1. Who we are
ARYZ is a local marketing, content, customer-engagement and business intelligence platform. The legal entity responsible for this website and for the personal data described in this Privacy Policy is DR Rent Ltd, trading as ARYZ.
- Company number: 17279894
- Registered in: England and Wales
- Registered office: 1 Walpole Road, Slough, England, SL1 6AU
- ICO registration number: ZC180247
- Email: hello@aryz.co.uk
In this Privacy Policy, “ARYZ”, “we”, “us” and “our” mean the legal entity identified above.
2. What this Privacy Policy covers
This Privacy Policy explains how we collect, use, disclose, store and protect personal data when you:
- visit aryz.co.uk or any ARYZ webpage;
- create or use an ARYZ account or workspace;
- purchase a subscription, credits, add-on or managed service;
- contact us, request a demonstration, complete a form or communicate with support;
- connect Google, Meta, Instagram, Facebook, YouTube, Search Console, Google Analytics, Google Business Profile, Canva or another third-party service;
- upload screenshots, documents, images, videos, contact records, leads, reviews, messages or other content;
- use ARYZ to create, approve, schedule, publish, analyse or report on marketing activity; or
- appear in information uploaded to ARYZ by one of our customers.
It also explains the choices and legal rights available to individuals.
3. Our roles as controller and processor
3.1 When ARYZ is a controller
ARYZ normally acts as a data controller when we decide why and how personal data is used, including for:
- website visitors;
- account owners, users and team members;
- billing, subscription and payment administration;
- sales, enquiries and customer support;
- security, fraud prevention, audit logs and service administration;
- product analytics and service improvement;
- our own business-to-business communications; and
- compliance with legal and regulatory duties.
3.2 When ARYZ is a processor
ARYZ normally acts as a data processor on behalf of a customer when the customer uploads or connects personal data relating to its own prospects, customers, tenants, landlords, contractors, reviewers, followers, contacts, employees or other individuals. Examples include:
- screenshots of posts, comments, direct messages or reviews;
- names, telephone numbers, email addresses and lead records;
- customer communications and support histories;
- social-media content and audience interactions;
- connected Google Business Profile reviews and account data;
- marketing lists and campaign data; and
- customer-generated reports and attribution records.
In those circumstances, the customer decides the purposes and lawful basis for the processing and is generally the controller. We process that data on the customer’s documented instructions under our Terms of Service and Data Processing Terms.
If you are an individual whose data has been uploaded by an ARYZ customer, you should usually contact that customer first. We will assist the customer with valid data-rights requests.
4. Personal data we collect
Depending on how ARYZ is used, we may collect the following categories.
4.1 Identity and contact information
- name;
- business name and role;
- work email address;
- telephone or mobile number;
- postal or business address;
- profile photograph or avatar;
- login identifier; and
- contact preferences.
4.2 Account and workspace information
- user ID and workspace ID;
- team membership and permissions;
- account status;
- subscription, plan and entitlements;
- connected locations, brands and channels;
- Business DNA, Company Brain, brand settings and audience information;
- approval and publishing permissions;
- user preferences; and
- account activity.
4.3 Billing and transaction information
- subscription plan;
- billing name and address;
- VAT status and tax information;
- payment status;
- invoices, credits, refunds and transaction references;
- payment method type and limited card metadata supplied by our payment processor, such as card brand and last four digits; and
- Stripe customer and subscription identifiers.
ARYZ does not normally receive or store full payment-card numbers.
4.4 Website, device and technical information
- IP address;
- browser and device type;
- operating system;
- time zone and approximate location derived from IP;
- referring page;
- pages and features used;
- login and session data;
- cookie and similar-technology identifiers;
- error, diagnostic and performance data; and
- security and audit logs.
4.5 Customer Content
“Customer Content” includes information that customers or authorised users enter, upload, connect, create or process through ARYZ, such as:
- screenshots;
- posts, comments, captions, replies and direct messages;
- images, video, audio, logos and documents;
- names and contact details visible in uploaded material;
- reviews and review replies;
- lead, opportunity and CRM records;
- notes, tasks, calendars and approval histories;
- social-media and website content;
- campaign details and tracking links;
- performance and revenue-attribution information;
- prompts, instructions, AI-generated drafts and user edits; and
- data imported from connected services.
