Legal
Privacy policy
Caryvane is built to keep your data in storage you own, and this policy is written in the same spirit: it says exactly what we hold, why, and for how long. Last updated 17 September 2026.
1. Who we are
Caryvane is a product of Centurion Computers Ltd, a company registered in England and Wales (company number 10498449) with its registered office at First Floor St Matthews House, Haugh Lane, Hexham, Northumberland, NE46 3PU. Centurion Computers Ltd is the data controller for the personal data described in this policy. Contact us about anything here at hello@caryvane.com.
Caryvane is developed in partnership with Aurawolf Global, who help build and support the service and may see account data in the course of doing so, under contract with us and on our instructions.
2. Two roles: controller and processor
For the people who visit this website and hold accounts in the console, we are the controller. For the content of the backups themselves — the files, mailboxes and databases our customers protect — the customer is the controller and we act as a processor on their instructions. Section 7 explains what that means in practice.
3. Visitors to caryvane.com and help.caryvane.com
Server logs. Our web servers record the IP address, the page requested, the time, and the browser identification string of every request, for security and to keep the sites running. Logs are kept for 30 days.
Analytics. With your consent we use Google Analytics 4 to see which pages are useful. It is not loaded, and sets no cookies, until you allow it; see Cookies. IP addresses are anonymised by Google before storage.
Book a demo. When you send the form on the contact page we record your name, email address, company, message and the IP address it came from, and email it to our team. We use it to reply to you. It is kept for 12 months from your last contact, then deleted.
4. People with console accounts
To run an account we hold your username, email address, display name, a hash of your password (never the password), your two-factor secret if you enable it, the customer your account belongs to and your role, the times and IP addresses you sign in from, and an audit trail of the actions you take in the console (for example "created job", "revoked token"). If you sign in with a Microsoft or Google account we hold the identifier that account gives us and your email address; we do not receive your password.
We use this to provide the service, to secure it, to support you when you ask, to bill the account, and to tell you about things that affect your service (a failed backup, an agent that went offline, a change to these terms). We do not send marketing email without asking first.
The legal basis is the contract with you or your organisation, and our legitimate interest in keeping the service secure.
5. Machines running the Caryvane agent
Each installed agent reports to our servers: the machine's name, operating system, public IP address, agent version, a fingerprint derived from its hardware (used to recognise the same machine on reinstall and to prevent trial abuse), the jobs it is running and how they went, and its own application log. Run histories include the names and paths of files that were skipped or failed, so an administrator can act on them. Agents send this over TLS and keep only what is needed to run offline in a local database on the machine.
We hold agent and run data for as long as the customer's account is active and for 90 days after it closes. Application logs are kept for 30 days.
6. Your backups and your storage
Caryvane holds no copy of the data you back up. Every job writes to storage you supply — an S3 bucket, an Azure container, a share, a folder — using credentials you give us, which we store encrypted and use only to run your jobs. Data passes through the agent on your machine, or, for jobs you choose to run on the Caryvane Cloud Agent, through a hosted worker in the United Kingdom that holds it only for the duration of the transfer and keeps no copy afterwards.
For Microsoft 365 and Google Workspace backups we access your tenant with the permissions your administrator grants, copy the data into your storage, and keep a catalogue (item names, dates, sizes and where each landed) so you can find and restore it. Caryvane's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: that data is used only to provide the backup and restore you asked for, is never sold, and is never used for advertising.
7. When we process on your behalf
For everything in section 6 you decide what is backed up, where it goes and for how long; we act on those instructions. We process it only to provide the service, we do not use it for any purpose of our own, we keep it confidential, we apply the security measures in section 9, we use only the sub-processors listed in section 8, we help you meet your own obligations to the people whose data it is, and we delete or return it when the account ends. Where you need a signed data processing agreement, ask us.
8. Who we share data with
We do not sell personal data. We share it only with the providers we need to run the service, each bound by contract to process it only for us:
- Wildcard UK Limited — hosting of the Caryvane servers, in the United Kingdom.
- Cloudflare — DNS for our domains.
- Google — Analytics on the websites (only with your consent) and, for Google Workspace backups, the APIs your administrator authorises.
- Microsoft — for Microsoft 365 backups, the Graph APIs your administrator authorises; and for the emails we send you (notifications, password resets).
- Resend — email delivery where Microsoft is not used.
- Mollie — card payments. Your card details go to Mollie directly; we never see or store them.
- Xero — invoicing and accounts for business customers.
- Aurawolf Global — development and support, as described in section 1.
We will disclose data where the law requires it, or to protect the rights and safety of our customers, the public or ourselves.
9. Where data is kept, and how it is protected
Our servers are in the United Kingdom. Some of the providers above are in the European Economic Area or the United States; where data leaves the UK it does so under the UK's adequacy regulations or the International Data Transfer Agreement. Data in transit is encrypted with TLS; storage credentials and connector tokens are encrypted at rest; access to production systems is limited to named staff with two-factor authentication and is logged.
10. How long we keep things
- Account, agent, job and audit data: for the life of the account and 90 days after it closes, unless we must keep it longer for tax or legal reasons (invoices: six years).
- Application and web server logs: 30 days.
- Demo requests and support correspondence: 12 months from the last contact.
- Backup content: never held by us beyond a transfer in progress; what is in your storage is yours to keep or delete.
11. Your rights
Under UK data protection law you can ask us for a copy of the personal data we hold about you, ask us to correct or delete it, restrict or object to how we use it, and ask for it in a portable form. Email hello@caryvane.com; we answer within one month. If the data belongs to a backup run by one of our customers, we will pass your request to them, because they decide what is done with it. You can also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
12. Cookies
The websites set no cookies of their own. Google Analytics, if you allow it, sets its _ga cookies to tell returning visitors from new ones; they last up to two years. Your choice is stored in your browser as a preference (not a cookie) and can be changed at any time from Cookie settings in the footer. The console sets a session cookie to keep you signed in; it is essential to the service and needs no consent.
13. Children
Caryvane is a business service and is not directed at anyone under 18. We do not knowingly collect their data.
14. Changes to this policy
When this policy changes we update the date at the top and, for anything that matters to how your data is used, tell account holders by email before it takes effect.