privacy

Privacy notice

This notice covers two different things and keeps them apart on purpose. The first is this website, which Tenhaw LTD operates and is the controller for: it counts page views without cookies and stores nothing on your device at all, which is why you were not asked to accept anything on the way in. The second is Token Observe the software, which you run on your own infrastructure with your own provider keys — it sends Tenhaw no telemetry, we hold no copy of any trace database, and supplying it therefore does not make us a processor of anything flowing through your deployment. Conflating those two is what makes most vendor privacy notices useless, so they are answered separately below.
draft — not yet reviewed by counsel

This notice is a draft. No solicitor has reviewed it, and it is not yet a legal instrument you can rely on.

It is published in this state deliberately, because on a site that publishes its own defect list the alternative would be a placeholder. Counsel approval of the licence, the evaluation terms, the privacy and data-processing position and the support language is the first item on the product’s own mandatory commercial gate, and that gate has not passed. Until it does, read what follows as the company’s stated position rather than as a notice settled by a lawyer.

Where the draft cannot yet state a fact — a named processor, a retention period actually operated, the position on a data processing agreement — it says so in the clause instead of filling the gap, and clause 18 collects every one of those in a single list. If a supplier assessment depends on this page, write to hello@tenhaw.com and say so, and you will be told plainly which parts are settled and which are not.

Tenhaw LTD, registered in England and Wales, no. 12735685Last updated hello@tenhaw.com
On this page

1. The two things this notice keeps apart

This notice is about tokenobserve.com, the marketing website you are reading. Tenhaw LTD is the controller for the small amount of personal data that website processes, and clauses 2 to 12 describe all of it.

It is not a notice about your Token Observe deployment. Token Observe is self-hosted software: it runs inside your network, on infrastructure you control, against your own model-provider accounts using keys you supply. Whatever personal data passes through it is processed by you, under your own controllership, and supplying the software does not make Tenhaw a processor of it — not because a contract says so, but because no copy of it reaches us and there is no vendor-operated component anywhere in the request path. Clauses 13 to 15 set out that position, the narrow arrangements that would change it, and what a deployment actually holds, so that your own data protection officer knows where to look.

If you are completing a supplier assessment, those two halves usually map to different questions on the same form. Answering both from one paragraph is where most vendor notices go wrong, and it is the reason this one is shaped the way it is.

2. Who we are, and how to reach us

Tenhaw LTD, a company registered in England and Wales under company number 12735685, incorporated on 10 July 2020 and based in London, publishes Token Observe and operates this website. The registration is public and linked below, so it is a checkable fact rather than a claim.

Privacy questions and data subject requests about this website go to hello@tenhaw.com. Vulnerability reports go to security@tenhaw.com. Both are read by a person rather than a queue, and both are the addresses published in the product’s own repository rather than mailboxes invented for a website. There is no separate privacy@ or dpo@ address: creating one for this document would make its first specific statement untrue.

Tenhaw has not appointed a data protection officer and, on the processing described in clauses 3 to 12, is not required to. Whether that changes once the product is sold under a signed agreement is one of the questions counsel is being asked.

3. What this website collects, in full

Page-level analytics through Plausible, which sets no cookies and stores nothing on your device. It records the page, the referring source, the country derived from your IP address, and the class of device and browser. Your IP address is used in transit to derive a rotating daily hash so that returning visits are not double-counted, and is not stored; nothing is set that could follow you to another site.

A small number of named events, so that the site can tell which arguments are actually read: a page opened, a page scrolled far enough to have been read, a named section reached, a call to action clicked, a command copied, a link to the repository followed, and a question asked of the on-page assistant. Each carries the page and a short label. None carries anything you typed, and none is attached to a person.

That is the whole of the automated collection. There is no second analytics tool, no advertising or cross-site tracking, no visitor-identification or IP-to-company resolution service, no session recording or replay, and no product analytics of any kind. One third party is contacted by your browser when you load a page, and it is the one named above.

Whatever our hosting provider records in order to serve the page, which is an ordinary request log: IP address, timestamp, path and user agent.

That is the complete list. There is no advertising or cross-site tracking, no visitor-identification or IP-to-company resolution tool, no session recording or replay, no embedded chat, no booking calendar and no form of any kind. The typefaces are served from this site, having been fetched at build time, so loading a page makes no request to Google Fonts.

