Custodia logo Custodia.
  • Features
  • For societies
  • Pricing
  • About
  • Contact
Login Try it for free

Legal

Privacy Policy

Last updated: 24 August 2026


Introduction

This policy explains how information about people is handled when they visit custodiacms.org, contact the business, create or use an account, receive account-related communications, or use the Custodia Collection Management System software on behalf of an organisation. It also explains the respective responsibilities of the business operator and organisations using the software.

Terms used in this policy

“Custodia”, “we”, “us” and “our” refer to Ángel Torres Rodriguez operating the Custodia business. “Custodia CMS” or "the system" means the collection management software application.

“The service” means the services Custodia provides in connection with Custodia CMS, including providing online access, hosting client content, administering accounts, maintaining and securing the application, delivering service communications, providing support and enabling data exports.

“Client” means an organisation that has an account for the service and uses it to manage its archive records and, where applicable, related conservation work.

“The website” means the public website at custodiacms.org, which provides information about Custodia CMS and the related services.

“Personal data” means information relating to an identified or identifiable living person. It includes information that identifies someone directly, such as their name or email address, and information that could identify them indirectly when combined with other information.

About Custodia and how to contact us

Custodia is the trading name of Ángel Torres Rodriguez, a sole trader based in the United Kingdom whose professional name is Andrew Torres.

Ángel Torres Rodriguez is the data controller for personal data used to operate the website and provide the service, including enquiries, accounts, billing, support, security and legal compliance.

You can contact us about this policy or how we handle personal data using the following details:

Ángel Torres Rodriguez
Keeper's House, Gordonbush
BRORA
KW9 6LX
United Kingdom

Email enquiries@custodiacms.org. You may also use our contact form.

Custodia’s role and client’s role

For account, billing, enquiry, support, security and service-administration data, Custodia decides why and how that information is used and acts as a data controller.

The client decides what information is entered, why it is used, who may access it and what is published through its archive portal. The client is the data controller for that content. Custodia acts as the client’s data processor by hosting and operating the service in accordance with the client’s instructions and our agreement with it.

Personal data we handle

Website enquiries and demonstrations

When you contact us or request a demonstration, we may receive your name, email address, organisation, website, role, approximate archive size, availability, message, and any other information you choose to provide. Form details are delivered to our relevant mailbox rather than stored in a separate enquiries database.

Support communications

When a signed-in user contacts us for support, we receive the information included in the request together with the relevant account and client identifiers. Support requests are delivered to our relevant mailbox rather than stored in a separate support database.

Accounts and client administration

We handle account names, username, email address, password hash, optional telephone number and profile image, language or region preference, permissions, email-verification status, onboarding status and interface preferences, account creation date, and sign-in information. Passwords are stored as secure hashes, not in readable form.

We also handle organisation names, contact details, addresses, branding and portal settings, subscription plan and status, billing frequency and dates, invoice details, payment status, paid-plan acceptance records, and related service communications. A paid-plan acceptance record contains the organisation and administrator identity shown at checkout, the selected plan and billing details, invoice reference, acceptance time, Terms of Service version, and the wording accepted. Custodia does not collect payment-card details through the current service.

Archive and operational content

Clients and their users may add archive descriptions, provenance and acquisition information, donor and contributor details, locations, condition assessments, assessors, restoration projects, project leaders, tasks, notes, dates, images, and supporting documents. This content may identify staff, volunteers, donors, owners, researchers, suppliers, historical subjects, or other people, including people who did not provide the information directly to Custodia.

Technical information

When you use the website or service, our application and infrastructure providers may process IP address, requested page, date and time, browser and device information, response status, session and security events, and similar diagnostic information. We use essential cookies and browser storage as described in our Cookie Notice.

Information you provide when signing up

When you sign up for the service, we ask for the information needed to create the client account and set up its initial administrator user. Contact forms require enough information for us to understand and answer the request. If required information is not provided, we may be unable to create the account, provide the service, or respond. Fields marked as optional may be left blank.

How we obtain personal data

We receive personal data directly from you when you submit a form, create or update an account, contact us or use the service. We may also receive personal data about you from a client and its authorised users, including when they add archive or operational records. Browsers, devices and the infrastructure used to deliver and secure the service also provide technical information automatically.

