Security & Trust

How we look after your data.

Landing Platform holds your clients, your campaigns and your commercial numbers. This page sets out how that data is separated, encrypted, governed and — when you ask — deleted, in enough detail that your IT or legal team can assess it without sending us a questionnaire first.

Separation

The question we get asked most is whether one customer can ever see another's data. Here is how the boundary is drawn.

01 Per-tenant isolation

Every record belongs to exactly one account and is filtered at the query layer on every request. There is no shared table of customer records and no cross-account view.

02 Your data stays yours

Your CRM, contacts, companies, campaigns and documents are yours. We process them on your instruction as your processor, under our DPA — and never use them to build anything of our own.

03 Our data is clearly marked

The media contacts directory is ours, held as an independent controller and served to every account. It is a separate system with its own governance, and it never mixes with your records.

Access and encryption

Controls that apply to every account, not only to enterprise plans.

Encrypted in transit and at rest

TLS 1.2 or better for everything on the wire. Credentials, tokens and connected-account secrets are encrypted at rest.

Granular access profiles

Permissions are assigned per person, per feature, with least-privilege defaults. Someone who should only see one part of the system only sees that part.

Multi-factor authentication

Available on every account and enforced for administrative access, by authenticator app, SMS or email.

Full audit logging

Sensitive actions are logged with who, what and when — including support impersonation, which is always recorded and always visible to you.

The part most platforms will not show you

Media contacts governance

Our directory holds around 260,000 journalists. They did not sign up for it, so the burden is on us to hold it properly. This is the actual mechanism, not a statement of intent.

01

A journalist asks to be left alone

By email to our published privacy address, or through the unsubscribe link in any message sent through the platform.

02

It applies to every customer at once

Not just the sender's list. One request withholds their details across the whole platform — no account can reveal, list, sync or email them again.

03

Deletion that actually survives

If they ask to be removed, the record is deleted and a minimal, hashed marker is kept — visible to nobody — purely so a later data refresh cannot quietly bring them back.

04

We tell the customers who held their details

Every access is logged, so we know precisely which accounts saw that contact — and we notify them to delete their own copies rather than hoping they notice.

05

People who have left the profession come out

Retired and deceased contacts are withdrawn from the directory, so you are never handed details for someone it would be a mistake to approach.

Where your data lives

Hosting, the third parties involved in running the service, and what happens when a new one is added.

WhatWhere and how
Application & databaseDedicated infrastructure in the European Economic Area, operated by OVH. Automated daily backups, plus a full backup taken immediately before every deployment.
Analytics & searchDedicated infrastructure in the United Kingdom, operated by OVH, reachable only from our own application servers.
Email deliveryTransactional and campaign mail is sent through named providers; sending domains are authenticated with SPF, DKIM and DMARC.
Sub-processorsPublished in full, with what each one does and where it operates. We give 30 days' notice of any addition, with a right to object.
International transfersAs a UK controller, transfers into the European Economic Area rely on the UK's adequacy regulations. Where a provider operates further afield, transfers run on Standard Contractual Clauses with the UK Addendum.

Questions we get asked, answered

These arrive on nearly every security questionnaire. Rather than making you send one, here are our answers.

QuestionOur answer
Are you our processor?For everything you create or upload, yes — under our DPA, with the full Article 28 terms. The media contacts directory is different: there we are an independent controller with our own lawful basis and published notice, and you are an independent controller of how you use it. They are separate systems.
Can you access our data?Only where support requires it. Access is role-limited, every instance is logged, and support impersonation is recorded and visible to you.
Do you use our data to train AI?No. Where a feature calls an AI provider, only the data needed for that task is sent, and it is not used to train models.
Do you sell data?No — not your data, and not the media directory.
What happens if we leave?Your data stays exportable for 30 days after termination, then is deleted from live systems, with backups rotating out within 90 days — except anything the law requires us to keep, such as financial records for tax.
How do you handle a subject access or deletion request?Within one calendar month. We assist with requests that reach you as controller, and handle directly those aimed at data we control.
Do you notify us of new sub-processors?Yes — 30 days' notice, with a right to object.
Can we audit you?Yes. We provide our security documentation on request, and the DPA sets out audit rights beyond that.

Rights and retention

Specific periods rather than "as long as necessary", so you can hold us to them.

Acting on a request

Requests to our published privacy address get a response within one calendar month. Corrections and objections are actioned across the whole platform, not just the account that raised them. Where the law requires us to keep something, or we need it to defend a legal claim, we keep that much and say so.

Your data after you leave

Exportable for 30 days, deleted from live systems thereafter, and out of backups within 90 days. Financial records are kept for six years because tax law requires it.

Media directory records

Kept while someone is professionally active, reviewed on a rolling basis, and withdrawn when they leave the profession or ask us to stop.

Access and analytics logs

Directory access records are kept for 24 months and then deleted automatically. Website analytics, including visitor IP addresses, expire after 13 months.

When something goes wrong

! We tell you quickly

If a breach affects your data we notify you without undue delay and within 72 hours of confirming it — early enough for you to meet your own regulator deadline.

! We tell you what we know

What happened, whose data, likely consequences, what we have done and a named contact — in stages if the picture is still forming, rather than silence until it is complete.

! We write it down

Every incident is recorded and reviewed, and our runbook is updated from what we learn. Findings are available to customers on request.

Something we have not answered?

Security and privacy questions go to a monitored mailbox and get a real answer, not a form response. Questionnaires welcome — most of the answers are already on this page.

privacy@pivotal.digital