Sennote Privacy Policy
Version: 1.0
Effective date: 13 August 2026
Last updated: 13 August 2026
This Privacy Policy explains how Sennote Limited handles personal data when you use the Sennote mobile application, website, support channels and related services (together, the Service).
It also explains how we protect confidential professional content entered into Sennote. Confidential business information is not always personal data, but we apply the access and use commitments in this Policy to both.
1. Who we are
Sennote Limited (Sennote, we, us or our) is a company incorporated in Scotland under company number SC897954.
- Registered office: Office 1710, 3 Fitzroy Place, 1/1 Sauchiehall Street, Finnieston, Glasgow Central, Glasgow, Scotland, G3 7RH, United Kingdom
- Office and correspondence address: 4/15, 843 Crow Road, Glasgow, Scotland, G13 1LF, United Kingdom
- Privacy contact: [email protected]
- Support contact: [email protected]
For the personal data described in this Policy, Sennote is generally the controller for account administration, authentication, security, support, service operation and our own business records.
Where a business customer separately instructs Sennote to process personal data on its behalf, the relevant order form or data processing agreement may allocate responsibilities differently. If there is a conflict about processing carried out for that customer, the data processing agreement takes priority.
2. Scope
This Policy applies to:
- individual professional users of Sennote;
- people invited or pre-registered by an authorised business contact;
- winery, consultancy or laboratory representatives who arrange access to the Service;
- people who contact support, submit feedback or visit a Sennote website that links to this Policy.
The Service is intended for professional and business use by adults. It is not directed to children and must not be used by anyone under 18.
3. Our private-workspace model
In the current product, each professional user has a private workspace. A user's association with a company may determine eligibility, seat allocation and branding, but it does not give colleagues, managers or other members of that company access to the user's tasting records or reports.
Sennote is designed to assist professional work, not to provide silent employee monitoring. We will not give an organisation access to a private workspace unless:
- the user instructs or clearly agrees to the disclosure;
- a future organisation feature expressly provides that access and its permissions are shown to the user before use;
- a separate contract lawfully requires it and the user has been appropriately informed; or
- disclosure is required by law.
If we introduce manager, supervisor or mentor roles, we will explain who can see what, update the relevant privacy information and contractual documents, and avoid retrospectively exposing existing private records without an appropriate legal basis and notice.
This product access model does not decide who legally owns information under an employment, consultancy, confidentiality or client agreement.
4. Personal data and content we collect
4.1 Account and profile information
We may process:
- email address and email-verification status;
- display name and profile image, if supplied;
- account role, status and internal user identifier;
- account creation, update and closure information;
- authentication and session information. Passwords are handled by our identity provider; Sennote does not receive your password in readable form.
4.2 Preferences
We may process settings such as language, theme, page size and form layout so the Service works as you expect.
4.3 Organisation information
Where relevant, we may process an organisation's name, logo, brand colours, seat allocation, account status and subscription period, together with the user's association with that organisation.
4.4 Professional wine and tasting content
The Service allows a user to enter and organise information including:
- winery, wine, plot, variety, vintage and production information;
- tasting titles, dates, observations, answers, scores, actions and conclusions;
- Wine Evaluation, Wine Profile, Berry, Vinification and Custom form content, together with content entered into other professional sensory-tasting, evaluation or workflow templates that we may add in the future;
- reports, tasting history and user-generated PDF exports;
- free-text notes and identifiers relating to clients, wineries, projects or individual contacts.
We call this Professional Content. It may include personal data if a user identifies an individual, sole trader, client contact or other person. All Professional Content should be treated as confidential, whether or not it legally qualifies as personal data.
Please do not enter special-category data, criminal-offence data or personal data that is not professionally necessary. If you enter information about another person, you are responsible for having an appropriate reason and authority to do so and for providing any notice the law requires.
4.5 Support, contact and feedback data
When you ask for help, contact us or submit feedback, we may process:
- your email address;
- your message and any attachments or context you choose to provide;
- feedback category;
- application version and device platform;
- records of our response and resolution.
Do not include client-identifying or confidential wine information in a support message unless it is necessary to resolve the issue. If it is necessary, share the minimum amount needed.
4.6 Technical and security data
When the Service communicates with our systems, we and our service providers may process limited technical information, such as:
- request date and time;
- request method and technical route;
- response status and processing duration;
- internal request or event identifiers;
- authentication, security and error information;
- network information, including IP address, that infrastructure providers necessarily receive when delivering the Service.