Purposes and lawful bases

  • Contract and steps before a contract: to respond to requested demonstrations, create and authenticate accounts, provide the service, administer subscriptions, produce invoices, deliver exports, and provide requested support.
  • Legitimate interests: to respond to business enquiries, administer and improve the service, send necessary service communications, diagnose faults, protect accounts and infrastructure, prevent abuse, and establish or defend legal claims. These interests are balanced against the rights and expectations of the people concerned.
  • Legal obligation: to meet applicable tax, accounting, data-protection, regulatory, and lawful disclosure requirements.
  • Consent: where we specifically ask for consent for an optional use. Consent can be withdrawn at any time without affecting processing that was lawful before withdrawal.

When Custodia processes organisation content as a processor, the client organisation is responsible for identifying and documenting the lawful basis and, where relevant, an additional condition for special-category or criminal-offence data.

Custodia does not sell personal data or disclose it to others in exchange for commercial benefit. We do not currently send direct-marketing email campaigns or use people’s activity to profile them for targeted or behavioural advertising; necessary account, billing, security and service emails are not marketing. We do not use automated systems, without meaningful human involvement, to make decisions that have legal or similarly significant effects on people.

Archive portal and sensitive content

Each Conservator-plan client is provided with a public archive portal populated from information in its archive. The client decides whether to use or share the portal with members of the public and remains responsible for deciding what information is suitable for publication. Depending on the client’s records, the portal may display archive descriptions, donor or contributor names, provenance, condition assessors, project leaders, locations, project and treatment notes, dates, images and downloadable supporting files.

The client organisation is responsible for deciding what it is lawful and appropriate to enter and publish, providing privacy information to the people concerned where required, respecting third-party rights, and responding to requests about that content. Organisations should not upload or publish unnecessary special-category data, criminal-offence data, children's data, confidential material, or other highly sensitive information. Internal notes and uploaded documents should be reviewed carefully before they are made available through a public portal.

Who can access personal data

Depending on the context, personal data may be available to:

  • authorised users and administrators of the relevant client organisation;
  • public visitors where the client organisation shares its content through its archive portal;
  • Andrew Torres and authorised professional or technical advisers who need access to operate, support, secure, or advise on the service and are subject to appropriate confidentiality obligations;
  • hosting, storage, email-delivery, and other service providers described below; and
  • courts, regulators, law-enforcement bodies, or other parties where disclosure is legally required or necessary to protect rights, safety, and the service.

Hosting, service providers, and international transfers

Railway

The Custodia CMS application and its PostgreSQL database are configured to use Railway's EU West region in Amsterdam, Netherlands. The production media bucket is configured in the same region. Railway's region documentation identifies EU West as Amsterdam. The production database is reached through Railway's private network rather than a public database endpoint.

This regional configuration describes the primary location of the live application, database, and media. It does not mean that every supporting operation or copy remains exclusively in Amsterdam. Railway's control plane, support operations, logs, backups, and authorised subprocessors may process or access information in other countries as described in Railway's Privacy Policy and Data Processing Addendum.

Resend

Custodia CMS uses Resend to deliver account verification, password reset, support, billing, notification, and enquiry emails. Resend receives email addresses, message metadata and content, and any attachments, such as invoice PDFs. Resend states that its primary processing operations take place in the United States; further details are in the Resend Privacy Policy and Data Processing Addendum.

DiceBear

If a user has not uploaded a profile image, the admin may load a generated identicon from DiceBear using an internal account identifier as the seed. The browser connects directly to DiceBear and therefore discloses ordinary request information such as IP address, browser information, and the requested seed. Custodia does not send the user's name or email address as that seed. DiceBear's handling of the request is described in its privacy policy.

Transfer safeguards

The UK recognises the EU and European Economic Area, including the Netherlands, as providing adequate protection for personal data. Where a provider processes personal data in a country not covered by UK adequacy regulations, the transfer is covered as applicable by the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, another approved safeguard, or a lawful exception. Contact us if you would like more information about the safeguard relevant to a particular transfer.

Security

Custodia uses measures appropriate to the service and the risks involved. These include HTTPS in production, secure and same-site session cookies, CSRF protection, password hashing and validation, email verification, a 30-minute admin inactivity timeout, tenant-scoped routing and queries, role and permission controls, private database networking, and controlled media storage. Access to organisation-wide data exports is limited to client administrators and the Custodia CMS system administrator.

No internet service can guarantee absolute security. After information is removed from the live service, copies may remain temporarily in provider logs, backups, or disaster-recovery systems in accordance with the applicable provider’s retention policy. These residual copies are not ordinarily accessible through the live Custodia CMS application and are deleted or overwritten through the provider’s normal retention cycle. Further information is provided under “How long we keep personal data” section below.

