Legal
Privacy notice
Version 1.0 · Last updated 1 August 2026
This notice covers the Toleris marketing website. The Toleris application at app.toleris.co is a separate system, governed by the customer agreement.
At a glance
Last updated: 1 August 2026 · Version: 1.0
This website does one thing with personal data: it takes the details you enter in the Book a demo form and emails them to our sales inbox so that we can reply to you. We call what you send us your demo request, and the email it produces the enquiry email.
No cookies, no advertising tags and no database. There is one optional analytics tool, which runs only if you allow it and which sets nothing on your device.
The rest of this notice sets out the detail, including the IP address our abuse controls read, the fact that your name and firm appear in the subject line of the enquiry email, and what exercising your rights looks like when there is no database to search.
What this notice covers — and what it does not
In scope. This notice covers the Toleris marketing website at www.toleris.co and its subpages, and the /api/demo-request endpoint that the demo form posts to.
Not in scope. The Toleris application at app.toleris.co is a separate system with its own authentication, its own data storage and its own processing. Personal data in the application is governed by the customer agreement and the data processing agreement we enter into with the subscribing firm, not by this notice. Nothing on our Security page — which describes the application's controls — should be read as a description of this website.
When you click Sign in, you leave this website and arrive at app.toleris.co. From that point the application's terms and its data processing agreement apply.
No other collection points. The demo form is the only place on this website where you can give us personal data. There is no account creation, no newsletter sign-up, no file upload, no live chat, no comments and no site search.
Who we are
Toleris is a trading name of Toleris Ltd, a company registered in England and Wales with company number 17259283, registered office Viglen House Business Centre, Alperton Lane, Wembley, England, HA0 1HD.
For the processing described in this notice we are the controller. We decide what is collected and why.
Data protection contact: Data Protection Lead — privacy@toleris.co, or by post at Viglen House Business Centre, Alperton Lane, Wembley, England, HA0 1HD.
Data protection officer. We are not required to appoint a statutory data protection officer under Article 37 UK GDPR and have not appointed one. The contact above is the responsible point of contact for everything in this notice.
We are established in the United Kingdom, and this notice is written to the UK GDPR.
What we collect
3.1 What you give us in a demo request
| Field | Required? | Limit enforced on submission |
|---|---|---|
| First name | Yes | 1–100 characters |
| Last name | Yes | 1–100 characters |
| Work email address | Yes | Valid email format, up to 200 characters |
| Firm name | Yes | 1–200 characters |
| Your role | Yes | 1–120 characters |
| Firm type | Yes | 1–120 characters, chosen from a list on the form |
| Message | No | Up to 2,000 characters |
We do not ask for, and this website has no way of receiving, a telephone number, a postal address, a date of birth, a payment detail, a government identifier, or any special category data as defined in Article 9 UK GDPR.
The message box. Whatever you type there is placed into the enquiry email and sent to our sales inbox. Please do not use it to send confidential incident details, regulatory correspondence, or personal data about anyone other than yourself. If you need to discuss something sensitive, ask us for a call in the message and we will arrange one.
If a demo request does contain personal data about someone else, we delete that part on receipt wherever we can. Where we cannot, we treat it under Article 14 UK GDPR — which means telling that person how we are using their data, unless that proves impossible or would involve disproportionate effort, in which case this notice is the public statement of that processing.
3.2 The hidden anti-spam field
The form contains a hidden field that you will never see: it sits off-screen and is kept out of the keyboard tab order, so it cannot be completed by a person using the form normally. Automated form-filling software does complete it. Any demo request that arrives with that field filled in is discarded and no email is sent. It is not stored, and it is not included in any email we send.
3.3 Your IP address
See section 6.
3.4 What your browser exposes to the page
The website reads two display settings that your browser makes available as standard: the width of your browser window, and whether you have asked your operating system to reduce motion. They are used for one purpose — deciding how the page lays out and whether it animates. They are evaluated in your browser, used immediately to render the page, and never transmitted to us or to anyone else. Section 8 explains the legal position on that reading.
3.5 What we do not collect from anywhere else
We collect personal data only from you, directly, through the form. We do not obtain information about you from public web sources, data brokers, list vendors, enrichment services or social platforms, and we do not append anything to what you tell us.
