Privacy policy
Draft of 16 September 2026
Draft, not in force. Entitld is pre‑v1 and no production key has been issued. This page is a working draft for our solicitor to review, and the highlighted parts are still open. It will change before launch.
Who is responsible for your data
Entitld is run by Josh To add: surname and Jon To add: surname in partnership, and we are the controller for the personal data this policy describes. Contact us about it at hello@entitld.dev.
If you visit this website
- No cookies, analytics or tracking. The pages on entitld.dev and docs.entitld.dev set no cookies and store nothing in your browser.
- Our servers keep no visitor logs. The web servers for both sites are configured without access logging.
- Railway hosts the sites and handles the connection, so it processes your IP address and the page you asked for in order to deliver it. To decide: what Railway logs at its edge, for how long, and where
- Google Fonts. Pages load their typefaces from Google, so your browser sends your IP address to Google when a page loads.
Our lawful basis is legitimate interests: showing you the site and keeping it secure.
If you contact us
The form on the contact page is not connected yet, so nothing you type into it reaches us.
If you email us, we get your email address, your name if you include it, and whatever you write. We use it to reply and to talk to you about Entitld. Our lawful basis is legitimate interests, or taking steps towards a contract if you are asking about becoming a customer. To decide: how long enquiry emails are kept, and which email provider holds them
If you use the API
Calculation inputs. Requests carry dates, hours, pay and similar figures about workers, with no names or other identifiers. Entitld calculates in memory and returns the answer. It does not store or log request or response bodies, and it has no database.
What is logged. One line per request: the time, the response status, how long it took, and a short fingerprint of the API key, which identifies the customer and not a worker. Caller IP addresses and request contents are not logged. To enforce rate limits, the service counts unauthenticated requests by IP address, in memory, for one minute. To decide: how long these logs are kept, and where they are sent
Customer details. When we issue keys and bill customers, we will hold the contact and billing details needed to do that. Key verification and usage counting will use Unkey, and billing a payment provider. To decide: the providers, and their locations
Workers’ data. For the figures about workers, our customer, or the employer it serves, decides how that data is used, and we act on their instructions. A data processing agreement will set this out. To decide: the roles, and the agreement
Who else processes data
- Railway, hosting for the API and both websites.
- Google, for the fonts on these pages.
- GitHub, for our source code. It holds no customer or visitor data.
Some of these providers are based in the United States, and one of us is too, so personal data may be handled outside the UK. To decide: the safeguards that apply to each transfer
Your rights
You can ask for a copy of your personal data, and ask us to correct it, delete it, or restrict or object to how we use it. Email hello@entitld.dev. We will reply within one month.
If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to put it right first.
Changes to this policy
We will update this page when what we collect or how we use it changes, and change the date at the top.