What this covers: what personal data Venakis holds, why, who else sees it, how long it is kept, and what you can ask us to do about it. Takes effect on 30 September 2026. Version 1.0.
In this document, "we", "us" and "our" mean Felix Venus, trading as Venakis.
There are two different things going on in this policy and it is worth separating them before you start.
- Data about you, our customer. Your name, your business, your login, your billing, your support emails. Here we are the controller. We decide what happens to it, and this policy is the notice the law requires us to give you.
- Data about your clients. The names, contact details and appointment history your clients' records contain. Here we are only the processor. You decide what happens to it. We act on your instructions, under the data processing terms in Annex A of the Terms of Service. The notice your clients are entitled to has to come from you, not from us, because you are their controller.
We cannot be controller and processor for the same information, and the system keeps the two apart.
1. Who we are
| Controller | Felix Venus, trading as Venakis |
| Legal status | Sole trader (an individual in business, not a limited company) |
| Trading address | 30 Queens Road, Cheltenham GL50 2LT |
| Email for data protection questions | help@venakis.com |
| Telephone | 07494 745157 |
| ICO registration number | Pending; published here once issued |
There is no data protection officer. The law requires one only in specific circumstances, and Venakis does not meet them: it is not a public authority, its core activity is booking administration rather than large scale monitoring, and it is very small. We have recorded that assessment in writing. We deliberately do not give anyone the title of data protection officer, because a voluntary appointment brings a whole regime with it, including independence from the business, and in a business run by one person nobody can be independent of it.
2. Data we hold as controller, and why
| What | Why | Lawful basis | How long |
|---|---|---|---|
| Your name, business name, business address, email, telephone | Setting up and running your account; contacting you about the service | Performance of our contract | For the contract, then 12 months |
| Login credentials, password hashes, session and authentication records, security logs | Letting you in and keeping other people out | Performance of our contract; and our legitimate interest in securing the service | For the contract, then 12 months (security logs 12 months) |
| Billing records, invoices, payment references, Stripe customer and payment identifiers | Taking payment; keeping proper accounts | Performance of our contract; and compliance with a legal obligation for tax records | Financial records: 6 years after the end of the relevant tax year |
| Support emails and ticket history | Answering your questions; keeping a record of what was reported and fixed | Performance of our contract; and our legitimate interest in improving the service | 3 years from the end of the contract |
| Usage records showing which features your account uses and how often | Understanding what works, sizing capacity, diagnosing faults | Our legitimate interest in running and improving the service | 24 months |
| Your marketing preferences, and emails sent to you | Sending product news you have asked for | Consent, or the soft opt in where you are an existing customer | Until you opt out, then a suppression record kept indefinitely so we do not contact you again |
| Records of enquiries and demonstrations from prospective customers | Responding to the enquiry; following it up | Our legitimate interest in responding to people who contact us; consent for marketing where required | 12 months from last contact |
On legitimate interests. Where we rely on legitimate interests, the interest is running, securing and improving a small software business. We have weighed that against your privacy in each case, and we will share the assessment if you ask.
Card details. We never see or hold your card number. Payments run through Stripe, and card data goes straight to them.
3. Data about your clients, held as processor
Through the Service we process, on your behalf:
- your clients' names, email addresses, telephone numbers, and postal addresses where you collect them;
- appointments: date, time, service booked, staff member, status, and history;
- notes you or your staff record against a client;
- payment records and references relating to their bookings;
- the names, email addresses and access rights of your own staff users.
We process this only on your documented instructions, which means the functionality of the Service and anything else you tell us in writing. We do not use it for our own purposes, we do not sell it, we do not market to your clients, and we do not use it to train models.
Where a boundary genuinely exists, here it is. Operational monitoring, fault diagnosis and keeping the Service working are part of providing the Service and we do them as your processor. Producing aggregated statistics about the Service that are irreversibly anonymised is also within that. Anything beyond that, such as analysing your clients' booking records to derive commercial insight, would make us a controller for that activity, so we do not do it. If that ever changes, we will tell you in advance, explain the basis, and give you a choice.
If a client contacts us directly about their data, we will not answer the substance of it. We will refer them to you and tell you it happened. You hold the relationship and the legal duty.