Why we use it, and our lawful basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Reading your demo request, replying to you, and arranging and running the demo you asked for | All demo request fields | Article 6(1)(b) — steps taken at your request before entering into a contract. You asked us to contact you; we cannot do that without your details |
| Continuing the conversation after the demo — following up, answering later questions and keeping the opportunity open | Name, work email, firm name, role, firm type and anything in your message | Article 6(1)(f) — our legitimate interest in pursuing an opportunity you started. We have carried out and recorded a legitimate interests assessment; you can ask us for a summary, and you can object at any time |
| Protecting the form from automated abuse: the hidden-field check, the submission rate limit and the origin check | IP address; the hidden field value | Article 6(1)(f) — our legitimate interest in keeping a public form usable and in preventing our infrastructure being used to send bulk unsolicited mail. We have carried out and recorded a legitimate interests assessment and will provide a summary on request |
| Keeping the enquiry email on file while the opportunity is live and for a limited period afterwards, so that we can answer follow-up questions, honour what we told you, and evidence what we did | The enquiry email | Article 6(1)(f) — our legitimate interest in a reliable record of an enquiry we were asked to answer |
| Complying with a legal obligation, or establishing, exercising or defending a legal claim | The enquiry email, and our correspondence with you about it | Article 6(1)(c) where we must comply with a specific legal obligation — for example responding to a lawful request from a court, a regulator or a law enforcement body, or retaining records required by tax and company law if the enquiry becomes a transaction. Article 6(1)(f) where we need to establish, exercise or defend a legal claim |
Your right to object — set out separately because the law requires it. Where we rely on legitimate interests, you have the right to object at any time under Article 21(1), on grounds relating to your particular situation. Where anything we send you amounts to direct marketing, your right to object under Article 21(2) is absolute — we must stop, with no balancing exercise and no exceptions. To object, email privacy@toleris.co or reply to any message from us. There is no charge, and you do not have to give a reason for a direct marketing objection.
What we do not do with it. We do not add you to a mailing list, and we send no marketing emails from this website. We do not put your details into a marketing automation platform, score you as a lead, or make any decision about you by automated means. If we ever want to market to you beyond replying to and following up on the demo request you made, we will update this notice first and, where the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) require consent, ask for it separately and unbundled from anything else.
Do you have to provide it?
No. Providing your details is not a statutory requirement, not a contractual requirement, and not a requirement necessary to enter into a contract with us — at this stage there is no contract between us, and you are under no obligation to give them.
The practical consequence of not providing them is that we cannot arrange a demo. The form will not submit without a first name, last name, work email address, firm name, role and firm type, because we have no other way to identify who has asked and how to reply. The message field is optional and the form works without it.
If you would rather not use the form, email privacy@toleris.co or use the details on our Contact page, and we will arrange a demo without it.
Your IP address and our abuse controls
Everything else in this notice starts with you filling in the form. This does not, so we set it out in full.
What happens. When you submit a demo request, the code that handles the request reads the client IP address that our hosting provider attaches to the incoming request (the x-forwarded-for header) and uses it as the key for a counter. The counter allows five submissions from the same IP address within a 60-second period, after which further submissions are rejected with an error message and no email is sent. Each server instance keeps its own counter, so this is a deterrent against casual abuse rather than a hard ceiling.
Where the counter lives. In the working memory of the individual server instance handling your request. It is not written to a database — this website has none. It is not written to disk. It is not put into the enquiry email. Our own code does not write it to a log; our hosting provider's platform logging is separate and is described at the end of this section. The IP address is never used to identify you, to locate you, or to build any record or profile, and it is never combined with the details you entered in the form.
How long it is held. The 60 seconds is the length of the counting window, not a deletion timer, and our code does not actively delete entries. Where a fixed period is not possible, the law lets us give you the criteria we use instead, so here they are: an entry exists only in the working memory of the single server instance that handled your request, and only until our hosting platform recycles that instance — which it does routinely, on its own schedule, and outside our control. Nothing is written to persistent storage, each instance holds only what it has itself seen, and nobody at Toleris can read the contents of that memory.
We also make a best-effort check of where the request came from, by reading the request's Origin and Host headers. It rejects submissions that a browser reports as coming from an unrelated website. It is a deterrent against casual misuse rather than a guarantee — a request that sends no origin information is allowed through, and the hidden-field and rate-limit checks are what catch it. Neither header is stored or logged.
Separately, our hosting provider logs your IP address. Vercel operates the servers that deliver this website and logs the IP address of every request as part of running and defending the platform. That happens whether or not our own code reads it. Vercel does this as our processor for the purpose of serving this website; to the extent it also uses platform logs for its own platform security, abuse-prevention and service-integrity purposes, it acts as a controller in its own right for those uses, under its own privacy policy. Either way the logs are subject to the retention set out in section 10.
