your rights
Depending on the circumstances, you may have rights to be informed, access,
rectify, erase, restrict, object, obtain portable information and challenge a
solely automated decision. Contact privacy@nativecms.co.uk. We may need to
verify identity and decide whether NativeCMS or the relevant customer should
handle the request. You can complain to the UK Information Commissioner's
Office at https://ico.org.uk/.
9. Cookies and local storage
NativeCMS uses essential session, security and preference storage needed to sign in, maintain the selected workspace and protect requests. Non-essential analytics or advertising cookies will not be enabled without an appropriate consent control and notice.
10. Security and incidents
Controls include encryption in transit, restricted workload identities,
tenant-level database controls, MFA, session revocation, immutable release
provenance, protected secrets, role-based access, backups, WAF and rate
limiting, logging and security testing. No service is risk-free. We notify
affected customers and regulators without undue delay when law or the DPA
requires it. Security reports should be sent to security@nativecms.co.uk.
11. Children
NativeCMS customer accounts are for adults acting for an organisation and are not directed at children. Customers whose sites or apps concern children must carry out their own assessment and implement suitable notices, consent or age-assurance controls.
12. Changes
We publish the current version, effective date and document hash. A material change creates a new immutable version and requires renewed acceptance of the Terms or acknowledgement of this Privacy Policy. We will notify account users before a material change takes effect where reasonably possible.