Sennote Privacy Policy

Version: 1.0
Effective date: 13 August 2026
Last updated: 13 August 2026

This Privacy Policy explains how Sennote Limited handles personal data when you use the Sennote mobile application, website, support channels and related services (together, the Service).

It also explains how we protect confidential professional content entered into Sennote. Confidential business information is not always personal data, but we apply the access and use commitments in this Policy to both.

1. Who we are

Sennote Limited (Sennote, we, us or our) is a company incorporated in Scotland under company number SC897954.

For the personal data described in this Policy, Sennote is generally the controller for account administration, authentication, security, support, service operation and our own business records.

Where a business customer separately instructs Sennote to process personal data on its behalf, the relevant order form or data processing agreement may allocate responsibilities differently. If there is a conflict about processing carried out for that customer, the data processing agreement takes priority.

2. Scope

This Policy applies to:

The Service is intended for professional and business use by adults. It is not directed to children and must not be used by anyone under 18.

3. Our private-workspace model

In the current product, each professional user has a private workspace. A user's association with a company may determine eligibility, seat allocation and branding, but it does not give colleagues, managers or other members of that company access to the user's tasting records or reports.

Sennote is designed to assist professional work, not to provide silent employee monitoring. We will not give an organisation access to a private workspace unless:

If we introduce manager, supervisor or mentor roles, we will explain who can see what, update the relevant privacy information and contractual documents, and avoid retrospectively exposing existing private records without an appropriate legal basis and notice.

This product access model does not decide who legally owns information under an employment, consultancy, confidentiality or client agreement.

4. Personal data and content we collect

4.1 Account and profile information

We may process:

4.2 Preferences

We may process settings such as language, theme, page size and form layout so the Service works as you expect.

4.3 Organisation information

Where relevant, we may process an organisation's name, logo, brand colours, seat allocation, account status and subscription period, together with the user's association with that organisation.

4.4 Professional wine and tasting content

The Service allows a user to enter and organise information including:

We call this Professional Content. It may include personal data if a user identifies an individual, sole trader, client contact or other person. All Professional Content should be treated as confidential, whether or not it legally qualifies as personal data.

Please do not enter special-category data, criminal-offence data or personal data that is not professionally necessary. If you enter information about another person, you are responsible for having an appropriate reason and authority to do so and for providing any notice the law requires.

4.5 Support, contact and feedback data

When you ask for help, contact us or submit feedback, we may process:

Do not include client-identifying or confidential wine information in a support message unless it is necessary to resolve the issue. If it is necessary, share the minimum amount needed.

4.6 Technical and security data

When the Service communicates with our systems, we and our service providers may process limited technical information, such as:

If the application stops unexpectedly, a crash report is sent to our crash-reporting provider. It contains the technical error, the stack trace, the device model, operating-system version and application version, and the IP address the report is sent from, from which an approximate city is derived. The report also carries a random identifier created when the application is installed on a device, together with a device identifier generated by the crash-reporting provider. These let us tell how many devices a fault affects rather than only how many times it occurred. They are not your account identifier, we do not use them to identify you, and we do not combine them with your account. We use crash reports only to find and fix defects.

Sennote does not currently use advertising trackers or third-party behavioural analytics in the application. We do not use session recording, product-usage telemetry or performance tracing. We do not collect precise location, contacts or advertising identifiers through the application. Apart from the crash-report identifiers described immediately above, we do not collect device identifiers. We do not upload your device photo library merely because the application is installed.

4.7 Commercial and legal records

If you or your organisation contracts with us, we may process business contact details, correspondence, order forms, invoices, payment status, tax records and transaction references. Payment providers or banks may process payment details under their own privacy terms; we do not need to receive complete payment-card credentials where payment is handled by them.

4.8 Cookies, local storage and similar technologies

The application and website may use strictly necessary cookies, secure tokens, local storage or similar technologies to keep you signed in, remember settings, prevent abuse and deliver requested features. These technologies are required for the Service to function and are not used for third-party advertising.

If we later introduce optional analytics or another non-essential technology, we will update this Policy and provide any consent controls required by law before enabling it.

5. How we obtain data

We obtain personal data:

Some information is required to provide the Service. For example, we need an email address and authentication information to create and secure an account, and we need the content you choose to enter to produce the corresponding record or report. If required information is not provided, we may be unable to create the account or provide the requested feature. Profile images, most preference fields and the content of optional free-text fields are voluntary.

