Privacy policy
Last modified: June 22, 2026
1. About Efestra
If there are any questions regarding this Privacy Policy you may contact us using the information below.
Efestra is the trading name of Digital Tonic Ltd
Bartle House, Oxford Court
Manchester M2 3WQ
United Kingdom
Phone: +44 161 870 6749
E-mail:in**@*****ra.com
Company registration number 07811720
VAT GB206256333
Our customers may submit inquiries regarding personal data protection, privacy and security matters to CEO Manuel da Costa via email on in**@*****ra.com.
2. Introduction
This policy sets out the different areas where user privacy is concerned and outlines the obligations and requirements of the users, the website and website owners. Furthermore, the way this website processes, stores and protects user data and information will also be detailed within this policy.
This website and its owners take a proactive approach to user privacy and ensure the necessary steps are taken to protect the privacy of its users throughout their visiting experience. This website and the Efestra platform comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the EU General Data Protection Regulation (EU) 2016/679 where applicable.
3. Data Controller
Digital Tonic Ltd (trading as Efestra) is the data controller for personal data collected through our website, platform and services. Our contact details are set out in Section 1.
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.
4. Lawful Basis For Processing
Under UK GDPR, we must have a valid lawful basis for processing your personal data. The lawful bases we rely on are:
Contract: where processing is necessary for the performance of a contract with you, or to take steps at your request before entering into a contract. This applies to account creation, service delivery, billing and customer support.
Legitimate interests: where processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those interests. This applies to platform analytics, security monitoring and product improvement.
Consent: where you have given clear consent for us to process your personal data for a specific purpose. This applies to marketing communications and optional AI-powered features. You may withdraw consent at any time by contacting us at in**@*****ra.com or by using the unsubscribe link in marketing emails.
Legal obligation: where processing is necessary for us to comply with the law. This applies to regulatory and tax record-keeping.
5. Information We Collect
Directly Provided Data
When you sign up for our platform, purchase our products, complete assessment tools or communicate with us, you may choose to voluntarily give us certain information. This includes:
- Name, email address and organisation details when creating an account
- Billing and payment information when purchasing services
- Responses to assessment tools such as the Evidence Gap Score
- Content you enter into the platform, including experiment documentation, insights and decision records
- Communications with our support team
Automatically Collected Data
When you use our website or platform, we automatically collect certain technical information:
- Device and browser information
- IP address and approximate location
- Pages visited and features used
- Session duration and interaction data
We use PostHog (hosted in the EU) for product analytics. PostHog collects anonymised usage data to help us understand how our platform is used and to improve the experience. PostHog does not use this data for any purpose other than providing analytics services to us.
User Authorised Data
Depending on your settings or the privacy policies for other online services, you may give us permission to obtain information from your account with those other services. For example, this can be via social media or by choosing to send us your location data when accessing our website from your smartphone.
Mosaic Companion (Meeting Recording)
If you or your organisation uses Mosaic Companion, our AI-powered meeting tool, the following additional data may be collected:
- Meeting audio recordings and transcriptions, processed via Recall.ai
- Extracted insights, experiment ideas and action items generated from meeting content
- Participant names as visible in the meeting platform
Mosaic Companion only joins meetings when explicitly invited by a user. Meeting recordings and transcriptions are processed to extract structured insights and are then stored within your organisation’s Efestra account. Participants should be informed that the meeting is being recorded in accordance with applicable laws.
6. AI & ML Processing
Efestra’s AI features (branded as Mosaic) are powered by commercial API integrations with Anthropic (Claude) and OpenAI. These features include experiment design recommendations, evidence synthesis and meeting analysis.
How AI processing works:
- When you use AI-powered features, relevant context from your session is sent to the AI provider’s API for processing
- All data is transmitted via encrypted connections (TLS 1.3)
- AI providers process data under their commercial API terms, which prohibit the use of API inputs and outputs for model training
- Customer data is not used, even in de-identified form, to train or improve any AI model
- AI features are optional and can be disabled at any time without affecting core platform functionality
Data Processing Agreements:
We hold Data Processing Agreements with both Anthropic and OpenAI, incorporating Standard Contractual Clauses for international data transfers. These agreements contractually prohibit the use of customer data for model training or improvement.
7. Cookies and Tracking
What are cookies?
Cookies are small files saved to your device that track, save and store information about your interactions and usage of the website. This allows the website to provide you with a tailored experience.
What do we use cookies for?
Strictly necessary cookies: These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. Without these cookies, services you have asked for cannot be provided.
Analytics cookies: We use PostHog (hosted in the EU at eu.posthog.com) for website and product analytics. PostHog uses cookies to track visitor usage in an anonymised manner. PostHog does not store, save or collect personal information for its own purposes.
Functional cookies: We may use cookies to remember personal settings you have chosen on our website, such as your login session. If you log into the platform as a registered user, your session cookie will also contain your user ID so that we can check which services you are allowed to access.