If the application stops unexpectedly, a crash report is sent to our crash-reporting provider. It contains the technical error, the stack trace, the device model, operating-system version and application version, and the IP address the report is sent from, from which an approximate city is derived. The report also carries a random identifier created when the application is installed on a device, together with a device identifier generated by the crash-reporting provider. These let us tell how many devices a fault affects rather than only how many times it occurred. They are not your account identifier, we do not use them to identify you, and we do not combine them with your account. We use crash reports only to find and fix defects.
Sennote does not currently use advertising trackers or third-party behavioural analytics in the application. We do not use session recording, product-usage telemetry or performance tracing. We do not collect precise location, contacts or advertising identifiers through the application. Apart from the crash-report identifiers described immediately above, we do not collect device identifiers. We do not upload your device photo library merely because the application is installed.
4.7 Commercial and legal records
If you or your organisation contracts with us, we may process business contact details, correspondence, order forms, invoices, payment status, tax records and transaction references. Payment providers or banks may process payment details under their own privacy terms; we do not need to receive complete payment-card credentials where payment is handled by them.
4.8 Cookies, local storage and similar technologies
The application and website may use strictly necessary cookies, secure tokens, local storage or similar technologies to keep you signed in, remember settings, prevent abuse and deliver requested features. These technologies are required for the Service to function and are not used for third-party advertising.
If we later introduce optional analytics or another non-essential technology, we will update this Policy and provide any consent controls required by law before enabling it.
5. How we obtain data
We obtain personal data:
- directly from you when you register, use the Service or contact us;
- from an authorised organisation contact when they arrange or pre-register access;
- automatically from the application and service infrastructure when the Service is used;
- from Apple or another authorised distribution or payment channel where needed to validate a transaction, subscription or application installation;
- from professional advisers, authorities or public sources where necessary for legal and business administration.
Some information is required to provide the Service. For example, we need an email address and authentication information to create and secure an account, and we need the content you choose to enter to produce the corresponding record or report. If required information is not provided, we may be unable to create the account or provide the requested feature. Profile images, most preference fields and the content of optional free-text fields are voluntary.
6. Why we use personal data and our lawful bases
The lawful basis depends on the context. The principal purposes are:
| Purpose | Categories typically used | UK/EU lawful basis |
|---|---|---|
| Create and administer accounts; provide authentication, features, reports and exports | Account, preferences, organisation and Professional Content | Performance of a contract, or steps requested before entering one |
| Arrange business access, seats and pre-registration | Account, organisation and commercial records | Contract and our legitimate interests in administering B2B access |
| Provide support and respond to feedback | Account, support, technical data and relevant Professional Content supplied by the user | Contract and our legitimate interests in supporting and improving the Service |
| Secure, troubleshoot and maintain the Service; prevent fraud and misuse | Account, technical, security and limited relevant content | Our legitimate interests in operating a secure and reliable professional service; legal obligation where applicable |
| Keep business, tax, contract and compliance records; establish or defend legal claims | Account, commercial, support and relevant service records | Legal obligation and our legitimate interests in business administration and legal protection |
| Produce genuinely de-identified, aggregated service statistics | De-identified account, technical and usage information | Our legitimate interests in understanding and improving the Service, after assessing privacy impact |
| Send product or service communications | Account and contact information | Contract for necessary service messages; consent or legitimate interests where lawful for optional communications |
Where we rely on legitimate interests, we consider the necessity of the processing, its effect on individuals and the safeguards available. You may object as explained in section 15.
We do not currently make decisions that produce legal or similarly significant effects using solely automated processing.
7. How we use confidential Professional Content
We use identifiable Professional Content only as needed to:
- provide features requested by the user;
- create user-requested reports and exports;
- provide support when the user asks us to investigate an issue;
- protect the security and integrity of the Service;
- comply with law or establish, exercise or defend legal claims.
We do not sell Professional Content. We do not use identifiable Professional Content for third-party advertising, public demonstrations, unrelated benchmarks or training general-purpose or third-party artificial-intelligence models without specific permission from the person or customer authorised to give it.
We may use aggregated or genuinely de-identified information to improve the Service only where we have taken reasonable steps to prevent identification through winery names, vintages, plots, free text, rare combinations or other indirect identifiers. We will not attempt to re-identify that information.