4. Cookies, and why there is no banner

This website sets no cookies. Not “no non-essential cookies” and not “none until you accept”: none at all. It writes nothing to your device, reads nothing from it, and stores nothing in localStorage, sessionStorage or IndexedDB.

That is why you were not shown a consent banner, and the reason is worth stating rather than leaving you to wonder whether one failed to load. The rule that produces cookie banners is about storing information on, or gaining access to information already on, your equipment. This site does neither, so there is nothing to ask you about — and a banner asking permission for something that was going to happen regardless would be a worse thing to have built than no banner at all.

The consequence is that there is nothing for you to switch off, and nothing to withdraw. If that ever changes — if a tool is added that writes to your device — a banner comes back with it and this clause is rewritten in the same commit, because the assertion above is a total and one addition falsifies it.

5. Why the one analytics tool runs for everyone

Plausible runs for every visitor, and it is not behind a gate. It stores nothing on your device and reads nothing from it, so the rule that requires consent before storing or accessing information on your equipment has nothing to bite on. Our lawful basis is legitimate interests — knowing which pages are read and which answer the question somebody arrived with — and the balancing test is short because the processing is aggregate, cookieless and carries no identifier that could follow you anywhere.

Running one ungated tool rather than a gated one beside it is a deliberate choice with a cost, and the cost falls on us rather than on you. What is given up is demographic breakdown, cross-device identity and user-level funnels, none of which is available without storing something on your device. What is gained is that the measurement is complete: a gated tool is declined most often by exactly the privacy-conscious readers this site is written for, so its numbers would have been systematically missing the people who matter most here.

Your IP address is used in transit to derive a rotating daily hash so returning visits are not double-counted, and is not stored. Plausible Insights OÜ processes on our behalf, in the European Union.

6. What this site deliberately does not run

An earlier draft of this notice described a consent-gated Google Analytics property alongside the cookieless counter. That arrangement was removed rather than configured, and this clause records the absence so a reader comparing versions is not left wondering which is current.

There is no Google Analytics, no Google Tag Manager and no Google script of any kind on this site — the content security policy in next.config.ts no longer permits those origins, so one could not load even if a page asked for it. There is no advertising network, no remarketing pixel, no A/B testing tool, no heatmap or session replay, no chat widget, no booking calendar and no form of any kind on the site.

The typefaces are served from this origin, having been fetched at build time, so loading a page makes no request to Google Fonts either. On any page you load, your browser contacts this site and Plausible, and nothing else.

7. What happens when you email one of the published addresses

This site has no contact form, no calendar and no lead-capture step, deliberately. The way to reach us is to write to a person, and the addresses are published on every page.

An email reaches a mailbox operated by our email provider and is read by James Rooney, or by whoever is named on the address you wrote to. We keep it so that we can answer you and, where a conversation follows, so that we can remember what was said. The lawful basis is our legitimate interest in responding to an enquiry addressed to us, or, where you are asking about evaluating or buying the product, the steps taken at your request before entering a contract.

What you send is what we hold: your address, your name if you sign it, your employer if the address or the signature shows it, and whatever you wrote. Nothing is enriched from a third-party data provider, scored, or added to a marketing list — there is no marketing list to add it to, and this site sends no marketing email.

The email provider is a processor, and it must be named here, with its location and its transfer basis, before this draft is published as a settled notice. That is the first open item at clause 18.

8. The on-page assistant

Several pages carry a panel that answers questions about the page you are on. What you type is sent to this site’s own server and from there to Anthropic PBC, which generates the answer; the API key stays on the server and never reaches your browser. Each message is capped at a thousand characters, and at most the last ten messages of a conversation are sent.

Nothing you type is written to a database, because this website has no database. The only thing the endpoint retains is a short in-memory record of the requesting IP address and the times of its recent requests, so that a public endpoint which spends money cannot be run up by a script. It is discarded within a minute and never persisted.

Anthropic’s own terms govern what it does with what it receives. Do not type anything confidential into the panel: it is a reading aid on a public marketing site, not a support channel, and the support channel is email.

9. Lawful bases, in one place

Plausible and the aggregate event counts: our legitimate interest in understanding which pages of our own site are read, assessed as low-risk because nothing identifies a visitor and nothing is stored on their device.

Nothing on this site relies on consent, because nothing on it stores or reads anything on your device. Where a notice like this one would normally list a consent basis, the honest entry is that there is no processing here that needs one.

Answering your email: our legitimate interest in responding to correspondence addressed to us, or, where you are asking about evaluating or buying the product, steps taken at your request prior to a contract.

