Fenora Pro
/ Legal

Privacy Policy

How Fenora Pro collects, uses, stores and protects personal data — including exactly what we do with data from connected mailboxes, and what we will never do with it.

Effective 3 August 2026 · Last updated 3 August 2026

1.Who we are

Fenora Pro ("Fenora", "we", "us") is a business-to-business software platform for joinery workshops, window fabricators and installers. The platform provides a visual window and door configurator, pricing engine, quotation and e-signature tools, a customer relationship management (CRM) workspace, a field survey application and an integrated email workspace.

Fenora is operated from the United Kingdom and is provided at https://fenora.pro, with the application workspace at https://app.fenora.pro and the field survey application at https://survey.fenora.pro.

For the personal data of our own customers (the businesses that subscribe to Fenora and the individual users within them), Fenora is the data controller. For the personal data that a subscribing business enters into, or connects to, its own workspace — its customers, leads, quotations, surveys and mailbox content — Fenora acts as a data processor on that business's instructions, and the subscribing business is the controller.

Contact for privacy, account and general enquiries
hello@fenora.pro
Postal enquiries
Written enquiries may be requested by email and will be answered in writing.

2.Scope of this policy

This policy explains what personal data Fenora collects, why we collect it, how we use and protect it, who we share it with, how long we keep it and what rights you have. It applies to:

  • The Fenora marketing website (fenora.pro) and any public pages such as quotation signing links.
  • The authenticated Fenora workspace (app.fenora.pro), including the CRM, quoting, pricing, production and mail modules.
  • The Fenora field survey application (survey.fenora.pro), including its offline capture and installable app behaviour.
  • Third-party services we connect on your instruction, including Google (Gmail), Microsoft 365 / Outlook, IMAP/SMTP mail servers, Stripe and QuickBooks.

This policy does not govern how a subscribing business uses the personal data of its own customers. Each subscribing business is responsible for its own lawful basis, notices and retention decisions in respect of the records it holds in its workspace.

3.Personal data we collect

a. Account and identity data

When you register or are invited to a workspace we collect your name, email address, password (stored only as a salted hash by our authentication provider), workspace role and permissions, invitation status, and the display name and signature you choose for outgoing email.

b. Business and billing data

Company name, trading address, VAT status, chosen subscription plan, purchased seats and add-ons, subscription status, billing period and the payment identifiers returned to us by Stripe. We never receive or store full card numbers.

c. Workspace content you create

Leads, contacts, companies, addresses, telephone numbers and email addresses of your own customers; notes, tasks, activities and pipeline history; quotations, product configurations, pricing, discounts, documents and drawings; signatures, signer names, signing timestamps and the IP address recorded at the moment a quotation is signed; supplier records, purchase orders and delivery information.

d. Survey and field data

Site addresses and access notes; window and door measurements and specifications; photographs and annotations; sketches; voice notes and their transcriptions; checklist answers; customer sign-off names, drawn signatures and declarations; the surveyor assigned and the times a survey was started, submitted and reviewed. Survey data may be captured offline on a device and uploaded when connectivity returns.

e. Email data from connected mailboxes

Where you connect a mailbox, we process message headers (sender, recipients, subject, dates, Message-ID and threading references), message bodies, attachments, read and draft state, and folder or label information, for the mailboxes and time period you select. See section 6 for the specific Google disclosures.

f. Technical and usage data

IP address, browser and device type, operating system, pages and features used, timestamps, error and diagnostic logs, authentication events, and product analytics events describing in-app actions (for example that a quotation was created). We do not use analytics events to build profiles for advertising.

g. Communications with us

Messages you send us by email or through the platform, including support requests and demo enquiries.

4.Why we use your data, and our lawful bases

Under the UK GDPR and EU GDPR we rely on the following lawful bases:

Performance of a contract
To create and administer your account and workspace, deliver the configurator, pricing, quoting, CRM, survey and mail features you subscribe to, process your subscription, and provide support.
Legitimate interests
To secure the platform and prevent abuse; to maintain audit trails of who changed what and when; to diagnose faults and improve the product; to enforce plan entitlements and seat limits; to send service and administrative messages about your account.
Consent
To connect a third-party mailbox or accounting account on your behalf (given through the provider's own authorisation screen), to send optional marketing email, and to place any non-essential cookies. Consent may be withdrawn at any time.
Legal obligation
To keep tax, accounting and VAT records, and to respond to lawful requests from authorities.

