Privacy

Last updated 15 August 2026

1. Who we are

Isola is operated from the United Kingdom. For UK GDPR, we are the data controller for account data and the processor for the figures teams enter. Contact: isola@sundappleapp.com

2. What we hold

We do not hold tax identification numbers, bank account details, or identity documents.

3. Why we hold it

To perform the contract with you — running the product you signed up for. Nothing here is used for advertising or profiling, and we do not sell or share it with anyone for their own purposes.

4. Who else sees it

Nobody else.

5. Where it lives

On servers in the United Kingdom or European Economic Area. If that ever changes we will say so here first.

6. Keeping and deleting it

This is the part worth reading properly, because there is a real tension and we would rather set it out than gloss over it.

Isola's value comes from the ledger being append-only. Entries are never edited or deleted; a correction is a new entry that reverses an old one. That is what makes it possible to show what your team agreed in September when you are arguing about it in December.

That sits awkwardly with the right to erasure. Our position:

If that trade-off is not acceptable to you, export your statement and close your account before you have anything credited.

7. Your rights

You can ask for a copy of what we hold, correction of anything wrong, deletion as described above, or a portable export. The last one needs no request: your statement of account exports as CSV from your own page, on any plan, at any time, including if the team stops paying.

If you think we have handled your data badly, tell us first, and you can complain to the Information Commissioner's Office at ico.org.uk.

8. Cookies

One cookie, to keep you signed in. It is HttpOnly, SameSite=Strict, and Secure. There is no analytics, no tracking, and no advertising cookie, which is why there is no cookie banner.

9. Security

Passwords are hashed with scrypt. Sign-in attempts are rate limited. Everything travels over HTTPS. Sessions expire and are invalidated when you reset your password.

No system is perfect. If we ever have a breach affecting your data we will tell you and the ICO within the time the law requires.

10. Changes

If we change anything material here we will tell you by email rather than quietly updating the page.