Throughout this document, the term “Raven Controls” will be used to refer collectively to both Raven Controls Limited and Raven Controls Inc. This document applies to Raven Controls Limited and its owned subsidiary, Raven Controls Inc.
Privacy Notice
Raven Controls (“we”, “us”, “our”) is committed to respecting and protecting your privacy. This privacy notice explains how we collect, use, and store your personal data. It also outlines your legal rights under data protection laws.
About Us
Raven Controls is a limited company registered in Scotland, with its registered office at: 227 West George Street, Glasgow, G2 2ND, UK.
You can contact us in regards to our Data Protection Policy at:
• Email: privacy@ravencontrols.com
• Post: Raven Controls, 227 West George Street, Glasgow, G2 2ND, UK.
Our Commitment
We process your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (“Data Protection Law”). This means we ensure data processing is:
• Lawful, fair, and transparent
• Limited to the purposes we have communicated
• Adequate, relevant, and limited to what is necessary
• Accurate and up-to-date
• Kept only as long as needed
• Secure and protected against unauthorised access
Why We Process Personal Data
As a provider of incident management software and SaaS solutions, we process personal data to:
• Deliver our services to clients
• Manage relationships with professional contacts, partners, and suppliers
• Respond to enquiries and provide marketing communications
• Improve and secure our platforms and services
• Fulfil legal and regulatory obligations
This privacy notice applies to you if you interact with us as a client, prospective client, business contact, website user, office visitor, marketing recipient, or other relevant individual.
How We Collect Your Personal Data
We may collect your data from:
• Direct interactions (e.g., emails, phone calls, meetings, online portals, website, social media)
• Third parties (e.g., clients, partners, suppliers, public sources, identity verification services)
• Professional referrals (e.g., other advisers, technology or business partners)
• Automated tracking (e.g., website cookies, system logs, analytics tools)
Types of Data We Process
Client and Contact Data
Examples: Name, address, email, phone number, job title, relationship details.
Financial Data
Examples: Payment details, billing records (processed securely; no card data stored).
SaaS Usage Data
Examples: Login credentials, account activity, IP address, device information, error logs.
Collaboration Platform Data
Examples: Meeting registration and participation details, chat logs, recordings (with notice).
Call Recordings
Examples: Recorded for compliance, quality and training purposes (with notice).
Correspondence
Examples: Emails, letters, audio recordings and call notes.
Marketing Data
Examples: Marketing preferences and engagement data.
Website Data
Examples: Cookies, IP address, browser type, operating system, location and time zone.
Professional Adviser Data
Examples: Business contact details, credentials and compliance documentation.
How We Use Your Data
We process your data under lawful bases including contract performance, legal obligations, legitimate interests, and (where applicable) your consent.
Service Delivery and Account Management
Lawful Basis: Contract / Legitimate Interests
Identity Checks, Compliance and Record-Keeping
Lawful Basis: Legal Obligation
Marketing to Clients and Contacts
Lawful Basis: Legitimate Interests (opt-out available)
Marketing to Non-Clients
Lawful Basis: Consent (opt-out available)
Website Analytics and Cookies
Lawful Basis: Legitimate Interests / Consent
Call and Video Recordings (e.g. Webinars)
Lawful Basis: Legitimate Interests / Consent
AI Features (e.g. Note-Taking and Analytics)
Lawful Basis: Legitimate Interests
Security, IT Operations and System Integrity
Lawful Basis: Legitimate Interests
Data Sharing
We may share data with:
• Service providers (e.g., cloud storage, communication platforms, analytics tools)
• Professional advisers and consultants
• Regulatory authorities and law enforcement
• Courts and legal representatives
• Third parties in mergers, acquisitions, or restructuring (with prior notice)
We do not sell your data or permit third-party marketing. We do not use customer data to train shared or third-party AI models. Where we offer per-customer AI features (such as Smart Issue Completion), models are trained only on that customer’s own data, with no cross-customer training.
Data Security
We apply strong technical and organizational measures to protect your data:
• Secure AWS cloud regions, with EU/UK customer data hosted in the EEA and US customer data hosted in the United States
• Access controls and encryption
• Regular security assessments and training
• Identity verification for platform access
• Anti-virus and data-loss prevention controls
Please note that internet transmission is not completely secure. Once we receive your data, we implement strict procedures to prevent unauthorised access. Our website may contain links to third-party sites whose privacy practices we cannot control.
Data Retention
We retain data only as long as necessary for the purposes set out above, in line with our Data Management Policy (available upon request).
Your Rights
Under Data Protection Law, you have rights including:
• Right to be informed
• Right of access (free Subject Access Request)
• Right to rectification or erasure
• Right to restrict processing
• Right to data portability
• Right to object to certain uses (e.g., direct marketing)
• Right to withdraw consent at any time where applicable
We may request proof of identity for certain requests. Most requests will be handled within one month.