4.6 Connected-platform information
Where you authorise a connection, we may receive information from Google, Meta, YouTube, Canva or another provider. The exact data depends on the permissions you approve and the features you use. This may include:
- account, channel, page, profile and location identifiers;
- business names, addresses, categories, opening hours and profile information;
- reviews, comments, messages and replies;
- posts, media and publishing status;
- audience and performance metrics;
- Google Analytics properties, metadata and report data;
- Search Console properties and performance data;
- YouTube channel and video metadata;
- OAuth access and refresh tokens;
- token expiry and connection-health information; and
- permission and authorisation records.
We do not receive your Google, Meta, Canva or other third-party account password.
4.7 Communications and support information
- emails, chat messages and contact-form submissions;
- support tickets;
- call notes and demonstration requests;
- attachments;
- feedback, survey responses and feature requests; and
- records of notices or service communications sent to you.
4.8 Marketing information
- whether you have opted in or objected to marketing;
- campaign source;
- email engagement information where legally permitted;
- event or webinar registration; and
- business interests inferred from your interaction with ARYZ.
5. Information about other people
ARYZ allows customers to upload screenshots and other material that may contain personal data about third parties.
Customers must only upload or process personal data where they have a valid legal basis and must provide any privacy information required by law. Customers must not use ARYZ to scrape, profile, contact, discriminate against, harass or market to people unlawfully.
Customers should minimise personal data before uploading screenshots. Where possible, they should crop, blur or remove information that is irrelevant to the intended task.
ARYZ is not designed for the routine processing of:
- special-category data, such as health, racial or ethnic origin, religious beliefs, political opinions, trade-union membership, biometric data or sexual-life information;
- criminal-offence data;
- children’s data; or
- highly confidential government identifiers or payment credentials.
Do not upload this information unless the feature expressly supports it, the processing is lawful, appropriate safeguards are in place and ARYZ has agreed to the processing in writing.
6. How we collect personal data
We collect data:
- directly from you;
- from your employer, agency, workspace owner or team administrator;
- from connected third-party accounts that you authorise;
- from Customer Content uploaded by you or another authorised user;
- automatically through use of our website and platform;
- from payment, authentication, hosting, communications and security providers;
- from publicly available business sources where lawful; and
- from another person who refers or introduces you to us.
7. How and why we use personal data
We only use personal data where we have a lawful basis.
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Create and administer accounts and workspaces | identity, contact, account and technical data | performance of a contract; legitimate interests |
| Provide ARYZ features | Customer Content, connected-platform data, account data | performance of a contract; where we act as processor, the customer’s documented instructions |
| Connect and operate third-party integrations | connected-account data, OAuth tokens, identifiers and content | performance of a contract; user authorisation; legitimate interests |
| Create AI-assisted drafts, analysis and recommendations | prompts, Customer Content, approved business context and limited connected-platform data | performance of a contract; legitimate interests; processor instructions |
| Schedule or publish approved content | Customer Content, connected-account tokens and publishing instructions | performance of a contract; user authorisation |
| Import and display analytics, reviews and performance data | connected-platform and usage data | performance of a contract; legitimate interests |
| Process payments, invoices, credits and renewals | billing and transaction data | performance of a contract; legal obligation |
| Provide support and respond to enquiries | contact, account and communications data | performance of a contract; legitimate interests |
| Protect accounts, prevent fraud and investigate misuse | identity, device, technical, audit and usage data | legitimate interests; legal obligation |
| Maintain, test and improve ARYZ | usage, diagnostic, feedback and de-identified or aggregated data | legitimate interests |
| Send service messages | account and contact data | performance of a contract; legitimate interests |
| Send optional marketing | contact and preference data | consent where required; otherwise legitimate interests for lawful business-to-business marketing |
| Comply with law and enforce our rights | any relevant data | legal obligation; legitimate interests; establishment, exercise or defence of legal claims |
| Corporate transactions | relevant account and business records | legitimate interests; legal obligation |
Where we rely on legitimate interests, those interests may include operating and securing ARYZ, supporting customers, improving product reliability, preventing misuse, measuring service performance and developing our business. We assess whether those interests are overridden by the rights and interests of individuals.
8. Artificial intelligence and automated analysis
ARYZ uses artificial intelligence and automated rules to assist with tasks such as:
- drafting posts, comments, replies, blogs, messages and reports;
- analysing screenshots and classifying potential opportunities;
- extracting names, locations, dates and contact details;
- suggesting audiences, actions, channels and calls to action;
- identifying duplicate leads;
- generating or editing images;
- analysing performance and making recommendations; and
- scoring or prioritising possible leads or opportunities.
AI output can be incomplete, inaccurate, inappropriate or misleading. ARYZ is designed to support human decision-making, not replace it. Users must review outputs before relying on or publishing them.
ARYZ does not use automated processing to make decisions that produce legal effects, or similarly significant effects, about individuals without meaningful human involvement.
