Document key: trine-privacy Version: 1.0 Status: Published Approved by: Hyun Kyu Han, Director Approved on: 1 September 2026 Published: recorded in the legal registry at publication Effective: 19 days after publication Acceptance: informational, link only (no checkbox) Published at: https://trine.uk/legal/privacy
Trine is operated by Purinode Ltd, a company registered in England and Wales under company number 17395630, with registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ.
We are registered with the Information Commissioner's Office under reference ZC235279.
Our privacy lead is Hyun Kyu Han, Director. Contact [email protected] about anything in this notice.
Trine holds two different kinds of information, and our role differs between them.
Records your organisation keeps in Trine — staff files, recruitment and pre-employment checks, training records, compliance documents, incidents, safeguarding matters, resident information. For all of this, the care provider is the controller and we are only the processor. We hold it on their instructions and we do not decide what goes in it. If you are a member of staff, a job applicant, a resident or a relative, and you want to know what is held about you or ask for it to be corrected or deleted, contact the care provider, not us. If you contact us we will pass the request to them and tell you we have done so, but we will not confirm or deny what any provider holds.
Our processing of that data is governed by our Data Processing Agreement with the provider.
Information we hold in our own right — account and login details, billing records, support correspondence, and security logs. For this we are the controller, and the rest of this notice explains what we do with it.
| What | Why | Lawful basis |
|---|---|---|
| Name, work email, job title, care home and organisation | To create and run your user account and set your access level | Performance of a contract |
| Password (stored hashed), login timestamps, two-factor settings | To authenticate you and secure the account | Performance of a contract |
| IP address, browser and device information, request logs | To keep the platform secure, detect misuse and diagnose faults | Legitimate interests — securing a platform that holds sensitive information |
| Records of what you did in the platform (audit log) | To provide an accountability trail your organisation and its regulator can rely on | Performance of a contract, and legitimate interests in an accurate audit record |
| Billing contact details, subscription and payment records, VAT information | To take payment and meet accounting and tax obligations | Performance of a contract; legal obligation |
| Support emails and correspondence | To answer your questions and improve the service | Legitimate interests — supporting our customers |
| Acceptance records: who accepted which document version, when, and from what IP address | To evidence agreement to our contractual terms | Legal obligation and legitimate interests in evidencing a contract |
Where we rely on legitimate interests, we have considered the impact on you and are satisfied our interest does not override your rights. You can ask us for that assessment.
We do not use your information for automated decision-making or profiling, and we do not sell it.
We use a small number of service providers. They act on our instructions and are bound by contract.
| Who | What for | Where |
|---|---|---|
| Microsoft Azure | Hosting the application, database and file storage | United Kingdom (UK South) |
| AC PM LLC (Postmark) | Sending transactional email such as invitations and password resets | United States |
| Stripe Payments Europe Ltd | Payment processing, where paid billing is enabled | Global, including the United States |
| Google Ireland Ltd | Our own business email, which is where support correspondence lands | European Economic Area |
Transactional email content is stored by Postmark for 45 days. We never send passwords by email, and access links are time-limited.
Stripe acts as an independent controller for payment card data. We do not receive or store full card details, and Stripe's own privacy notice governs that processing.
Transfers to the United States rely on the EU-U.S. Data Privacy Framework and its UK Extension, or on the UK International Data Transfer Addendum where that framework does not apply. We keep a transfer risk assessment and will share a summary on request.
The current list of our sub-processors is maintained in Annex 3 of our Data Processing Agreement.
We will also disclose information where we are legally required to, or to establish or defend legal claims.
| What | How long |
|---|---|
| Account and authentication data | 12 months after the account is closed or the user is deactivated |
| Billing and accounting records | 7 years |
| Support correspondence | 3 years |
| Security and access logs | 12 months |
| Audit log | Indefinitely. The audit log is append-only, and for deleted records it is often the only evidence that the record existed |
| Transactional email content held by Postmark | 45 days |
Our full approach is in the Data Retention Policy.
Data is hosted in the United Kingdom on Microsoft Azure and encrypted at rest. Connections are encrypted in transit using TLS 1.2 or above, and unencrypted database connections are rejected. Access is role-based and enforced server-side, two-factor authentication is available on user accounts, and material actions are recorded in an append-only audit log.
Purinode Ltd holds Cyber Essentials certification, scoped to the whole organisation, certificate number 6fcde322-bedf-487a-839b-e6977a72f9ed, valid until 1 September 2027.
Fuller detail is in Annex 2 of our Data Processing Agreement.
We use cookies that are strictly necessary to run the platform: keeping you signed in, maintaining your session, and protecting against cross-site request forgery. These do not require your consent.
If we introduce analytics or any other non-essential cookie, we will ask for your consent first and you will be able to change your choice at any time.
You can ask us to give you a copy of the information we hold about you, correct it if it is wrong, delete it, restrict how we use it, or provide it in a portable format. You can object to processing we carry out on the basis of legitimate interests, and withdraw consent where we have relied on it.
To exercise any of these, email [email protected]. We will respond within one month. We may ask you to confirm your identity first.
Some of these rights are not absolute. Where we cannot do what you have asked — for example where we must keep billing records for tax purposes, or where an audit entry is the only evidence that a deletion took place — we will tell you why.
If you are unhappy with how we have handled your information, please tell us so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or by calling 0303 123 1113. You do not have to raise it with us first.
We may publish new versions of this notice. Each version is published at its own address and earlier versions remain readable. Where a change materially affects you, we will tell you.
The current version is always at https://trine.uk/legal/privacy.