Privacy Policy
Last updated 25 September 2026
In plain English
- The Next Renaissance Ltd runs Slurry and is responsible for the personal data we collect about our customers and website visitors.
- We collect what we need to run accounts, take payment, keep the service secure and support you: names, work emails, billing details (held by Stripe), IP addresses and usage logs.
- Simulations must never contain real personal data. If some gets in by mistake, we treat it under our Data Processing Addendum and may delete it.
- We do not sell your data and we do not use advertising or analytics cookies.
- You can ask to see, correct or delete your data by emailing privacy@slurry.io, and you can complain to the ICO.
1. Who we are
1.1 Slurry (slurry.io) is operated by The Next Renaissance Ltd, a company registered in England and Wales with company number 10373346, whose registered office is at [registered office address] ("we", "us", "our").
1.2 We are the controller of the personal data described in this policy. You can contact us about privacy at privacy@slurry.io or by post to our registered office. We have not appointed a data protection officer because we are not required to; privacy@slurry.io reaches the person responsible for data protection.
1.3 This policy applies to visitors to slurry.io, people who create or use a Slurry account, people who contact us, and people named as contacts by our business customers.
2. Data inside Simulations
2.1 Slurry creates simulated test environments filled with synthetic data. Our Terms of Service and Acceptable Use Policy prohibit customers from putting real personal data into Simulations, and we scan for it.
2.2 If a customer does put personal data into a Simulation, the customer is the controller of that data and we act as its processor under our Data Processing Addendum. Questions about that data should go to the customer concerned. If we detect it, we may quarantine or delete it.
2.3 Synthetic names, emails and other values in Generated Data are fictitious. Any resemblance to a real person is coincidental. If you believe a Simulation contains data about you, email privacy@slurry.io with the address of the Simulation and we will investigate.
3. What we collect and why
| Category | Examples | Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|---|---|
| Account data | Name, work email, organisation, role, hashed password, multi-factor settings | Create and run your account, authenticate you | Contract (6(1)(b)); for contacts of a business customer, legitimate interests (6(1)(f)) in running the customer relationship |
| Billing data | Billing contact, billing address, VAT number, payment status, last four digits and expiry of card (full card data is held by Stripe, not us) | Take payment in advance, issue invoices, calculate tax, prevent fraud | Contract (6(1)(b)); legal obligation (6(1)(c)) for tax and accounting records |
| Security and access data | IP addresses, IP allow-list entries, API key identifiers, login times, device and browser information, MCP Server client identifiers | Enforce IP restrictions, secure accounts, detect intrusion and abuse | Legitimate interests (6(1)(f)) in securing the Service; contract (6(1)(b)) for allow-listing you configure |
| Usage and request logs | Requests to Simulations (time, source IP, endpoint, status, size), feature usage, Credit consumption, error logs | Operate and bill the Service, debug, capacity planning | Contract (6(1)(b)); legitimate interests (6(1)(f)) in improving reliability |
| Abuse monitoring data | Results of automated scans of Customer Content and Generated Data, flagged content samples, abuse reports and investigation notes | Enforce the Acceptable Use Policy, protect third parties from phishing, malware and attacks | Legitimate interests (6(1)(f)) in preventing abuse and fraud; legal obligation (6(1)(c)) where we must report |
| Support and correspondence | Emails, support tickets, feedback | Respond to you and improve the Service | Legitimate interests (6(1)(f)); contract (6(1)(b)) |
| Marketing preferences | Whether you want product news | Send product updates and news | Legitimate interests (6(1)(f)) for existing business customers with an easy opt-out; consent (6(1)(a)) where required by PECR |
| Website data | IP address and request logs from visiting slurry.io, strictly necessary cookies | Deliver and secure the website | Legitimate interests (6(1)(f)) |
3.1 We do not intentionally collect special category data and ask you not to send it to us.
3.2 We do not make decisions that have legal or similarly significant effects on you based solely on automated processing. Automated abuse scanning may block a request or flag an account, but suspension or termination of an account for abuse is reviewed by a person, except where immediate action is needed to stop serious harm, in which case a person reviews it promptly afterwards.
