Legal — Data protection
Privacy Policy
The short version
On this website we collect only what you type into the early-access form — your name, work email, company and a couple of optional details — and we email it to ourselves so we can reply. There are no accounts and no advertising or cross-site tracking cookies.
The guided demo stores nothing. It runs entirely in your browser on fabricated data, with no login and no persistence.
Inside the platform itself we act as a processor on behalf of the agency that engages us. We handle their file data on their instructions, under a written agreement. We do not sell data to anyone, ever.
01Who we are
Eskro is a project of Banana Fritters Ltd, a company registered in England and Wales. References to Eskro, we, us or our refer to that entity, which is the controller for the personal data described in section 2.
Data protection enquiries: privacy@eskro.ai. General enquiries: founders@eskro.ai.
02This website
What we collect
The only personal data we collect on eskro.ai is what you submit through the early-access form:
- First name and surname
- Work email address
- Company or agency name, and industry
- Optionally, your biggest time sink and your state or market
The submission is relayed to founders@eskro.ai by our email provider. Alongside it we record the submission timestamp and the country code our CDN attaches to the request. We do not receive or store your full IP address, and we do not fingerprint your browser.
What we do not collect
- No advertising, profiling or cross-site tracking cookies
- No user accounts, passwords or authentication data on this site
- No payment information — nothing is sold through this site
- No special category data under UK GDPR Article 9
Our hosting provider generates standard edge and security logs, as any web host does. These are used for delivery and abuse prevention and are not linked to form submissions or used to build a profile of you.
How we use it
To reply to you, to work out whether your shop is a fit for the preview cohort, and to keep in touch about that specific conversation. We do not add you to a marketing list without asking, and we do not share your details with anyone outside the sub-processors in section 7.
03The guided demo
The demo at eskro.ai/demo is a self-contained illustration running in your browser. It uses fabricated file data, contacts no external system, requires no login, and writes nothing to browser storage or to us. Your interactions with it — which steps you complete, what you click — are not transmitted or recorded.
04The Eskro platform
This section describes how the platform handles data when an agency engages us. It is a summary; the binding terms are in the written agreement and data processing agreement between us and that customer, which prevail over this page.
Roles
For file data processed in the platform, the customer agency is the controller and Eskro is a processor acting on documented instructions. That data may include personal data about buyers, sellers, borrowers and other parties to a transaction. We do not determine the purposes for which it is used, and we do not use it for our own purposes.
What the platform handles
- File data from the customer’s production system and from third-party sources the customer authorises us to access on their behalf
- Credentials for those third-party systems, held in a per-tenant vault, scoped to the capability that needs them, and injected at the point of use — not placed into model context
- Provenance records — the hash-chained ledger of what was perceived and done, including the identity of the officer who authorised each irreversible action
- Exception resolutions — the corrections and decisions officers make when the platform escalates
Isolation and model training
Customer file data is isolated per tenant. Where connector improvements are shared across customers, they are derived from interface evidence — how a portal is laid out and how an intent is recognised — and not from tenant file data, credentials or ledger entries, which never cross a tenant boundary.
We do not use customer file data to train general-purpose models, and we do not permit our model providers to do so. Any use of customer data for model improvement beyond the tenant that produced it requires that customer’s written agreement.
05Legal basis
For the personal data we control under section 2, our lawful bases under UK GDPR are:
- Legitimate interests, Article 6(1)(f) — responding to a business enquiry you initiated, and operating and securing the site. Our interest in replying to you does not override your rights, given the limited data involved.
- Steps prior to a contract, Article 6(1)(b) — where the conversation progresses towards an agreement.
For platform processing under section 4, the lawful basis is determined by the customer as controller, and our processing is carried out on their instructions.
06Retention
| Data | Kept for | Then |
|---|---|---|
| Early-access enquiry | 24 months from last contact | Deleted on review |
| Email correspondence | 24 months from last contact | Deleted on review |
| Hosting / edge security logs | Provider default, short | Automatic expiry |
| Demo interactions | Not collected | — |
| Customer file data | Per customer agreement | Customer-directed deletion or return |
| Provenance ledger entries | Per the agency’s own record-retention obligations | Customer-directed |
| Vaulted credentials | Until revoked by the customer | Destroyed on revocation or termination |
If you ask us to delete your enquiry sooner, we will, subject to anything we are required to keep by law.
07Sub-processors
We use the following third parties. Each is bound by its own terms and, where it processes personal data for us, by a data processing agreement.
- Cloudflare — site hosting, CDN and DNS for eskro.ai. Standard edge logs apply.
- Resend — transactional email relay for the early-access form.
- Cloud infrastructure and model providers — used to operate the platform. The current list is provided to customers under the data processing agreement and updated with notice.
We do not sell, rent or share personal data with third parties for marketing or advertising. We never have, and we do not intend to.
08International transfers
We are a UK company and our early customers are in the United States, so personal data may be transferred outside the UK. Where it is, we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.
09Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict or object to our processing of your personal data, and the right to data portability. To exercise any of these, email privacy@eskro.ai. We will respond within one month.
If your data is in the platform because you are a party to a transaction handled by one of our customers, that customer is the controller. Send your request to them; we will assist them in answering it.
You may also complain to the Information Commissioner’s Office at ico.org.uk. We would rather you raised it with us first, but it is your right either way.
10Security
- Data in transit is encrypted with TLS 1.2 or higher; data at rest is encrypted with AES-256.
- Third-party credentials are held in a per-tenant vault, scoped to the capability that requires them, and are not placed into model context.
- Access to production systems follows least privilege and is logged.
- Irreversible actions in the platform cannot be dispatched without an authenticated human authorisation written to the provenance ledger.
No system is perfectly secure. If you believe you have found a vulnerability, please tell us at security@eskro.ai before disclosing it publicly, and we will work with you.
11Terms of use
Permitted use
This website and the guided demo are provided for informational and evaluation purposes. Use of the Eskro platform requires a separate written agreement and credentials issued by us.
Prohibited use
- Presenting demo output as a real transaction record, or as legal, title or financial advice
- Scraping, systematically extracting from, or attempting to reverse-engineer the site or platform
- Accessing the platform without valid credentials issued by us
- Using the platform to access any third-party system you are not authorised to access
Intellectual property
The Eskro platform, its architecture, intent-graph and provenance methodology, and the content of this site are the intellectual property of the operating entity. See the Patent Notice.
Liability
Use of this site is subject to the Disclaimer, which limits our liability to the extent permitted by law. Use of the platform is governed by the written customer agreement, which prevails over these terms in the event of conflict. These terms are governed by the laws of England and Wales.
12Changes to this policy
We will update this policy as the product develops. Material changes will be flagged at the top of this page with a revised date, and the current version always lives at eskro.ai/privacy.
Questions about this policy: privacy@eskro.ai. Last updated 31 July 2026.