Personalise

Privacy Policy

Last updated: 4 October 2026

This Privacy Policy explains how Personalise ("Personalise", "we", "us" or "our") collects, uses, stores and protects personal information when people use our website, platform and related services.

Personalise is a B2B website personalisation platform that enables organisations to create personalised web experiences for individual contacts, companies and audience segments.

For privacy questions, users may contact us through the support/contact functionality made available through the Service.

1. Scope of this Privacy Policy

This Privacy Policy applies to visitors to our website; people who create or use a Personalise account; people who contact us, request a demonstration or subscribe to our communications; authorised users of customer accounts; and, where described below, individuals whose information is processed through Personalise on behalf of one of our customers.

It does not replace the privacy notice of a customer using Personalise on its own website.

2. Our role when processing personal information

When we act as controller

We normally act as a controller when we process information about our own customers, prospective customers and website visitors for purposes such as managing accounts, billing, communicating with customers, providing support, securing and improving the platform, managing our website and conducting our own marketing. This means we determine why and how this information is used.

When we act as processor

When a customer uses Personalise to personalise its website or digital experiences using information about its prospects, customers or website visitors, the customer normally determines why that information is processed. In those circumstances, the customer is the controller and Personalise acts as its processor. We process that information only to provide the Service and in accordance with the customer's instructions, our Terms & Conditions and our Data Processing Addendum.

If someone encounters Personalise through a personalised experience provided by one of our customers, they should also read that organisation's privacy notice. Requests relating to information controlled by that organisation should normally be directed to that organisation.

3. Information we may collect

Account and profile information

Account and profile information may include name, business email address, company, job title, username, account settings, authentication information and user permissions or role.

Billing and subscription information

Billing and subscription information may include organisation name, billing contact, billing address, subscription, payment status, transaction information and tax information. Payment card information may be processed by our payment provider. We do not intend to store complete payment card details ourselves.

Platform usage and technical information

Platform usage and technical information may include IP address, browser and device information, operating system, login events, pages or features used, timestamps, approximate geographic information derived from an IP address, referral information, error and diagnostic data, and security and audit logs.

Communications

Communications may include information contained in support requests, emails, chat conversations, feedback, product research and other communications with us.

Customer Content and Customer Personal Data

Customer Content and Customer Personal Data may include first and last name, business email address, company, industry, department, role or job title, account or campaign identifiers, CRM or marketing automation attributes, audience or segment membership, website activity, campaign source information, information imported through authorised integrations, content, images and assets supplied by the customer, and personalisation rules configured by the customer.

Customers determine which information they provide to the Service and must ensure they have an appropriate lawful basis for doing so.

Website and personalisation activity

Website and personalisation activity, where enabled by a customer and permitted by applicable law, may include pseudonymous visitor identifiers, campaign identifiers, page visited, personalisation or segment assigned, interactions with personalised content, browser or device information, session information and other attributes provided or configured by the customer.

We recommend that customers use pseudonymous identifiers rather than directly identifying information in URLs.

Connected services

If a user authorises an integration with a CRM, marketing automation platform or other third-party service, we may receive and transmit information necessary to operate that integration. The information accessible to us depends on the permissions granted and the configuration of the connected service.

4. How we obtain information

We may receive personal information directly from users; from their employer or organisation; automatically when they use our website or platform; from services connected to Personalise; from a Personalise customer; from authorised third-party service providers; and from publicly available business information where permitted by law.

5. Why we use personal information and our lawful bases

Where UK data protection law applies, we rely on an appropriate lawful basis for each use.

To provide and administer the Service

To create and manage accounts, provide the Service, authenticate users, operate integrations, deliver support, process subscriptions and communicate important service information. Our lawful basis is normally performance of a contract or our legitimate interests in operating our business.

To secure the Service

To protect accounts, prevent fraud or abuse, identify security incidents, investigate suspicious activity and maintain platform integrity. Our lawful basis is normally our legitimate interests and, where relevant, compliance with legal obligations.

To improve the Service

We may analyse product usage to understand performance and improve features and user experience. Our lawful basis is normally our legitimate interests. Where practical, we use aggregated or de-identified information for this purpose.

Marketing

We may contact business users about our products, services and relevant content where permitted by law. Depending on the circumstances, we rely on consent or legitimate interests. Users can opt out of marketing communications at any time.

Legal and regulatory obligations

We may process information to comply with legal obligations, respond to lawful requests, establish or defend legal claims, maintain accounting and tax records, and enforce our agreements. Our lawful basis is compliance with a legal obligation or our legitimate interests.

6. Customer-controlled personalisation data

Customers are responsible for ensuring that their use of Personalise complies with applicable privacy, electronic communications and marketing laws.

Customers must, where required, provide appropriate privacy information to individuals; establish a valid lawful basis for processing; obtain required consent for cookies or similar technologies; respect objections and opt-outs; respond to data subject rights requests; ensure that information supplied to Personalise has been collected lawfully; and configure personalisation appropriately for their audience and jurisdiction.