ARYZ does not itself use Customer Content or Google user data to train a general-purpose foundation model. Where a third-party AI provider processes data to deliver an ARYZ feature, it acts as a contracted service provider under its applicable business or API terms. We aim to send only the data reasonably necessary for the selected feature.
9. Google user data
This section applies when a user connects a Google account or uses a Google-powered integration.
9.1 Google permissions ARYZ may request
Depending on the features selected, ARYZ may request access to:
- Google Business Profile (business.manage) — to identify and connect authorised business accounts and locations; display or update business information; import reviews and performance information; draft or publish approved replies; and publish approved content where supported.
- Google Search Console (webmasters.readonly) — to identify verified website properties and display read-only search-performance information and recommendations.
- Google Analytics (analytics.readonly) — to identify authorised properties and display read-only analytics reports, metrics and dimensions.
- YouTube read access (youtube.readonly) — to identify the connected channel and read channel, video and publishing metadata needed for account selection, content management and reporting.
- YouTube upload access (youtube.upload) — to upload videos that an authorised user has selected and approved for publication.
ARYZ will not take an action on a Google account beyond the functionality disclosed to the user and authorised through the relevant feature.
9.2 How ARYZ uses Google data
We use Google user data only to:
- authenticate and maintain the requested connection;
- show the user the accounts, locations, properties or channels available to them;
- provide the connected feature selected by the user;
- create dashboards and reports requested by the user;
- draft content or replies for human review;
- perform an approved upload, update, reply or publishing action;
- diagnose connection and permission errors;
- protect the connection from fraud or misuse; and
- comply with legal obligations.
We do not use Google user data for unrelated advertising, surveillance or sale.
9.3 How Google data is stored
We may store:
- encrypted or otherwise protected OAuth access and refresh tokens;
- Google account, property, location and channel identifiers;
- selected profile or business metadata;
- imported reviews, metrics and report data required for ARYZ features;
- publishing and approval records; and
- connection-health and audit information.
We do not store a user’s Google password. Access is limited according to workspace permissions and operational need.
9.4 Sharing and human access
We do not sell Google user data. We share Google user data only:
- with infrastructure, hosting, security or AI service providers acting under contract where necessary to deliver the requested ARYZ feature;
- with the relevant Google API to perform the action requested by the user;
- with authorised members of the same ARYZ workspace according to permissions;
- where the user expressly directs us to disclose or publish it; or
- where required by law.
ARYZ personnel may access Google user data only where reasonably necessary to provide user-requested support, investigate a security or abuse incident, comply with law, or maintain the service, and access is subject to confidentiality and access controls.
9.5 Google Limited Use commitment
ARYZ’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
9.6 Retention and deletion of Google data
Google OAuth tokens are retained only while the relevant connection remains active or while needed to complete a user-requested action. A user may disconnect Google within ARYZ or revoke ARYZ access through their Google Account.
Following disconnection, account closure or a valid deletion request, we will delete or render unusable stored OAuth tokens and Google user data that is no longer required, subject to:
- reasonable deletion cycles;
- temporary encrypted backups;
- fraud, security and audit requirements;
- legal retention duties; and
- information that the user has independently published or exported.
Our target is to remove active OAuth credentials promptly and delete associated active-system data within 30 days, unless a shorter period is technically available or a longer period is legally required. Backup copies are deleted or overwritten through the normal backup cycle, normally within 90 days.
9.7 Revoking Google access
Users may revoke access by:
- disconnecting the integration in ARYZ Settings → Integrations; or
- removing ARYZ from the third-party apps and services section of their Google Account.
A user may also email hello@aryz.co.uk for assistance.
10. Other connected services
Where a customer connects Meta, Facebook, Instagram, Canva, Stripe or another service, ARYZ uses the authorised information only to provide the selected integration, maintain connection health, perform approved actions and provide related reporting.
Third-party platforms operate under their own terms and privacy policies. ARYZ does not control how those providers independently process personal data.
11. Payment processing
Payments are processed by a specialist payment provider, currently Stripe or another provider shown at checkout. Payment providers process payment information as independent controllers or processors according to their own privacy terms.
ARYZ normally stores only transaction references, subscription status, invoices and limited payment-method metadata.
13. Direct marketing
We may send business-to-business information about ARYZ where lawful and relevant. We use consent where required by law.
Every electronic marketing message will include a way to opt out. You can also object by emailing hello@aryz.co.uk. Opting out of marketing does not stop essential account, billing, security or service communications.
