Privacy Policy
Last updated: 27 July 2026
Who we are
Virtus Nemeton Ltd is registered in England and Wales under company number 17181232. Our registered office is 24 Dymchurch Avenue, Radcliffe, Manchester, M26 1BB. We are registered with the Information Commissioner's Office under number ZC161313.
Contact us about privacy at team@virtusnemeton.co.uk.
Our role
We are the controller for our website, enquiries, account administration, billing and our own marketing. When an organisation uses Nemeton Works to manage its clients, employees, contractors, sites, assets and work records, that organisation will normally be the controller and Virtus Nemeton will act as its processor under a data-processing agreement.
Data we process
- Identity and contact details supplied through enquiries, accounts or contracts.
- Organisation, role, site and team membership information.
- Job sheets, assignments, timesheets, comments and customer communications.
- Asset, maintenance and field evidence, which may include photographs or audio.
- Authentication, device, security and audit-log information.
- Billing and transaction references; complete card details are handled by Stripe.
- Cookie preferences and optional website analytics.
Customers must not upload special-category or criminal-offence data unless this has been agreed in writing and appropriate safeguards are in place.
Why we use data
- Contract: to provide accounts, platform services, support, billing and agreed professional services.
- Legitimate interests: to secure, operate and improve our services, respond to business enquiries and maintain auditable business records.
- Legal obligation: for accounting, tax, fraud prevention and regulatory duties.
- Consent: for optional analytics and electronic marketing where consent is required. Consent can be withdrawn at any time.
Service providers
We use a controlled set of service providers. A provider is used only when the relevant service or customer configuration requires it.
| Provider | Purpose |
|---|---|
| Vercel | Website and application hosting |
| Supabase | Authentication, database and file storage |
| Resend | Transactional and approved marketing email |
| Stripe | Payment processing |
| Google and Microsoft | Sign-in or calendar services when a customer enables them |
| Twilio | SMS delivery when a customer enables it |
| Anthropic | AI-assisted processing where a configured workflow requires it |
We do not sell personal data. We may disclose information where required by law, to protect rights or security, or as part of a properly governed corporate transaction.
International transfers
We prefer UK-hosted services where practical. Some providers may process data in the United Kingdom, European Economic Area or other countries. Where UK data-protection law requires it, we rely on adequacy regulations, the UK International Data Transfer Agreement or Addendum, and contractual and technical safeguards.
Retention
- Enquiries: up to 24 months after the last meaningful contact.
- Account data: while the account is active and normally 90 days after closure.
- Operational records: according to the customer contract and configured schedule.
- Security and audit logs: normally up to 12 months unless an incident requires longer.
- Payment and accounting records: normally seven years.
- Marketing records: until consent is withdrawn or after 24 months of inactivity.
Data may be retained longer where law, litigation, fraud prevention or an active dispute requires it. When retention ends, data is deleted or irreversibly anonymised.
Security and automated processing
We use access control, tenant isolation, encryption in transit, managed encryption at rest, audit trails and human review gates. No machine-proposed output is intended to take consequential action, create permanent operational memory or contact a customer without an authorised human review step.
No internet service is risk free. Security information and responsible-disclosure details are available on our security page.
Your rights
Depending on the circumstances, you may have rights to access, correct, erase, restrict or object to processing, receive portable data, and withdraw consent. Send requests to team@virtusnemeton.co.uk. We may need to verify identity and, where we act as a processor, route the request to the relevant customer organisation.
You may complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint.
Cookies and changes
Our Cookie Policy explains essential storage and optional analytics. We will update this notice when our processing changes materially and will provide additional notice where required.