Privacypolicy.
This notice explains what personal data DetenX uses when you visit the site, talk to us, or buy studio work or a product. It is written for the UK GDPR and the Data Protection Act 2018. It also draws the line between data we control and lead data you control.
Last updated 2 October 2026
1. Who is responsible
DetenX, a software house based in London, United Kingdom, is the controller of personal data about our own clients, site visitors and enquiries. Email hello@detenx.studio for privacy requests. We have not appointed a statutory data protection officer. That address is the contact for these requests.
When you upload contacts, call recordings, messages or scripts into SMS Marketing, Power Dialer, AI Lead Bot, or a system we host for you, you are the controller of that data. We are the processor. We use it only to provide the service, on your instructions, and on the terms below. We do not sell it and we do not use it to market our own services to your contacts.
2. Data we collect as controller
- Identity and contact details you send us: name, company, email, phone, and the project or booking details in a form.
- Commercial records if you become a client: orders, invoices, correspondence and support history.
- Technical data from the site: IP address, browser type, pages viewed and rough location derived from the IP address, kept in server logs so the site can run and so we can deal with abuse.
- Any other information you choose to send, such as a brief or a file.
Enquiry forms on this site currently keep what you type in the browser until email delivery is connected. Do not put secrets in a form that the page says stays on the page. Once delivery is connected, the same fields are sent to us by email and stored as an enquiry.
We do not ask for special category data. Please do not send it.
3. Why we use it, and the lawful basis
- To answer an enquiry and prepare a proposal. Legitimate interests, or steps toward a contract if you asked for one.
- To perform a contract, take payment, and provide studio work or a product. Contract.
- To keep invoices and records we must hold. Legal obligation.
- To secure the site, prevent fraud, and understand which pages are used, using server logs rather than an advertising profile. Legitimate interests.
- To send product updates you asked for. Consent, which you can withdraw at any time. We do not send marketing email without a lawful basis, and we do not send marketing SMS to people who have not dealt with us.
We do not use automated decision-making that produces legal or similarly significant effects about you.
4. Lead data we process for you
Your contact lists, call outcomes, recordings, message content and booking details belong to your business. You must have a lawful basis, and any consent required, before that data is uploaded or a person is contacted. The Terms set that duty out, including the Privacy and Electronic Communications Regulations and, where you call or text people in other countries, the laws of those countries.
While we are your processor we will:
- process the data only on your documented instructions, including the settings you choose in the product;
- ensure people who handle it are bound by confidentiality;
- use appropriate technical and organisational security;
- use sub-processors needed to run the service, such as hosting, telecoms and email delivery, and remain responsible for them;
- help you respond to data-subject requests and regulatory enquiries, taking into account the nature of the processing;
- at the end of the service, delete or return the data as section 6 describes;
- tell you without undue delay after we become aware of a personal data breach affecting that data.
You authorise us to use infrastructure and telecoms providers that may process this data. We will not appoint a sub-processor for a new kind of processing of your lead data without telling you. You can object on reasonable data-protection grounds, and if we cannot offer an alternative you can cancel the affected product.
5. Who we share data with
We share personal data with:
- providers who host the site, send email, carry calls or messages, or process payments, only as needed to perform that job;
- professional advisers such as accountants or lawyers, under confidentiality;
- a buyer of the business, under confidentiality, if we sell or reorganise it;
- authorities or carriers when the law requires it, or when we need to protect our rights, users or network.
We do not sell personal data.
6. How long we keep it
- Enquiries that do not become a contract: 24 months after our last contact with you.
- Contracts, invoices and related correspondence: six years after the contract ends, so we can deal with tax and limitation periods.
- Server logs: up to 12 months.
- Lead data we process for you: for the life of the subscription, then for 30 days so you can export it, unless you ask us to delete it sooner or the law requires us to keep it.
We then delete it or anonymise it.
7. Where it is processed
We are based in the United Kingdom. Some providers may process data outside the UK. Where they do, we rely on a lawful transfer tool, such as an adequacy regulation or the UK International Data Transfer Agreement, plus any extra measures those tools require.
8. Security
We use access controls, encrypted transport where the service supports it, and limits on who can see client and lead data. No online service is perfectly secure. If a breach creates a risk to people, we will notify the people and the regulator the law requires us to notify.
9. Your rights
If we are the controller, you can ask to access, correct, erase or restrict your personal data, and you can object to processing based on legitimate interests. Where the basis is consent, you can withdraw it. Where the basis is contract and the processing is automated, you can ask for a portable copy. We respond within one month, or we will tell you why we need longer.
If your data is in a customer's campaign, contact that customer. We will help them if they ask us to. We may refuse a request that is manifestly unfounded or excessive, or that the law lets us refuse, and we will explain why.
You can complain to the Information Commissioner's Office at ico.org.uk. We would like the chance to put things right first. Write to hello@detenx.studio.
10. Cookies
The marketing site uses only cookies and similar storage that are strictly necessary to run the site, such as remembering a session. We do not use advertising cookies or third-party analytics cookies. Strictly necessary cookies do not need a consent banner under the Privacy and Electronic Communications Regulations. If that changes, we will update this notice and ask before non-essential cookies are set.
11. Children
Our site and products are for businesses and are not directed at children under 18. We do not knowingly collect their data. If you believe we have, email us and we will delete it.
12. Changes
We will post changes on this page and change the date at the top. If a change materially affects how we use client contact data, we will also email active customers.