Privacy Policy
Effective 8 July 2026
Who we are
Patch14 (patch14.co.uk) is a product operated by Granite & Fleur Digital Ltd, a company registered in England and Wales (company no. 17289418), registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. We are registered with the UK Information Commissioner's Office (ICO registration reference ZC185621) and are the data controller for the personal data described in this policy, except where stated otherwise below.
Scope
Patch14 is a B2B compliance-monitoring tool sold to managed service providers (MSPs). This policy covers personal data we process about (a) your account users, and (b) individuals whose personal data may incidentally appear in the client and asset records your organisation uploads or syncs into Patch14 (for example, a device name that identifies an employee of one of your clients). Where we process data described in (b), we generally do so as a processor acting on your instructions — see our Data Processing Agreement for how that works.
What we collect
- Account data — name, email address, and authentication data, via Supabase Auth
- Client and asset data — the SME client records, device/software inventory, and CVE compliance status you create or sync into Patch14, via Microsoft Intune, Lansweeper, CSV upload, or your PSA integration
- Integration credentials — OAuth tokens and API keys for the integrations you connect, encrypted at rest and never stored in plaintext
- Billing data — handled directly by Stripe; we store your plan tier and subscription status, not your card details
- Support and correspondence — anything you send us by email
- Usage data — aggregated, anonymised page-view analytics via Vercel Analytics (see our Cookie Policy)
Why we process it
We rely on the following legal bases under UK GDPR:
- Performance of a contract — running the service you've signed up for: monitoring assets, computing compliance status, dispatching alerts, and generating evidence packs
- Legitimate interests — securing the service, preventing abuse, and improving the product, where this doesn't override your rights
- Legal obligation — retaining billing records for tax and accounting purposes
Who we share it with
We use the following sub-processors to run Patch14:
- Supabase — database, authentication, file storage, and secrets storage (UK region, London)
- Vercel — application hosting, scheduled jobs, and cookieless analytics
- Stripe — payment processing and billing
- Resend — transactional email (compliance alerts, trial reminders)
- Microsoft — via the Microsoft Graph API, only if you connect Intune
If you connect a PSA or RMM integration (Halo PSA, ConnectWise Manage, Autotask, or Lansweeper), that connection uses your own credentials with that provider, and your data is also processed by them as a service you've chosen to use — not because we've shared it with them independently. We never sell personal data, and we don't share it with third parties for their own marketing purposes.
International transfers
Your core account, client, and asset data is stored in the UK. Some sub-processors above may process limited data (such as billing or email delivery metadata) outside the UK. Where that happens, we rely on an applicable UK adequacy regulation or appropriate safeguards such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
How long we keep it
We retain account, client, and asset data for as long as your subscription is active, and for up to 90 days after account closure to allow for reactivation and export, unless a longer period is required by law (for example, billing records for accounting purposes). Deleting a client in Patch14 soft-deletes its records immediately and removes them from active views; the underlying data is purged on the same retention schedule.
Security
Integration credentials and other secrets are stored using Supabase Vault, encrypted at rest, and never exposed in plaintext. Access to customer data is scoped by row-level security so accounts can only see their own data. All traffic to Patch14 is encrypted in transit.
Your rights
Under UK GDPR, you have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent where processing relies on it. To exercise any of these rights, email us at privacy@graniteandfleur.com. You also have the right to lodge a complaint with the ICO at ico.org.uk.
Children
Patch14 is a business tool sold to MSPs and is not directed at, or knowingly used by, children.
Changes to this policy
If we make material changes to this policy, we'll update the effective date above and, where appropriate, notify account holders by email.