3.3 We do not use customer content or Generated Data to train language models, and we configure our model providers not to use it for training where that option is available.
4. Where we get data from
Most data comes from you or your organisation when you sign up, configure the Service or contact us. Some comes from Stripe (payment status and fraud signals), from our infrastructure providers (logs), and from people who report abuse.
5. Who we share data with
5.1 We share personal data only with:
- our sub-processors and service providers, listed at https://slurry.io/legal/subprocessors, who act on our instructions (hosting, payments, content delivery and security, email and language model providers);
- your organisation, where you use the Service as one of its Authorised Users (for example, account owners can see who has access and audit logs);
- professional advisers such as lawyers, accountants and insurers, under confidentiality;
- law enforcement, regulators and other authorities where we are required by law, or where we reasonably believe disclosure is needed to prevent crime, fraud or harm, including in response to abuse under our Acceptable Use Policy;
- a buyer or successor if our business or assets are sold or restructured, under equivalent protections.
5.2 We do not sell personal data and we do not share it for third-party advertising.
5.3 If you use your own language model key, requests you make go to your chosen model provider under your own agreement with it. That provider is not our sub-processor.
6. International transfers
6.1 Some of our sub-processors store or access data outside the United Kingdom, including in the European Economic Area and the United States. Where we transfer personal data outside the UK we make sure it is protected by one of the following: UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework where the recipient is certified); the International Data Transfer Agreement issued by the ICO; or the EU Standard Contractual Clauses with the UK International Data Transfer Addendum. We carry out a transfer risk assessment where required.
6.2 You can ask for more information about the safeguards for a specific transfer by emailing privacy@slurry.io.
7. How long we keep data
| Data | Retention |
|---|---|
| Account data | For the life of the account, then deleted within 90 days of closure unless needed for the purposes below |
| Billing and invoice records | 6 years after the end of the financial year they relate to, to meet UK tax and company law obligations |
| Request logs for Simulations | 30 days rolling |
| Security and access logs | 12 months |
| Abuse investigation records | 3 years after the case is closed, or longer if needed for legal claims or law enforcement |
| Support correspondence | 2 years after the last contact |
| Marketing preferences and suppression list | Until you opt out, then the suppression record is kept so we do not contact you again |
| Customer Content and Generated Data | For the life of the Simulation; deleted within 60 days of account termination (see Terms of Service clause 16.6), with backups expiring within 35 days after that |
8. Security
We protect personal data using measures appropriate to the risk, including encryption in transit (TLS) and at rest, hashing of passwords and API keys, encryption of stored third-party model keys, IP allow-listing and multi-factor authentication, least-privilege access for staff, audit logging, separation of staging and production environments, and regular review of our controls. No system is completely secure; if a breach affecting your personal data occurs, we will notify you and the ICO where required by law.
9. Your rights
9.1 Under UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have data erased in certain circumstances;
- restrict our processing in certain circumstances;
- object to processing based on legitimate interests, and to object at any time to direct marketing;
- data portability, for data you provided to us that we process by automated means on the basis of contract or consent;
- withdraw consent at any time where we rely on consent, without affecting processing already carried out.
9.2 To exercise a right, email privacy@slurry.io. We may need to verify your identity. We will respond within one month, which may be extended by up to two further months for complex requests; we will tell you if so. We do not charge a fee unless a request is manifestly unfounded or excessive.
9.3 Where your data is held by us as a processor for a customer (see section 2.2), we will pass your request to that customer and help them respond.
10. Complaints
If you have a concern, please contact us first at privacy@slurry.io so we can try to resolve it. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection: https://ico.org.uk/make-a-complaint/, telephone 0303 123 1113, or by post to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. If you are in the European Economic Area you may also complain to the supervisory authority in your country.
11. Cookies
We use only strictly necessary cookies. See our Cookie Policy at https://slurry.io/legal/cookies.
12. Children
The Service is for businesses and is not directed at children. We do not knowingly collect data about anyone under 18.
13. Changes
We may update this policy. We will post the new version here with a new version date and, for material changes, tell account holders by email.
The Next Renaissance Ltd, trading as Slurry, registered in England and Wales, company no. 10373346. Questions: legal@slurry.io