Skip to document
N NativeCMS Service status
Terms of Service Privacy Policy Data Processing Addendum Subprocessor List Support Policy Security Reporting

NativeCMS Privacy Policy

Version 1.0 Effective 31 July 2026

1. Who we are

NativeCMS is operated by Sam Lewis, a sole trader trading as NativeCMS, at Mortimer Court, Abbey Road, London, NW8 9AD ("NativeCMS", "we" or "us"). Contact privacy@nativecms.co.uk about privacy matters.

This notice explains how we use personal information when you visit nativecms.co.uk, create or use a NativeCMS workspace, receive support, or act as a customer contact. It does not replace a customer's privacy notice for the Drupal sites and apps that customer operates.

We will reassess the Information Commissioner's Office data-protection fee position immediately before inviting external beta customers. If registration is required, the reference will be added here without changing the substance of this notice.

2. Our roles

We normally act as a controller for NativeCMS account, security, contract, support and service-analytics information.

For personal information that a customer places in its managed Drupal sites, files, forms and Native app content, the customer normally determines why and how it is used. The customer is the controller and NativeCMS acts as its processor under the Data Processing Addendum. The facts determine each party's role in any particular case.

3. Information we collect

  • Account and workspace details: name, organisation, email, role, invitations, authentication, legal acceptance and recovery status.
  • Security and audit details: session identifiers, device or browser label, timestamps, IP address, approximate IP-derived location, MFA state, Git credential metadata and administrative actions. Passwords, recovery codes and tokens are stored in protected or hashed form where applicable.
  • Service content and metadata: site names, domains, environment status, deployments, Git commits, backups, configuration, support diagnostics and usage against service limits.
  • Communications: support requests, verification and invitation delivery, feedback and incident communications.
  • Website and reliability information: essential cookies, request and security logs, performance and availability results.
  • Customer-hosted information: content, accounts, form submissions, files and app interactions processed under the customer's instructions.

The invited beta does not collect payment-card information. If a paid service is introduced, this notice and the Subprocessor List will be updated before payment processing begins.

4. Why we use it

Purpose Typical UK GDPR basis
Provide accounts, workspaces, hosting, deployment, backups and support Contract; steps requested before contract
Authenticate users, prevent abuse, investigate incidents and protect tenants Legitimate interests; legal obligation where applicable
Keep contract and tax records if required Contract; legal obligation
Send verification, invitation, security and operational messages Contract; legitimate interests
Improve reliability and usability using proportionate service telemetry Legitimate interests
Send optional marketing Consent, or another basis where law permits; unsubscribe is always provided
Process customer-hosted personal information Customer's documented instructions under the DPA

Where we rely on legitimate interests, we balance the service or security benefit against people's rights and reasonable expectations. We do not use customer site content for unrelated advertising or to train general-purpose AI models.

5. Sharing and subprocessors

We share only what is necessary with providers that support hosting, email and service operations. Current providers are listed in Subprocessors. We may also disclose information when required by law, to protect people or the service, or during a business transfer subject to appropriate confidentiality.

Workspace Owners and authorised members can see information within their workspace according to their role. They cannot use NativeCMS to access another workspace.

6. International transfers

Primary customer workloads are hosted in the EU Azure region shown in the dashboard. A provider or support operation may process information elsewhere. Before a restricted transfer, we use an applicable adequacy regulation, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard, with a transfer-risk assessment where required.

7. Retention

Information Retention
Active account and workspace records For the agreement
Deleted-site recovery copy 30 days after deletion unless a legal hold applies
Routine backups The schedule displayed for the environment
Security and audit logs 12 months
Support records 24 months after closure
Expired invitations and verification tokens Token expiry plus up to 30 days of minimal audit evidence
Contract and tax records Up to 6 years where required by law or to establish or defend claims

We delete or anonymise information when it is no longer needed. Protected backup deletion may follow the backup cycle rather than immediate primary deletion.

8. Your rights

Depending on the circumstances, you may have rights to be informed, access, rectify, erase, restrict, object, obtain portable information and challenge a solely automated decision. Contact privacy@nativecms.co.uk. We may need to verify identity and decide whether NativeCMS or the relevant customer should handle the request. You can complain to the UK Information Commissioner's Office at https://ico.org.uk/.

9. Cookies and local storage

NativeCMS uses essential session, security and preference storage needed to sign in, maintain the selected workspace and protect requests. Non-essential analytics or advertising cookies will not be enabled without an appropriate consent control and notice.

10. Security and incidents

Controls include encryption in transit, restricted workload identities, tenant-level database controls, MFA, session revocation, immutable release provenance, protected secrets, role-based access, backups, WAF and rate limiting, logging and security testing. No service is risk-free. We notify affected customers and regulators without undue delay when law or the DPA requires it. Security reports should be sent to security@nativecms.co.uk.

11. Children

NativeCMS customer accounts are for adults acting for an organisation and are not directed at children. Customers whose sites or apps concern children must carry out their own assessment and implement suitable notices, consent or age-assurance controls.

12. Changes

We publish the current version, effective date and document hash. A material change creates a new immutable version and requires renewed acceptance of the Terms or acknowledgement of this Privacy Policy. We will notify account users before a material change takes effect where reasonably possible.

Sam Lewis, sole trader trading as NativeCMSMortimer Court, Abbey Road, London, NW8 9AD