8. Who can access data within Sennote
Access is limited to authorised personnel and contractors who need it for defined support, security, legal or operational purposes and who are subject to confidentiality obligations. Access to Professional Content is not permitted for curiosity, routine observation of a user's work or employee monitoring.
We use role-based restrictions and review access appropriate to the sensitivity of the information. Where practical, we use de-identified information for troubleshooting and product decisions.
9. Service providers and other recipients
We use selected providers to operate and distribute the Service. Depending on how you use Sennote, recipients may include:
- Amazon Web Services (AWS) — application hosting, databases, storage and related cloud infrastructure;
- Amazon Cognito — identity and authentication services;
- Cloudflare — network delivery, security and domain services;
- Expo / EAS — application build, distribution and update services;
- Sentry — application crash reporting, processed in the European Union;
- Apple — App Store distribution, device-platform services and any Apple-managed transactions;
- professional advisers, insurers, auditors, banks and payment providers where required for business administration;
- courts, regulators, law-enforcement bodies or other authorities where disclosure is legally required;
- a buyer, investor or successor in connection with a proposed or completed corporate transaction, subject to appropriate confidentiality and data-protection safeguards.
Service providers may use personal data only to provide their contracted services to us or as otherwise disclosed under their own controller responsibilities. We require processors to protect data, keep it confidential, assist with rights and security obligations, and delete or return it at the end of their services as the law and contract require.
We do not sell or rent personal data and do not share it with data brokers or advertising networks.
10. International transfers
Our primary application systems are hosted in the European Economic Area. Some providers operate globally or from the United States, so personal data may be processed outside the United Kingdom or EEA.
Where an international transfer requires a safeguard, we use an available lawful mechanism such as:
- a UK or EU adequacy decision;
- the European Commission's Standard Contractual Clauses;
- the UK International Data Transfer Addendum or International Data Transfer Agreement; or
- another lawful transfer mechanism, together with supplementary measures where appropriate.
You may contact us for further information about the safeguard relevant to your data.
11. Retention
We keep identifiable data only for as long as needed for the purposes described above, including legal, accounting and security requirements.
Our retention schedule is:
| Data | Proposed retention |
|---|---|
| Active account, preferences and Professional Content | While the account is active |
| Account and Professional Content after subscription expiry or withdrawal of access, where erasure is not requested | Retained so access can be restored and an export remains possible; deleted on request |
| Verified account-erasure request | Completed without undue delay and normally within 30 days, subject to lawful exceptions |
| Data remaining in protected backups after deletion from live systems | Isolated from normal use and overwritten or deleted within 90 days |
| Support, contact and feedback records | Up to 24 months after the matter closes, unless a longer period is needed for a dispute or legal duty |
| Security and application logs | Up to 12 months, unless a shorter operational period applies or longer retention is necessary to investigate an incident |
| Contracts, invoices, tax and core corporate records | Normally 6 years after the relevant financial year or contract ends, or longer where law requires |
| Evidence that a rights or deletion request was handled | Minimum information necessary, normally up to 3 years |
| Genuinely de-identified aggregate information | May be retained because it no longer identifies a person or customer |
We may suspend deletion where information must be preserved for a legal claim, regulatory requirement, fraud or security investigation. During that period, use is restricted to the preservation purpose.
12. Exports and account deletion
An active user may request an export at any time. PDF export is a separate feature intended for reading and sharing an individual professional report. For access and portability, a signed-in User may download one structured JSON file from the application's profile screen. A verified User may also request the same file by contacting [email protected].
Subject to legal restrictions and the rights of other people, the JSON export includes:
- account identifiers, email, verification status, display name, profile-image reference, role, account status and relevant account dates;
- application preferences;
- the name of the organisation that arranged access, if any;
- User-created wineries, wines and plots, including retained deleted records and their deletion dates;
- tasting sessions, reports, answers and the human-readable question and answer type associated with each answer;
- feedback and contact messages that can reasonably be matched to the User, including contact messages matched by sender email;
- User-created templates, their current complete structure and User-created evaluation parameters; and
- export-generation time, export-format version and an explanation of exclusions.
To avoid excessive duplication, the JSON file does not repeat every frozen form structure stored with every historical report where the question text, answer type and value already preserve the meaning of each answer. A retained source structure may be requested separately where it is needed and disclosure is lawful.