We do not sell data

Fenora does not sell, rent or licence personal data. We are a software supplier, not a lead marketplace or advertising business. The leads and customers in your workspace are never pooled with those of other workspaces, resold or used to market to your customers.

5.Artificial intelligence features

Certain optional features use large language models and machine transcription — for example summarising an email conversation, extracting a window specification from correspondence, drafting a reply, transcribing a surveyor's voice note, or answering questions about your own workspace records.

  • These features run only when you invoke them, on the specific content you invoke them against.
  • Content is sent to our AI infrastructure provider solely to generate the requested output, and is returned to your workspace.
  • Content processed by these features is not used to train or improve generalised AI or machine-learning models.
  • Data from connected Google mailboxes is never used for AI or machine-learning model development, as set out in section 6.
  • AI output is an assistance tool. It may be inaccurate and must be checked before it is relied on commercially — see the Terms of Service.

6.Google user data — access, use, storage and sharing

Fenora's email module can connect to your Gmail or Google Workspace mailbox so that customer correspondence appears alongside the relevant deal, quotation and survey in your CRM. This section is the disclosure required by the Google API Services User Data Policy, including its Limited Use requirements.

a. Scopes requested and why

openid and userinfo.email
To confirm which mailbox address you have authorised, so messages are filed to the correct connection.
gmail.readonly
To read the messages, threads and attachments in the mailboxes and time window you select, so that correspondence can be shown in Fenora and matched to the right customer, deal or quotation.
gmail.send
To send, on your explicit instruction, the emails you compose in Fenora — quotations, survey requests, replies and invitations — from your own address so your customer sees a normal message from you.
gmail.modify
To reflect actions you take in Fenora back in your mailbox where you have enabled that, such as marking a conversation read or archiving it.

We request the narrowest scopes that support the features you enable, and we do not use these scopes for any purpose other than those stated above.

b. How Google user data is stored

OAuth access and refresh tokens are held by our platform's secure connector layer and are retrieved server-side at the moment of use. They are never stored in application records and never exposed to the browser. Message content that has been synced is stored in your isolated workspace database so that conversations remain readable, searchable and linkable within the CRM.

c. How Google user data is shared

Google user data is not transferred to any third party except: (i) our infrastructure and hosting sub-processors, acting under contract solely to operate the service; (ii) other authorised users of your own workspace, in accordance with the sharing setting you choose for each conversation (private, shared or team); and (iii) where required by law. It is never sold, and never shared for advertising.

Google Limited Use commitment

Fenora's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the user-facing features described above; we do not use it for advertising or serve advertisements of any kind; we do not use it to develop, train or improve generalised artificial-intelligence or machine-learning models; we do not sell it; and we allow humans to read it only where you have given explicit consent for a specific message, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.

d. Retaining and deleting Google user data

You may disconnect a mailbox in Fenora at any time under Settings, which stops all further access. Disconnecting stops synchronisation immediately; you may also request that the synced message content be deleted, and we will delete it. You can independently revoke Fenora's access to your Google Account at any time at https://myaccount.google.com/permissions. Revoking access does not delete correspondence already stored in your workspace — email hello@fenora.pro to have it removed. When a Fenora workspace is closed, connections and synced mail content are deleted in accordance with section 10.

7.Other connected services

Microsoft 365 / Outlook
Where connected, we process mail data through the Microsoft Graph API for the same email purposes described in section 6, under the permissions granted at authorisation.
IMAP / SMTP mailboxes
For providers without OAuth, you may connect using a username and an application-specific password. Host settings are stored in your workspace; credentials are stored only in encrypted secret storage and are never displayed back to the browser.
Stripe
Handles subscription checkout and payment. Stripe processes your billing details as an independent controller under its own privacy policy; we receive only subscription status, plan, seat and add-on information and non-sensitive identifiers.
QuickBooks
Where connected, quotations and estimates you choose to push are sent to your QuickBooks account, together with the associated customer name and contact details necessary to create the record.
Infrastructure and AI providers
Cloud hosting, database, file storage, email delivery and AI inference providers process data strictly on our instructions as sub-processors.

