Skip to main content
Deployed runs composer.id, its documentation and the reference sandbox behind it. This notice tells you what personal data that involves, and what composerID processes when it runs inside a customer’s Triage deployment.
Last updated 22 September 2026
This Privacy Policy applies to the composerID website, documentation and reference sandbox located at or accessed through composer.id (together, the “Services”), which are owned and operated by Deployed, a company based in London, United Kingdom (“Deployed”, “we”, “us”). We recognise and respect your privacy. This Policy explains what personal data we collect through the Services, why, who we share it with, how long we keep it, and the rights you have under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where it applies, the EU General Data Protection Regulation (EU GDPR). Use of the Services is also subject to our Terms of Use, API Terms, End User Terms and, for customers, the Data Processing Agreement (together, the “Terms”). Capitalised terms used but not defined here have the meaning given in the Terms. We may change this Policy from time to time. The date at the top moves when we do, material changes are noted in the changelog, and your continued use of the Services after a change constitutes acceptance of the revised Policy.

1. Who is responsible for your data

For personal data collected through the Services, Deployed is the controller. Contact: jamie.gannaway@deployed.co. For personal data that composerID processes inside a customer’s Triage deployment, Deployed is the processor and the customer is the controller; Section 13 explains what that means for you.

2. Information we collect

We collect personal data directly from you and automatically through your use of the Services:
  • Sandbox credentials: there is no sign-up form and no account. When you call POST /v1/sandbox/keys we store the tenant identifier we generate, hashes of the credentials we issue, the time they were issued and the time they expire, and the optional free-text label you choose to send. The label is personal data only if you put something personal in it. Your network address is counted against a rate limit of five credential sets an hour.
  • Correspondence: the content of any email you send us, your email address, and our replies.
  • Sandbox usage: the credential used, request timestamps, the endpoints called and the request bodies you send. The sandbox is for test data only; do not send it real personal data.
  • Technical information collected automatically by our hosting provider when you visit the Site: IP address, browser type and version, device type, the pages requested, the referring page and timestamps.
  • Preferences stored only in your own browser: your light or dark theme choice.
  • Information about third parties only where you provide it to us with their permission, for example when you name a colleague in an email.
We do not collect special category data through the Services and ask you not to send it to us.

3. How we use information, and our lawful basis

Deployed does not use personal data collected through the Services to develop, improve or train generalised artificial intelligence or machine-learning models. We do not sell personal data and we do not share it with advertisers.

4. Cookies and similar technologies

The Site sets no advertising cookies and no analytics cookies, and uses no web beacons or third-party trackers. It stores one value in your browser’s local storage: your light or dark theme preference. The developer documentation is hosted by Mintlify, which stores your theme and navigation preferences in the browser and may set the functional cookies its service needs; Mintlify’s own privacy notice describes them. You can clear local storage and cookies at any time in your browser. If we introduce analytics in future, we will update this Section and, where the law requires it, ask for your consent first.

5. Who we share personal data with

We share personal data with the following categories of recipient, and no others:
  • Service providers acting as our processors, under written contracts that restrict their use of the data to providing their service to us: Vercel (hosting of the composer.id website and of the hosted sandbox function at https://sandbox.composer.id/v1; server logs), Upstash (the key-value store behind the hosted sandbox, provisioned through Vercel, which holds tenant credential hashes and sandbox Intent Records) and Mintlify (hosting of the developer documentation, its search and its documentation assistant). The current list is also published in Annex III of the Data Processing Agreement.
  • Professional advisers such as lawyers, accountants and insurers, where necessary.
  • Public authorities, courts and regulators, where required by law, a court order or a binding request, or to protect our rights, property or the safety of any person.
  • A buyer or successor in the event of a merger, acquisition, reorganisation or sale of all or part of our business, in which case this Policy continues to apply to your data.

6. International transfers

Deployed is based in the United Kingdom. Our processors may store or access personal data outside the United Kingdom, including in the United States and the European Economic Area. Where a transfer leaves the United Kingdom we rely on an adequacy regulation made under the UK GDPR where one exists, and otherwise on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with supplementary measures where a transfer risk assessment calls for them. Where a transfer of EU-origin data leaves the European Economic Area we rely on an adequacy decision or on the EU Standard Contractual Clauses. You can ask us for a copy of the relevant safeguard at the contact address below.

