Privacy Policy

This privacy policy explains how Dearthwood Software collects, uses, stores, and protects personal information when you use our website, tools, software, and services.

We take a minimal approach to data collection. We only process personal data where it is necessary for the relevant service, enquiry, contract, legal obligation, security purpose, or legitimate business purpose.

Last updated: June 2026

Who we are

We are Dearthwood Software, a software and web development business based in Lincolnshire, United Kingdom.

Our website address is https://dearthwood.uk.

You can contact us via our contact page or by telephone on 01400 595 093.

Dearthwood Software is registered with the Information Commissioner’s Office under registration reference ZC180535.

Data controller and data processor roles

For personal data collected through this website, our contact page, our website audit tool, our own business records, and direct enquiries made to Dearthwood Software, Dearthwood Software is normally the data controller.

Where we provide software, hosting, maintenance, support, website development, or technical services for a client, our role may vary depending on the work being carried out.

In some cases, we act as a data processor on behalf of the client. In other cases, we may act as an independent data controller for our own business administration, security, billing, and client-management records.

Where we act as a data processor for a client, we process personal data only in accordance with that client’s instructions, our contract with them, and any applicable Data Processing Agreement.

How to make a data protection complaint

If you are unhappy with how we have handled your personal data, you can make a data protection complaint by contacting us through our contact page.

Please make it clear that your message is a data protection complaint. This helps us identify it correctly and handle it under the correct process.

When making a data protection complaint, please include enough information for us to understand the issue. This will usually include your name, your contact details, what personal data or service the complaint relates to, what you believe has gone wrong, and what outcome you are asking for.

We will acknowledge receipt of a data protection complaint within 30 days of receiving it.

We will then take appropriate steps to investigate the complaint, keep you informed where appropriate, and tell you the outcome without undue delay.

If we need more information from you in order to understand or investigate the complaint, we may ask you to provide that information. We may also need to verify your identity where this is necessary to protect personal data.

If your complaint relates to personal data we process on behalf of one of our clients, we may need to refer the matter to that client because they may be the data controller responsible for deciding how that personal data is used.

If you remain unhappy after we have responded, you have the right to complain to the Information Commissioner’s Office. The ICO’s website is https://ico.org.uk.

Website audit tool

When you use our website audit tool, we process information in order to provide the requested audit and protect the service from misuse.

This may include:

  • The website URL you submit, so the tool can perform the requested analysis
  • Your selected option showing how you found us or the tool
  • Your IP address, for rate-limiting, abuse prevention, and security purposes
  • A timestamp, for rate-limiting, abuse prevention, and security purposes
  • Technical audit results generated from the submitted website URL

We do not collect your name, email address, or telephone number through the audit tool unless you separately choose to contact us afterwards.

We retain audit submissions, including submitted URLs, timestamps, generated audit results, and associated rate-limiting or security data, for up to 30 days.

This allows us to operate the tool, enforce fair-use limits, identify abuse, diagnose faults, and understand how the tool is being used.

After this period, this data is deleted or anonymised unless we need to retain specific information for security, abuse-prevention, legal, or administrative reasons.

We may review aggregated audit-tool usage information for our own internal business purposes, such as understanding which routes lead people to the tool. We do not sell this information or use it to add you to a mailing list.

If you wish to discuss your audit results with us, you are welcome to get in touch via our contact page. Any such contact is initiated by you.

Dearthwood Maps API

The Dearthwood Maps API is a self-hosted mapping service built on OpenStreetMap data.

When you or your application makes a request to the Dearthwood Maps API, we process information in order to return the requested mapping data and protect the service from misuse.

This may include:

  • The location query, address, place name, or coordinates submitted, so the API can return the requested mapping data
  • Your IP address, for rate-limiting, security, and abuse-prevention purposes
  • A timestamp, for rate-limiting, security, and abuse-prevention purposes
  • Technical request information, such as the requested endpoint and response status, for service operation and fault diagnosis

We do not use Dearthwood Maps API requests to build personal profiles, track individuals for advertising, or sell location data.

Location queries and technical request data are processed only for the operation, security, rate-limiting, and maintenance of the API.

Where logs are retained, they are retained only for as long as reasonably necessary for those purposes unless a longer retention period is required for security, abuse-prevention, legal, or administrative reasons.

Roomslate property management software

Roomslate is a hotel and accommodation property management system provided as a software service to hospitality businesses.

If you are a guest of a hotel, bed and breakfast, holiday let, or accommodation provider that uses Roomslate, your personal data is normally controlled by that accommodation provider, not by Dearthwood Software.

The accommodation provider is responsible for its own privacy notice, lawful basis for processing, guest communications, retention periods, and legal obligations.

In operating the Roomslate platform, Dearthwood Software normally acts as a data processor on behalf of each accommodation provider.

We process guest data only in accordance with the instructions of the accommodation provider and only to the extent necessary to operate, maintain, secure, and support the service.

