SECURITY & COMPLIANCE

Security and compliance, built into Wren.

Wren combines UK-hosted infrastructure with data protection practices shaped by ICO guidance, helping your team use business data with greater control and confidence.

  • UK-hosted infrastructure
  • Registered with the ICO
  • UK GDPR and PECR
  • DMA member
DocumentedaccountabilityGovernanceSecurityIndividualrightsPrivacy

ACCOUNTABILITY BY DESIGN

Guided by the ICO accountability framework

Good data protection requires more than a policy. It requires clear responsibilities, documented decisions and controls that work throughout the data lifecycle. Our approach is shaped around the accountability and data protection by design principles set out by the Information Commissioner’s Office.

Lawful, fair and transparent

We document why personal data is processed and explain how business information is collected, used and shared through our privacy information.

Purpose limitation

Data is processed for defined business purposes, with controls intended to prevent incompatible or unexpected use.

Data minimisation

We limit the information we process and provide to fields that have a clear and relevant business use.

Retention and deletion

Defined retention schedules govern customer uploads, account information, operational records and other data held by the platform.

Demonstrable accountability

Policies, responsibilities, processing records and risk assessments help us document what we do and why.

Wren Data is registered with the Information Commissioner’s Office as a data controller.

ICO registration number: ZA000000

View our ICO registration ↗

RESPONSIBLE MARKETING

Built to support compliant B2B marketing

UK GDPR and PECR do not prevent responsible business marketing, but the rules depend on the information used, the recipient and the method of contact. Wren provides the information and controls customers need to make informed decisions about their campaigns.

Where a business contact can be identified, their details may be personal data. Customers must identify an appropriate lawful basis, apply the relevant PECR rules and respect objections to direct marketing.

Compliance is shared

Wren is responsible for how it compiles and maintains its data. Customers remain responsible for deciding who they contact, why they contact them and how each campaign is carried out.

Read the ICO’s direct marketing guidance ↗

Before using business data

  • Confirm the purpose of the campaign
  • Select and document an appropriate lawful basis
  • Apply the correct rules for the contact and marketing channel
  • Check applicable TPS, CTPS and suppression information
  • Clearly identify the sender
  • Provide a simple way to object or opt out
  • Honour objections and maintain suppression records

Suppression, TPS and CTPS screening are applied throughout Wren’s own validation process.See how we build our data →

PLATFORM SECURITY

Protected from upload to export

Security controls protect customer and platform data throughout its lifecycle, from authentication and upload through to processing, storage and export.

Encryption

Stored data is protected using AES-256 encryption, with TLS used to protect data moving between users, services and the platform.

Access control

Role-based permissions, multi-factor authentication and controlled administrative access help limit data access to authorised users.

Monitoring and audit records

System monitoring and audit logging help us detect unusual activity, investigate events and maintain operational oversight.

Resilience and recovery

Automated backups and documented recovery processes support platform availability and the restoration of protected data.

Secure uploads and retention

Uploaded files pass through controlled, access-checked processes and are retained only for defined periods.

Private, controlled AI

AI-assisted processing runs within controlled services. Customer uploads are not submitted to public AI tools or used to train public models.

Your data stays in the UK

Wren is built, hosted and maintained in the UK. Customer data, processing and primary storage remain within our controlled UK-hosted environment.

CLEAR RESPONSIBILITIES

Knowing who is responsible for your data

Our contracts and privacy information set out the role Wren performs for each type of processing.

Wren business data

Wren acts as a controller when compiling and maintaining its business and contact information. Customers normally become independent controllers when selecting, exporting and using that information.

Customer uploads

Where Wren processes an uploaded customer file solely to provide an agreed service, its role is set out in the applicable contract and Data Processing Agreement.

Account and service data

Wren acts as a controller for information required to operate accounts, manage billing, provide support and protect the service.

Read our privacy policyData Processing AgreementOn requestSubprocessor listOn requestTerms of service

INDIVIDUAL RIGHTS

Straightforward access, correction and opt-out

People can ask about the personal data Wren holds, request corrections and object to the use of their information for direct marketing. Requests are reviewed through a defined rights-handling process.

Access

Ask whether Wren holds personal data about you and request a copy where applicable.

Correction

Tell us if business or contact information is inaccurate or out of date.

Objection

Object to the use of your personal data for direct marketing.

Erasure and suppression

Request removal where applicable. We may retain limited suppression information where this is necessary to ensure that an objection continues to be respected.

Need more detail for a security review?

We can provide further information about our security controls, data handling, retention, supplier management and contractual protections to support your review.

SECURITY & COMPLIANCE FAQ

Security and compliance questions

  • Is Wren Data registered with the ICO?

    Yes. Wren Data is registered with the Information Commissioner’s Office as a data controller. Registration confirms our inclusion on the ICO’s public register of data protection fee payers. It is not an ICO certification or endorsement.

  • Is Wren Data hosted in the UK?

    Yes. Wren’s primary platform infrastructure, customer data and processing are hosted in the UK.

  • Does UK GDPR allow B2B marketing?

    UK GDPR does not prohibit B2B marketing. Organisations must have an appropriate lawful basis when processing personal data, follow the relevant PECR rules and respect the absolute right to object to direct marketing. The requirements vary according to the recipient and marketing channel.

  • Does using Wren make a campaign compliant?

    Wren provides data, suppression information and platform controls designed to support responsible marketing. Each customer remains responsible for the purpose, targeting, lawful basis and delivery of its campaigns.

  • Does Wren use customer files to train AI models?

    No. Customer uploads are not used to train public or shared AI models. AI-assisted processing takes place through controlled services subject to Wren’s security and data handling requirements.

  • How long are uploaded files retained?

    Uploaded files are retained according to the service being used and the applicable retention schedule. Files uploaded to Pulse are automatically deleted after 30 days. Read our privacy policy