Private Alpha Privacy Notice
alpha-privacy-1.0 · Controlled alpha · Operator review draft
Who operates TELSTEAD
Elliot Cardwell operates TELSTEAD. Contact hello@elliotcardwell.uk about privacy, correction, access, export or deletion. This notice concerns the private alpha application; the public website enquiry notice covers a different workflow.
Information and purposes
We use your business email, name, organisation membership, account security information, acceptance records and concise feedback to provide and secure the controlled alpha. Passwords are stored as secure hashes; MFA secrets are encrypted. Security and operational events help investigate access, faults and misuse. We do not record keystrokes or use session-replay tracking.
For service account administration and security, the proposed basis is legitimate interests in operating and protecting the agreed business evaluation, subject to operator confirmation. Plastim remains responsible for the authority and instructions governing supplied QMS content. Optional feedback is used to evaluate product usefulness; this application does not enrol you in marketing.
Providers and geography
Microsoft Azure supplies hosting, storage and the selected Foundry semantic service. Planned application storage is UK South; GlobalStandard inference may occur in the United States. OpenAI US processing is an operator-accepted assumption where applicable, not a verified Astra-specific processor chain. Review the Data Processing Acknowledgement and service-provider disclosure for the remaining conditions.
Retention and rights
The proposed alpha schedule removes active QMS content within 30 days of termination or an agreed deletion request, subject to identified legal obligations. Minimal account, acceptance and security records are proposed for 12 months after the alpha. Backup expiry is separate and must be verified before real intake. These are proposed controlled-alpha periods requiring operator approval.
You may ask about access, correction, deletion, restriction, objection and portability where applicable, and complain to the UK Information Commissioner at ico.org.uk. We verify the requester and applicable rights before disclosure. Contact hello@elliotcardwell.uk first if you wish us to investigate a concern.
Security and review status
The application uses authenticated organisation access and MFA, with TLS required for hosting. No security system eliminates all risk. Essential session cookies support sign-in; no non-essential analytics or advertising tracking is included. This private notice is a draft for operator review before real onboarding; it does not assert unrestricted production approval.