Special category data. If your business is health adjacent, for example physiotherapy, counselling, dentistry, aesthetics or podiatry, your clients' appointment records may amount to health data, which the law treats as needing extra protection. Tell us at signup if that applies to you, because it changes how the data must be handled at both ends.
4. Who else is involved
These are the suppliers who process personal data as part of running Venakis. This list is versioned and dated, and we tell existing customers by email at least 30 days before adding or replacing anyone on it.
| Supplier | What it does | Where the company is established | Transfer mechanism |
|---|---|---|---|
| Vercel Inc. | Hosts the web application | United States (Delaware) | Standard contractual clauses with the UK Addendum, as used in Vercel's own data processing agreement |
| Render Services, Inc. | Hosts the API and the PostgreSQL database, in Frankfurt, Germany | United States (California) | UK Extension to the EU-US Data Privacy Framework, with the UK Addendum as a fallback |
| Resend (Plus Five Five, Inc.) | Sends transactional email: confirmations, reminders, password resets, receipts, service notices | United States (California) | UK Addendum to the EU standard contractual clauses |
| Stripe Payments Europe, Limited, with Stripe, LLC | Takes subscription payments | Ireland, with a United States element | Data Privacy Framework, then EU standard clauses with the UK Addendum |
| IONOS Cloud Ltd | Hosts the help@venakis.com mailbox and the venakis.com domain | United Kingdom | UK company; any storage in the EU is covered by the UK's adequacy regulations |
Two things about this list you should actually read.
Frankfurt is not the whole story. The database sits in Frankfurt, which is good for latency and good for the physical location of the data. But the law does not follow the servers, it follows the company. Render is a United States company, so using it is a transfer of data to the United States even though the machines are in Germany. Render's own suppliers, and Resend's, are also United States companies. Saying only "hosted in Frankfurt" would understate that, so we are not saying only that.
Stripe is not simply our supplier. By its own terms, Stripe decides for itself what to do with payment data for fraud monitoring, anti money laundering checks, payment method selection, legal compliance and its own product improvement. For those purposes Stripe is a separate controller in its own right, not our processor, and its own privacy policy governs what it does. That is worth knowing because it is not something we can control on your behalf.
Transfers outside the UK. There is no adequacy decision needed for the European Economic Area: transfers there are already covered by UK law with no expiry date. For the United States, the mechanisms above apply. Because we chose these suppliers and we initiate the transfers, the transfer risk assessments are our legal obligation, not yours, and we keep them under review at least once a year. You may ask to see them.
Others who may see data. Our accountant, for financial records. Professional advisers where we need advice. A regulator, court or law enforcement body where we are legally required to disclose. Nobody else, and we do not sell personal data to anyone.
5. Cookies and similar technologies
Venakis uses the minimum it can.
- Strictly necessary: a session cookie to keep you logged in, and security tokens that protect forms against abuse. These do not need your consent, and there is no way to turn them off and still use the application.
- Analytics: none. Venakis does not currently measure how venakis.com or the application are used. If that changes, the measurement will be first party and aggregated, used only to improve them, and not shared with anyone else. Under the rules that came into force on 5 February 2026 that would not require consent, but it would require us to tell you clearly and to give you a simple, free way to object. You can object now, in advance, at https://venakis.com/privacy/preferences or by emailing help@venakis.com, and it will be honoured from the day any measurement starts. Your choice on that page is kept in your browser's own storage, only to remember it. A Global Privacy Control signal from your browser counts as an objection. Objecting costs you nothing and changes nothing else about the service.
- No advertising, no remarketing, no third party tracking, no cross site profiling. If that ever changed, a consent banner would appear, and rejecting would be exactly as easy as accepting.
In plain terms: there is no cookie banner because there is nothing here that needs your consent. That is not a shortcut. It is a consequence of not doing advertising tracking.
6. How long data is kept
The table in section 2 gives the periods for data we hold as controller. Two notes on it.
Tax records are different. Financial records are kept for 6 years after the end of the relevant tax year, because HMRC requires it. That period applies to invoices and accounts, and it does not leak into anything else. It is not a reason to keep your marketing preferences or your clients' appointment history.
