Last updated: 12 July 2026
This App Privacy Policy explains how Democratic Technologies Limited of 1a Kingsburys Lane, Ringwood, Hampshire, England, BH24 1EL (we, us, or our) collects and uses personal data in connection with access to, and use of, Enqora.
This policy applies to authorised users, administrators, account owners, billing contacts, support contacts, and other people who use or manage access to Enqora.
It is separate from our landing-page privacy policy, which covers visitors to our public website and people who contact us through public forms.
Enqora is a casework and relationship management platform used by organisations to manage correspondence, cases, contacts, documents, internal notes, workflows, and related activity.
Customers may use Enqora to process personal data about constituents, correspondents, casework subjects, staff, public officials, and other people. Where we process that customer-controlled data on behalf of a customer, we normally act as a processor. That processing is governed by our Data Processing Agreement, rather than this App Privacy Policy.
This App Privacy Policy mainly explains how we process personal data where we act as controller, including account, access, security, support, billing, and service administration data.
For the personal data covered by this App Privacy Policy, the controller is:
Democratic Technologies Limited 1a Kingsburys Lane, Ringwood, Hampshire, England, BH24 1EL contact@enqora.uk
Where a customer organisation uses Enqora to manage its own casework, correspondence, contacts, emails, documents, and records, that customer is normally the controller of that customer data.
We may collect and process the following types of personal data.
This may include:
(a) your name;
(b) your email address;
(c) your organisation;
(d) your role or job title;
(e) your account status;
(f) your user permissions;
(g) authentication details, excluding passwords in plain text;
(h) multi-factor authentication settings, where used;
(i) account preferences; and
(j) records of invitations, account creation, account changes, and account deletion.
This may include:
(a) IP address;
(b) browser type and version;
(c) device information;
(d) operating system;
(e) session information;
(f) login attempts;
(g) authentication events;
(h) security events;
(i) error logs;
(j) audit logs;
(k) timestamps;
(l) approximate location derived from technical data; and
(m) information needed to detect, investigate, or prevent misuse, abuse, unauthorised access, or security incidents.
This may include information about how authorised users interact with Enqora, such as:
(a) pages or areas accessed;
(b) features used;
(c) searches, exports, imports, or actions performed;
(d) timestamps and activity records;
(e) system performance information;
(f) configuration activity; and
(g) audit records showing actions taken within an organisation’s account.
We use this information to provide, secure, monitor, debug, support, and improve the service.
If you contact us for support, training, onboarding, billing, security, or service administration, we may process:
(a) your name;
(b) your email address;
(c) your organisation;
(d) your message content;
(e) support ticket information;
(f) screenshots, files, or logs you provide;
(g) records of our communications with you; and
(h) information needed to investigate or resolve your request.
You should avoid sending unnecessary personal data or sensitive casework data in support messages unless it is needed to investigate the issue.
Where relevant, we may process:
(a) customer organisation name;
(b) billing contact details;
(c) account owner details;
(d) order details;
(e) invoices;
(f) payment status;
(g) subscription records;
(h) contract records;
(i) tax and accounting records; and
(j) related communications.
Where a customer connects a third-party service, such as an email account, identity provider, or other integration, we may process technical and administrative information needed to connect, secure, and operate that integration.
This may include:
(a) account identifiers;
(b) email addresses;
(c) integration status;
(d) permission scopes;
(e) authentication tokens or credentials, stored securely;
(f) connection logs;
(g) sync status;
(h) error messages; and
(i) information needed to operate or troubleshoot the integration.
Where the integration processes customer-controlled casework, correspondence, contact, email, or document data, that processing is normally governed by our Data Processing Agreement.
Customers may use Enqora to process personal data, special category data, criminal offence data, political opinions, health information, safeguarding information, immigration information, financial hardship information, children’s data, and other sensitive casework data.
For this customer-controlled data:
(a) the customer is normally the controller;
(b) we normally act as processor;
(c) we process the data on the customer’s documented instructions;
(d) the processing is governed by our Data Processing Agreement; and
(e) the customer is responsible for providing privacy information to the relevant individuals, unless otherwise agreed.
This App Privacy Policy does not replace the customer’s own privacy notices or data protection obligations.
We use personal data covered by this App Privacy Policy to:
(a) create, manage, and administer user accounts;
(b) authenticate users and manage sessions;
(c) provide access to Enqora;
(d) manage organisations, authorised users, roles, and permissions;
(e) provide support, training, onboarding, and service communications;
(f) operate, maintain, secure, monitor, and debug the service;
(g) detect, investigate, prevent, and respond to security incidents, misuse, abuse, or unauthorised access;
(h) maintain audit logs and security records;
(i) manage subscriptions, billing, invoices, payments, and contracts;
(j) comply with legal, tax, accounting, regulatory, and contractual obligations;
(k) improve the reliability, usability, security, and performance of the service;
(l) enforce our Terms of Service and other agreements; and
(m) protect our rights, users, customers, systems, and business.