International transfers
Vercel and Resend are US-headquartered and operate global infrastructure, so personal data submitted through the demo form is transferred outside the UK. The mechanism relied on for each transfer is set out below.
| Recipient | Transfer destination | Mechanism relied on |
|---|---|---|
| Vercel Inc. (Covina, California, USA) — hosting | Processing happens in the United Kingdom. The function that receives your demo request is pinned to Vercel's London region, so the form data is handled on UK infrastructure. Our contract is with Vercel's US parent, and its staff can access the platform for support, so a transfer to the USA can still occur. | Adequacy — Vercel Inc. is certified under the UK Extension to the EU–US Data Privacy Framework for non-HR data. Vercel's data processing addendum also incorporates the ICO's International Data Transfer Addendum, which applies if that certification lapses. |
| Plus Five Five, Inc., trading as Resend (San Francisco, California, USA) — email delivery | United States | Adequacy — Plus Five Five, Inc. is certified under the UK Extension to the EU–US Data Privacy Framework for non-HR data, with the ICO's International Data Transfer Addendum in its data processing addendum as the fallback. |
| Google Cloud EMEA Limited (Dublin, Ireland) — the sales@toleris.co mailbox | Ireland in the first instance. Google may transfer onward to Google LLC in the United States for hosting and support. | To Ireland: covered by the UK's adequacy regulations for the EEA, so not a restricted transfer at all. Onward to the USA: adequacy — Google LLC is certified under the UK Extension for non-HR data, with the EU standard contractual clauses and the UK Addendum in Google's data processing addendum as the fallback. |
Where the mechanism stated is adequacy, we rely on regulations made under Article 45A UK GDPR — specifically the UK Extension to the EU–US Data Privacy Framework — and on the provider's active certification under that framework for the relevant category of data.
Where the mechanism stated is appropriate safeguards, we rely on the ICO's International Data Transfer Agreement or the UK Addendum to the European Commission's standard contractual clauses, supported by a transfer risk assessment carried out against the data protection test in Article 45B UK GDPR.
Every transfer above is to a destination covered by adequacy regulations made under Article 45A UK GDPR — Ireland under the regulations for the European Economic Area, and the United States under the Data Protection (Adequacy) (United States of America) Regulations 2023, each of Vercel Inc., Plus Five Five, Inc. and Google LLC being currently certified under the UK Extension for the type of data concerned. We check those certifications on the Data Privacy Framework list rather than taking the provider's word for it, and if one lapses the transfer falls back to the contractual safeguards named above, supported by a transfer risk assessment.
You can obtain a copy of the safeguards by emailing privacy@toleris.co. We will send them, redacted only where a copy would disclose commercially confidential terms unrelated to your data.
We monitor the standing of the frameworks we rely on. If an adequacy route ceased to be available for a provider, we would move that transfer onto appropriate safeguards under Article 46 — the ICO's International Data Transfer Agreement or the UK Addendum — or suspend the transfer.
We make no claim about the country in which any individual demo request is physically processed at a given moment. If data residency matters to your firm's assessment of us, ask and we will tell you the current configuration of each provider in writing.
How long we keep it
There is no database behind this website, so there are only four places a demo request exists.
| Where | What is there | How long |
|---|---|---|
| Our sales inbox | The enquiry email, containing everything you submitted | 24 months from our last contact with you about it, after which we delete it. If the enquiry becomes a customer relationship, the information moves into that relationship and is retained under the customer agreement instead |
| Resend's sending records | Its record of the message we asked it to send, including the subject line and body | Resend's standard retention period for sent-message records. We will tell you the current period on request, and we ask Resend to purge records on request |
| Vercel's platform logs | Request logs including IP addresses, and — if an email failed to send — the resulting error | Our hosting provider's standard retention period, after which they are deleted automatically. We will tell you the current period on request |
| The rate-limit counter | An IP address only | In one server instance's memory until that instance is recycled. See section 6 |
Delivery errors. If the enquiry email fails to send, our code records the error returned by the email provider. Those error messages come from the provider, and in some delivery failures they quote the email address involved. Form contents are never deliberately logged, but that path can put an email address into a hosting log entry for the retention period above.
Retention is enforced by us, not by the software. Nothing in this website deletes anything, because it stores nothing. Deleting a demo request means deleting the enquiry email. Deletion is a scheduled control with a named owner, run against the sales inbox on a quarterly cycle.