Your clients' data is on your clock, not ours. You decide how long it is kept. The Service gives you retention controls and deletion tools. At the end of our contract we delete it or return it, at your choice, on the timetable in Data Ownership and Exit.
7. Security
Current measures:
- Data encrypted in transit (TLS) and at rest.
- Access to production systems restricted to Felix Venus alone, with multi factor authentication and unique credentials.
- Secrets held in managed secret storage, never in code.
- Logical separation of each customer's data, with access controls tested as part of the release process.
- Continuous backups with 3 days of point-in-time recovery, provided by our hosting provider.
- Dependency and vulnerability scanning on every release.
- Audit logging of administrative access.
- Card data never touches Venakis systems; it goes directly to Stripe.
Security documentation, and answers to a written security questionnaire, are available on request. Venakis is run by one person, so we will tell you plainly what is in place rather than imply a security team.
If there is a breach. If a breach affects your account data, we will tell you without undue delay and, where the law requires it, report it to the Information Commissioner within 72 hours. If it affects your clients' data, we will tell you within 24 hours of becoming aware, with what we know, and it is then your decision as controller whether to report it. We will never report your breach to the regulator on your behalf.
8. Your rights
Where we are the controller of data about you, you can ask us to:
- give you a copy of the personal data we hold about you;
- correct it if it is wrong;
- delete it, where we no longer have a reason to keep it;
- restrict what we do with it while a disagreement is sorted out;
- give it to you or another provider in a machine readable form, where that right applies;
- stop processing it where we rely on legitimate interests and you object;
- withdraw consent where consent is what we relied on, at any time.
There is no automated decision making in Venakis that produces legal effects for you, and no profiling of that kind.
How to ask. Email help@venakis.com. It is free. We will respond within one month. If a request is complex or you have made several, we may need up to two further months, and if so we will tell you why within the first month.
If you are unhappy: complain to us first. Since 2026 you have a statutory right to complain directly to us about how we handle your data. Send it to help@venakis.com with "Complaint" in the subject line. We will acknowledge it within 30 days and respond without undue delay, and we will tell you what we have done about it.
And you can go to the regulator. You can complain to the Information Commissioner's Office at any time, whether or not you have complained to us first. ico.org.uk/make-a-complaint, or 0303 123 1113. You can also take a claim to court.
If your complaint is about your own client's data held in a Venakis system, the controller is the business you booked with, not us. Ask them.
9. Marketing
We email customers about product changes and, occasionally, new features. You can opt out of the non essential ones at any time using the link in the email or by emailing help@venakis.com, and we will keep a record of the opt out so it is not undone.
Service messages are different from marketing. Confirmations, receipts, password resets, security notices, outage notices and changes to these documents are not marketing, and you cannot opt out of them while you have an account, because they are how the service works.
We will not add a promotional line to a service email, because doing so would turn the whole message into marketing.
Prospective customers. If you enquire, we will reply and may follow up. If we contact you cold, we do so on the basis that applies to you, which for many small businesses, including sole traders and most partnerships, means consent or a prior enquiry rather than "it is a business address". You can tell us to stop at any time and we will.
10. Children
Venakis is sold to businesses and is not for use by children. Your clients' records may include data about a child, for example a parent booking a child's appointment. Where that happens you are the controller of it and the extra care that child data needs is your responsibility, supported by the security and access controls in the Service.
11. Changes to this policy
If we change this policy we will publish the new version with its date, keep the old versions available, and email customers before anything material takes effect. If we ever want to use personal data for a genuinely new purpose, we will tell you before we start, and explain the basis.
12. Summary of the legal position, for anyone who needs it in one place
- Controller of customer account, billing, support, usage and marketing data: Felix Venus trading as Venakis.
- Processor of end client booking data: Felix Venus trading as Venakis, acting for each business customer as controller, under Annex A of the Terms of Service, which is the Article 28 contract.
- Separate controller for parts of payment processing: Stripe.
- Transfers outside the UK: to the United States, under the mechanisms in section 4, with transfer risk assessments held by us.
- ICO registration: pending, fee tier 1; the number is published here once issued.
- Records of processing: maintained separately for the controller activities and the processor activities.