Last updated: 25 June 2026.
01. Scope & Contact Details
Datro is a guided business data workspace designed to help small businesses organise sales, customers, costs, and operations. This Privacy Policy explains how we collect, use, store, and share your personal data when you visit our marketing website (https://datro.co.uk), use the Datro platform (https://app.datro.co.uk), or communicate with us.
Datro is a trading name of Mission Metrics LTD, a company registered in England and Wales under Company Number 16984989. Our registered office is at 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE.
For any questions, requests, or to exercise your privacy rights, please contact our team:
- General Support & Support Privacy Email: hello@datro.co.uk
- Corporate & Legal Enquiries Email: info@missionmetrics.io
02. Datro as a Data Controller vs. Data Processor
Depending on how you interact with our platform, we operate in two distinct roles under the UK General Data Protection Regulation (UK GDPR) and related EU laws:
- Datro as a Data Controller: We act as a Data Controller for account registrations (your email, name, organization settings), invoicing and transaction data, marketing enquiries, and cookies tracking your website visit. In these scenarios, we decide why and how the data is processed.
- Datro as a Data Processor: We act as a Data Processor for all data that you enter, import, or synchronise into your Datro tables, databases, reports, or collect through public form submissions. In these scenarios, you are the Data Controller. We process your workspace data strictly on your instruction and in accordance with our terms of service.
Are you a form respondent?
If you have filled out a public form created by a Datro customer, your submission is controller-owned by that business. Datro only stores and formats this data for them. To request access, modification, or deletion, please contact the business that shared the form link with you.
03. The Information We Collect
We collect and process the following categories of information depending on your activity on the platform:
| Data Category | Specific Elements | Primary Purpose | Legal Basis (UK GDPR) |
|---|---|---|---|
| Account Data | Name, email, company, password hash. | Authenticate and manage your workspace account. | Performance of a Contract |
| Billing Data | Billing address, tax ID, transaction logs. | Process subscription fees (handled securely by Stripe). | Performance of a Contract |
| Workspace Database | Records in tables, products, costs, public form submissions, imports. | Render customer tables, build reports, and run dashboards. | Performance of a Contract (Processor instructions) |
| Ari AI Prompts | Questions about your numbers or table generation commands. | Instruct the AI assistant to perform actions or analyse data. | Performance of a Contract |
| Enquiry Data | Name, email, company size, custom query message. | Respond to marketing site contact forms. | Consent / Legitimate Interest |
| Technical Logs | IP address, browser version, access timestamps, usage logs. | Maintain platform stability, spot bugs, and block fraud. | Legitimate Interest |
04. How We Use Your Information
We process your data to deliver a secure, fast, and guided workspace experience. Specifically, we use collected information to:
- Create and configure your workspace tables and default dashboard.
- Process subscription payments and manage trials via Stripe.
- Generate performance insights, monthly reports, and CSV exports at your command.
- Execute Ari AI assistant actions (e.g. creating tables or summarising margin trends).
- Secure our servers, prevent unauthorized logins, and stop malicious bots.
- Respond to enquiries, feedback, and support tickets sent through our help channels.
- Perform analytics to understand how visitors engage with the marketing website.
05. Disclosing Data to Subprocessors
We do not sell, rent, or trade your personal or business data. We share data only with third-party service providers (subprocessors) necessary to host and deliver the platform under strict data processing agreements:
| Partner | Service Provided | Data Disclosed | Location / Safeguard |
|---|---|---|---|
| Stripe, Inc. | Payment gateway & invoice billing. | Billing address, card token (card details bypass our servers). | US / UK Adequacy & SCCs |
| Hosting Infrastructure | Cloud database, server hosting, API gateways. | All workspace tables and account profiles. | UK / EEA regions |
| AI API Partners | LLM endpoints to power Ari AI. | In-transit prompts and query schemas (not stored permanently). | UK / US (No model training permitted) |
| FormSubmit | Marketing contact form routing. | Enquiry name, email, and message details. | UK / EEA / US |
| Google Analytics | Web traffic counting and page interaction statistics. | Anonymised IP addresses, page clicks, session duration. | EEA / US |
Stripe Secure Payments
Billing is managed directly by Stripe. All transactions are PCI-DSS Compliant. Datro never stores, logs, or views raw payment card numbers.
06. Ari AI Data Commitment
Ari is Datro's built-in AI assistant. To provide table recommendations, custom schema generations, and answers about your numbers, Ari must securely interpret query context from your workspace databases.
Our AI Privacy Commitment
Your database records and text queries sent to Ari AI are processed via secure API endpoints. We explicitly enforce commercial agreements with our LLM partners ensuring that none of your proprietary business data is ever retained or used to train public foundation models. Furthermore, Ari's access is isolated to your private account and verified server-side.
07. Data Security Measures
We deploy robust organizational and technical measures to protect your records:
- Encryption: All connections to Datro are encrypted via Transport Layer Security (TLS/HTTPS). Database contents are encrypted at rest.
- Access Control: We enforce row-level database separation to prevent crossover between accounts. Customer database tables are accessible only to authenticated users belonging to that workspace.
- Staff Access: Our support staff will never access your private workspace tables unless you explicitly request assistance with a spreadsheet import or troubleshooting ticket.
08. Data Retention
We retain your data only for as long as necessary to fulfill the purposes outlined in this policy or to comply with corporate accounting and legal standards:
- Active Subscription Data: Retained for the duration of your active account subscription.
- Account Deletion: If you delete your account, we delete all customer table databases, reports, forms, and account profile details within 30 days.
- Billing Auditing: Stripe transactional data, invoices, and payment histories are retained for statutory tax record-keeping (up to 7 years in the UK).
- Inquiries: Contact form details are deleted or anonymised 12 months after the enquiry has been resolved.
09. Cookies and Analytics
This website uses cookies to remember settings, identify sessions, and measure page activity:
- Essential Cookies: Required to keep you logged into the application and prevent cross-site request forgery (CSRF). These cannot be disabled as the app would cease to function safely.
- Analytics Cookies: Set by Google Analytics to help us understand which marketing pages are working. These are only stored if you consent to site tracking. You can manage or block cookies through your browser privacy dashboard.
10. Your Rights & Complaints
Under UK GDPR, EU GDPR, and relevant privacy laws, you possess substantial rights regarding your personal data. You are entitled to request:
- Access: Retrieve a complete copy of all personal information we hold about you.
- Correction: Correct any inaccurate or incomplete personal records.
- Deletion (Right to be Forgotten): Erase your account profile and associated personal data from our systems.
- Portability: Transfer your data to another platform. You can export any table as a CSV directly in the Datro application.
- Restriction & Objection: Object to automated processing, or restrict processing under specific disputes.
To exercise these rights, please email us at hello@datro.co.uk or info@missionmetrics.io. We will confirm your identity and respond to your request within 30 days free of charge.
If you feel we have not handled your data fairly, you have the right to lodge a complaint with the UK supervisor, the Information Commissioner's Office (ICO), at https://ico.org.uk, or contact your local European data protection commissioner.