6. Why we use personal data and our lawful bases

The lawful basis depends on the context. The principal purposes are:

Purpose Categories typically used UK/EU lawful basis
Create and administer accounts; provide authentication, features, reports and exportsAccount, preferences, organisation and Professional ContentPerformance of a contract, or steps requested before entering one
Arrange business access, seats and pre-registrationAccount, organisation and commercial recordsContract and our legitimate interests in administering B2B access
Provide support and respond to feedbackAccount, support, technical data and relevant Professional Content supplied by the userContract and our legitimate interests in supporting and improving the Service
Secure, troubleshoot and maintain the Service; prevent fraud and misuseAccount, technical, security and limited relevant contentOur legitimate interests in operating a secure and reliable professional service; legal obligation where applicable
Keep business, tax, contract and compliance records; establish or defend legal claimsAccount, commercial, support and relevant service recordsLegal obligation and our legitimate interests in business administration and legal protection
Produce genuinely de-identified, aggregated service statisticsDe-identified account, technical and usage informationOur legitimate interests in understanding and improving the Service, after assessing privacy impact
Send product or service communicationsAccount and contact informationContract for necessary service messages; consent or legitimate interests where lawful for optional communications

Where we rely on legitimate interests, we consider the necessity of the processing, its effect on individuals and the safeguards available. You may object as explained in section 15.

We do not currently make decisions that produce legal or similarly significant effects using solely automated processing.

7. How we use confidential Professional Content

We use identifiable Professional Content only as needed to:

We do not sell Professional Content. We do not use identifiable Professional Content for third-party advertising, public demonstrations, unrelated benchmarks or training general-purpose or third-party artificial-intelligence models without specific permission from the person or customer authorised to give it.

We may use aggregated or genuinely de-identified information to improve the Service only where we have taken reasonable steps to prevent identification through winery names, vintages, plots, free text, rare combinations or other indirect identifiers. We will not attempt to re-identify that information.

8. Who can access data within Sennote

Access is limited to authorised personnel and contractors who need it for defined support, security, legal or operational purposes and who are subject to confidentiality obligations. Access to Professional Content is not permitted for curiosity, routine observation of a user's work or employee monitoring.

We use role-based restrictions and review access appropriate to the sensitivity of the information. Where practical, we use de-identified information for troubleshooting and product decisions.

9. Service providers and other recipients

We use selected providers to operate and distribute the Service. Depending on how you use Sennote, recipients may include:

Service providers may use personal data only to provide their contracted services to us or as otherwise disclosed under their own controller responsibilities. We require processors to protect data, keep it confidential, assist with rights and security obligations, and delete or return it at the end of their services as the law and contract require.

We do not sell or rent personal data and do not share it with data brokers or advertising networks.

10. International transfers

Our primary application systems are hosted in the European Economic Area. Some providers operate globally or from the United States, so personal data may be processed outside the United Kingdom or EEA.

Where an international transfer requires a safeguard, we use an available lawful mechanism such as:

You may contact us for further information about the safeguard relevant to your data.

11. Retention

We keep identifiable data only for as long as needed for the purposes described above, including legal, accounting and security requirements.

Our retention schedule is:

Data Proposed retention
Active account, preferences and Professional ContentWhile the account is active
Account and Professional Content after subscription expiry or withdrawal of access, where erasure is not requestedRetained so access can be restored and an export remains possible; deleted on request
Verified account-erasure requestCompleted without undue delay and normally within 30 days, subject to lawful exceptions
Data remaining in protected backups after deletion from live systemsIsolated from normal use and overwritten or deleted within 90 days
Support, contact and feedback recordsUp to 24 months after the matter closes, unless a longer period is needed for a dispute or legal duty
Security and application logsUp to 12 months, unless a shorter operational period applies or longer retention is necessary to investigate an incident
Contracts, invoices, tax and core corporate recordsNormally 6 years after the relevant financial year or contract ends, or longer where law requires
Evidence that a rights or deletion request was handledMinimum information necessary, normally up to 3 years
Genuinely de-identified aggregate informationMay be retained because it no longer identifies a person or customer

We may suspend deletion where information must be preserved for a legal claim, regulatory requirement, fraud or security investigation. During that period, use is restricted to the preservation purpose.