How we protect it
In transit. The site is served over HTTPS by our hosting provider, and we send an HTTP Strict Transport Security header with a two-year lifetime covering our subdomains, so that browsers which have visited us before refuse an unencrypted connection to this site. We also set X-Content-Type-Options: nosniff; Referrer-Policy: strict-origin-when-cross-origin; X-Frame-Options: SAMEORIGIN, which stops other websites embedding our pages in a frame, the standard protection against clickjacking; and a Permissions Policy that disables camera, microphone and geolocation. The server does not advertise the software it runs.
On submission. Every field is validated on the server and capped in length, so what can be submitted is bounded. Values placed into the HTML version of the enquiry email are escaped, so submitted text is rendered as text rather than as markup. The hidden-field check, the rate limit and the origin check are described in sections 3.2 and 6.
By design. This website has no user database, no document store, no session store and no local file writing. There is no store for an attacker to reach through the website itself, which leaves the mailbox described in section 7 as the place where a demo request is held longest and in full. That is why the access controls on it matter more than anything on the website.
If a breach affecting your personal data occurred and it was likely to result in a risk to your rights and freedoms, we would report it to the ICO within 72 hours of becoming aware, and tell you directly where the risk was high.
Your rights
You have the following rights over personal data we hold about you. Exercising them is free of charge, and we respond within one month.
- Access (Article 15) — a copy of what we hold, and information about how we use it.
- Rectification (Article 16) — correction of anything inaccurate, and completion of anything incomplete.
- Erasure (Article 17) — deletion, where one of the Article 17 grounds applies.
- Restriction (Article 18) — a pause on our use of it while a dispute about accuracy or our legitimate interests is resolved.
- Objection (Article 21) — to any processing we base on legitimate interests, and absolutely to direct marketing. Set out in full in the callout in section 4.
- Portability (Article 20) — a copy in a structured, commonly used, machine-readable format, and transmission to another controller where technically feasible. This applies to the details you submitted through the form, which we process by automated means in order to respond to your demo request. In practice this means we send you the contents of your demo request; because we hold no database record, there is nothing further to export.
- Withdrawal of consent — we do not currently rely on consent for anything on this website. If that changes, you will be able to withdraw at any time, and withdrawal will not affect the lawfulness of what we did before it.
- Rights relating to automated decision-making (Article 22 and the provisions that replaced it) — not engaged. There is no automated decision-making and no profiling on this website.
What exercising these rights looks like in practice
This website holds no record with an identifier attached to it. There is no account to open, no dashboard to export from, and no row to delete. Servicing a rights request means searching our sales inbox for the demo request you sent, acting on what we find, and asking our email provider to purge the corresponding sending record.
So when you contact us, tell us the email address and firm name you used on the form, and roughly when you submitted it. Where we need that clarification to find your data, the one-month clock pauses from the day we ask until the day you reply. We will say why we are asking.
We will carry out a reasonable and proportionate search. For this website that means a search of the sales inbox and a request to our email provider. Our hosting provider's logs are not searchable by enquirer and hold at most an email address where a delivery failure occurred; section 10 sets out what can appear in them and for how long.
To make a rights request, contact privacy@toleris.co or write to Viglen House Business Centre, Alperton Lane, Wembley, England, HA0 1HD.
How to complain
You have two routes. You can complain to us, and you can complain to the Information Commissioner. We would rather you came to us first, because we can usually put things right faster — and the ICO may ask whether you have already raised the matter with us.
Complain to us. You have a statutory right under section 164A of the Data Protection Act 2018 to complain to us about how we have handled your personal data. A complaint runs separately from a rights request under section 12, and on its own timetable. Send it to privacy@toleris.co, marked Data protection complaint, or by post to Viglen House Business Centre, Alperton Lane, Wembley, England, HA0 1HD. We will acknowledge it within 30 days and respond without undue delay, telling you what we found and what we have done.
Complain to the Information Commissioner. You have the right under section 165 of the Data Protection Act 2018 to complain to the ICO, the UK's data protection regulator.
Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 ico.org.uk/make-a-complaint
You may also apply to the court.
Changes to this notice
We will update this notice when what we do changes. The version number and date at the top of the page will change with it, and a short summary of what changed will appear at the foot of this page.
If we ever want to use information you already gave us for a new purpose, we will tell you about that purpose, and give you the relevant information, before we start.
We do not operate a mailing list, so we do not routinely announce changes — the version and date at the top of this page are the reliable check. If we change this notice in a way that affects a demo request you have already sent us, we will email you at the address you gave.
Contact us
Email: privacy@toleris.co Post: Data Protection Lead, Toleris Ltd, Viglen House Business Centre, Alperton Lane, Wembley, England, HA0 1HD
Our registration details are in section 2. For personal data held inside the Toleris application, see section 1.