Applies to: deepwell.software, the Deepwell application, and the Report portals Deepwell hosts for its customers.
The short version
- We collect what you type into our forms, what you need to sign in, and the data your connected systems return when you build a Report.
- We use it to run Deepwell, to answer you, and to see how the website and the product are being used.
- On the public website we use analytics, ad-measurement cookies, and session recording, but only after you accept the cookie banner.
- We do not sell your personal information. We share it with the service providers we use to run Deepwell, and we name them.
- Data from your connected systems belongs to you and your clients. We process it only to build and deliver your Reports.
- You can ask us what we hold about you, ask us to correct it, or ask us to delete it, at any time.
The full policy below is what governs. If the short version and the full text ever differ, the full text is correct.
Who we are
Deepwell Software is operated by Ummm Software, LLC, an Indiana limited liability company ("Deepwell", "we", "us").
You can reach us about anything in this policy at legal@deepwell.software or through the contact form.
Who this policy is for
This policy covers three groups of people. Different sections apply to each.
- Visitors to deepwell.software, including people who fill in a form or read the documentation.
- Users of the Deepwell application: the people at a managed service provider (an "MSP") who have a Deepwell account, and the people at an MSP's client (an "Organization") who are invited to view Reports.
- People whose information appears in an MSP's data. If your name is in a ticket, a device record, or a report that an MSP built with Deepwell, we hold that information on the MSP's behalf and under its instructions. See "Data from your connected systems" below, and contact the MSP for questions about it.
If you visit deepwell.software
In short: we keep what you send us through a form, and we measure how the site is used only if you accept the cookie banner.
Forms
When you use the contact, support, booking, or Early Access forms, we keep what you type. That means your name, work email, company, phone number, and your answers to any other fields on the form. We use it to reply to you and to follow up on your enquiry, and we keep it until you ask us to delete it or until we no longer need it to work with you.
The "Keep me updated" form takes only your email address, which we use to send you product updates. Every email to that list includes an unsubscribe link, and we do not give your address to anyone except the email service that sends the mail for us and our customer relationship system.
Cookies, analytics, and session recording
When you first visit, a banner asks whether you accept analytics and ad-measurement cookies and session recording. Before you decide, the Google tag on the page sends Google anonymous, cookieless signals: the page address, the page that referred you, and the ad click that brought you if there was one. No cookie is set, no identifier is stored, and nothing is recorded until you accept. If you reject, the site remembers only your choice, in your browser, so it does not ask again, and Google keeps receiving only those anonymous signals.
If you accept, these run on the public pages of deepwell.software:
| Service | What it does | Their policy |
|---|---|---|
| Google Analytics | Counts page views and which buttons and forms are used, so we can see what works | How Google uses information from sites that use its services |
| Google Ads conversion measurement | Tells Google Ads when a visit from one of our ads led to an enquiry. We do not build advertising audiences or show you ads on other sites based on your visit. | Google Privacy Policy |
| Microsoft Clarity | Records how the page is used (clicks, scrolling, mouse movement) as heatmaps and session replays, so we can see where the site is confusing. Clarity masks what you type into forms. Microsoft may also use what it collects for its own purposes. | Microsoft Privacy Statement |
None of these run inside the signed-in application's Report portal or on a custom domain an MSP has set up for its own clients.
You can withdraw your acceptance at any time by clearing the site's cookies.
California residents: we do not sell personal information. Sending conversion data to Google Ads may count as "sharing" under California law. Rejecting the banner stops it, and we honor the Global Privacy Control browser signal as an opt-out.
Do Not Track: there is no agreed standard for how websites respond to this signal, so the cookie banner, not the signal, controls what we set.
Server logs
Like any website, our servers keep standard logs so we can keep the site running and find faults, and errors in your browser on our site are reported to us. Logs are kept for a limited time.
If you have a Deepwell account
In short: we keep the details you need to sign in and use Deepwell, we record which pages you open so we know which features get used, and we do not record your sessions.
To create and run your account we keep your name, email address, and, if you give it, your phone number, along with which MSP or Organization you belong to and what you are allowed to do there. That includes details an MSP admin enters when inviting you. When you sign in with Microsoft, Microsoft tells us your name, email address, and account identifier, and we keep those. We never receive your Microsoft password.
To keep you signed in, we set sign-in cookies that expire after a short period and are not used for analytics or advertising, and we keep an identifier for the browser you signed in from for a limited time.
Inside the signed-in application we count which pages are opened, tagged with your account and MSP identifiers rather than your name or email address, so we know which features get used. We do not record sessions, keystrokes, or screen contents inside the application.
If you use the feedback form in the application, we keep what you write together with which page you were on and enough about your browser and the page to reproduce what you saw.
Data from your connected systems
In short: it is yours. We use it to build and deliver your Reports and for nothing else.
When an MSP connects a tool such as a PSA, backup, or security platform, it gives Deepwell credentials for that tool. We encrypt those credentials before we store them and decrypt them only when a Report or Data Source needs to call the tool. We never show them to anyone, including our own staff.
Data that comes back from those tools ("Connected Data") can include information about the MSP's clients and their people. We store Connected Data when a Report runs, as part of the Report Snapshot the MSP delivers to its client.