8.Who your data is shared with

  • Other users of your workspace, according to the roles, permissions and field-level rules your workspace administrator configures.
  • Recipients you choose — for example a customer sent a quotation, a signing link or a survey report.
  • Sub-processors providing hosting, storage, email delivery, payment processing and AI inference, under written terms restricting them to our instructions.
  • Professional advisers, auditors and insurers where necessary and confidential.
  • A purchaser or successor, if Fenora is reorganised, merged or acquired, subject to this policy continuing to apply.
  • Law enforcement, regulators or courts where we are legally required to disclose, or to protect our rights, safety or property.

Workspaces are isolated from one another at the database level by row-level security. No other business using Fenora can access your records.

9.International transfers

Fenora is operated from the United Kingdom. Some of our sub-processors — including cloud hosting, email and AI infrastructure providers — may process data outside the UK and the European Economic Area, including in the United States.

Where personal data is transferred outside the UK or EEA, we rely on an adequacy decision where one applies, or otherwise on the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, together with additional technical and organisational safeguards such as encryption in transit and at rest.

10.How long we keep data

Workspace content
Retained for as long as your subscription is active, because it is your operational business record. You control creation, editing and deletion within the app.
After cancellation
Workspace data is retained for 30 days so the workspace can be restored or exported, then deleted or irreversibly anonymised, except where we must keep records by law.
Synced email content
Deleted when you disconnect a mailbox and request deletion, and in any event on workspace deletion.
Billing and tax records
Retained for seven years, as required by UK accounting and tax law.
Security and audit logs
Retained for up to 12 months for security, integrity and dispute-resolution purposes.
Signed quotations and audit trails
Retained for the life of the workspace, and for six years thereafter where necessary to evidence a contract, unless you instruct deletion.

11.How we protect data

  • Encryption in transit (TLS) and encryption of stored data at rest.
  • Database-level tenant isolation enforced by row-level security on every read and write, so records cannot cross workspace boundaries.
  • Role-based access control and configurable per-user permissions, including restrictions on what field staff may see of the CRM.
  • OAuth tokens and mail credentials held in a secure secret store, resolved only server-side and never exposed to the browser.
  • Passwords stored only as salted hashes; multi-step verification on registration.
  • Server-side re-checking of every permission and entitlement, so a modified client request cannot widen access.
  • Regular backups, monitored infrastructure and least-privilege administrative access.

No system can be guaranteed absolutely secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the UK Information Commissioner's Office within 72 hours where required, and inform affected controllers and individuals without undue delay.

12.Your rights

Subject to the conditions in applicable data protection law, you have the right to:

  • Be informed about how your personal data is used — this policy.
  • Access a copy of the personal data we hold about you.
  • Have inaccurate or incomplete data corrected.
  • Have your data erased where there is no overriding lawful reason to keep it.
  • Restrict or object to processing, including processing based on legitimate interests.
  • Receive your data in a portable, machine-readable format — workspace records can be exported at any time.
  • Withdraw consent, including by disconnecting a mailbox or revoking access at your provider.
  • Not be subject to solely automated decisions with legal or similarly significant effects. Fenora does not make such decisions.
  • Complain to a supervisory authority — in the UK, the Information Commissioner's Office at ico.org.uk.

To exercise any right, email hello@fenora.pro. We respond within one month, and will tell you if we need longer. If your data sits inside a subscribing business's workspace, we will refer your request to that business as controller and support them in answering it.

13.Cookies and local storage

We use strictly necessary cookies and browser storage to keep you signed in, maintain your session across the marketing, workspace and field subdomains, remember interface preferences, and protect against abuse. These are essential to the service and cannot be switched off within the platform.

The field survey application stores survey data, photographs and pending uploads in your device's local storage so it can work offline on site. This data is held on your device until it has synced, and is cleared when you sign out.

We use privacy-respecting product analytics to count feature usage. We do not use advertising cookies, cross-site tracking pixels or third-party ad networks. Where Fenora embeds a tracking pixel in an email you send, it is your own open-tracking feature operating on your own outbound message, and can be disabled.

14.Children

Fenora is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has been provided to us, contact hello@fenora.pro and we will delete it.

15.Changes to this policy

We may update this policy to reflect changes to the platform, our sub-processors or the law. The effective date at the top of this page always shows the current version. Where a change materially affects how we handle your personal data, we will notify workspace administrators by email or in the app before it takes effect. Continued use of Fenora after that date constitutes acceptance of the updated policy.

16.Contact us

Questions, requests or complaints about privacy should be sent to hello@fenora.pro. We aim to resolve concerns directly, but you always retain the right to complain to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority.