Legal

Privacy Policy

Who is responsible for your data

The data controller is RAY AMJAD LTD, trading as Impello, a company registered in England and Wales under number 14506459.

You can reach us about anything in this policy at legal@impello.ai. Our postal address is available on request.

What we collect

When you enquire

The form on our home page collects your company name, first name, work email address, business address and whatever you write in the comments field. We also record the country your request came from, the page that referred you, your browser’s user agent and your IP address, which we use to rate-limit the form against abuse.

When you hold an account

Your email address, a hashed password, your email verification status, your team membership, and the version of our terms you accepted with the date and time you accepted them.

When you pay

Your billing identity and transaction history. Card details are collected and held by our payment provider and never reach our systems.

When you use sandboxes

Lifecycle events for each sandbox — when it was created, paused, resumed and stopped, and the CPU, memory and disk allocated to it. This is how usage is metered and how invoices are evidenced.

The contents of your sandboxes

Your code, your data, your files and your templates are yours. We access them only where it is necessary to operate the service, to answer a support request you have made, to investigate a suspected breach of our acceptable use policy, or to comply with a binding legal demand.

Two things about how sandbox content is stored are worth stating plainly, because they are easy to miss:

  • When you pause a sandbox, its memory and disk are written to storage so it can be resumed. That content is at rest until the sandbox is deleted.
  • Templates you build are copied to encrypted off-site backup storage in the EU, so that a hardware failure does not lose them.

The operational metrics we do collect — sandbox counts, CPU seconds, memory allocated, error rates — describe how much compute ran, never what ran on it.

Who else processes your data

We use the following processors. Each is bound by contract to process data only on our instructions and to keep it confidential.

We do not sell personal data, and we do not share it with third parties for their own marketing.

Where your data is processed

Sandboxes run on dedicated servers in Germany and Finland. The fleet database, the usage-event store, the cache and the backup storage holding your templates are all in the European Union. Your code and your data do not leave the EU in the course of running.

Some of the processors listed above operate from, or replicate to, the United States — payments, transactional email, analytics, application hosting and our internal handling of sales enquiries. Those services handle account, billing, contact and usage information. They do not handle the contents of your sandboxes. Where data reaches a country without a UK or EU adequacy decision, the transfer is made under standard contractual clauses and the UK international data transfer addendum.

We may add processing regions in future. This page will say so when we do.

How long we keep it

Enquiries submitted through the form on our home page are kept for up to 24 months, and the de-duplication record that stops the same address submitting twice is kept for 90 days.

Your rights

Under the UK GDPR and the EU GDPR you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to how we process it, to receive it in a portable form, and to withdraw consent where consent is the basis we rely on.

Email legal@impello.ai and we will respond within one month. If you are not satisfied you may complain to the UK Information Commissioner’s Office at ico.org.uk, or to your local supervisory authority in the EU.

Security

Sandboxes are isolated virtual machines, each running under a hardware-virtualised hypervisor rather than shared kernel namespaces. Traffic to the fleet is encrypted in transit and terminates at our own load balancer. Passwords are hashed, API keys are stored so that they cannot be read back, and the session cookie the dashboard uses is HTTP-only.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority as the law requires.

Cookies and analytics

Our dashboard sets cookies that are strictly necessary to keep you signed in. Our marketing site uses a product analytics tool to understand which pages are read and which are not; it is served through our own domain so that it is not blocked, and it records page views, referrers and coarse device information.

We do not run advertising cookies, and we do not share analytics data with advertising networks. Your browser can refuse cookies, though the dashboard will not be able to keep you signed in if it does.

Children

Impello is sold to businesses and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, email us and we will delete it.

Changes to this policy

We may update this policy. The current version is always the one published here, and changes take effect when they are posted. The date this version came into force is shown at the top of the page.

Contact

RAY AMJAD LTD, trading as Impello. Registered in England and Wales, company number 14506459.

legal@impello.ai