12. Exports and account deletion

An active user may request an export at any time. PDF export is a separate feature intended for reading and sharing an individual professional report. For access and portability, a signed-in User may download one structured JSON file from the application's profile screen. A verified User may also request the same file by contacting [email protected].

Subject to legal restrictions and the rights of other people, the JSON export includes:

To avoid excessive duplication, the JSON file does not repeat every frozen form structure stored with every historical report where the question text, answer type and value already preserve the meaning of each answer. A retained source structure may be requested separately where it is needed and disclosure is lawful.

Passwords are not included because Sennote does not hold them in readable form. Additional authentication-provider records and relevant server request logs may be supplied separately on request. Internal staff permission markers and organisation-owned logos and brand colours are not part of a User's portability file. We may exclude or redact information where disclosure would adversely affect another person's rights, reveal protected security information or is otherwise restricted by law.

Retained deleted records are included while they remain in our systems and are marked with their deletion date. After genuine deletion or irreversible anonymisation, they are no longer available for export.

Before voluntary deletion, we will offer an opportunity to export. Export is optional and will not be used to delay an erasure request.

The application allows a User who can create an account to initiate account deletion. After initiation, the account and associated data are scheduled for deletion through an automated process with a 30-day grace period. By the end of that period, the account and associated user-controlled content are deleted or irreversibly anonymised rather than merely suspended or deactivated, except for limited information we must lawfully retain. The deletion process is designed to cover application account data, Professional Content, matching feedback and contact records, and the authentication identity. Residual protected backup copies remain isolated from ordinary use and expire within 90 days.

We may verify identity before acting on a request. PDFs or other copies already exported to a device or shared with another person are outside Sennote's control and cannot be recalled by us.

13. Security

We use proportionate technical and organisational measures designed to protect personal data and confidential Professional Content. These include access controls, authentication protections, encryption in transit and at rest, backups, service-provider controls and procedures for responding to security events.

No service can guarantee absolute security. You must protect your credentials, keep your device secure, use current software and notify us promptly if you believe your account has been compromised.

If a personal-data breach creates a legal notification obligation, we will notify the appropriate regulator and affected individuals in accordance with applicable law.

14. Your data-protection rights

Depending on your location and the circumstances, you may have the right to:

These rights are not absolute. For example, we may need to retain limited records to meet a legal obligation or defend a claim, and we must protect the rights of other people.

To exercise a right, contact [email protected]. You do not need to use a particular form. We may ask for information reasonably needed to verify identity and locate the relevant data. We will respond without undue delay and normally within one calendar month. Where the law permits an extension for a complex request, we will explain it within the initial period.

Your right to object

Where we rely on legitimate interests, you may object to the processing for reasons relating to your situation. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. If personal data is used for direct marketing, you may object at any time and we will stop using it for that purpose.

15. Privacy complaints

You may make a privacy complaint by writing to [email protected]. Please describe what happened, the data or account involved and the outcome you seek.

We will:

You may also complain directly to the regulator. In the United Kingdom, this is the Information Commissioner's Office: ico.org.uk/make-a-complaint. If you are in the EEA, you may complain to the supervisory authority in the country where you live or work or where the issue occurred. In France, this is the CNIL: cnil.fr.

We would appreciate the opportunity to resolve the issue first, but contacting us does not limit your right to approach a regulator.

16. Other websites and services

The Service may link to third-party websites or operating-system features. Their privacy practices are governed by their own notices. Sennote is not responsible for a third party's independent processing.

17. Changes to this Policy

We may update this Policy to reflect changes to the Service, law or our practices. We will post the updated version and change the date above. If a change materially affects how existing personal data is used, we will provide appropriate advance notice in the application, by email or through the Service and request consent where the law requires it.

We will not use a Policy update to retrospectively give an organisation access to an existing private workspace without an appropriate legal basis and clear notice.

18. Contact us

Questions, rights requests and privacy complaints should be sent to:

Sennote Limited Company number: SC897954 Registered office: Office 1710, 3 Fitzroy Place, 1/1 Sauchiehall Street, Finnieston, Glasgow Central, Glasgow, Scotland, G3 7RH, United Kingdom Office and correspondence address: 4/15, 843 Crow Road, Glasgow, Scotland, G13 1LF, United Kingdom Email: [email protected]