7. How long we keep personal data

We keep personal data only for as long as needed for the purposes in Section 3, unless a longer period is required or permitted by law:
  • Sandbox credentials: every set expires 30 days after it is issued, and the stored hashes and tenant record are deleted at expiry. There is no account to close.
  • Sandbox request data: up to 90 days, or sooner when the sandbox is reset.
  • Hosting and access logs: as retained by our hosting provider, typically 30 days.
  • Email correspondence: for as long as the conversation is active and for a reasonable period after, so that we can pick it up again if you write back.
  • Records we need to establish or defend legal claims: for the applicable limitation period.
When the purpose no longer applies we delete or irreversibly anonymise the data. You can request deletion at any time (Section 8).

8. Your rights

Under the UK GDPR and, where it applies, the EU GDPR, you have the right to:
  • be told what personal data we hold about you and receive a copy of it (access);
  • have inaccurate personal data corrected and incomplete personal data completed (rectification);
  • have your personal data deleted in certain circumstances (erasure);
  • restrict how we process your personal data in certain circumstances (restriction);
  • receive the personal data you provided to us in a structured, machine-readable format and have it transmitted to another controller (portability);
  • object to processing based on our legitimate interests, and to direct marketing at any time (objection);
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects; we make no such decisions through the Services.
To exercise any right, email jamie.gannaway@deployed.co. We respond within one month, extendable by two further months for complex requests, and we may ask you to verify your identity first. There is no fee unless a request is manifestly unfounded or excessive. If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office (ico.org.uk, 0303 123 1113) or, if you are in the European Economic Area, to your local supervisory authority. We would welcome the chance to address your concern first.

9. Email

We have your email address only if you have written to us or asked us for something. We use it to answer your enquiries and to send service notices, such as a change to the Terms or a security notice that affects you. If you ask us for product news we will send it. Every marketing email carries an unsubscribe link; you can also opt out by emailing jamie.gannaway@deployed.co. Opting out of marketing does not stop service notices, which we send only when we need to.

10. Children

The Services are not directed at children under 13 and we do not knowingly collect personal data from them. If you learn that a child has provided us with personal data, tell us at jamie.gannaway@deployed.co and we will delete it. The Services link to third-party websites, principally vendor documentation, our documentation host and our hosting provider. Your use of those websites is governed by their privacy notices, not this Policy, and we are not responsible for their information practices.

12. Security

We protect personal data with technical and organisational measures appropriate to the risk. The Site and the sandbox are served over TLS only. API keys are compared in constant time and are scoped to a single tenant, so one set can expire or be abandoned without affecting anyone else; client-credentials tokens expire after an hour, carry only the scopes the client was granted and are stored only as hashes. Inbound webhooks are accepted only with a valid HMAC-SHA256 signature over the raw request body. Callers never supply destination credentials to composerID: they are held per tenant and injected by the adapter. Sandbox credentials carry no identity: POST /v1/sandbox/keys mints a tenant identifier with no name, email address or organisation attached, stores every secret as a SHA-256 hash, shows the secrets once, expires them after 30 days and limits minting to five sets an hour per network address. The documentation itself is open and needs no account. The measures that apply to customer deployments are set out in Annex II of the Data Processing Agreement. No transmission over the internet is completely secure; if you have a security concern or believe you have found a vulnerability, contact jamie.gannaway@deployed.co.

13. What composerID processes inside a Triage deployment

When composerID runs for a customer organisation, Deployed acts as that customer’s processor under the customer agreement and the Data Processing Agreement. The customer’s own privacy notice explains to its people what is collected and why; this Policy does not replace it. Two facts hold in every deployment and are published on the platform pages:
  • An Intent Record carries what is needed to publish a decision into a system of record: the work request fields the destination requires, an Intent ID, and an append-only timeline of what was done and when.
  • A destination system receives only a valid request plus the Intent ID. Diagnostic answers, scores and the Compliance File never leave composerID. Each platform page lists what crosses the boundary and what is never sent.
Retention and deletion of customer deployment data are governed by the customer agreement and the Data Processing Agreement. If you are an individual whose request was handled through your employer’s deployment, direct rights requests to your employer in the first instance; we will assist them as the Data Processing Agreement requires.

14. How to contact us

Questions, comments and requests about this Policy or about your personal data: jamie.gannaway@deployed.co. We aim for error-free performance but cannot always catch an unintended privacy issue on our own, so we welcome your questions.