Privacy Policy
Last updated: 21 September 2026
RapidLayer Ltd. ("RapidLayer", "we", "us"), company number 17429287, registered office 88 Colson Road, Loughton, IG10 3RJ, United Kingdom, is the data controller for the personal data described in this policy. This policy explains what personal data we collect through the RapidLayer platform (the "Service"), why, and the rights you have over it. It applies to visitors to our website and to users of the Service.
1. Data we collect
Account data — name, work email address, and a securely hashed password for you and any users your administrators create.
Organisation data — the portfolio, benchmark, FX and market-value data your organisation uploads or enters to use the Service. This may incidentally include personal data such as a named portfolio manager.
Usage and audit data — login times, pages visited and actions taken within the Service (create, edit, upload, export, delete), recorded against your account for security, troubleshooting and audit-trail purposes.
Billing data — for paid subscriptions, our payment processor Stripe collects and stores your payment card details on our behalf. RapidLayer does not receive or store full card numbers.
Support communications — anything you send us via the in-product support form or by email.
2. Why we process it, and our legal basis
- To provide the Service — account data and organisation data are processed to run the platform you or your organisation subscribed to (performance of a contract).
- Security and audit — usage and audit data are kept to detect misuse, investigate incidents, and meet the audit-trail expectations of an institutional platform (legitimate interests).
- Billing — billing data is processed to collect payment and administer your subscription (performance of a contract).
- Support and product communications — to respond to you, and to send service notices (e.g. renewal reminders, account-created confirmations) directly related to your use of the Service (performance of a contract / legitimate interests).
3. Who we share data with
We use a small number of subprocessors to run the Service, each engaged under a data processing agreement:
- Microsoft Azure(UK South region) — hosting, database and file storage. Your organisation's data resides in the UK.
- Stripe — payment processing and subscription billing.
- Resend — delivery of transactional emails (account creation, password reset, billing and renewal notices).
We do not sell personal data, and we do not share Customer Data with other organisations using the Service — tenant data is logically isolated. Some subprocessors may process data outside the UK; where that happens, we rely on appropriate safeguards such as Standard Contractual Clauses.
4. Cookies
We use a small number of strictly necessary cookies to keep you signed in: a session cookie on this site, and an HttpOnly authentication cookie on the API. These are required for the Service to function and are not used for advertising or cross-site tracking. We do not currently use third-party analytics or advertising cookies.
5. How long we keep data
- Account data is kept for as long as your organisation has an active subscription, plus a reasonable period afterwards in case you resubscribe or as required for legal/accounting purposes.
- Audit log entries are retained according to your organisation's subscription tier — 1 year, 3 years or 7 years depending on tier, reflecting institutional record-keeping expectations. Deleted records (portfolios, benchmarks, users) are soft-deleted and recoverable for an administrator-visible period before permanent removal.
- Billing records are retained for as long as required by UK tax law.
- Demo account data is not retained beyond the demo period.
6. Your rights
Under UK data protection law, you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Most account data can be viewed and updated directly in your account settings. For anything else, or to make a formal request, contact us at support@rapidlayer.io. If you are not satisfied with our response, you have the right to complain to the UK Information Commissioner's Office (ico.org.uk).
Where the data in question is Customer Data uploaded by your organisation rather than your own account data, we will generally direct the request to your organisation's administrator, who controls that data.
7. Security
We apply role-based access control, tenant isolation, encryption in transit (HTTPS) and at rest, and audit logging across the Service. Access to production data is restricted to what is necessary to operate the platform.
8. Children
The Service is intended for business use by investment professionals and is not directed at children.
9. Changes to this policy
We may update this policy from time to time. Material changes will be notified to account administrators by email or through the product before they take effect.
10. Contact
Questions about this policy, or requests relating to your personal data, can be sent to support@rapidlayer.io.