Legal

Privacy Policy

How RhSoft collects, uses, stores, and shares personal data when you visit our website or work with us on software — AI, blockchain, web, e-commerce, and mobile.

Last updated: September 7, 2026

This policy covers rhsoft.co.uk and related RhSoft sites. A signed statement of work or data processing addendum (DPA) controls if it conflicts with this page. We do not sell personal information.

1. Who we are

RhSoft (“we”, “us”) is a software development company. For website inquiries we are the controller of the personal data you submit. For production systems we build for a client, that client is typically the controller and we act as a processor under their instructions.

2. Information we collect

We collect only what we need to respond, quote, deliver, and operate the site. Categories include:

Identity & contact

Name, email, phone, preferred contact method, and company details you type into contact or quote forms.

Project details

Scope notes, tech stack, files you upload, repositories you grant access to, and messages about AI, blockchain, web, e-commerce, or mobile work.

Technical data

IP address, browser type, device, pages viewed, and approximate location derived from analytics and server logs.

Cookies

Session and analytics cookies (including Google Analytics) that help us understand site use and keep the theme/session working.

We do not intentionally collect special-category data (health, biometrics, precise location) through the public website. Do not paste secrets, private keys, or production dumps into contact forms.

3. How we use data

  • Answer contact and quote requests and send confirmation emails.
  • Prepare proposals, SOWs, and technical estimates for AI, blockchain, web, e-commerce, and mobile work.
  • Deliver, support, and invoice contracted software projects.
  • Improve the website, diagnose errors, and measure which pages help visitors.
  • Comply with law, enforce our Terms of Service, and protect against fraud or abuse.

Legal bases (where GDPR or similar rules apply) include contract, legitimate interests in running a software studio, consent for optional analytics where required, and legal obligation.

4. Cookies and analytics

We use Google Analytics (measurement ID G-7CBBF8YY45) to understand traffic: pages viewed, approximate geography, device, and referral source. Google may process this data under its own terms. You can block analytics with browser settings, extensions, or Google’s opt-out tools.

Essential cookies or local storage may remember theme (light/dark) and session state. We do not use advertising pixels to sell profiles to third-party ad networks.

5. Sharing and processors

We do not sell personal information. We share data only with:

  • Email / SMTP. Form notifications and confirmations are sent through our email provider so we can reply to you.
  • Hosting & CDN. The website is served from our hosting platform; logs may include IP and user-agent.
  • Analytics. Google Analytics, as above.
  • Cloud & tools on projects. If you grant access, data may sit in AWS, GCP, Vercel, GitHub, Supabase, Firebase, app-store consoles, or similar tools you approve in an SOW.
  • Professional advisers and law. Accountants, insurers, or authorities when legally required.

Vetted subcontractors who help deliver code work under confidentiality. They may only use personal data to perform that work.

6. AI and project data

  • Prompts, datasets, and evaluation files you send for an AI engagement are used only to build and test that product, unless you agree otherwise in writing.
  • We do not use your confidential production data to train public foundation models.
  • If an SOW uses a third-party model API (OpenAI, Google, Anthropic, or similar), that vendor processes prompts under its policy. Avoid sending live customer PII in prompts unless the SOW and DPA cover it.
  • You are responsible for lawful collection of any training data you supply (consent, licenses, employment notices).

7. Blockchain and public chains

Wallet addresses, transaction hashes, and contract events written to a public blockchain are public by design. We cannot erase on-chain data. Off-chain KYC, admin dashboards, and custodial systems are separate; those are processed only as agreed in the SOW. We are not a crypto exchange and do not custody user funds unless a contract expressly says so.

8. Retention

  • Contact and quote records: typically up to 24 months after last correspondence, unless a contract or tax rule requires longer.
  • Project repositories and credentials: for the life of the engagement, then returned or deleted per the SOW.
  • Analytics: according to Google Analytics’ settings and our hosting log rotation (often 14 months or less for detailed hits).
  • Invoices and legal correspondence: as required by accounting and limitation periods.

9. Security

We use HTTPS, access-controlled inboxes, and reasonable technical and organizational measures. No method of transmission is perfectly secure. You should use unique passwords, 2FA on cloud and git accounts, and a secrets vault instead of emailing private keys. Report suspected incidents to the contact below promptly.

10. Your rights

Depending on where you live (including the EEA/UK and certain U.S. states), you may have the right to access, correct, delete, or port personal data, to object or restrict certain processing, and to withdraw consent. You may also lodge a complaint with a supervisory authority.

California residents: we do not sell or share personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. To exercise rights, email us with enough detail to verify the request. We will not discriminate against you for exercising privacy rights.

11. International transfers

We and our processors may store or access data in the United States and other countries. Where a transfer tool is required (for example EU Standard Contractual Clauses), we will use it for client project data under a DPA. The public website may be viewed globally.

12. Children

Our website and services are directed at businesses and adults. We do not knowingly collect personal data from children under 16 (or 13 where that is the applicable threshold). If you believe we have, contact us and we will delete it.

13. Changes

We may update this policy as products, laws, or processors change. The “Last updated” date is the effective date. Material changes will be reflected on this page; continued use of the site after that date constitutes awareness of the new policy.

14. Contact