Privacy Policy
Last updated: 19 July 2026
1. Who we are
Inkli is a service operated by Penned Ltd, a company registered in England & Wales.
- Company number: 12989856
- Registered office: The Firs, Cudham Lane South, Sevenoaks, TN14 7QE
- General contact: hello@inkli.app
- Data-protection contact: hello@inkli.app
- ICO registration: C1987399
When we say "Inkli", "we", "us", or "our" in this policy, we mean Penned Ltd.
2. Two data-protection roles — please read carefully
Inkli acts in two different data-protection roles depending on whose data is being processed.
As Controller — we act as the controller for personal data about you as our customer (account details, billing information, communications with us). This Privacy Policy covers that processing.
As Processor — we act as the processor for personal data about the recipients of your letters (names, addresses, custom fields) that you upload to our platform. In that role, you are the controller and we process the data on your instructions under our Data Processing Agreement.
3. What personal data we collect (about you as our customer)
When you create an account:
- Full name
- Email address
- Password (hashed — never stored in readable form)
- Company name
- Country
- Optionally: role, sending volume, API interest (used to route relevant onboarding communications)
When you use the platform:
- Content of your campaigns (messages, design settings, handwriting choices)
- Account activity (campaigns created, submitted, completed; downloads; API calls)
- Communications you send us (support tickets, feedback)
- Billing information (we currently invoice partners directly; when we introduce a payment processor we will update this policy and the sub-processor list)
Automatically collected:
- IP address (security, fraud prevention, consent audit)
- Browser type and device information
- Cookies and similar (see §11)
We do not collect special-category data (health, race, sexual orientation, biometrics, etc.). Please do not include these in recipient uploads.
4. Why we process your data (legal bases under UK/EU GDPR)
| What we do | Legal basis |
|---|---|
| Create + operate your account; process letter renders you request | Contract (Art. 6(1)(b)) |
| Bill you | Contract + legitimate interests |
| Send service updates (product changes, security notices) | Legitimate interests |
| Send marketing about new features | Consent (opt-in) |
| Detect fraud, abuse, security incidents | Legitimate interests |
| Comply with legal obligations (tax, audits, court orders) | Legal obligation |
| Record your agreement to our terms (DPA, Privacy, Beta) | Legitimate interests + legal obligation |
5. Who we share your data with
5.1 Our sub-processors:
| Sub-processor | Service | Region |
|---|---|---|
| Supabase, Inc. | Auth + database | US (EU-US DPF, SCCs) |
| Hetzner Online GmbH | Object storage, compute | Germany, Finland (EU adequacy) |
| Cloudflare, Inc. | CDN, DDoS protection | Global edge (UK IDTA / SCCs) |
| Twilio SendGrid | Transactional email | US (EU-US DPF, SCCs) |
| Google LLC (Google Analytics) | Product analytics | US (EU-US DPF, SCCs) |
5.2 Professional advisors: lawyers, accountants, auditors under confidentiality.
5.3 Law enforcement: where legally compelled (subpoena, court order, statutory duty).
5.4 Business transfer: if Penned Ltd is acquired, merged, or restructured, your data may transfer to the successor entity, who must honour this Privacy Policy or notify you of changes.
We do not sell your personal data, share it for third-party advertising, or provide bulk access for AI model training.
6. International transfers
Some sub-processors are in the United States or process globally. Where personal data leaves the UK/EEA to a country without an adequacy decision, we rely on the UK International Data Transfer Agreement (IDTA), UK Addendum to EU Standard Contractual Clauses, or the EU-US Data Privacy Framework where the recipient is certified.
For copies of the transfer safeguards in place with a specific sub-processor, email hello@inkli.app.
7. How long we keep your data
| Data | Retention |
|---|---|
| Account information | Life of your account + 6 years (UK tax / legal record-keeping) |
| Campaign content + rendered output | Per your configured retention window (default 30 days). See Settings → Retention. |
| Recipient personal data | Same as campaign — purged at retention window per your instructions (as controller) |
| Billing records | 6 years (UK statutory) |
| Consent records (agreement acceptances) | Indefinitely — evidence of lawful processing |
| Support ticket contents | 3 years |
| IP address logs (security) | Full IP 90 days; truncated to /24 indefinitely |
8. Your rights under UK / EU GDPR
You have the right to:
- Access — get a copy of the personal data we hold about you
- Rectify — correct inaccurate or incomplete data
- Erase — ask us to delete your data, subject to legal exceptions
- Restrict processing — ask us to pause processing in certain circumstances
- Data portability — get a machine-readable copy of data you gave us
- Object — object to processing based on legitimate interests
- Withdraw consent — where processing is based on consent, at any time
- Not be subject to solely automated decisions — we don't make automated decisions that significantly affect you
To exercise any right, email hello@inkli.app. We'll respond within one month.
You can also complain to a supervisory authority:
- UK: Information Commissioner's Office (tel 0303 123 1113)
- Ireland: Data Protection Commission
- Other EU: your national DPA
9. Recipient data (people you send letters to)
Where you upload recipient data (names, addresses, custom fields), we act as your processor — you are the controller. Please make sure you:
- Have a lawful basis for holding and processing recipient personal data
- Have provided recipients with your own privacy notice covering how you use their data
- Do not include special-category data in uploads
- Deal with recipient rights requests directly (we'll help you locate the data — see the DPA)
Recipient data is governed by our Data Processing Agreement.
10. Security
We implement industry-standard technical and organisational measures including encryption in transit (TLS 1.2+) and at rest, access controls (role-based, least privilege), multi-factor authentication for privileged staff, continuous logging and monitoring, regular vulnerability scanning, vendor security reviews, and a documented incident response process.
No system is 100% secure. If we become aware of a breach affecting your data, we'll notify you without undue delay and, where required, notify the ICO within 72 hours.
11. Cookies
We use strictly necessary cookies for authentication and session management. Any analytics cookies are set only with your consent via the cookie banner. You can change your preferences by clearing site data in your browser.
12. Children
Inkli is not directed at children under 16. We do not knowingly process children's personal data. If you believe we have, contact us and we'll delete it.
13. Changes to this policy
We'll update the "Last updated" date at the top when we make material changes. Substantive changes trigger a re-consent prompt when you next log in.
14. Contact
Data-protection queries: hello@inkli.app
General queries: hello@inkli.app
Postal: The Firs, Cudham Lane South, Sevenoaks, TN14 7QE