We rely on the following lawful bases under UK data protection law.
| Purpose | Lawful basis |
|---|---|
| Providing access to Enqora and managing accounts | Contract, or legitimate interests |
| Authenticating users and maintaining sessions | Contract, legitimate interests |
| Providing support and service communications | Contract, legitimate interests |
| Security monitoring, audit logs, abuse prevention, and incident response | Legitimate interests, legal obligation where applicable |
| Billing, accounting, tax, and contract administration | Contract, legal obligation, legitimate interests |
| Improving service reliability, usability, and performance | Legitimate interests |
| Handling legal claims, disputes, or regulatory matters | Legal obligation, legitimate interests |
| Complying with applicable law | Legal obligation |
Where we rely on legitimate interests, our interests include operating, securing, improving, and administering Enqora, supporting customers and users, preventing misuse, and protecting our business, systems, and legal rights.
We do not generally need to process special category data about authorised users for our own controller purposes.
However, special category data may appear in customer-controlled casework, correspondence, emails, documents, notes, or records processed through Enqora. Where this happens, we normally process that data as processor on behalf of the customer, and the processing is governed by our Data Processing Agreement.
You should not include special category data in support messages unless it is necessary for us to investigate or resolve your request.
Enqora may include AI-assisted features, such as classification, summarisation, drafting, extraction, search, and triage.
Where customer-controlled data is processed by AI-assisted features, we normally process that data as processor on behalf of the customer.
We do not use customer data to train general-purpose AI models.
Where AI processing is performed by a sub-processor, we require equivalent restrictions to apply.
Users remain responsible for reviewing AI-assisted outputs before relying on, sending, filing, publishing, or using them to make decisions about individuals.
Enqora uses cookies and similar technologies, such as local storage or session storage, where needed to provide, secure, and operate the app.
More information is available in our App Cookie Policy.
We may share personal data with:
(a) cloud hosting providers;
(b) database providers;
(c) storage providers;
(d) email and communications providers;
(e) identity and authentication providers;
(f) AI model providers, where AI-assisted features are enabled;
(g) monitoring, logging, diagnostics, and security providers;
(h) payment, billing, accounting, and professional advisers;
(i) legal, regulatory, tax, or public authorities where required; and
(j) other suppliers or sub-processors needed to provide, secure, support, or administer the service.
Where third parties process customer-controlled data on our behalf, they are listed in our Sub-processor List.
Our Sub-processor List is available at /sub-processor-list.
Where reasonably practicable, we use UK or EEA-based hosting regions for customer data.
Some suppliers or sub-processors may process or access limited personal data from outside the United Kingdom. Where this involves a restricted transfer, we use appropriate safeguards where required by law, such as an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism.
We use appropriate technical and organisational measures to protect personal data.
These may include:
(a) encryption in transit;
(b) encryption at rest;
(c) access controls;
(d) least-privilege administrative access;
(e) authentication controls;
(f) audit logging;
(g) monitoring and alerting;
(h) customer organisation separation;
(i) secure software development practices;
(j) backup and resilience measures;
(k) incident response procedures; and
(l) confidentiality obligations.
More information is available in our Security Overview.
We keep personal data only for as long as reasonably necessary for the purposes described in this policy.
Typical retention periods include:
| Type of data | Typical retention |
|---|---|
| Account data | For the life of the account, then for a limited period afterwards |
| Security and audit logs | For a reasonable security and compliance period |
| Support communications | For as long as needed to handle the request, maintain records, and improve support |
| Billing, tax, and accounting records | For the period required by law |
| Contract records | For the term of the agreement, then for a reasonable limitation period |
| Customer-controlled data | Handled in accordance with the Terms of Service and Data Processing Agreement |
We may retain limited records for longer where required for legal, tax, accounting, regulatory, security, dispute resolution, or enforcement purposes.
Depending on the circumstances, you may have the right to:
(a) access your personal data;
(b) request correction of inaccurate personal data;
(c) request deletion of your personal data;
(d) object to processing;
(e) request restriction of processing;
(f) request data portability;
(g) withdraw consent, where processing is based on consent; and
(h) complain to the Information Commissioner’s Office.
Some requests may need to be handled by the customer organisation rather than by us, especially where the request relates to customer-controlled casework, correspondence, contact, email, or document data.
You can contact us at:
contact@enqora.uk
If your request relates to data controlled by one of our customers, we may refer your request to that customer, or ask you to contact them directly.
We may need to verify your identity before responding to a request.
You can contact us first using:
contact@enqora.uk
You also have the right to complain to the UK Information Commissioner’s Office.
We may update this App Privacy Policy from time to time.
If we make material changes, we will take reasonable steps to notify affected users or customers, such as by email, in-app notice, or notice on our website.
Questions about this App Privacy Policy should be sent to:
Democratic Technologies Limited 1a Kingsburys Lane, Ringwood, Hampshire, England, BH24 1EL contact@enqora.uk