Data exports

A client administrator can download an organisation-wide export while the account is accessible. It includes organisation settings, user details, archive and restoration records, contributor information, invoices, and uploaded media stored in the system when the export is created. Passwords and password hashes are not included. The system administrator may also create an export to support an organisation, including during the post-deactivation retention period.

We delete the temporary export file from our server after sending it for download. The recipient is responsible for storing, sharing, or deleting any copy they download securely.

How long we keep personal data

  • Active clients: client account and content is kept while Custodia provides the service, unless particular information is deleted sooner by an authorised user or a valid request requires another outcome.
  • Trials: a trial remains usable through day 30 after signup. Access is locked from day 31. If the client does not activate a paid plan, its account, users, records, and associated media are scheduled for permanent purge on day 45.
  • Cancelled client accounts: access continues until the end of the paid billing period. The account is then deactivated and the operational client account, users, collection records, and associated media are scheduled for permanent purge 14 days after deactivation. The limited paid-plan acceptance record described below is retained separately.
  • Enquiries and support: routine correspondence is kept for up to 24 months after the last meaningful contact.
  • Paid-plan acceptance records: the minimal record of who accepted a paid plan, what was accepted, and the associated invoice is retained while the subscription exists and for six years after the subscription ends. It is then automatically deleted. This record is kept to administer the contract, establish payment obligations, and establish or defend legal claims.
  • Other billing, legal, and complaint records: limited information may be kept longer where necessary for tax or accounting duties, to handle a current rights request or complaint, to resolve a dispute, or to establish or defend legal claims.
  • Technical records and provider copies: operational logs, email-delivery records, and residual backups follow the period needed for security, diagnosis, legal compliance, and the applicable provider's retention cycle.

Deletion from the service may not immediately remove residual information from provider backups, where such copies exist. Custodia does not carry out the retention, deletion, or recovery of those copies. The relevant provider manages them under its own retention and recovery processes, may retain them where required by law, and may restore them where it considers this necessary for disaster recovery or another legitimate operational reason.

Your data-protection rights

Depending on the circumstances and lawful basis, you may have the right to:

  • ask for access to your personal data and information about how it is used;
  • ask us or the relevant client organisation to correct inaccurate or incomplete data;
  • ask for erasure or restriction of processing;
  • object to processing based on legitimate interests;
  • receive personal data you provided in a portable format where the right applies; and
  • withdraw consent where consent is the lawful basis.

To exercise any of these rights, use the contact details provided at the beginning of this policy.

Custodia handles requests about information we control, such as account, billing, enquiry, support, and service-administration records. If information about you appears in a client's archive or public portal, such as an inaccurate name, biographical detail, or attribution, the client is normally responsible for deciding whether and how to correct it. You may contact the client directly or contact Custodia; where appropriate, we will communicate with the relevant client organisation about your request.

These rights are not absolute and exemptions may apply. We will respond without undue delay and within one month of receiving your request. Where we reasonably need proportionate evidence of identity or authority, the response period begins when we receive it. If we reasonably need clarification to identify the information requested, the response period pauses from the day we ask for clarification and resumes the day after we receive it. If a request is complex or numerous, we may extend the period by up to two further months where the law permits; we will tell you within the first month and explain why.

Client administrators can also obtain the organisation-wide export described above. However, that export is an account feature and does not replace an individual's legal right of access.

Data protection complaints

To make a data-protection complaint, use the contact details provided at the beginning of this policy. Please identify your message as a privacy complaint and explain what you believe has gone wrong.

We will acknowledge a data-protection complaint within 30 days of receipt. We will take appropriate steps to investigate without undue delay, keep you informed where the investigation is ongoing, and tell you the outcome. Where a complaint concerns content controlled by a client organisation, such as information in its archive or public portal, the client is normally responsible for deciding the outcome; where appropriate, Custodia will communicate with the relevant client organisation about the complaint.

We would appreciate the opportunity to resolve your concern first. You also have the right to complain to the UK Information Commissioner's Office. Visit the ICO's complaints service or call 0303 123 1113.

Changes to this policy

We review this policy when our services, providers, data uses, or legal obligations change. The date at the top shows when it was last updated. If a material change affects account users or introduces a new use of their personal data, we will bring it to their attention before or when the change takes effect where required.

Custodia logo Custodia.

Heritage managment software.

Product

  • Features
  • For societies
  • Pricing
  • Roadmap

Company

  • About
  • Contact

Legal

  • Privacy policy
  • Terms of service
  • Cookie notice
© Custodia. All rights reserved. Built for the heritage sector.