What we collect when you visit composer.id, sign up for developer access or use the reference sandbox; why we collect it and on what lawful basis; who we share it with; how long we keep it; the rights you have under the UK GDPR; and what composerID processes when it runs inside a customer’s Triage deployment.
This Privacy Policy applies to the composerID website, documentation, developer portal and reference sandbox located at or accessed through composer.id (together, the “Services”), which are owned and operated by Deployed, a company based in London, United Kingdom (“Deployed”, “we”, “us”). We recognise and respect your privacy. This Policy explains what personal data we collect through the Services, why, who we share it with, how long we keep it, and the rights you have under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where it applies, the EU General Data Protection Regulation (EU GDPR).
Use of the Services is also subject to our Terms of Use, API Terms, End User Terms and, for customers, the Data Processing Agreement (together, the “Terms”). Capitalised terms used but not defined here have the meaning given in the Terms.
We may change this Policy from time to time. The date at the top moves when we do, material changes are noted in the changelog, and your continued use of the Services after a change constitutes acceptance of the revised Policy.
For personal data collected through the Services, Deployed is the controller. Contact: jamie.gannaway@deployed.co. For personal data that composerID processes inside a customer’s Triage deployment, Deployed is the processor and the customer is the controller; Section 12 explains what that means for you.
We collect personal data directly from you and automatically through your use of the Services:
We do not collect special category data through the Services and ask you not to send it to us.
| Purpose | Lawful basis (UK GDPR Article 6) |
|---|---|
| Providing developer access, issuing and managing API keys and client credentials | Performance of a contract with you (the API Terms) |
| Operating, securing and improving the Site and the sandbox, including rate limiting, abuse prevention and debugging | Our legitimate interest in running a secure, working service |
| Responding to enquiries, support requests and security reports | Our legitimate interest in answering the people who contact us; performance of a contract where you are a customer |
| Telling you about material changes to the Services, the Terms or this Policy | Our legitimate interest, and our legal obligations |
| Sending occasional product news to developer-access account holders | Our legitimate interest in keeping account holders informed; you can opt out at any time (Section 9) |
| Evaluating business opportunities and following up a demo request | Our legitimate interest in developing our business |
| Establishing, exercising or defending legal claims; complying with law and regulatory requests | Legal obligation; legitimate interest |
| Producing aggregated, de-identified statistics about use of the Services | Legitimate interest; the output is not personal data |
Deployed does not use personal data collected through the Services to develop, improve or train generalised artificial intelligence or machine-learning models. We do not sell personal data and we do not share it with advertisers.
The Site sets no advertising cookies and no analytics cookies, and uses no web beacons or third-party trackers. It stores one value in your browser’s local storage: your light or dark theme preference. Our identity provider, Clerk, sets the cookies it needs to keep you signed in on the developer access pages and to protect against sign-in abuse; Clerk’s own privacy notice describes them. You can clear local storage and cookies at any time in your browser; clearing Clerk’s cookies signs you out. If we introduce analytics in future, we will update this Section and, where the law requires it, ask for your consent first.
We share personal data with the following categories of recipient, and no others:
Deployed is based in the United Kingdom. Our processors may store or access personal data outside the United Kingdom, including in the United States and the European Economic Area. Where a transfer leaves the United Kingdom we rely on an adequacy regulation made under the UK GDPR where one exists, and otherwise on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with supplementary measures where a transfer risk assessment calls for them. Where a transfer of EU-origin data leaves the European Economic Area we rely on an adequacy decision or on the EU Standard Contractual Clauses. You can ask us for a copy of the relevant safeguard at the contact address below.
We keep personal data only for as long as needed for the purposes in Section 3, unless a longer period is required or permitted by law:
When the purpose no longer applies we delete or irreversibly anonymise the data. You can request deletion at any time (Section 8).
Under the UK GDPR and, where it applies, the EU GDPR, you have the right to:
To exercise any right, email jamie.gannaway@deployed.co. We respond within one month, extendable by two further months for complex requests, and we may ask you to verify your identity first. There is no fee unless a request is manifestly unfounded or excessive. If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office (ico.org.uk, 0303 123 1113) or, if you are in the European Economic Area, to your local supervisory authority. We would welcome the chance to address your concern first.
We use your email address to answer your enquiries, to administer your developer account and to send service notices, such as a change to the Terms or a security notice that affects you. Developer-access account holders may also receive occasional product news from us. Every marketing email carries an unsubscribe link; you can also opt out by emailing jamie.gannaway@deployed.co. Opting out of marketing does not stop service notices, which we send only when we need to.
The Services are not directed at children under 13 and we do not knowingly collect personal data from them. If you learn that a child has provided us with personal data, tell us at jamie.gannaway@deployed.co and we will delete it.
The Services link to third-party websites, principally vendor documentation, our identity provider and our hosting provider. Your use of those websites is governed by their privacy notices, not this Policy, and we are not responsible for their information practices.
We protect personal data with technical and organisational measures appropriate to the risk. The Site and the sandbox are served over TLS only. API keys are compared in constant time and are personal, so a single key can be revoked without affecting anyone else; client-credentials tokens expire after an hour, carry only the scopes the client was granted and are stored only as hashes. Inbound webhooks are accepted only with a valid HMAC-SHA256 signature over the raw request body. Callers never supply destination credentials to composerID: they are held per tenant and injected by the adapter. Access to the platform’s field-level documentation is gated behind a personal account so that an audit line runs from key to person. The measures that apply to customer deployments are set out in Annex II of the Data Processing Agreement. No transmission over the internet is completely secure; if you have a security concern or believe you have found a vulnerability, contact jamie.gannaway@deployed.co.
When composerID runs for a customer organisation, Deployed acts as that customer’s processor under the customer agreement and the Data Processing Agreement. The customer’s own privacy notice explains to its people what is collected and why; this Policy does not replace it. Two facts hold in every deployment and are published on the platform pages:
Retention and deletion of customer deployment data are governed by the customer agreement and the Data Processing Agreement. If you are an individual whose request was handled through your employer’s deployment, direct rights requests to your employer in the first instance; we will assist them as the Data Processing Agreement requires.
Questions, comments and requests about this Policy or about your personal data: jamie.gannaway@deployed.co. We aim for error-free performance but cannot always catch an unintended privacy issue on our own, so we welcome your questions.