Version of September 6, 2026. This notice explains how ROWSH LTD, trading as Rowsh, handles personal data on the public website, during evaluation and signup, and when operating the Rowsh SaaS service. ROWSH LTD is registered in England and Wales under company number 17352462. Its registered office is 350 Abbey Hey Lane, Abbey Hey, Manchester, England, M18 8RP.
1. Controller identity and contact
For Rowsh's public website, account administration, sales, billing records, security, and internal business operations, ROWSH LTD generally acts as controller. Send privacy enquiries, rights requests, and complaints to team@rowsh.com or use the Contact page. Postal requests may be sent to the registered office above and should be marked "Data protection".
For personal data in workspace content that a customer submits and controls, the customer is generally the controller and Rowsh acts as its processor. Contact that customer first for a request about content it controls. Rowsh's processing obligations are described in the Data Processing Addendum.
2. Personal data we receive
- Account and organisation data: name, username, email, contact details, organisation, role, workspace membership, authentication settings, and administrator configuration.
- Customer Content: tasks, messages, files, calendar items, notes, knowledge pages, forms, candidate and CRM records, help desk records, invoice metadata, approvals, whiteboards, and other content users submit.
- Public, sales, support, and hiring data: contact and demo requests, chatbot conversations, public forms, booking details, job applications, CVs, files, and communications.
- Billing data: plan, billing contact, subscription, transaction, invoice, tax, and payment status metadata. Hosted payment providers handle full payment credentials under their own notices.
- Technical and security data: IP address, user agent, device and browser information, session and security events, audit records, diagnostic data, and page or feature interactions.
- Integration data: identifiers, tokens, permissions, and content exchanged when an authorised user enables an integration.
3. Sources
We receive data directly from individuals; customer administrators and users; public form, careers, booking, or support participants; configured integrations; payment and service providers; devices and browsers; and logs generated through use of Rowsh. If a customer or integration provides another person's data, that customer or provider is responsible for having authority to do so and for giving any required notice.
4. Purposes and UK lawful bases
- Provide and administer the Service: performance of the customer contract and steps requested before entering it.
- Authentication, permissions, fraud prevention, service security, support, and fault diagnosis: contract performance, Rowsh's legitimate interests in operating a reliable and secure service, and legal obligations where applicable.
- Billing, invoices, tax, accounting, and payment reconciliation: contract performance and legal obligations.
- Respond to contact, sales, demo, and support requests: requested precontract steps and legitimate interests in communicating with current and prospective business customers.
- Recruitment: steps requested by an applicant, legitimate interests in assessing and managing recruitment, and employment law obligations.
- Service diagnostics and improvement: legitimate interests in improving reliability and usability, or consent where the technology or purpose requires it. Optional browser diagnostics follow the choices described in the Cookie Policy.
- Legal compliance, disputes, and corporate transactions: legal obligations and legitimate interests in establishing, exercising, or defending rights and managing the business responsibly.
- Direct marketing: consent where required, or legitimate interests and the business marketing permissions available under applicable electronic marketing rules. Every marketing message must provide a working opt out.
Where Rowsh relies on legitimate interests, those interests are the secure, proportionate, and commercially reasonable operation and improvement of a business SaaS service. Rowsh must balance those interests against the individual's rights and expectations and cannot use this basis where the individual's interests override them.
5. Required and optional data
Account, authentication, workspace routing, and necessary billing information is required to create and perform the contract. If it is not provided, Rowsh may be unable to create an account, provide a paid plan, or complete a requested transaction. Optional profile, marketing, application, and integration fields are identified by their context; choosing not to provide them may limit only the related feature or request.
6. Special category and sensitive data
Rowsh is not designed to require special category data or criminal offence data for ordinary use. A CV or customer controlled workspace may nevertheless contain it. The controller that chooses to submit that data must identify a valid UK GDPR Article 6 basis, an applicable Article 9 condition or other statutory condition, provide required notices, and configure access appropriately. Regulated or high risk processing requires a written agreement and any necessary data protection impact assessment before use.
