Deronda Works Ltd
Privacy notice
Deronda holds what putting someone on cover actually requires, and does very little with it. The paragraphs below say exactly what, exactly who can see it, and — the part worth reading — what nobody can.
Who we are
Deronda Works Ltd operates Deronda, software used by employers, their insurance broker, and the people covered by an employer’s international private medical insurance. For the records an employer puts into Deronda about its own people, the employer is the data controller and Deronda is its processor. For your account with us — the email address you sign in with — we are the controller.
What we hold about a covered person
A member’s record holds their name, date of birth, nationality and country of residence, an employee reference, a start date, a work email address, and whether they have taken up the cover. Where a spouse, partner or children are covered under the same policy, we hold the same details for them.
This is what an insurer requires to put somebody on cover, and what an employer needs to administer it. Deronda holds it so there is one authoritative list rather than three partial ones — the employer’s spreadsheet, the broker’s email trail and the insurer’s system.
We hold no medical information. Deronda is not where claims are made. Claims are made with your insurer; Deronda records what the insurer reports back, as amounts and dates, to produce aggregate figures.
What your employer and your broker can see — and cannot
Both can see the details above, because both administer your cover. Your broker sees the membership of the clients they are assigned to; they could obtain the same list from the insurer, and having it here is what lets them go to market at renewal without rebuilding it from email.
Neither can see what you claimed for, what you read, or what you asked. That is the boundary that matters and it has not moved. Claims reach an employer and a broker as aggregates only — how many, how much, how long to settle — never who, and withheld entirely below three claims. Nothing records which articles you opened, and no exchange with the assistant reaches either of them.
Requests, and how briefly they hold detail
A request to add or change someone carries their details while it is open, so whoever actions it can act. Those details are not copied into the audit trail or into any notification, and they are cleared once the request settles — the standing record is the roster, not a trail of requests about it.
The retention window for settled requests is set by the employer’s own compliance decision and applied automatically. Until an employer sets one, details are kept rather than purged — a surprise deletion is worse than holding a record a fortnight too long, and only one of those is reversible.
Enforced, not promised
None of the limits above is a setting on our screens. Each is enforced in the database by row-level security, and each is covered by an automated test that runs against the live system on every change — 61 of them at the last count, including one that exists purely to check a broker still cannot read a single assistant exchange.
Who else sees anything
- Your employer’s insurance broker — the clients they are assigned to, the policies they placed, and claims as the same aggregates, for the purpose of advising on and renewing the cover.
- An investor, where your employer has one on Deronda — identity only (that the company is on Deronda, its headcount, its renewal month) unless your employer has switched financial sharing on. That switch belongs to your employer and can be turned off again, at which point the figures stop.
- Nobody else. We do not sell data, we do not share it with advertisers, and we do not aggregate one client’s data into a product sold to another.
Companies that process data for us
- Supabase — the database and sign-in, hosted in London (eu-west-2).
- Vercel — application hosting.
- Resend — sending invitation and notification emails, where an employer has that enabled.
- Anthropic — only where the member assistant is switched on for your employer. The question and the relevant part of your own cover are sent. The prompt is built on the server from your own record and carries no name, because a name would not help it answer and there is no reason to send one. No client data is used to train any model.
Tracking
There is none. No analytics, no advertising pixels, no third-party scripts, and no cookie banner — because there are no cookies to consent to until you sign in. See the cookie statement, which is short enough to read.
How long we keep things
Member records are kept while the cover runs and afterwards as part of the employer’s record of who was covered and when — that is what a renewal and a late claim both turn on. Personal details on requests are purged as described above. The commission ledger and the audit log cannot be edited or deleted by anyone, including us; a correction is a new dated entry. No retention window reaches them, and that is deliberate: a record of who was paid what is only worth having if it cannot be quietly revised.
Your rights
You can ask for a copy of what we hold about you, ask us to correct it, or object to how it is used. Where your employer is the controller, we will pass the request to them and help them answer it. Write to privacy@deronda.works. If you are not satisfied, you can complain to the Information Commissioner’s Office at ico.org.uk.
Changes
If this notice changes in a way that affects what we hold or who sees it, the date at the top changes and anyone signed in is told. We do not make a material change quietly.