Privacy Policy
Last updated: 22 July 2026
1. Who is responsible
The data controller for scanhive.net is eNetIdeas Ltd (company number 07465254), registered in England and Wales at 3rd Floor, 86–90 Paul Street, London, EC2A 4NE — enetideas.com. Contact: [email protected]. For documents your organisation scans through Scanhive, your organisation is the controller and we act as a processor on its instructions.
2. What we collect
- Account data — name, email address, organisation name, hashed password, optional two-factor settings, session records (IP address, browser user-agent).
- Service configuration — printers, verified recipient addresses, destinations and their credentials (encrypted at rest), routing rules.
- Scanned documents — received from your printers, held transiently while being delivered. Documents are stored longer only if you enable a storage destination, in which case they are encrypted at rest with a key unique to your organisation.
- Activity records — per-scan metadata (sender, recipients, sizes, timestamps, delivery outcomes) for your activity log and our abuse prevention.
- Contact form — the name, email and message you send us, protected by Cloudflare Turnstile (which processes technical signals such as your IP address to distinguish humans from bots).
3. Why we process it
- To provide the service (contract): receiving, virus-scanning, processing, delivering and — where enabled — storing your scans; operating your account.
- Security and abuse prevention (legitimate interest): recipient verification, rate limits, audit records, spam filtering.
- Service emails (contract): verification links, password resets, important notices. We do not send marketing email without consent.
- Legal obligations: records we must keep, and responding to lawful requests.
4. Where your data lives and who helps us
Data is hosted in the UK and EU. We use a small number of sub-processors:
- Mailgun (EU region) — outbound email delivery (scans to email, service emails).
- Cloudflare — DNS, web proxying, and Turnstile bot protection.
- DigitalOcean — hosting for our inbound mail server.
- UK-based object storage and servers operated for eNetIdeas Ltd — document spool and opt-in storage.
We do not sell personal data, and we do not share documents with anyone except the destinations you configure.
5. How long we keep it
- Scans in transit — raw messages are held in a delivery spool and removed on a short rolling basis after successful delivery.
- Stored documents (opt-in storage only) — until you delete them, your retention policy removes them, or your account closes.
- Account and activity data — for the life of the account and up to 90 days after closure, except records we must keep longer by law.
6. Your rights
Under UK and EU data-protection law you can ask for access to, correction of, deletion of, or a copy of your personal data, object to or restrict processing, and withdraw consent where processing is based on it. Write to [email protected] and we will respond within a month. You can also complain to the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
7. Cookies
The dashboard uses one essential, HttpOnly session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies. Cloudflare Turnstile may set its own cookie strictly for bot detection on protected forms.
8. Security
Transport encryption end-to-end from our intake onward; destination credentials and stored documents encrypted at rest with per-organisation keys; recipient double opt-in so documents cannot be sent to unverified addresses; antivirus scanning of every attachment; tenant isolation enforced at the application and database layers. No system is perfectly secure — if we become aware of a breach affecting your data we will notify you without undue delay.
9. Changes
We will post any changes to this policy here and, for material changes, notify you by email or in the dashboard.