← All legal documents
Privacy Notice · Version 1.0 · Informational
Published 2026-09-03 · Effective 2026-09-22 · Approved by Hyun Kyu Han, Director on 2026-09-01
Permanent version link: /legal/privacy/1.0

Trine Privacy Notice

Document key: trine-privacy Version: 1.0 Status: Published Approved by: Hyun Kyu Han, Director Approved on: 1 September 2026 Published: recorded in the legal registry at publication Effective: 19 days after publication Acceptance: informational, link only (no checkbox) Published at: https://trine.uk/legal/privacy


1. Who we are

Trine is operated by Purinode Ltd, a company registered in England and Wales under company number 17395630, with registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ.

We are registered with the Information Commissioner's Office under reference ZC235279.

Our privacy lead is Hyun Kyu Han, Director. Contact [email protected] about anything in this notice.

2. This notice covers our own processing, not your employer's records

Trine holds two different kinds of information, and our role differs between them.

Records your organisation keeps in Trine — staff files, recruitment and pre-employment checks, training records, compliance documents, incidents, safeguarding matters, resident information. For all of this, the care provider is the controller and we are only the processor. We hold it on their instructions and we do not decide what goes in it. If you are a member of staff, a job applicant, a resident or a relative, and you want to know what is held about you or ask for it to be corrected or deleted, contact the care provider, not us. If you contact us we will pass the request to them and tell you we have done so, but we will not confirm or deny what any provider holds.

Our processing of that data is governed by our Data Processing Agreement with the provider.

Information we hold in our own right — account and login details, billing records, support correspondence, and security logs. For this we are the controller, and the rest of this notice explains what we do with it.

3. What we collect and why

WhatWhyLawful basis
Name, work email, job title, care home and organisationTo create and run your user account and set your access levelPerformance of a contract
Password (stored hashed), login timestamps, two-factor settingsTo authenticate you and secure the accountPerformance of a contract
IP address, browser and device information, request logsTo keep the platform secure, detect misuse and diagnose faultsLegitimate interests — securing a platform that holds sensitive information
Records of what you did in the platform (audit log)To provide an accountability trail your organisation and its regulator can rely onPerformance of a contract, and legitimate interests in an accurate audit record
Billing contact details, subscription and payment records, VAT informationTo take payment and meet accounting and tax obligationsPerformance of a contract; legal obligation
Support emails and correspondenceTo answer your questions and improve the serviceLegitimate interests — supporting our customers
Acceptance records: who accepted which document version, when, and from what IP addressTo evidence agreement to our contractual termsLegal obligation and legitimate interests in evidencing a contract

Where we rely on legitimate interests, we have considered the impact on you and are satisfied our interest does not override your rights. You can ask us for that assessment.

We do not use your information for automated decision-making or profiling, and we do not sell it.

4. Where your information goes

We use a small number of service providers. They act on our instructions and are bound by contract.

WhoWhat forWhere
Microsoft AzureHosting the application, database and file storageUnited Kingdom (UK South)
AC PM LLC (Postmark)Sending transactional email such as invitations and password resetsUnited States
Stripe Payments Europe LtdPayment processing, where paid billing is enabledGlobal, including the United States
Google Ireland LtdOur own business email, which is where support correspondence landsEuropean Economic Area

Transactional email content is stored by Postmark for 45 days. We never send passwords by email, and access links are time-limited.

Stripe acts as an independent controller for payment card data. We do not receive or store full card details, and Stripe's own privacy notice governs that processing.

Transfers to the United States rely on the EU-U.S. Data Privacy Framework and its UK Extension, or on the UK International Data Transfer Addendum where that framework does not apply. We keep a transfer risk assessment and will share a summary on request.

The current list of our sub-processors is maintained in Annex 3 of our Data Processing Agreement.

We will also disclose information where we are legally required to, or to establish or defend legal claims.

5. How long we keep it

WhatHow long
Account and authentication data12 months after the account is closed or the user is deactivated
Billing and accounting records7 years
Support correspondence3 years
Security and access logs12 months
Audit logIndefinitely. The audit log is append-only, and for deleted records it is often the only evidence that the record existed
Transactional email content held by Postmark45 days

Our full approach is in the Data Retention Policy.

6. How we protect it

Data is hosted in the United Kingdom on Microsoft Azure and encrypted at rest. Connections are encrypted in transit using TLS 1.2 or above, and unencrypted database connections are rejected. Access is role-based and enforced server-side, two-factor authentication is available on user accounts, and material actions are recorded in an append-only audit log.

Purinode Ltd holds Cyber Essentials certification, scoped to the whole organisation, certificate number 6fcde322-bedf-487a-839b-e6977a72f9ed, valid until 1 September 2027.

Fuller detail is in Annex 2 of our Data Processing Agreement.

7. Cookies

We use cookies that are strictly necessary to run the platform: keeping you signed in, maintaining your session, and protecting against cross-site request forgery. These do not require your consent.

If we introduce analytics or any other non-essential cookie, we will ask for your consent first and you will be able to change your choice at any time.

8. Your rights

You can ask us to give you a copy of the information we hold about you, correct it if it is wrong, delete it, restrict how we use it, or provide it in a portable format. You can object to processing we carry out on the basis of legitimate interests, and withdraw consent where we have relied on it.

To exercise any of these, email [email protected]. We will respond within one month. We may ask you to confirm your identity first.

Some of these rights are not absolute. Where we cannot do what you have asked — for example where we must keep billing records for tax purposes, or where an audit entry is the only evidence that a deletion took place — we will tell you why.

If you are unhappy with how we have handled your information, please tell us so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or by calling 0303 123 1113. You do not have to raise it with us first.

9. Changes

We may publish new versions of this notice. Each version is published at its own address and earlier versions remain readable. Where a change materially affects you, we will tell you.

The current version is always at https://trine.uk/legal/privacy.