◆ legal

Security

How we protect your data and your customers.

Last updated: July 2026. This page is provided for transparency, is not a contract, and is a template that must be reviewed by a qualified solicitor before launch.

Hosting and infrastructure

Warmenna runs on Amazon Web Services (AWS) in the eu-west-2 (London) region. Production workloads run inside an isolated virtual private cloud with private subnets, so application and database nodes are not directly reachable from the internet, and public endpoints sit behind edge security and DDoS protection. Customer data is not moved outside the UK/EU region except where a connected messaging or AI provider necessarily processes it to deliver the service.

Encryption

Every connection — browser, API and internal service-to-service — uses TLS with modern cipher suites; we do not accept plaintext HTTP. Data at rest, including databases, object storage, backups and logs, is encrypted with AES-256 using keys managed by AWS KMS.

Access control and least privilege

  • Multi-factor authentication is enforced for administrative access, and staff access follows the principle of least privilege — people and services get only the access they need.
  • Role-based access controls govern what each user can see and do.
  • Sensitive actions — such as credential changes, data exports and integration changes — are logged for audit.
  • Production access by our staff is restricted, authenticated and logged.

Tenant isolation

Each business's data is logically isolated from every other business's data. API authentication is scoped per business and per key, so requests cannot reach another business's messages, bookings or contacts. Message content and customer data are only ever processed to deliver the receptionist features a business has configured.

Backups and recovery

  • Databases are backed up automatically each day, encrypted and stored securely.
  • Point-in-time recovery is available within a defined retention window.
  • Object storage uses versioning so recently deleted files can be recovered.

Vulnerability management

Dependencies are scanned continuously and security-relevant updates are prioritised. We follow secure-development practices including code review and secret scanning, and we monitor our infrastructure for anomalous activity.

Incident response

We maintain an incident response process with clear ownership and communication channels. For incidents affecting personal data, we will notify affected customers and, where required, the UK Information Commissioner's Office within 72 hours of confirming scope, in line with Article 33 of the UK GDPR, followed by a review of root cause and remediation.

Compliance

Warmenna is operated by Huup Ltd, registered with the UK Information Commissioner's Office under registration number ZC165061. We process personal data in accordance with the UK GDPR and EU GDPR. Card data is handled by Stripe and is never stored on Warmenna's own systems. A Data Processing Agreement is available to business customers on request.

Responsible disclosure

If you believe you have found a security issue, please email [email protected]. We will acknowledge your report and work with you in good faith to resolve it. Please do not perform testing that degrades the service, accesses other customers' data, or breaks applicable law.