01Who we are
Burnback is a trading name of Sciuridae Labs Ltd, a company registered in England and Wales with company number 17213331, whose registered office is at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom (“we”, “us”, “our”).
For the personal data described in this policy, we are the controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, except where section 6 explains that we act as a processor on your behalf. We are registered with the Information Commissioner’s Office (ICO) under registration number [ICO registration number].
Questions about privacy? Email privacy@burnback.co.uk.
02What this policy covers
This policy applies when you:
- visit our website at burnback.co.uk;
- sign up for, or use, the Burnback app on any plan, including the free plan and free trials;
- contact us for support or sales, or receive emails from us.
Burnback is a service for businesses. When we say “you”, we mean the person using Burnback, usually on behalf of a business such as its owner, a director or an office manager.
03Information we collect
Information you give us
- Account details: your name, work email address, phone number (optional), job role and password (stored securely as a hash).
- Business details: business name, website, address, services, areas covered and team names you choose to add.
- Brand information: your answers during set-up, your chosen brand voice, and the edits you make to drafts, which form your “brand memory”.
- Billing details: billing name and address and VAT number. Card details are collected and held by our payment provider, not by us.
- Communications: messages you send to our support team and feedback you give us.
- Early-access list: if you ask for early access before launch, your name, email address, business name, any optional answers you give (such as which job you’d hand over first), and how you reached the form (for example, the button or link you clicked and the plan you were looking at).
Information from platforms you connect
When you connect a platform such as Google Business Profile, Trustpilot, Checkatrade, Facebook or LinkedIn, you authorise us to access information from that account through the platform’s official integration. Depending on the platform this may include your business profile, posts, reviews and the public names of reviewers, and performance statistics. We never see or store your password for those platforms, and you can disconnect them at any time.
Information collected automatically
- Usage information: which features you use, drafts approved or edited, and when you log in, so we can run and improve the service.
- Device and log information: IP address, browser type, device type and error logs, used for security and troubleshooting.
Information from other sources
To learn about your business during set-up, we may read publicly available information such as your website and public review pages. We do not buy personal data from data brokers.
04How we use it and why
UK data protection law requires us to have a lawful basis for each use of personal data. Ours are:
| What we do | Lawful basis |
|---|---|
| Create and manage your account, and provide Burnback’s features | Contract: we need it to provide the service you signed up for |
| Take payments, issue invoices and keep financial records | Contract and legal obligation (tax and accounting law) |
| Send service messages, such as approval requests, trial reminders and security alerts | Contract |
| Provide customer support | Contract and legitimate interests (helping our customers) |
| Keep Burnback secure and prevent fraud and misuse | Legitimate interests (protecting our service and customers) |
| Understand how Burnback is used so we can improve it | Legitimate interests (improving our product), using aggregated or de-identified data where possible |
| Send your early-access invitation and occasional pre-launch updates you asked for, and contact you to ask about your needs | Consent: you give it when you join the list, and can withdraw it at any time |
| Send product news and offers | Legitimate interests for existing business customers, or consent where required. You can opt out at any time |
| Comply with the law and respond to lawful requests | Legal obligation |
Where we rely on legitimate interests, we have weighed them against your rights. You can ask us for details of that assessment.
05How we use AI
Burnback uses artificial intelligence to draft content for your business, such as review replies, social posts, Google Business Profile updates and emails, and to summarise what’s working.
- To do this, we send relevant information (for example, a review and your brand memory) to AI model providers who process it on our instructions under contract. See section 7.
- We do not use your data to train public or third-party AI models, and our contracts with AI providers do not allow them to do so.
- Your brand memory is used only to produce work for your business. It is never shared with, or used for, other customers.
- Content is approval-based by default: nothing is published until you approve it, unless you choose to switch on auto-publishing for particular content types.
- We do not make decisions based solely on automated processing that have legal or similarly significant effects on you.
06Your customers’ data
Some Burnback features involve personal data about your customers. For example, the names of people who leave reviews, or the contact details you give us so Burnback can send review requests after a job.
For that data, your business is the controller and we are your processor. We process it only on your instructions and to provide Burnback to you, under the data processing terms that form part of our Terms & Conditions.
That means you are responsible for having a lawful basis to share your customers’ details with us and for telling them how you use their data, for example in your own privacy notice. Review requests sent through Burnback are service messages about a job the customer has had done. Please make sure your use of them follows the law and the relevant platform’s rules.
08International transfers
We aim to store your data in the UK or European Economic Area. Some of our service providers, including AI model providers, may process data in other countries such as the United States. When data is transferred outside the UK, we make sure it is protected by one of the safeguards recognised by UK law, such as a UK adequacy regulation (including the UK–US Data Bridge for certified organisations), the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
09How long we keep it
We keep personal data only as long as we need it:
| Data | How long |
|---|---|
| Account, business and brand memory data | While your account is open, then deleted within 30 days of closure |
| Data from connected platforms | While the platform is connected, then deleted within 30 days of disconnecting or closing your account |
| Invoices and billing records | 6 years from the end of the financial year they relate to, as required by tax law |
| Support correspondence | 2 years from the last contact |
| Security and server logs | Up to 90 days |
| Backups | Overwritten on a rolling basis within 90 days |
| Early-access list | Until you become a customer or ask to be removed, and no longer than 12 months after launch |
| Marketing preferences | Until you opt out. We keep a record of the opt-out so we don’t contact you again |
You can export your brand memory and history before closing your account.
10Keeping it secure
We use appropriate technical and organisational measures to protect personal data. These include encryption in transit and at rest, access controls based on least privilege, secure authentication through each platform’s official sign-in, and regular reviews of our providers. No system is perfectly secure. If a breach is likely to put your rights at risk, we will tell you and the ICO as the law requires.
11Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you;
- correct data that is inaccurate or incomplete;
- erase your data in certain circumstances;
- restrict how we use your data in certain circumstances;
- object to processing based on legitimate interests, and to direct marketing at any time;
- data portability: receive data you gave us in a reusable format;
- withdraw consent where we rely on it, without affecting what we did before.
To use any of these rights, email privacy@burnback.co.uk. It’s free, and we’ll reply within one month. We may need to confirm your identity first. If your request is about your customers’ data (section 6), we’ll help your business respond.
If you’re unhappy with how we’ve handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.
13Marketing emails
We may email you occasional product news, tips and offers. Every marketing email has an unsubscribe link, or you can email privacy@burnback.co.uk. Unsubscribing won’t affect service emails you need, such as approval requests, billing notices and security alerts.
14Children
Burnback is a business service and is not intended for anyone under 18. We do not knowingly collect children’s personal data.
15Changes to this policy
We may update this policy from time to time. The date at the top shows when it last changed. If we make significant changes, we’ll let account holders know by email or in the app before they take effect.
16Contact us
Sciuridae Labs Ltd (trading as Burnback)71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Email: privacy@burnback.co.uk