If you have questions about how your personal data is used within Roomslate, or wish to exercise rights in relation to guest data held by an accommodation provider, you should usually contact the accommodation provider directly.

Accommodation providers using Roomslate are required to enter into a Data Processing Agreement with Dearthwood Software before using the service where required by data protection law.

This website

The following data handling applies to standard website functionality on https://dearthwood.uk.

Comments

If you leave a comment on our site, we collect the information shown in the comment form, along with your IP address and browser user agent string to assist with spam detection.

An anonymised string derived from your email address may be sent to the Gravatar service to check whether you use it. The Gravatar privacy policy is available at https://automattic.com/privacy/.

If your comment is approved, your name and comment content may be visible publicly.

Cookies

This website may use cookies and similar technologies where they are necessary for the website to function, to remember choices you have made, to support security, or to provide features you have requested.

If you leave a comment, you may opt to save your name, email address, and website URL in cookies for convenience. These cookies last for one year.

When you visit the login page, a temporary cookie is set to check whether your browser supports cookies. It contains no personal data and is removed when you close your browser.

When authorised users log in, we set cookies to save login sessions and screen display preferences. Login cookies last for two days and screen options cookies last for one year.

If “Remember Me” is selected, the login may persist for two weeks. Logging out removes login cookies.

If an authorised user edits or publishes a page or post, an additional cookie may be saved containing no personal data. It expires after one day.

We do not use third-party advertising cookies, remarketing pixels, or behavioural advertising trackers on this website.

Embedded content from other websites

Pages on this site may include embedded content such as videos, images, maps, articles, or other media from other websites.

Embedded content behaves as if you had visited the other website directly.

Those websites may collect data about you, use cookies, embed additional third-party tracking, or monitor your interaction with that embedded content, including where you have an account and are logged in to that service.

Contact and enquiries

When you contact us via our contact page, by telephone, by email, or through another direct communication route, we process the personal information you provide so that we can respond to your enquiry.

This may also be used to provide requested information, discuss potential work, supply services, manage our relationship with you, and keep appropriate business records.

This may include your name, business name, email address, telephone number, website address, message content, project details, and any other information you choose to provide.

We do not add you to any mailing list, newsletter, or automated marketing campaign simply because you contact us.

We do not use third-party CRM or marketing automation platforms to store enquiry data.

We may retain enquiry and correspondence records where necessary for business administration, contract management, legal, accounting, dispute-resolution, security, or legitimate business reasons.

Cloudflare Turnstile

We may use Cloudflare Turnstile on forms or other interactive parts of this website to help protect the website, our services, and our inbox from spam, automated abuse, malicious requests, fake submissions, and excessive bot traffic.

Turnstile is a security tool provided by Cloudflare. It helps check whether a request appears to come from a real person rather than an automated bot.

When Turnstile is used, Cloudflare may process technical information relating to your browser, device, network connection, and interaction with the protected form or page. This may include information such as IP address, browser and device signals, timestamps, security challenge results, and technical data needed to validate the request.

We use Turnstile only for website security, spam prevention, abuse prevention, and service protection. We do not use Turnstile for advertising, behavioural profiling, remarketing, or tracking visitors across unrelated websites.

Our lawful basis for using Turnstile, where personal data is involved, is our legitimate interest in protecting our website, forms, systems, services, inbox, and users from spam, abuse, malicious activity, and automated attacks.

Cloudflare may process Turnstile-related data as an external service provider. Cloudflare’s own privacy information is available at https://www.cloudflare.com/privacypolicy/ and its Turnstile privacy information is available at https://www.cloudflare.com/turnstile-privacy-policy/.

Clients and service delivery

If you become a client, we may process personal data needed to provide our services, manage the project, communicate with you, issue invoices, maintain records, provide support, and meet legal or tax obligations.

This may include contact details, business details, project notes, website or software access information, support requests, billing records, contract documents, correspondence, and technical information required to deliver the service.

Where a project involves access to your systems, website, hosting, databases, email configuration, or customer data, the specific handling of that data may be covered by a separate contract, support agreement, or Data Processing Agreement.

Lawful bases for processing

Depending on the context, we may rely on one or more lawful bases under UK GDPR.

These may include:

  • Contract: where processing is necessary to provide a service, take steps before entering into a contract, manage a project, or fulfil our agreement with you.
  • Legitimate interests: where processing is necessary for normal business operations, responding to enquiries, securing our systems, preventing abuse, managing client relationships, improving services, and keeping appropriate business records, provided those interests are not overridden by your rights and freedoms.
  • Legal obligation: where processing is necessary to comply with tax, accounting, regulatory, legal, or statutory obligations.
  • Consent: where we specifically ask for consent for a particular activity. Where processing is based on consent, you may withdraw that consent at any time.

Who we share your data with

We do not sell or rent personal data.

We do not share personal data with third parties for their own marketing purposes.

