Privacy Policy

Effective 8 July 2026

Who we are

Patch14 (patch14.co.uk) is a product operated by Granite & Fleur Digital Ltd, a company registered in England and Wales (company no. 17289418), registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. We are registered with the UK Information Commissioner's Office (ICO registration reference ZC185621) and are the data controller for the personal data described in this policy, except where stated otherwise below.

Scope

Patch14 is a B2B compliance-monitoring tool sold to managed service providers (MSPs). This policy covers personal data we process about (a) your account users, and (b) individuals whose personal data may incidentally appear in the client and asset records your organisation uploads or syncs into Patch14 (for example, a device name that identifies an employee of one of your clients). Where we process data described in (b), we generally do so as a processor acting on your instructions — see our Data Processing Agreement for how that works.

What we collect

Why we process it

We rely on the following legal bases under UK GDPR:

Who we share it with

We use the following sub-processors to run Patch14:

If you connect a PSA or RMM integration (Halo PSA, ConnectWise Manage, Autotask, or Lansweeper), that connection uses your own credentials with that provider, and your data is also processed by them as a service you've chosen to use — not because we've shared it with them independently. We never sell personal data, and we don't share it with third parties for their own marketing purposes.

International transfers

Your core account, client, and asset data is stored in the UK. Some sub-processors above may process limited data (such as billing or email delivery metadata) outside the UK. Where that happens, we rely on an applicable UK adequacy regulation or appropriate safeguards such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.

How long we keep it

We retain account, client, and asset data for as long as your subscription is active, and for up to 90 days after account closure to allow for reactivation and export, unless a longer period is required by law (for example, billing records for accounting purposes). Deleting a client in Patch14 soft-deletes its records immediately and removes them from active views; the underlying data is purged on the same retention schedule.

Security

Integration credentials and other secrets are stored using Supabase Vault, encrypted at rest, and never exposed in plaintext. Access to customer data is scoped by row-level security so accounts can only see their own data. All traffic to Patch14 is encrypted in transit.

Your rights

Under UK GDPR, you have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent where processing relies on it. To exercise any of these rights, email us at privacy@graniteandfleur.com. You also have the right to lodge a complaint with the ICO at ico.org.uk.

Children

Patch14 is a business tool sold to MSPs and is not directed at, or knowingly used by, children.

Changes to this policy

If we make material changes to this policy, we'll update the effective date above and, where appropriate, notify account holders by email.

Questions about this policy: privacy@graniteandfleur.com