Privacy policy
Version 0.2, 26 July 2026. This policy describes how WIKI-TECH LIMITED (company no. 14141095, registered office 21 Curzon Road, Maidstone, Kent ME14 5BB) processes personal data in connection with Parity Backup. Because the Service holds copies of business email, files and sites, everything below is a statement about what the software actually does, and was checked against the running system on the date above.
1. Who is responsible for what
Two different relationships run through this Service, and the difference decides who you go to about what.
| Data | Controller | Our role |
|---|---|---|
| Backup content and its index (mailboxes, files, sites) | You, the customer whose tenant it came from | Processor, acting on your instructions |
| Your account, contacts, security settings and billing | WIKI-TECH LIMITED | Controller |
| Enquiries and trial registrations from this website | WIKI-TECH LIMITED | Controller |
Where a managed service provider runs your backups, the chain is one link longer: you remain the controller of your own data, your provider acts as your processor, and we act as their sub-processor. Your contract for the Service is with your provider, and they can act on your data in the console. Our data processing agreement is written to sit in either position.
2. What we process, and why
- Backup content. Exchange Online mailboxes (including In-Place Archives), OneDrive files, SharePoint document libraries, lists and pages, and Microsoft 365 Groups team sites, copied from your tenant so they can be restored or exported. This can contain any personal data your organisation puts in those services, including special category data if your people put it there. We do not inspect it and we do not use it for anything but running the Service for you.
- Backup index. To find and restore an item without opening every blob, we keep a searchable index of its metadata: sender, recipients, subject, folder path, date, size, filename, and for Teams the team, channel or chat name and the message author. This is content-adjacent personal data and we treat it as such.
- Account and security data. Company name, work email addresses, your notification and billing contacts, a hashed password (never the password itself), and multi-factor authentication material: a TOTP secret, registered security key identifiers and public keys, and one-time backup codes stored hashed. Multi-factor authentication is mandatory on every console.
- Billing data. Company, billing contact, billing address and the tax and invoice records we must keep. Card details are entered directly with Stripe and never reach our servers; we hold only the brand and last four digits, for display.
- Operational records. An audit trail of security-relevant actions (sign-ins that led to an admin action, restores, downloads, exports, support access, billing events), job and restore history, and server logs. Requests carry an IP address, which is used to rate limit abuse and is not used to profile anyone.
- Website enquiries. If you submit the trial form, the email address, optional company and seat count are forwarded to our internal notification channel and recorded in our server logs so we can contact you. This form does not create an account and the details are not loaded into a marketing system.
Our lawful bases: performance of a contract for account, security and billing data; legitimate interests for operational records, security and abuse prevention, and for responding to an enquiry you sent us; and legal obligation for tax and accounting records. Backup content is processed on your documented instructions as controller, not on a basis of our own.
3. What we never do with it
- We do not sell personal data, and we do not share it for advertising.
- We do not use backup content to train machine learning models, ours or anybody else’s.
- We do not email the mailboxes we protect. Alerts go to the notification contacts on the account, and the system refuses to deliver an alert to an address inside a tenant it backs up.
- No analytics, advertising or tracking cookies are set on this site. See §9.
4. Who can see your backups
Access is restricted to the account that owns the data, any managed service provider you have linked to it, and the small number of our staff who operate the Service. Staff access to a customer console happens through an audited impersonation mechanism that requires a rotating access code held by the account owner, and every use is written to the audit trail. It is a policy control backed by logging, not a cryptographic guarantee: we run the servers, so we are technically capable of reaching stored data, and any provider who tells you otherwise while fetching your mail server-side is being imprecise with you.
5. Where data is stored
| What | Where |
|---|---|
| Backup content (the blobs themselves) | Helsinki, Finland (EU), Hetzner object storage |
| The application, database and backup index | Helsinki, Finland (EU), Hetzner cloud |
| Off-site copy of the nightly database backup, which includes the index | Falkenstein, Germany (EU), Hetzner Storage Box |
| Payment and invoice records | Stripe, European Union, with onward transfer to the US |
| Transactional email in transit | SMTP2GO EU endpoint, European Union |
Backup content itself stays in Finland. The database backup is deliberately kept in a different city and a different failure domain from the data it describes, which is why that one copy is in Germany; both are in the European Union. We are a UK company, so operating the Service involves UK access to EU-stored data, which the UK’s adequacy regulations for the EEA and the EU’s adequacy decision for the UK both cover. Transfers to Stripe entities outside the EU rely on Stripe’s own standard contractual clauses.