Records we are required by law to keep, including records relating to a contract once one exists: legal obligation.

There is no processing on this website that relies on performance of a contract with you, because reading a website is not a contract you have entered. There is no automated decision-making producing legal or similarly significant effects, no profiling, and no sale or sharing of personal data for anybody else’s purposes.

10. Who else processes data for this website

Vercel Inc., which hosts and serves the site. Plausible Insights OÜ, in the European Union, for the cookieless page counts. Anthropic PBC, for the text of questions typed into the on-page assistant. Our email provider, for correspondence, which clause 18 records as still to be named. That is the complete list, and it is four entries long because the site loads one third-party script.

That is the whole list, and it is short because the site is deliberately plain: no font content delivery network, no tag manager loading third parties nobody has reviewed, no embedded video, no chat, no calendar, no testing tool. A content security policy restricts what a page is permitted to load to that list, so a tool added to the site without being added here fails to load rather than running unannounced.

No sub-processor of a Token Observe deployment appears on that list, because Tenhaw has none. Your deployment calls the providers and tool servers you configure, with the credentials you supply, and we are not in that path at all.

11. Transfers out of the UK and the EEA

Vercel, Google and Anthropic are established in the United States. Where personal data reaches them, it is transferred under the UK International Data Transfer Addendum or the EU standard contractual clauses incorporated in their respective terms, with the supplementary measures those terms describe. Plausible processes within the European Union. The transfer basis for the email provider follows once that provider is named.

A Token Observe deployment makes no transfer to Tenhaw, in any jurisdiction, because it sends us nothing. There is no international transfer to assess between you and us in respect of the software, which is a shorter answer than a transfer impact assessment and a more durable one.

12. How long any of it is kept

Plausible holds aggregate statistics rather than a record about a visitor, so there is nothing attached to you to age out and no retention period to state. That is a consequence of the tool choice rather than a policy we operate: there is no per-visitor record here whose age we could decide.

Correspondence is proposed to be kept for 24 months from the last message, unless you become a customer, in which case for the term of the agreement and six years afterwards to meet the record-keeping obligations that follow a contract. Assistant conversations are not kept at all beyond the life of the request that produced them.

Every figure in this clause is a proposal in a draft. Retention is the first thing a data protection officer checks and the thing a draft is least entitled to state as settled, so it is flagged here rather than presented as operating practice, and it appears again at clause 18.

13. The product: why supplying it makes us a processor of nothing

Token Observe is self-hosted, bring-your-own-key software. It runs on infrastructure you control, authenticates to model providers with keys you supply, and keeps its whole persistent state in one configured database on your disk. There is no vendor-operated component anywhere in the request path, and no hosted or managed offering exists.

It sends us nothing: no telemetry, no usage counter, no crash reporting, no licence callback and no phone-home of any kind. That is a property of the code rather than a setting you could forget to turn off — no such call exists to disable. The security page publishes the procedure for confirming it yourself in about five minutes, and section 9 of the licence exists so that you may run it, including fuzzing and penetration-testing your own deployment and commissioning somebody else to do it, with no gag clause and no pre-approval of what you publish.

The consequence for data protection is the important one. We hold no copy of your traces, your prompts, your policy decisions or your audit chain. We cannot reach your deployment and we hold no credential into your estate; every integration points inwards. And we cannot act on your instructions in respect of that data, because none of it arrives here. On the ordinary meaning of the words, supplying this software does not make Tenhaw a processor of anything that flows through it.

The same fact cuts the other way and is stated on the security page in the same terms: if the database file is lost and there is no backup, the traces and the audit chain are gone, because there is no vendor-side copy to restore from. Back it up like evidence, to storage the operators of the database cannot rewrite.

14. What would change that, and what counsel is being asked

The architecture settles a technical question and does not by itself settle the legal one, so the position in clause 13 is stated for the running software and not for every arrangement around it. Four things can put personal data into our hands by choice rather than by design, and each needs an answer of its own.

A support ticket. The default is that we receive nothing, so a diagnostic bundle, a trace excerpt or an export attached to a ticket is a decision you make rather than something the product does. What happens to it is governed by the support agreement rather than by the architecture. Redact before sending.

An evaluation. The thirty-day evaluation grant in the licence excludes live production traffic and regulated personal data in its own words. An evaluation run inside those limits leaves the position in clause 13 intact; one run outside them does not.