Passwords are not included because Sennote does not hold them in readable form. Additional authentication-provider records and relevant server request logs may be supplied separately on request. Internal staff permission markers and organisation-owned logos and brand colours are not part of a User's portability file. We may exclude or redact information where disclosure would adversely affect another person's rights, reveal protected security information or is otherwise restricted by law.
Retained deleted records are included while they remain in our systems and are marked with their deletion date. After genuine deletion or irreversible anonymisation, they are no longer available for export.
Before voluntary deletion, we will offer an opportunity to export. Export is optional and will not be used to delay an erasure request.
The application allows a User who can create an account to initiate account deletion. After initiation, the account and associated data are scheduled for deletion through an automated process with a 30-day grace period. By the end of that period, the account and associated user-controlled content are deleted or irreversibly anonymised rather than merely suspended or deactivated, except for limited information we must lawfully retain. The deletion process is designed to cover application account data, Professional Content, matching feedback and contact records, and the authentication identity. Residual protected backup copies remain isolated from ordinary use and expire within 90 days.
We may verify identity before acting on a request. PDFs or other copies already exported to a device or shared with another person are outside Sennote's control and cannot be recalled by us.
13. Security
We use proportionate technical and organisational measures designed to protect personal data and confidential Professional Content. These include access controls, authentication protections, encryption in transit and at rest, backups, service-provider controls and procedures for responding to security events.
No service can guarantee absolute security. You must protect your credentials, keep your device secure, use current software and notify us promptly if you believe your account has been compromised.
If a personal-data breach creates a legal notification obligation, we will notify the appropriate regulator and affected individuals in accordance with applicable law.
14. Your data-protection rights
Depending on your location and the circumstances, you may have the right to:
- be informed about how your personal data is used;
- request access to your personal data and receive a copy;
- correct inaccurate or incomplete personal data;
- request deletion of personal data;
- restrict how personal data is used;
- receive personal data you provided in a structured, commonly used and machine-readable format and transmit it to another controller;
- object to processing based on legitimate interests or to direct marketing;
- withdraw consent at any time where processing relies on consent, without affecting earlier lawful processing;
- complain to a data-protection authority;
- receive information about safeguards used for international transfers;
- not be subject to a solely automated decision that has legal or similarly significant effects, where the law provides that right.
These rights are not absolute. For example, we may need to retain limited records to meet a legal obligation or defend a claim, and we must protect the rights of other people.
To exercise a right, contact [email protected]. You do not need to use a particular form. We may ask for information reasonably needed to verify identity and locate the relevant data. We will respond without undue delay and normally within one calendar month. Where the law permits an extension for a complex request, we will explain it within the initial period.
Your right to object
Where we rely on legitimate interests, you may object to the processing for reasons relating to your situation. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. If personal data is used for direct marketing, you may object at any time and we will stop using it for that purpose.
15. Privacy complaints
You may make a privacy complaint by writing to [email protected]. Please describe what happened, the data or account involved and the outcome you seek.
We will:
- acknowledge a data-protection complaint without undue delay;
- investigate it without undue delay;
- keep you appropriately informed; and
- tell you the outcome and how you can escalate the matter.
You may also complain directly to the regulator. In the United Kingdom, this is the Information Commissioner's Office: ico.org.uk/make-a-complaint. If you are in the EEA, you may complain to the supervisory authority in the country where you live or work or where the issue occurred. In France, this is the CNIL: cnil.fr.
We would appreciate the opportunity to resolve the issue first, but contacting us does not limit your right to approach a regulator.
16. Other websites and services
The Service may link to third-party websites or operating-system features. Their privacy practices are governed by their own notices. Sennote is not responsible for a third party's independent processing.
17. Changes to this Policy
We may update this Policy to reflect changes to the Service, law or our practices. We will post the updated version and change the date above. If a change materially affects how existing personal data is used, we will provide appropriate advance notice in the application, by email or through the Service and request consent where the law requires it.
We will not use a Policy update to retrospectively give an organisation access to an existing private workspace without an appropriate legal basis and clear notice.
18. Contact us
Questions, rights requests and privacy complaints should be sent to:
Sennote Limited Company number: SC897954 Registered office: Office 1710, 3 Fitzroy Place, 1/1 Sauchiehall Street, Finnieston, Glasgow Central, Glasgow, Scotland, G3 7RH, United Kingdom Office and correspondence address: 4/15, 843 Crow Road, Glasgow, Scotland, G13 1LF, United Kingdom Email: [email protected]