7. AI and automated decisions
When an authorised user invokes an AI feature, Rowsh processes the prompt and relevant workspace context to return an answer or requested action. The active deployment may use OpenAI or a configured self hosted model path. Users must review AI output before relying on it. Rowsh does not use its own controller data to make solely automated decisions producing legal or similarly significant effects unless the specific use is disclosed and the required safeguards are provided. Customers remain responsible for workflows and decisions they configure using their content.
8. Recipients
Rowsh discloses data only as needed to authorised personnel, service providers supporting the active deployment, customer directed integrations, payment providers, professional advisers, transaction counterparties under confidentiality, and authorities or other parties where required by law or reasonably necessary to protect rights and safety. Rowsh does not sell personal data or use it for cross context behavioural advertising. See the Subprocessor List for relevant provider categories.
9. Workspace administrators and other users
Administrators may access, configure, export, restrict, or delete workspace information according to their permissions. Content may be visible to other authorised users, guests, recipients, or public link visitors based on the customer's configuration. Customers are responsible for notices and permissions for the people whose data they submit.
10. International access and transfers
Rowsh and configured providers may process data outside the UK. Authorised operational access may occur from Pakistan. Access by personnel within ROWSH LTD remains under Rowsh's UK GDPR responsibilities. Where Rowsh makes a restricted transfer to a separate organisation outside the UK, Rowsh uses an applicable UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard clauses, or another lawful mechanism, together with the required data protection test. Contact Rowsh for a copy of applicable safeguards. Current service providers and processing locations are identified in the Subprocessor List.
11. Retention
Rowsh retains data only as long as reasonably needed for the purpose collected, the customer agreement, legal and tax duties, security, disputes, and verified backup recovery. Criteria include the data type, workspace and account status, customer instructions, limitation periods, statutory recordkeeping, active investigations, and backup schedules. Exact customer content deletion or backup periods apply only where supported by the current operational schedule or a signed customer document.
12. Security and personal data breaches
Rowsh uses access controls and other safeguards described on the Security page. No system is completely secure. Rowsh must assess suspected personal data breaches, keep required records, notify the ICO without undue delay and where feasible within 72 hours when the reporting threshold is met, and notify affected people without undue delay where the law requires it.
13. UK data protection rights
Subject to the applicable basis and legal exceptions, individuals may ask for access, correction, erasure, restriction, or portability of their personal data; object to processing; withdraw consent prospectively; and request safeguards relating to significant automated decisions. Rowsh may verify identity and authority. Rowsh normally responds without undue delay and within one month after receiving a valid request, subject to any lawful extension or exception. Workspace users should normally contact the customer controlling their workspace content first.
Your right to object: you may object at any time to direct marketing, and Rowsh will stop it. You may also object to processing based on legitimate interests or a task in the public interest; Rowsh will assess the request under the applicable legal test.
14. Data protection complaints
Use the Data Protection Complaints Procedure or select "Data protection request or complaint" on the Contact page. Rowsh will acknowledge a complaint within 30 days, investigate it without undue delay, keep the complainant informed as appropriate, and communicate the outcome. You may also complain to the UK Information Commissioner's Office.
15. Cookies and browser storage
Rowsh uses cookies and browser storage for authentication, security, session continuity, interface preferences, and optional diagnostics. The purpose, duration, legal treatment, and available controls are described in the Cookie Policy.
16. Children
Rowsh is a business service and is not directed to children. Customers must not invite children or submit children's data unless they have confirmed a lawful, contractually approved use and implemented the protections the UK Children's Code and other applicable law require. Contact Rowsh if you believe a child's data was submitted inappropriately.
17. Changes
Rowsh may update this notice as the product, deployment, providers, or law changes. Material changes will be dated and communicated through an appropriate notice to workspace contacts or users. A privacy notice describes processing; continued use is not treated as consent where consent is not the lawful basis.