Privacy Policy
Last updated 28 July 2026
1. Who is responsible for your data
Yeema Holdings Ltd (company number 15809333, 128 City Road, London, EC1V 2NX) is the data controller for personal data we collect about our own customers and website visitors.
Where you run a community on Sovura, you are the controller for your members' data and we act as your processor — we handle it on your instructions, to provide the Service.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account data | Discord ID, username, avatar, email address | To create and authenticate your account |
| Organisation data | Community name, slug, roles, members, settings | To operate the Service you signed up for |
| Content you create | Applications, tickets, CAD records, site pages, uploaded media | To provide the modules you enable |
| Billing data | Plan, subscription status, invoices. Card details are handled by our payment processor and never reach our servers | To take payment and manage your plan |
| Technical data | IP address, browser type, request logs, error reports | Security, abuse prevention, diagnosing faults |
| Product analytics | Pages visited, features used, aggregated usage | To understand what to improve |
We do not intentionally collect special category data. Please do not put it into free-text fields.
3. Why we are allowed to use it
- Contract — providing the Service you signed up for, including billing.
- Legitimate interests — keeping the Service secure, preventing abuse, understanding product usage, and communicating about material changes. We balance these against your rights.
- Legal obligation — accounting and tax records, and responding to lawful requests.
- Consent — where we ask for it, such as optional marketing email. You can withdraw consent at any time.
4. Who processes data on our behalf
We use a small number of specialist providers to run the Service. We disclose them by category rather than by name; if you need the named list — for example for your own compliance records or a DPA — email us and we will provide it.
| Category | Purpose | Data location |
|---|---|---|
| Cloud application and database hosting | Running the Service and storing your data | European Union |
| Edge network and content delivery | Serving the sites, caching assets, DDoS protection | Global edge, with EU origin |
| Object storage | Uploaded media and community assets | European Union |
| Payment processing | Taking payment and issuing invoices | EU / US, under appropriate safeguards |
| Transactional email | Account, billing, and notification email | EU / US, under appropriate safeguards |
| Identity provider | Discord sign-in | US, under appropriate safeguards |
| Error monitoring and product analytics | Diagnosing faults and measuring feature usage | EU / US, under appropriate safeguards |
All providers act under contract, may only process data on our instructions, and are bound to appropriate security obligations. Where data leaves the UK or EEA, we rely on adequacy decisions or standard contractual clauses.
We do not sell your personal data, and we do not share it with advertisers.
5. How long we keep it
- Account and content data — for as long as your account is active, then 30 days after closure so it can be exported or recovered, then deleted.
- Backups — purged on their own rolling schedule, normally within 35 days.
- Billing records — retained for 6 years to meet UK accounting and tax obligations.
- Security and request logs — typically 90 days.
6. Your rights
Under UK GDPR you can ask us to:
- give you a copy of your personal data;
- correct data that is wrong or incomplete;
- delete your data, where we have no overriding reason to keep it;
- restrict or object to how we use it;
- port your data to another provider;
- withdraw consent, where consent was the basis for using it.
Email privacy@sovura.app. We respond within one month. If you are a member of someone else's community on Sovura, please contact that community's staff first — they control that data, and we will refer your request to them.
You can also complain to the UK Information Commissioner's Office at ico.org.uk.
7. Security
Data is encrypted in transit and at rest. Access to production systems is restricted and authenticated, and permissions inside the Service are scoped by role. No system is perfectly secure — if a breach affects your personal data and presents a risk to you, we will notify you and the ICO as required by law.
8. Children
The Service is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
9. Cookies
We use cookies and similar storage that are strictly necessary to sign you in and keep your session secure, plus limited analytics to understand product usage. We do not use advertising cookies or third-party ad trackers.
10. Changes
We may update this policy. Material changes will be notified by email or in-product notice before they take effect. The date at the top always reflects the current version.
11. Contact
privacy@sovura.app — Yeema Holdings Ltd, 128 City Road, London, EC1V 2NX, United Kingdom. Company number 15809333.