Managing cookies
Should you wish to deny the use and saving of cookies from this website onto your device, you should take the necessary steps within your web browser’s security settings to block all cookies from this website and its external serving vendors. You can also manage cookie preferences through the cookie consent banner displayed on your first visit.
8. Subprocessors
Efestra uses certain subprocessors to assist in providing services to our customers. A subprocessor is a third-party vendor or entity engaged by Efestra who has or potentially will have access to or process Customer Content (which may contain personal data).
We have entered into a Data Processing Addendum with each subprocessor to ensure that the privacy and security obligations we hold with our customers flow through to our subcontractors.
A current list of subprocessors is available in our Data Processing Addendum, available upon request by emailing in**@*****ra.com.
9. Data Storage and Residency
All primary customer data is stored within Amazon Web Services EU-Central-1 region (Frankfurt, Germany). Data does not migrate beyond the defined region unless explicitly required by the services you use (for example, AI processing via Anthropic or OpenAI APIs, which involves temporary data transfer to the United States for the duration of the API call).
Customer data stored in our primary infrastructure is encrypted at rest using AES-256 encryption and in transit using TLS 1.3.
Custom region deployment is available for enterprise customers with specific data residency requirements.
10. International Data Transfers
Where we transfer personal data outside the United Kingdom or the European Economic Area (for example, to AI subprocessors in the United States), we ensure appropriate safeguards are in place. These safeguards include:
- Standard Contractual Clauses (SCCs) as approved by the European Commission and the UK Information Commissioner
- Data Processing Agreements with all subprocessors
- Contractual commitments that customer data will not be used for purposes beyond service delivery
11. Data Retention
Digital Tonic Ltd will not retain your personal information longer than necessary. Our retention periods are as follows:
Active accounts: We retain your data for as long as your account is active and the services agreement is in effect.
Closed accounts: Following account closure, we retain essential records (billing, contractual) for up to six years to comply with legal and regulatory obligations. Platform data (experiments, insights, decisions) is deleted or anonymised within 90 days of account closure unless otherwise agreed.
Marketing contacts: We retain your contact information until you unsubscribe or request deletion.
Assessment data: Responses to self-assessment tools such as the Evidence Gap Score are retained for the purpose of delivering results and follow-up communications. You may request deletion at any time.
Application logs: Retained for a minimum of 90 days for security and operational purposes.
Support communications: Retained for as long as necessary to provide support-related reporting and trend analysis.
If legally required, or if it is reasonably necessary to meet regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our Terms and Conditions, we may also retain some of your information for a limited period of time as required, even after you have closed your account or it is no longer needed to provide the Services to you.
12. Your Rights
Under UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your personal data:
Right of access: You can request a copy of the personal data we hold about you. We will respond within 30 days.
Right to rectification: You can request that we correct any inaccurate or incomplete personal data.
Right to erasure: You can request that we delete your personal data, subject to any legal obligations we have to retain it.
Right to restrict processing: You can request that we restrict the processing of your personal data in certain circumstances.
Right to data portability: You can request that we provide your personal data in a structured, commonly used, machine-readable format.
Right to object: You can object to the processing of your personal data where we are relying on legitimate interests as the lawful basis.
Right to withdraw consent: Where we rely on your consent to process personal data, you can withdraw that consent at any time.
To exercise any of these rights, please contact us at in**@*****ra.com. Our security procedures mean that we may request proof of identity before we reveal information. We will respond to all legitimate requests within 30 days.
You also have the right to make a complaint to the Information Commissioner’s Office (ICO) if you are unhappy with how we have handled your personal data. The ICO can be contacted at www.ico.org.uk.
13. Children’s Privacy
Only persons who are age 18 or older have permission to access our Service. Our Service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If you are a parent or guardian and you learn that your child has provided us with personal information, please contact us. If we become aware that we have collected personal information from a child under age 13 without verification of parental consent, we take steps to remove that information from our servers.
14. Third-Party Links
Our website and platform may contain links to third-party websites. We are not responsible for the privacy practices or the content of those third-party websites. We encourage you to read the privacy policies of any third-party websites you visit.
15. Security
We are committed to ensuring that your personal data is secure. We have implemented appropriate technical and organisational measures to safeguard your personal data against unauthorised access, alteration, disclosure or destruction. Full details of our security practices are set out in our Security Policy, available upon request.
16. Changes to This Policy
This Privacy Policy will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted on this page.
We reserve the right to update or change our Privacy Policy at any time, and you should check this Privacy Policy periodically. Your continued use of the Service after we post any modifications to the Privacy Policy on this page will constitute your acknowledgement of the modifications and your consent to abide and be bound by the modified Privacy Policy.
Where changes are significant, we will make reasonable efforts to notify you by email or through a notice on our website.
