1 · Our core principle: metadata only
Org Warden is designed to never ingest your customer data. Our platform operates entirely on metadata: field definitions, object structures, permission configurations, and aggregate counts. Your actual customer records never leave Salesforce.
When we scan your Salesforce org for PII we see that you have a field called SSN__c. We never see the values stored in that field.
2 · Information we collect
Marketing site (orgwarden.co.uk)
- Contact information (name, work email, company) when you request a scan or reply to us.
- Basic usage data (pages visited, referrer, device) if we run analytics; we do not fingerprint or profile.
- Essential cookies for site functionality.
Console (app.orgwarden.co.uk)
The Console is where you bring the Evidence Packs your Salesforce org produces. It never connects to your org; nothing reaches it except a file a person in your company uploads. What it then holds:
- Account information: the work email address of each invited person, the sign-in codes we send to it (stored hashed), the sessions that result, and an audit log of sign-in events. No passwords are held.
- Evidence Packs, as uploaded: your org’s identifier and name, object and field API names, field counts, findings (which rule matched which field, and how many times), rule identifiers, coverage figures and content hashes. A pack is kept byte-for-byte as it arrived so that it can be re-verified later.
- What you author in the Console: org labels, packs you set aside, scan definitions you compose, and the redaction work-list — each recorded against the signed-in address and the date.
A pack contains no customer record and no field value — not a sample, not an excerpt, not a partial value. It does contain the names of your objects and fields and what our rules found about them, which is information about your organisation and is treated as confidential.
What we never collect
- Customer record data from your Salesforce orgs.
- Field values (names, SSNs, emails, addresses, and so on).
- File contents from ContentDocuments or Attachments.
- Salesforce user credentials or session tokens.
3 · How we use it
To provide, operate, and improve the service; to send administrative and security communications; to respond to your requests; and to meet legal obligations. We do not sell personal data. We do not use your Salesforce metadata for any purpose other than delivering the service to you.
4 · Retention
- Evidence Packs and what you author: kept until you delete them, or until 30 days after your agreement ends, whichever is first. A pack is evidence, so we do not expire it while your account is active; you can ask us to erase any pack, or everything, at any time and we do it within 30 days. Erasure removes the stored bytes and every derived record, and the fact of the erasure is itself recorded.
- Sign-in records: codes expire after ten minutes and are deleted; sessions expire after twelve hours.
- Audit logs (sign-ins, erasures, mail delivery events): retained for 2 years.
- Marketing contacts: retained until you unsubscribe or ask us to delete them.
5 · Security
- TLS in transit everywhere; server-side encryption at rest on every stored pack and database.
- Sign-in by one-time email code, bound to the browser that requested it; no passwords to leak. Single sign-on (SSO) is on the roadmap for customers who require it.
- Every customer’s data is isolated by row-level security in the database and by a per-customer prefix in storage — enforced by the database on every query, not by application code.
- The Console holds no credential for, and no connection to, any Salesforce org.
- Nothing is logged that a pack contains: no field names, no findings, no sign-in codes.
- No analytics, error-tracking or session-recording service runs inside the Console.
The architectural detail is on the Security page.
6 · Sharing
- Sub-processors — the three companies that host the Console, listed by name, role and region in section 7 and on our sub-processor page, each under written data-processing terms.
- Legal process where required by law or valid legal process.
- Business transfers in the event of a merger or acquisition, with notice.
- Your consent, when you explicitly authorise it.
We do not share, sell, or rent your Salesforce metadata for anyone else's marketing purposes.
7 · Where your data is, and who holds it
Everything the Console stores is in London. The application runs on Vercel’s London region; the database is Neon (running on AWS, eu-west-2); stored packs are in an AWS S3 bucket in eu-west-2; sign-in codes are sent through AWS SES in eu-west-2. There are no other sub-processors, and we will give you 30 days’ notice before adding one.
- Vercel Inc. — runs the application; packs pass through it in transit. London (lhr1).
- Neon Inc. — the database: the pack index, what you author, and account records. AWS eu-west-2, London.
- Amazon Web Services — stored pack bytes (S3) and sign-in email (SES). eu-west-2, London.
Jurisdiction. Residency in London answers where the data sits. It does not by itself answer whose law can reach it: Vercel and AWS are US companies, and US law (the CLOUD Act) can in principle compel a US provider to produce data it holds, wherever it is stored. Our position is the one nearly every UK software vendor is in, and we state it rather than obscure it: we choose UK/EU regions and providers with published transparency reporting and a policy of challenging over-broad requests; the material at stake is metadata about your Salesforce configuration, never customer records; and every pack can be erased on request. If your policy requires a UK-owned storage chain, tell us before you upload — that is a conversation we would rather have first.
8 · Your rights (GDPR / UK GDPR / CCPA)
- Access, rectification, erasure.
- Data portability.
- Objection to and restriction of processing.
- Withdrawal of consent where processing is consent-based.
Email privacy@orgwarden.co.uk to exercise any of these rights. We respond within 30 days.
9 · International transfers
We operate from the United Kingdom and store Console data only in the UK (see section 7). Our sub-processors are US-headquartered companies operating UK regions; the processing terms with each include the UK International Data Transfer Addendum or an equivalent lawful mechanism for any support access from outside the UK.
10 · Contact
- Privacy: privacy@orgwarden.co.uk
- DPO: dpo@orgwarden.co.uk
- General: hello@orgwarden.co.uk
Org Warden Ltd, United Kingdom. Salesforce® is a registered mark of salesforce.com, inc. Org Warden is not affiliated with, sponsored, or endorsed by salesforce.com, inc.