Privacy Policy
Last updated: 11 July 2026
This Privacy Policy explains how Octavo (the “Service”) collects, uses and protects your personal data, and describes the rights you have under the UK GDPR and EU GDPR. It should be read alongside our Terms of Service.
1. Who we are
The Service is operated by Cherry Wood Software Ltd, a company registered in England and Wales (company number 09547944) with its registered office at 28 Ferndale Road, Teignmouth, TQ14 8NH, United Kingdom. For the personal data we hold about you as an account holder, Cherry Wood Software is the data controller. You can reach us about privacy matters at robin@cherrywoodsoftware.com.
Where you use the Service to store personal data about other people (for example, inside your pages or in form responses your members submit), you are the data controller for that data and we act as your data processor, handling it on your instructions to provide the Service.
2. The data we collect
- Account data — your name and email address, and authentication data such as your hashed password and sign-in links.
- Workspace content — the pages your agents and members author, made up of typed content blocks, together with page titles and structure.
- Ingested images — images fetched from URLs your agents supply, which we store on our servers so they can be re-served on your pages.
- Form responses — answers submitted by members of your workspace through forms published on your pages.
- Sharing data — the guest share links you create and their settings.
- API keys — the keys you issue so your agents can connect over MCP.
- Technical data — limited server logs (such as IP address and timestamps) generated when you use the Service, kept for security and reliability.
3. How and why we use your data
We use personal data to:
- create and administer your account and authenticate you;
- operate the Service — storing, rendering and serving your pages, images and form responses;
- send transactional email such as sign-up verification, magic sign-in links and notifications to editors when a form response is submitted;
- provide support and respond to your enquiries;
- keep the Service secure, prevent abuse, and comply with our legal obligations;
- bill you if you subscribe to a paid plan (when paid plans launch).
AI and automated processing
Content in your workspace is authored by your own AI agents, which connect to the Service using the API keys you issue. We do not transmit your workspace content to third-party AI providers ourselves; any interaction with an AI model happens through your own agents, under your control. We render the structured data your agents send us with our own components.
4. Legal bases
We rely on the following legal bases under the GDPR:
- Performance of a contract — to provide the Service you have signed up for and to bill you for paid plans.
- Legitimate interests — to secure and improve the Service, prevent abuse, and communicate with you about your account, balanced against your rights.
- Legal obligation — to comply with applicable law, such as tax and accounting requirements.
- Consent — where we ask for it specifically; you can withdraw consent at any time.
5. Who we share data with
We do not sell your personal data, and we do not share it for advertising. We share it only with the service providers (sub-processors) we use to run the Service, each bound to protect it:
- Amazon Web Services (AWS Lightsail) — hosting and storage of the Service and its data.
- Postmark — delivery of transactional email (verification, sign-in links, and form-response notifications).
- Paddle — payment processing and billing, when paid plans launch. Paddle acts as merchant of record and processes your payment details directly.
We currently use no analytics or advertising services — we do not run Google Analytics or any comparable tracking. We may also disclose data where required by law or to protect our rights, and we may transfer data as part of a business reorganisation, in which case this Policy will continue to apply.
6. How your content is shared
Your workspace content is private to your workspace by default. Members can create revocable, read-only guest share links; a link covers the shared page and its sub-pages. Sources your agents flag as sensitive are withheld from shared views. You decide who is a member of your workspace and which share links exist, and you can revoke access at any time.
7. International transfers
Some of our providers may process data outside the United Kingdom or European Economic Area. Where that happens, we ensure appropriate safeguards are in place — such as an adequacy decision, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses — so your data receives an equivalent level of protection.
8. Data retention
We keep your personal data for as long as your account is active and as needed to provide the Service. When you close your account or ask us to delete your data, we delete or anonymise it within a reasonable period, except where we must keep certain records to comply with legal obligations (for example, billing and tax records) or to resolve disputes.
9. Cookies
We use only strictly necessary cookies — principally a session cookie that keeps you signed in. We do not use analytics, advertising or third-party tracking cookies.
10. Security
We take the security of your data seriously. Data is encrypted in transit using TLS, the infrastructure that runs the Service is hardened and kept up to date, and access to production systems is limited to the people who need it. No online service can be guaranteed completely secure, but we work to protect your data and to detect and respond to incidents promptly.
11. Your rights
Under the UK GDPR and EU GDPR you have the right to access, correct, erase, restrict and object to the processing of your personal data, to data portability, and to withdraw any consent you have given. To exercise any of these rights, contact us at robin@cherrywoodsoftware.com. We will respond within one month.
If we process personal data as your data processor (data you have stored about other people), please direct such requests to the relevant workspace owner, who is the controller for that data; we will assist them in responding.
You also have the right to complain to a supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO) at ico.org.uk.
12. Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you.
13. Contact
For any question about this Policy or your personal data, contact us at robin@cherrywoodsoftware.com, or by post to Cherry Wood Software Ltd, 28 Ferndale Road, Teignmouth, TQ14 8NH, United Kingdom.