eny Approvals

Privacy and how this trial handles data

Built to UK GDPR and Data Protection Act 2018 requirements. The controller is eny (enyinc.uk). Contact: info@enyinc.uk.

What we collect

At signup: your business name and work email, and nothing else. Inside the trial: the approval requests, decisions and audit records you create. The lawful basis is contract (providing the trial you asked for) and legitimate interest (supporting it).

How long we keep it

30 days from signup. Then the workspace locks and every row of it is deleted, including its audit log. There are no backups of trial data. You can delete it sooner from Account (Art. 17), and download all of it as JSON there first (Art. 15 and 20).

Financial data

Use demo or test data only. This trial does not accept card numbers, bank account details or credentials, and refuses text that looks like them. It is designed around FCA SYSC record-keeping principles: every request, decision and rule change is recorded with who, what and when, the record cannot be edited, and nobody can approve a request they raised. That is a description of how it works, not a certification.

Tracking

None. This site loads no analytics, advertising or third-party scripts, except Cloudflare Turnstile on the signup page to stop bots. The only cookie is the session cookie that keeps you signed in (HttpOnly, Secure, SameSite=Lax).

Who at eny sees what

eny staff see each trial’s business name, signup email and usage counts (how many actions, which kinds) to support the trial. We are told by email when a trial starts.

Security

HTTPS only, signed sessions, role-based access, hashed PINs, parameterised database queries, strict security headers and rate-limited sign-in.

Complaints

Tell us first at info@enyinc.uk. You also have the right to complain to the Information Commissioner’s Office: ico.org.uk/make-a-complaint.