Personalise does not determine whether a particular customer should target or personalise content for a particular individual.

7. AI-assisted features

Personalise may provide artificial intelligence or machine-learning features to help users identify personalisation opportunities, generate or adapt content, analyse pages or assist with campaign configuration.

AI-generated recommendations or content may be inaccurate, incomplete or unsuitable for a particular context and should be reviewed by a human before publication.

Identifiable Customer Personal Data will not be used to train general-purpose AI models unless the customer has expressly agreed to that use.

Where third-party AI providers process information to deliver an AI feature, they will be treated as service providers or sub-processors as appropriate and disclosed through our sub-processor information.

8. Cookies and similar technologies

Our website and Service may use cookies, local storage, pixels or other storage and access technologies for purposes including authentication, security, remembering settings, delivering requested functionality, personalisation, analytics and measuring marketing performance.

Where consent is required by applicable law, non-essential technologies will not be used until the necessary consent has been obtained. Some storage and access technologies may be used without consent where an applicable legal exemption applies.

Users can manage available choices through our consent-management controls and, where appropriate, their browser.

More detailed information may be provided in a Cookie Policy as the production implementation is finalised.

9. Information we share

We do not sell personal information.

We may disclose information to service providers and sub-processors that help operate the Service, including providers of cloud infrastructure, databases and storage, authentication, email delivery, customer support, analytics, payment processing, security, AI functionality, company-logo or business-data services, and other technical infrastructure.

A current list of material sub-processors will be made available before production launch.

Where a user activates an integration, information may be exchanged with the relevant third-party platform as necessary to provide that integration.

Information may also be disclosed to professional advisers, where required by law or legal process, to protect rights or users, prevent fraud or security threats, respond to lawful requests from authorities, or as part of a merger, acquisition, financing, restructuring or sale of all or part of our business, subject to appropriate safeguards.

10. International transfers

Some organisations that help us provide the Service may process information outside the United Kingdom.

Where personal information is subject to UK transfer restrictions, we will use an appropriate transfer mechanism where required, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved Standard Contractual Clauses, or another lawful safeguard.

11. Data retention

We keep personal information only for as long as necessary for the purpose for which it was collected.

Our intended production retention position is:

  • Customer Content: while the customer account remains active.
  • Customer Content following account termination: targeted for deletion from active systems within 30 days.
  • Backup copies: may remain for up to 90 days before being overwritten or deleted.
  • Security and platform logs: normally up to 12 months, unless longer retention is reasonably necessary to investigate a security event.
  • Billing and tax records: retained for the period required by applicable tax and accounting law.
  • Marketing records: until the person opts out or the information is no longer reasonably required.

These periods must be verified against the final production architecture before contractual publication. Aggregated or genuinely de-identified information that no longer identifies an individual may be retained for longer.

12. Security

We use appropriate technical and organisational measures designed to protect information against accidental or unlawful loss, destruction, alteration, disclosure or access.

Measures may include, where appropriate, encryption in transit, encryption at rest, role-based access controls, authentication controls, logging and monitoring, data separation, vulnerability management, backup and recovery procedures, and restricted staff access.

No system can guarantee absolute security. Customers are responsible for protecting their own login credentials and appropriately configuring their account.

13. Your rights

Depending on applicable law and our role in processing information, individuals may have rights including access, correction, deletion, restriction, data portability, objection, withdrawal of consent where processing is based on consent, and the right to complain to a supervisory authority.

Where we rely on legitimate interests, individuals have the right to object in appropriate circumstances. Individuals have an absolute right to object to personal information being used for direct marketing.

Requests relating to information for which Personalise is controller may be made through our support/contact functionality. If information is being processed by Personalise on behalf of one of our customers, we may refer the request to that customer.

14. Automated decision-making

Personalise may automate the selection or presentation of website content according to rules, segments or customer-provided information.

The Service is not intended to make solely automated decisions about individuals that produce legal effects or similarly significant effects.

Customers must not use the Service for such purposes unless they have independently established that their use is lawful and have entered into any additional arrangements required with us.

15. Sensitive information

The Service is not intended for processing special-category personal data under UK or EU data protection law; health or medical information; biometric or genetic information; government identification numbers; complete payment-card information; account passwords belonging to third-party services; precise location information; or other highly sensitive information, unless expressly agreed otherwise in writing.

Customers must not upload such information without prior written approval.

16. Children

Personalise is a business service and is not directed at children. Customers must not intentionally use the Service to profile or personalise experiences for children in a manner that would breach applicable law.

17. Changes to this Policy

We may update this Privacy Policy from time to time. Where changes are material, we will provide appropriate notice through the Service, website or other communication. The date at the top identifies the latest version.

18. Contact and complaints

Privacy questions and requests can be raised through the support/contact functionality available through the Service.

If an individual is in the United Kingdom and is unhappy with how their personal information has been handled, they also have the right to complain to the Information Commissioner's Office. We would appreciate the opportunity to address concerns first.

HomePrivacy PolicyTerms & Conditions