Incident handling, and any design-partner or professional-services arrangement under which someone from Tenhaw is given access to your environment. Both create a relationship the architecture says nothing about.

Any hosted or managed offering. None exists today. If one ever does it is a different product with a different data position, and it needs its own notice rather than a paragraph added to this one.

Whether any of those requires a data processing agreement is a question for counsel rather than for a marketing page, and it is on the list at clause 18. The product’s own readiness documentation reaches the same conclusion and is careful about it: runtime phone-home is zero, while evaluation terms, support handling and anything you choose to put in a diagnostic bundle are contracts rather than architecture.

15. What a Token Observe deployment holds, so your own DPO knows where to look

This is your processing rather than ours, and it is set out here because a controller cannot assess software whose storage they have to reverse-engineer. Every statement below is documented in full on the security page, and the limits travel with the claims.

The prompt corpus is bounded and post-redaction. A trace event holds an excerpt of up to four thousand characters, read off the outbound payload after redaction has run rather than off the original, so the search index cannot contain what the redactor removed; tool arguments and results are capped at sixteen thousand; redaction records are kinds and counts rather than values. Model response text is not stored. Full prompts are not stored. No API key exists in the database in any form.

Three tables deserve a data protection officer’s specific attention, and they are exactly the ones a summary would leave out. An approval record can contain up to 160 characters of unredacted model-generated text, because the action summary is built before egress redaction runs. Identity-provider group snapshots are attributes of a named person and should be treated like HR-adjacent data rather than like configuration. Radar findings can carry staff usernames, workstation hostnames and, where per-user seat spend is supplied, the email addresses of named employees.

Retention is unset by default, and unset means keep forever. That default over-satisfies the six-month minimum in Article 26(6) of the EU AI Act and satisfies nothing in Article 5(1)(e) of the UK GDPR, so a deployment processing personal data has to set the window rather than inherit it. Subject erasure reaches traces, trace events, the search index and trace scores, and nothing else: the audit log is deliberately never touched, which is what lets the record of a deletion outlive the deleted data, and approvals, radar findings and webhook delivery records are neither purged nor erasable by subject. Erasure acts on the live primary database, so restoring a pre-erasure backup can resurrect what was erased.

None of that is a Tenhaw processing activity. It is a map of where personal data in your own deployment actually sits, published so that your assessment can be done from documentation rather than from a support call.

16. Your rights

In respect of what this website holds about you — which in practice means your correspondence, since the analytics hold no record attached to you — you have the rights the UK GDPR gives you: access, rectification, erasure, restriction, objection, and portability where it applies. Write to hello@tenhaw.com and you will have a reply within one month. There is no charge and you do not have to give a reason.

In respect of a Token Observe deployment we cannot help you, and that is not a deflection. The controller is the organisation running it; we have no access to it and hold no copy of it, so a request addressed to us would reach nothing. Direct it to them. The product gives their operator an audited erasure endpoint with a dry run that reports the count before anything is removed, and clause 15 sets out what that endpoint does and does not reach.

If you are not satisfied with how we have handled something, you can complain to the Information Commissioner’s Office at ico.org.uk. You can do that without coming to us first, though we would rather you did.

17. Changes, and children

This notice will change: it is a draft, and the first substantial change to it will be whatever counsel returns. The date at the top of this page is generated from the change history of the file rather than typed by hand, so it moves when the words move. A material change affecting an existing customer will be notified directly rather than left to be noticed.

This site is not directed at children, no part of it is designed to appeal to them, and nothing on it asks for an age or collects one. It is documentation for enterprise software.

18. What this draft cannot state yet

Collected here rather than scattered through the document, so that a solicitor reviewing it has the open questions as a list and a reader relying on it knows exactly where the gaps are.

The email provider that holds correspondence, its location and its transfer basis. The retention periods actually operated, as against the ones proposed at clause 12. Whether Tenhaw’s processing requires registration with the Information Commissioner’s Office, and the registration number if it does. Whether evaluation terms, support handling, incident response or design-partner access require a data processing agreement, and what that agreement says. And whether the position at clause 13 survives review in the words used here.

Until each of those is closed, this document is exactly what the notice at the top of the page says it is.

19. Contact

Privacy questions and data subject requests about this website: hello@tenhaw.com. Vulnerability reports, about the software or about this site: security@tenhaw.com. Both reach a person rather than a queue.

Tenhaw LTD, London, England. Registered in England and Wales, company number 12735685, incorporated 10 July 2020.