Legal & compliance
Privacy Policy
How Epiow collects, uses and protects personal data across the platform.
Last updated: 27 September 2026
Who is responsible for your data
The controller of the personal data this policy describes is the company below, registered in England and Wales.
- Controller
- Epiow Limited
- Company number
- 16877523
- Registered office
- 128 City Road, London, EC1V 2NX, United Kingdom
- VAT number
- GB507912687
- Data protection contact
- privacy@epiow.com
1. About this policy
This policy explains how Epiow Limited ("we" or "us") collects, uses and protects personal data when you visit epiow.com, create an account or use the Epiow workspace and its apps. We are the controller of this data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where the EU GDPR or other local law also applies, sections 14 and 15 explain what changes.
2. Your workspace data
Data that an organisation, household or person puts into a workspace (for example employee records, pupil records or household documents) belongs to the workspace. For that data, the workspace owner is the controller and we process it only on their instructions, under the processing terms at epiow.com/legal/dpa. If you are an employee, pupil or member of someone else's workspace, send requests about that data to the workspace's administrator; we assist them as those terms require.
3. What we collect
As controller, we collect:
- Account details: name, email address and the workspaces you belong to.
- Workspace details: its name, type, country and the plan it is on.
- Billing details: billing contact, address, VAT number and invoices. Card details go to our payment provider and never reach us.
- Usage and device data: sign-in records, IP address, browser and device type, how the Service is used, and security logs.
- What you send us: support requests, feedback and messages to sales.
4. Why we use it, and our lawful basis
We use personal data for these purposes:
- To provide the Service to you, create and secure your account, and bill you, because it is necessary for our contract with you (UK GDPR Article 6(1)(b)).
- To keep accounting and tax records and answer lawful requests from authorities, because the law requires it (Article 6(1)(c)).
- Because we have legitimate interests that are not overridden by your rights (Article 6(1)(f)): to provide the Service to the Users of an organisation's workspace, run billing and accounts, keep the Service secure, detect and prevent fraud and abuse, fix and improve the Service, market our services to business customers and their contacts, and prepare for or carry out a sale or reorganisation of our business. You can ask us for the balancing test we rely on.
- To send product news to individuals: with your consent, or, where you are an existing customer, about similar services unless you opt out. You can withdraw consent or opt out at any time from the link in each email (Article 6(1)(a) and 6(1)(f)).
5. AI features
When you use the AI assistant, what you ask and the workspace data it needs are sent to our AI providers to generate a reply. We do not use your content to train AI models, and our AI providers may not use it for training. With zero data retention on (Settings, Security), providers keep no request data; with it off, they may keep request data for a limited period, for example to detect abuse.
6. Who we share it with
We do not sell personal data. We share it:
- with service providers that host, secure, support or bill for the Service, under written contracts; they are listed at epiow.com/legal/subprocessors;
- with our professional advisers, auditors and insurers;
- with authorities, courts or others where the law requires it or where needed to establish, exercise or defend legal claims;
- with a buyer, investor or successor, or their advisers, if all or part of our business or its assets is sold, financed or reorganised; and
- with anyone else when you ask us to or agree.
7. International transfers
Some providers process data outside the United Kingdom. When data leaves the UK, we rely on UK adequacy regulations or on the International Data Transfer Agreement or Addendum issued by the Information Commissioner, with additional safeguards where needed. You can ask us for a copy of the safeguards that apply.
8. How long we keep it
We keep account data while the account is open, and billing and accounting records for as long as tax law requires. Backups and logs are kept for a limited period and then overwritten or deleted. After a workspace is closed and its export period has passed, we delete or anonymise its data. We may keep data for longer where the law requires it, or where we need it to establish, exercise or defend legal claims or to prevent fraud and abuse.
9. Security
We protect personal data with measures appropriate to the risk, which currently include the following. No system is completely secure, and we cannot guarantee the security of data sent to or stored in the Service.
- encryption of data in transit (TLS);
- separation of each workspace's data from every other workspace's data;
- role-based access control, with access to production data limited to staff who need it; and
- audit logs of administrative actions.
10. Your rights
Under the UK GDPR, and subject to the conditions and exemptions in the law, you have the right to:
- get a copy of your personal data;
- have inaccurate data corrected;
- have your data deleted, where there is no reason for us to keep it;
- restrict how we use your data;
- receive your data in a machine-readable format, or have it sent to another provider;
- withdraw consent where we rely on it; and
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you.
11. Your right to object
You have the right to object at any time to our processing of your personal data based on our legitimate interests, on grounds relating to your situation, and to object to direct marketing, in which case we will stop.
12. Using your rights and complaints
Email privacy@epiow.com, or use the contact page at epiow.com/contact. We may ask you to confirm your identity first. We answer within one month, which we may extend by two further months where a request is complex or one of several, and we will tell you if we do. We carry out reasonable and proportionate searches. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse it. If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk. We would appreciate the chance to resolve your concern first.
13. Children
People must be 18 or over to have an Epiow sign-in. A household or school workspace can include children as members without their own sign-in, managed by a parent, guardian or the school, which is the controller of that data. We do not use children's data for advertising or profiling, and use it only to provide the workspace.
14. If you are in the European Union
If the EU GDPR applies to our processing of your data, you have the same rights as in sections 10 and 11 and the same lawful bases apply. You may also complain to the data protection authority in the EU country where you live or work.
15. If you are in Hong Kong
If the Personal Data (Privacy) Ordinance (Cap. 486) applies, you may ask to access and correct personal data we hold about you, and you may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong.
16. Cookies
We use only the cookies the Service needs to keep you signed in and to work, and any other cookie only with your consent. We do not use advertising cookies. Details are at epiow.com/legal/cookies.
17. Changes to this policy
We may update this policy. Changes take effect when we post them on this page and update the date above. If we plan to use your personal data for a new purpose, we will tell you before we do.
18. Contact
Email privacy@epiow.com, or use the contact page at epiow.com/contact.