We may share personal data where necessary with service providers, professional advisers, hosting providers, security providers, spam-prevention providers, payment or banking providers, legal or regulatory bodies, or other parties where required for the operation of our business, provision of services, legal compliance, security, abuse prevention, or dispute resolution.

If you request a password reset on this website, your IP address may be included in the reset email for security purposes.

Visitor comments may be checked through an automated spam detection service.

Where Cloudflare Turnstile is used, technical information connected with the security check may be processed by Cloudflare for the purpose of validating the request and protecting the website from abuse.

How long we retain your data

We keep personal data only for as long as reasonably necessary for the purposes for which it was collected.

This may include service delivery, business administration, legal compliance, accounting, tax, security, dispute-resolution, and record-keeping purposes.

If you leave a comment, the comment and its associated metadata may be retained indefinitely to allow us to recognise and approve follow-up comments automatically, rather than holding them for moderation each time.

For registered users of this website, we store the personal information provided in their user profile.

Users may view, edit, or request deletion of their personal information at any time, with the exception of their username. Site administrators can also access and edit this information.

Audit-tool submissions, including submitted URLs, timestamps, generated audit results, and associated rate-limiting or security data, are retained for up to 30 days unless we need to retain specific information for security, abuse-prevention, legal, or administrative reasons.

Dearthwood Maps API logs and technical request data are retained only for as long as reasonably necessary for service operation, fault diagnosis, security, rate-limiting, and abuse prevention, unless a longer retention period is required for legal, security, or administrative reasons.

Turnstile-related data is processed for security validation and abuse prevention. We do not use it to create advertising profiles or track visitors for marketing purposes.

Client, accounting, contract, and business administration records may be retained for longer where this is necessary for legal, tax, accounting, contractual, insurance, or dispute-resolution purposes.

Your rights over your data

Under UK data protection law, you may have rights in relation to your personal data.

These may include:

  • The right to request access to your personal data
  • The right to request correction of inaccurate personal data
  • The right to request erasure of personal data
  • The right to request restriction of processing
  • The right to object to processing
  • The right to data portability, where applicable
  • The right not to be subject to certain solely automated decisions

The availability of these rights depends on the type of data, the reason we process it, and whether we have a legal or legitimate reason to continue retaining or using it.

To exercise any of these rights, please contact us via our contact page.

If you make a subject access request, we will carry out reasonable and proportionate searches for personal data we hold about you.

We may ask for information needed to confirm your identity, clarify your request, refine your request, or confirm that a third party is authorised to act on your behalf.

Where the law allows the response period to be paused while we wait for information reasonably needed from you, the response period may restart or continue once that information has been received.

We will respond to valid data protection rights requests within the timescales required by law.

Where your data is stored and processed

Our own website, audit tool, Dearthwood Maps API, and core services are hosted on infrastructure located in the United Kingdom unless otherwise stated in a specific service agreement or Data Processing Agreement.

Where third-party services are used, personal data may be processed in the United Kingdom, the European Economic Area, or other locations where appropriate safeguards, adequacy arrangements, contractual protections, or legal mechanisms apply.

We aim to keep personal data within the United Kingdom or GDPR-compliant regions where reasonably possible, but some external services, embedded content, email systems, security tools, spam-prevention tools, or professional service providers may process data outside the United Kingdom depending on how those services operate.

Where we use Cloudflare Turnstile or other Cloudflare security services, technical data connected with security checks may be processed by Cloudflare outside the United Kingdom. Where this happens, it is handled under Cloudflare’s applicable data protection terms and transfer safeguards.

Security

We take reasonable technical and organisational measures to protect personal data from unauthorised access, loss, misuse, alteration, or disclosure.

These measures may include access controls, secure hosting, system monitoring, backups, software updates, rate-limiting, spam-prevention tools, bot protection, and other security controls appropriate to the service being provided.

No website, software service, or internet transmission can be guaranteed to be completely secure.

If we become aware of a personal data breach that creates a risk to individuals, we will take appropriate steps in accordance with applicable data protection law.

Automated decision-making and profiling

We do not use personal data collected through this website for automated decision-making that produces legal or similarly significant effects.

We do not use website visitors’ personal data to create advertising profiles.

Cloudflare Turnstile may automatically assess whether a request appears legitimate for security and abuse-prevention purposes. This is used to protect forms and services from bots and malicious activity, not to make legal, contractual, credit, employment, or similarly significant decisions about individuals.

Marketing

We do not add website visitors or people who contact us to automated mailing lists or newsletters without their consent.

We do not use third-party advertising networks, behavioural advertising pixels, or remarketing trackers on this website.

If we contact existing or previous clients about relevant services, updates, or legitimate business matters, we will do so in accordance with applicable data protection and electronic communications rules.

You can ask us not to contact you for marketing purposes at any time by contacting us through our contact page.

Changes to this policy

We may update this privacy policy from time to time. Any changes will be reflected on this page with an updated date at the top.

We recommend checking this page periodically if you use our services regularly.