
Privacy & cookies
How the DelaControl hub uses cookies, and what we record about you when you use it.
Cookies
The hub sets three cookies, all of them needed to sign you in and keep you signed in:
- Session token — proves you're signed in, so you don't have to log in on every page. It expires after about eight hours.
- Security token — protects forms against being submitted by another site on your behalf.
- Return address — remembers which page to send you back to after Zoho signs you in.
There is no advertising, no analytics and nothing from a third party. Because these cookies are strictly necessary to provide a service you asked for by clicking “Sign in with Zoho”, we don't need to ask your consent for them, which is why there's no cookie pop-up. We're telling you anyway.
What we record about you
DelaControl is the data controller for this. We record:
- Your name and work email, from your Zoho account, so we know who you are and what you should see.
- Which apps you have access to, and who granted it and when.
- Your sign-ins — the date and time, and a short description of the device taken from your browser, such as “Computer · Windows 10/11 · Chrome 140”. We keep the last 40. We do not record IP addresses or location.
- Which apps you've opened recently, so the home page can put them in front of you.
- Your device declarations — what you confirmed and the date you confirmed it.
We don't read your files, your email or anything inside the Zoho apps themselves through this hub — it takes you to them, it doesn't look inside them.
Why
Access records and sign-in history exist so we can tell who can reach what, and remove access when someone changes role or leaves. Declarations exist because DelaControl is working towards Cyber Essentials certification, which asks us to show that devices reaching our systems are looked after. Our lawful basis is legitimate interests — keeping the company's systems and data secure.
A declaration is your statement about your own device. The hub cannot inspect your device and does not try to. The device description in the sign-in log comes from what your browser reports about itself.
How long we keep it
Sign-in history is capped at your most recent 40 sign-ins, so it rolls over by itself. Declarations are kept for as long as you work here plus the current certification cycle, because the point of them is to show what was declared and when. Access records are removed when your access is removed.
Your rights
You can ask to see what we hold about you, have it corrected, or object to how it is used. Please contact the operations team. If you are not satisfied with how your request has been handled, you may complain to the Information Commissioner's Office at ico.org.uk.