For Connected Data, the MSP is the controller and Deepwell is a processor. That means:
- We process it only to provide Deepwell to the MSP and as the MSP instructs.
- We do not use it for advertising, and we do not sell it.
- We do not use it to train artificial-intelligence models, and our AI providers are contractually barred from doing so.
- The MSP is responsible for having the right to collect it and for its own privacy notices to its clients.
- If you are a client of an MSP and want to know what is held about you, contact the MSP. We will help the MSP answer you.
- The terms on which we process Connected Data are governed by our agreement with the MSP.
AI features
Deepwell uses AI models to help build Data Sources and charts. When you use one of those features, we send the model your request, the structure of the data you selected, and a small sample of the data so the model can understand it. Our AI providers are listed below, and none of them may use your data to train their models.
If you view Reports in a portal branded by your service provider
Some MSPs deliver Reports through a portal under their own name and domain. Deepwell hosts that portal for the MSP. When you sign in there, we hold your name, email address, and Microsoft account identifier so we can show you the Reports delivered to your Organization, and we set the same sign-in cookies described above. We run no analytics, advertising, or session recording on a custom domain. The MSP's own privacy notice governs what it does with the Reports and the data in them.
Who we share personal information with
In short: the companies whose services we use to run Deepwell, under contract, and nobody else unless the law requires it.
We do not sell personal information, and we do not give it to anyone for their own marketing.
We use these service providers. Each one processes data only to provide its service to us, under a written agreement, and each is based in the United States.
| Provider | What it does for us |
|---|---|
| Google Cloud Platform | Hosts Deepwell, its database, logs, and encryption keys |
| Google Vertex AI | Runs the AI models behind Deepwell's AI features |
| Twilio SendGrid | Sends our email: invitations, sign-in codes, enquiry notifications, product updates |
| Attio | Our customer relationship system: holds enquiries and the contacts and companies they come from, so we can follow up |
| Microsoft | Signs you in with your Microsoft account |
| Honeycomb | Application performance monitoring |
| Google Analytics, Google Ads, Microsoft Clarity | Website analytics and measurement, only with your consent |
We keep this list current. If we add a provider that handles Connected Data, we tell MSP customers in advance under our agreement with them.
We also share personal information when the law requires it: to comply with a court order, subpoena, or lawful request from a public authority; to enforce our agreements; or to protect the rights, safety, or property of Deepwell, our customers, or others. If a public authority asks us for a customer's data, we tell the customer unless we are legally prevented from doing so.
If Deepwell is sold, merged, or reorganised, or moves to a new company, personal information may be transferred as part of that. The new owner will be bound by this policy for the data it receives.
When our staff look at your data
Our staff can see account details, enquiries, feedback, and the Reports an MSP has built, in order to support customers and run the service. Support staff can also open Deepwell as a specific user, to see exactly what that user sees, when that is needed to resolve a problem.
How we keep it safe
We protect personal information with measures that include encryption in transit and at rest, managed encryption keys for stored credentials, short session lifetimes, and access to production systems limited to the staff who need it. No system is perfectly secure, but we take the protection of your data seriously and we will tell you if a breach affects you.
How long we keep it
We keep personal information for as long as we need it for the purpose we collected it, and then delete it. Account details stay while your account exists. Enquiries stay until you ask us to delete them or we no longer need them. Connected Data and Report Snapshots stay as long as the MSP keeps the Report, and are deleted when the MSP asks or closes its account. Logs, sign-in identifiers, and session recordings are kept for a limited time and then deleted automatically.
Your choices and rights
In short: ask, and we will tell you what we have, fix it, or delete it.
Whoever you are and wherever you live, you can ask us to:
- tell you what personal information we hold about you and give you a copy;
- correct it;
- delete it;
- stop sending you marketing email.
Email legal@deepwell.software. We will confirm it is you, usually by replying to the email address we hold, and answer within 30 days. Asking will never affect the service you get from us.
If you use Deepwell through an MSP, some requests need to go to the MSP, because the MSP controls its account and its Connected Data. We will point you to the right place and help the MSP respond where we reasonably can.
If you are in the European Economic Area or the United Kingdom, you also have the rights to restrict or object to processing, to data portability, to withdraw consent, and to complain to your data protection authority. Our legal basis for processing is the contract with you or your MSP, your consent for the cookie banner and marketing email, and our legitimate interest in running and improving Deepwell and keeping it secure. Deepwell is based in the United States and processes data there. Where we receive personal information from the EEA or the UK, we rely on standard contractual clauses with our providers.
Children
Deepwell is for businesses and is not directed at children. We do not knowingly collect their information. If you believe we have, contact us at legal@deepwell.software.
Changes to this policy
When we change this policy we update the date at the top and describe the change in the list below. If a change materially affects how we use personal information we already hold, we will tell you before it takes effect.
Change history
- September 17, 2026: said that the Google tag sends anonymous, cookieless signals before you accept the cookie banner.
- September 16, 2026: first version.
Contact
Ummm Software, LLC (Deepwell Software) legal@deepwell.software