If you need it stored somewhere else. The table above is our standard arrangement, and it is what the published price assumes. Where your own policy or a regulator requires a different provider or region, for example Azure or Wasabi, we can agree that in writing and your order will name the provider and location. In that case the provider you choose becomes a sub-processor for your data alone, on the terms in §6 of the data processing agreement, and the standard sub-processor list below continues to describe everybody else.
The full list of third parties, what each one does and what it can reach, is on the sub-processors page.
6. Security, as it actually is
What is in force today, stated plainly rather than aspirationally:
- In transit: TLS on every connection, to your tenant, to storage and to this site.
- At rest: backup content is encrypted with AES-256 server-side encryption using a key supplied by us on every request and never retained by the storage provider, so the stored objects are unreadable to anyone holding only the storage. It sits in a private, credential-scoped bucket in an ISO 27001 certified Hetzner facility in Finland, with no public access and no standing vendor access. Our own database backups are encrypted before they leave the server.
- Authentication: multi-factor authentication is mandatory for every account type, including our own administrative console. Passwords are stored hashed. Sessions expire and can be revoked.
- Separation: every query is scoped to one account, and one customer’s snapshot cannot be addressed from another customer’s session.
- Deletion: when an account is deleted, stored objects are removed including any prior versions, so erasure does not leave a recoverable copy behind. See §8.
- Certification: WIKI-TECH LIMITED holds Cyber Essentials. We do not hold SOC 2 or ISO 27001, and nothing here should be read as claiming either. Our infrastructure provider holds ISO 27001 for the facilities it operates, which is their certification and not ours.
7. Personal data breaches
If a breach affects personal data we process for you, we will notify you without undue delay after becoming aware of it, and in any event within 72 hours, with what we know: what happened, what data and whose it involved, what we are doing, and what you may need to do. Where we are the controller, we report to the Information Commissioner’s Office as required. Where you are the controller, the decision to report is yours, and we give you what you need to make it.
8. How long we keep things
- Backup snapshots: for the retention of the plan on the account. Essential keeps six months, Professional twelve months, and Compliance seven years, on a daily, weekly and monthly ladder. Snapshots past their retention are deleted by an automated sweep.
- When you close your account: account records, sessions and billing links are deleted at once, and stored backup content is deleted including prior versions. Where storage immutability is in force on an object, deletion is queued and retried until the storage confirms it is gone, and we tell you the window that applies.
- When a trial ends or payment stops: backups and restores pause, and your data is kept for 30 days so you can pick up where you left off. Nothing is deleted during that window.
- Database backups: the nightly dump is kept for about a week locally and about a month off-site, then rotated out. Erasure works through that cycle rather than being instant in the backups, which is inherent to holding backups at all.
- Operational records: audit records are kept for the life of the account and are deleted with it. Job and restore history is capped and rotated. Expired sessions and consent grants are deleted automatically.
- Billing records: kept for six years after the end of the relationship, as UK tax law requires.
- Website enquiries: deleted on request, and in any event when the enquiry has plainly gone nowhere.
9. Cookies
This site sets no analytics, advertising or tracking cookies, and embeds no third-party scripts that would set them. The only cookies are strictly necessary ones inside the portal:
| Cookie | Purpose | Lifetime |
|---|---|---|
| pb_session | Keeps you signed in | Until the session expires or you sign out |
| pb_impersonator | Marks a support or provider session that is acting as another account, so it can be labelled and audited | For the duration of that session |
| pb_wa_chal | Holds the one-time challenge while a security key or passkey is being registered or used | A few minutes |
Because all three are strictly necessary to deliver a service you asked for, no consent banner is required, and refusing them means not being able to sign in.
10. Your rights
Where we are the controller (account, security, billing and enquiry data), you have the rights UK GDPR gives you: access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests. Write to the address below and we will respond within one month.
For backup content, we are the processor and you are the controller. If one of your people asks you to delete or produce their data, you exercise that in your own tenant, and we assist: deleting from your tenant does not reach into an existing snapshot, so tell us and we will act on your instruction. The mechanics are in the data processing agreement.
You may complain to the Information Commissioner’s Office (ico.org.uk, 0303 123 1113). We would much rather you raised it with us first.
11. Changes
If we change this policy in a way that materially affects how we handle your data, we will tell the billing and notification contacts on the account before it takes effect. The version and date at the top always reflect the copy you are reading.
12. Contact
Privacy enquiries and data subject requests: [email protected] · WIKI-TECH LIMITED, 21 Curzon Road, Maidstone, Kent ME14 5BB · 020 3822 0899. We are not required to appoint a Data Protection Officer and have not appointed one; enquiries go to the address above.