Customers using ARYZ for their own outreach are responsible for complying with applicable privacy and electronic-marketing laws, including consent, legitimate-interests, suppression and opt-out requirements.
15. International transfers
Some service providers may process personal data outside the United Kingdom. Where required, we use an approved transfer mechanism, such as:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved standard contractual clauses; or
- another lawful safeguard.
We also assess relevant security and transfer risks where required.
16. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described, including legal, accounting, security and dispute-resolution requirements. Our usual retention approach is:
| Record | Typical retention |
|---|---|
| Account and workspace administration data | for the account term and up to 6 years after termination where needed for contractual, tax or legal claims |
| Customer Content in active systems | until deleted by the customer or until account termination, subject to the post-termination deletion process |
| Deleted Customer Content | removed from active systems through normal deletion cycles, generally within 30 days |
| Encrypted backup copies | overwritten or deleted through the backup cycle, normally within 90 days |
| OAuth tokens | until disconnection, revocation, expiry or account closure, then promptly disabled and removed from active systems |
| Billing, invoice and tax records | normally 6 years after the relevant accounting period, or longer where law requires |
| Support and complaint records | normally up to 6 years after closure where needed to establish or defend claims |
| Security and audit logs | normally 12 to 24 months, unless needed for an investigation |
| Sales enquiries that do not become customers | normally 24 months after the last meaningful interaction |
| Marketing preferences and suppression records | for as long as needed to honour the preference and demonstrate compliance |
| Aggregated or irreversibly anonymised information | may be retained without a fixed period because it no longer identifies an individual |
A customer may be able to configure shorter retention periods for some workspace information.
17. Security
We use technical and organisational measures designed to protect personal data, including where appropriate:
- encryption in transit and at rest;
- role-based access control;
- workspace separation;
- least-privilege access;
- multi-factor authentication for administrative access;
- secure credential and secret management;
- logging and audit trails;
- backups and recovery procedures;
- vulnerability management;
- supplier due diligence;
- confidentiality obligations;
- incident response procedures; and
- periodic review of security controls.
No online service is completely secure. Customers are responsible for protecting login credentials, configuring user permissions correctly and promptly notifying us of suspected unauthorised access.
18. Personal data breaches
We maintain procedures to identify, investigate and respond to security incidents.
Where ARYZ acts as a controller, we will notify affected individuals and the Information Commissioner’s Office where required by law.
Where ARYZ acts as a processor, we will notify the relevant customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide reasonable assistance with the customer’s legal obligations.
19. Your data-protection rights
Subject to applicable law and exemptions, individuals may have the right to:
- be informed about processing;
- access personal data;
- correct inaccurate or incomplete data;
- request deletion;
- restrict processing;
- object to processing based on legitimate interests;
- object to direct marketing;
- receive certain data in a portable format;
- withdraw consent at any time where processing relies on consent; and
- request human review of certain automated decisions.
To exercise a right, email hello@aryz.co.uk with enough information to identify the relevant account or record. We may need to verify identity. We normally respond within one month, although the period may be extended where legally permitted.
Where ARYZ processes data for a customer, we may refer the request to that customer and assist them.
20. Complaints
Please contact us first so we can try to resolve the issue.
You also have the right to complain to the UK Information Commissioner’s Office. Contact information is available on the ICO’s official website. If you are outside the United Kingdom, you may also have the right to complain to your local data-protection authority.
21. Children
ARYZ is a business service and is not intended for children. Account holders must be at least 18 years old and authorised to act for the relevant business.
Customers must not knowingly use ARYZ to target, profile or process children’s personal data unless the processing is lawful, necessary, appropriately safeguarded and expressly supported by the service.
22. Third-party links and public publishing
ARYZ may contain links to third-party websites and may publish content to connected platforms at a user’s direction.
Once information is published publicly, it may be copied, indexed, shared or retained by third parties outside ARYZ’s control. Users should review all content and personal data before publication.
23. Business transfers
If ARYZ or the relevant business is sold, reorganised, financed or transferred, personal data may be disclosed to professional advisers and prospective or actual transaction parties under appropriate confidentiality and data-protection safeguards.
24. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to ARYZ, the law, our suppliers or our data practices.
We will update the date at the top and, where a change is material, provide an appropriate notice. If we materially change how Google user data or other personal data is used, we will provide additional notice and obtain consent where required before using the data for the new purpose.
25. Contact us
Questions, requests and complaints should be sent to:
- Data Protection Contact, DR Rent Ltd trading as ARYZ
- Email: hello@aryz.co.uk
- Postal address: 1 Walpole Road, Slough, England, SL1 6AU