Effective Date: 26 September 2026 — Last Updated: 26 September 2026
This Privacy Policy explains what personal data Trefnus collects when you buy and use Trefnus CMMS, how we use it, and your rights.
The data controller for the personal data described in Sections 1 and 2 is Darren Jolley, a sole trader trading as "Trefnus". The maintenance records you keep in the Application stay on your own devices: we do not receive them, and we cannot see them.
Purchases are processed by Polar Software, Inc., acting as our Merchant of Record. Polar collects the information needed to complete your purchase (such as your name, email address, billing and tax details, and payment information) and processes it as a separate controller under its own privacy policy. We receive only limited information from Polar, such as your name, email address, and order and licence details. We do not receive or store your full card details.
Our website, www.trefnus.com, is hosted by Wix.com Ltd and uses cookies and analytics provided by that platform. How we handle personal data collected through the website is described in the privacy policy on our website.
If you email us, we keep your message, your email address, and our reply so that we can deal with your enquiry.
| Data | Purpose | Legal Basis |
|---|---|---|
| Order details | Processing your purchase, issuing your licence, handling refunds, keeping accounting and tax records | Performance of contract; Legal obligation (tax and accounting records) |
| Email address | Licence activation, sending sign-in links, essential service messages (for example, security notices and material changes to our terms) | Performance of contract; Legitimate interests (running and securing the service) |
| User ID, licence data | Verifying your licence and managing access | Performance of contract |
| Device identifier and label | Enforcing the device limit, preventing unauthorised use, helping you manage your devices | Performance of contract; Legitimate interests (protecting our licensing model and helping you manage devices) |
| Technical data | Delivering the Application, keeping services secure, preventing abuse | Legitimate interests (security and service delivery) |
| Correspondence | Responding to enquiries, support, and complaints | Legitimate interests (customer service); Performance of contract |
We do not use your data for advertising, we do not sell it, and we do not make decisions about you by automated means that have legal or similarly significant effects.
Everything you enter into the Application is stored on your own devices, in your browser's storage. We do not receive, have access to, or hold a copy of it. This includes:
Where your browser supports it, your records are encrypted on the device with AES-256, using a key protected by your password and recovery key. Attachment files are not covered by that device encryption.
If your organisation enters personal data about other people (for example staff, contractors, or supplier contacts), your organisation is the controller of that data and is responsible for it under data protection law. Because we never receive it, we are not a processor of it. Individuals who want to exercise their rights over that data should contact the organisation that uses the Application.
Some features make your device contact third parties directly. We do not receive the data involved, but those third parties will receive your IP address and technical request information and handle it under their own privacy policies:
We do not sell, rent, or trade your personal data. We share it only with:
Our processors act only on our instructions under contracts that require them to protect your data.
Our licence database is hosted in the European Union (Ireland), which the UK recognises as providing adequate protection. Some of our service providers are based in, or may access data from, other countries including the United States. Where personal data is transferred outside the UK, we rely on UK adequacy regulations or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
Data sent between your device and our services is encrypted in transit using HTTPS (TLS). Our providers encrypt data at rest. On your devices, the security of your data also depends on you. We recommend:
Under UK data protection law you have the right to:
To exercise any of these rights, contact us at apps.trefnus@gmail.com. We will respond within one month, which may be extended where the law allows. We may need to verify your identity first.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk. We would appreciate the chance to deal with your concerns first.
The Application is a business product and is not intended for anyone under 18. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us and we will delete it.
If you are in the European Economic Area, you have equivalent rights under the EU General Data Protection Regulation and may complain to your local supervisory authority. If you are in California, you may have rights under the California Consumer Privacy Act to know about and request deletion of your personal information and not to be discriminated against for exercising your rights. We do not sell or share personal information as those terms are defined in that Act.
If a personal data breach affecting data we hold occurs, we will notify you and the ICO where required by law.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. We will tell you about material changes by email or in the Application.
For questions or concerns about this Privacy Policy or our use of your personal data, contact:
Trefnus (Darren Jolley, sole trader)
Email: apps.trefnus@gmail.com