Privacy Policy

This policy says what personal data PikaEdge Ltd. holds about the people who use our control panel, API, websites and support, why, for how long, who else receives it and what your rights are.

Who we are

PikaEdge Ltd., trading as CacheGenie, is the controller of the data described here. We are registered in England and Wales, company number 17079599, registered office PikaEdge Ltd., Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA, United Kingdom, and with the Information Commission (the ICO) under number ZC258579. For anything about your data, email team@cachegenie.com.

What we hold, why and for how long

WhatWhat it holds, why, and for how long
UsersName, email address, a hashed password, the two-factor secret, the permission level and the last sign-in, and any other addresses on the Email contacts list. To run your account. Deleted the day a user is removed or the account closes, except addresses ticked for Billing emails, which stay with the billing records.
Sign-in recordsEach session's IP address and browser, kept 28 days from its last use or until you sign out; the IP address and email address of each failed sign-in and password reset request, kept 24 hours; and reset, welcome and email-change links, kept until used, or for 3 hours (a reset link) or 72 (the others). To keep accounts secure.
Billing recordsCompany and billing details, billing email addresses, invoices, credit notes, payment records (which can include a cardholder's name), the card's brand, last four digits and expiry month, and an EU client's business evidence. To invoice you, take payment and keep tax records. Kept at least six years after the end of the financial year they belong to, as UK tax law requires.
MessagesSupport messages and attachments, emails, reports about content, and contact form enquiries (name, email address, the message and the IP address it came from). To answer you. A queued email and its attachments are kept until delivered, at most 8 days; emails in our mailbox while needed to answer you and as a record of what was agreed or done.
Request countsCounts per IP address, for the API and our public pages and forms. To limit abuse. Kept up to two hours.
LogsOur web servers log each request to the control panel, API and websites (its time, URL, browser, referring page and connecting address) for up to 5 days. The fault log can hold an email address, an email's subject or a failed request's URL, for 30 days, or a month on a delivery server. To find and fix faults and abuse.
Records of access and changesWho, by email address, added or removed your users and zones or changed your account settings, and each time our team opens your account and why, with the IP address each came from. To keep access accountable. Kept with no time limit, as the lasting record of what was done on an account.
BackupsEncrypted copies of the database: hourly for a day, daily for a week, weekly for a month, monthly for a year, yearly for seven years, and one taken by hand until we delete it. Deleted data stays in a backup until that copy goes.

The data comes from you, your account's administrators or our team. Our lawful basis is our legitimate interest in providing, securing and supporting the service and in answering whoever writes to us (or, where you are the client yourself, performing our contract with you), and for billing records our legal obligation to keep them. We need this data to open and run your account. We never sell it, use it for advertising or profile you. Software alone applies sign-in lockouts, rate limits and the free-usage pause in the Terms of Service.

Your viewers

We deliver our clients' content to their viewers only as the client's processor: the Terms of Service say what we do with a viewer's data. The client is its controller.

Who receives it

We share personal data only with these kinds of provider, each receiving only what its job needs, and name them to a client or a prospective client on request.

Kind of providerWhat for
A database, hosting and storage providerRuns the control panel, API, websites and database, keeps their logs, and stores attachments, invoice PDFs, business evidence and encrypted backups
Server, network and DNS providersThe servers that deliver content and carry every request to our own sites
A card payment providerTakes card payments on its own page; the card number never reaches us
An email delivery providerDelivers the emails the service sends: ours to you, and your support messages and enquiries to us
A mailbox providerReceives your emails to us
A certificate authorityIssues certificates for your hostnames, which then appear in public certificate logs
The EU's public VAT number registerChecks an EU VAT number, which is all it receives
Providers of the tools we build and run the service withMay see data while we test and investigate faults

We also disclose data to our professional advisers, to a buyer of our business, where the law requires it, and, when you report a client's content, to that client.

Where it is held and international transfers

Our providers operate in the UK, the European Economic Area and other countries, and the data may be held in any of them. A transfer to a country without a UK adequacy decision is covered by the International Data Transfer Agreement, or by standard contractual clauses with the UK Addendum; email us for a copy.

Security

Every connection to the control panel, the API and our websites is encrypted, as is traffic between our own servers. Passwords and session tokens are stored only as hashes. Two-factor authentication is available to every user, and an account can require it. Ten failed sign-ins lock an IP address or an email address for up to 15 minutes. Our delivery servers are administered by key only, behind a firewall. Backups are encrypted with AES-256. Our team opens a client's account only with two-factor authentication and a stated reason, for at most an hour, and every change is recorded.

Cookies

We set only the cookies the service needs: no analytics or advertising cookies and no third-party scripts, so we ask for no consent. The documentation, the status page and the API set none. If you block cookies you cannot sign in to the NOC, our control panel.

CookieWhat it does
CG_NOC_SESSIONKeeps you signed in to the NOC, for 28 days from its last use or until you sign out
CG_CSRFProtects the forms on the NOC and www.cachegenie.com against forgery and automated abuse, for 28 days

Nine more, each beginning CG_, carry a one-off status message across a page change in the NOC and last 5 minutes. The NOC also caches its own static files and an offline page in your browser; clearing the site's data removes them.

Your rights

You can ask us for a copy of the personal data we hold about you, to correct or delete it, to restrict how we use it, and to have it given to you or another provider in a usable form. You can object at any time to any use that rests on our legitimate interest. Email team@cachegenie.com; we answer within a month.

If you think we have mishandled your data, complain to us at the same address: we acknowledge a complaint within 30 days and tell you the outcome. You can also complain to the Information Commission (the ICO) at ico.org.uk, or to the data protection authority where you live.

Changes

We email the contacts ticked for Account emails before a material change to this policy takes effect. It was last updated on 7 October 2026.

Was this helpful?