Legal

Privacy Policy.

How rendrOS collects, uses, and protects personal information. Written in plain English. Compliant with UK GDPR, EU GDPR, and UAE PDPL.

Effective 1 May 2026Version 2.0Region UK & UAE

Introduction

This Privacy Policy explains how rendrOS Ltd ("rendrOS", "we", "our", "us") collects, uses, stores, and protects personal information when you use our website (getrendros.com), product, or communicate with our team. We comply with the UK GDPR, the EU GDPR (where applicable), the UAE Personal Data Protection Law (PDPL), and the UK Data Protection Act 2018.

By using rendrOS, you agree to the practices described here. We last updated this policy on 1 May 2026.

Who we are

rendrOS is a software platform built for CGI and 3D rendering studios. We are the data controller for personal information collected through our marketing site and the data processor for content uploaded by studios into the rendrOS application.

Data we collect

We collect only the data we genuinely need to operate the service, communicate with prospects, and improve the product.

CategoryExamplesSource
Account dataName, work email, studio name, phone (optional)You provide it
Usage dataPages visited, features used, IP address, device typeAutomatic
Studio contentProject files, render references, comments, version historyUploaded by you
Billing dataCard last 4, billing address, VAT/TRNYou provide it (processed by Stripe)
Support dataEmail threads, screenshots, call recordings if consentedYou provide it

We do not collect special-category data (health, religion, biometrics) and we never buy data from third-party brokers.

How we use it

Under UK/EU GDPR we rely on the following lawful bases:

Who we share data with

We do not sell your data. We share it only with vetted sub-processors who help us run the service:

ProviderPurposeRegion
Amazon Web ServicesHosting, storage, backupsUK (eu-west-2), UAE (me-central-1)
StripePayment processingUK / EU / UAE
PostmarkTransactional emailEU
Plausible AnalyticsCookie-less analyticsEU
SentryError monitoringEU

A current list of sub-processors is available in our Data Processing Addendum.

Data retention

We retain account data for as long as your account is active, plus a 90-day grace window for recovery. After that, we delete or fully anonymise it. Billing records are retained for 7 years to meet UK and UAE tax requirements. You can request earlier deletion at any time.

Your rights

You have the right to:

To exercise any right, email hello@getrendros.com. We respond within 30 days.

Security

We use TLS 1.3 in transit and AES-256 at rest. Studio files are stored in encrypted, region-locked S3 buckets. Access to production systems is restricted, audited, and protected by hardware MFA. We run an annual third-party penetration test and publish summary reports to enterprise customers on request.

International transfers

Data is hosted in the region your studio is registered in (UK or UAE). We do not transfer personal data outside these regions except for limited operational use of EU-based sub-processors, covered by Standard Contractual Clauses and the UK International Data Transfer Addendum.

Contact us

Privacy questions or data requests

hello@getrendros.com