Privacy Policy
This policy says what personal data PikaEdge Ltd. holds about the people who use our control panel, API, websites and support, why, for how long, who else receives it and what your rights are.
Who we are
PikaEdge Ltd., trading as CacheGenie, is the controller of the data described here. We are registered in England and Wales, company number 17079599, registered office PikaEdge Ltd., Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset, BH16 6FA, United Kingdom, and with the Information Commission (the ICO) under number ZC258579. For anything about your data, email team@cachegenie.com.
What we hold, why and for how long
| What | What it holds, why, and for how long |
|---|---|
| Users | Name, email address, a hashed password, the two-factor secret, the permission level and the last sign-in, and any other addresses on the Email contacts list. To run your account. Deleted the day a user is removed or the account closes, except addresses ticked for Billing emails, which stay with the billing records. |
| Sign-in records | Each session's IP address and browser, kept 28 days from its last use or until you sign out; the IP address and email address of each failed sign-in and password reset request, kept 24 hours; and reset, welcome and email-change links, kept until used, or for 3 hours (a reset link) or 72 (the others). To keep accounts secure. |
| Billing records | Company and billing details, billing email addresses, invoices, credit notes, payment records (which can include a cardholder's name), the card's brand, last four digits and expiry month, and an EU client's business evidence. To invoice you, take payment and keep tax records. Kept at least six years after the end of the financial year they belong to, as UK tax law requires. |
| Messages | Support messages and attachments, emails, reports about content, and contact form enquiries (name, email address, the message and the IP address it came from). To answer you. A queued email and its attachments are kept until delivered, at most 8 days; emails in our mailbox while needed to answer you and as a record of what was agreed or done. |
| Request counts | Counts per IP address, for the API and our public pages and forms. To limit abuse. Kept up to two hours. |
| Logs | Our web servers log each request to the control panel, API and websites (its time, URL, browser, referring page and connecting address) for up to 5 days. The fault log can hold an email address, an email's subject or a failed request's URL, for 30 days, or a month on a delivery server. To find and fix faults and abuse. |
| Records of access and changes | Who, by email address, added or removed your users and zones or changed your account settings, and each time our team opens your account and why, with the IP address each came from. To keep access accountable. Kept with no time limit, as the lasting record of what was done on an account. |
| Backups | Encrypted copies of the database: hourly for a day, daily for a week, weekly for a month, monthly for a year, yearly for seven years, and one taken by hand until we delete it. Deleted data stays in a backup until that copy goes. |
The data comes from you, your account's administrators or our team. Our lawful basis is our legitimate interest in providing, securing and supporting the service and in answering whoever writes to us (or, where you are the client yourself, performing our contract with you), and for billing records our legal obligation to keep them. We need this data to open and run your account. We never sell it, use it for advertising or profile you. Software alone applies sign-in lockouts, rate limits and the free-usage pause in the Terms of Service.
Your viewers
We deliver our clients' content to their viewers only as the client's processor: the Terms of Service say what we do with a viewer's data. The client is its controller.
Who receives it
We share personal data only with these kinds of provider, each receiving only what its job needs, and name them to a client or a prospective client on request.
| Kind of provider | What for |
|---|---|
| A database, hosting and storage provider | Runs the control panel, API, websites and database, keeps their logs, and stores attachments, invoice PDFs, business evidence and encrypted backups |
| Server, network and DNS providers | The servers that deliver content and carry every request to our own sites |
| A card payment provider | Takes card payments on its own page; the card number never reaches us |
| An email delivery provider | Delivers the emails the service sends: ours to you, and your support messages and enquiries to us |
| A mailbox provider | Receives your emails to us |
| A certificate authority | Issues certificates for your hostnames, which then appear in public certificate logs |
| The EU's public VAT number register | Checks an EU VAT number, which is all it receives |
| Providers of the tools we build and run the service with | May see data while we test and investigate faults |
We also disclose data to our professional advisers, to a buyer of our business, where the law requires it, and, when you report a client's content, to that client.
Where it is held and international transfers
Our providers operate in the UK, the European Economic Area and other countries, and the data may be held in any of them. A transfer to a country without a UK adequacy decision is covered by the International Data Transfer Agreement, or by standard contractual clauses with the UK Addendum; email us for a copy.
Security
Every connection to the control panel, the API and our websites is encrypted, as is traffic between our own servers. Passwords and session tokens are stored only as hashes. Two-factor authentication is available to every user, and an account can require it. Ten failed sign-ins lock an IP address or an email address for up to 15 minutes. Our delivery servers are administered by key only, behind a firewall. Backups are encrypted with AES-256. Our team opens a client's account only with two-factor authentication and a stated reason, for at most an hour, and every change is recorded.
Cookies
We set only the cookies the service needs: no analytics or advertising cookies and no third-party scripts, so we ask for no consent. The documentation, the status page and the API set none. If you block cookies you cannot sign in to the NOC, our control panel.
| Cookie | What it does |
|---|---|
| CG_NOC_SESSION | Keeps you signed in to the NOC, for 28 days from its last use or until you sign out |
| CG_CSRF | Protects the forms on the NOC and www.cachegenie.com against forgery and automated abuse, for 28 days |
Nine more, each beginning CG_, carry a one-off status message across a page change in the NOC and last 5 minutes. The NOC also caches its own static files and an offline page in your browser; clearing the site's data removes them.
Your rights
You can ask us for a copy of the personal data we hold about you, to correct or delete it, to restrict how we use it, and to have it given to you or another provider in a usable form. You can object at any time to any use that rests on our legitimate interest. Email team@cachegenie.com; we answer within a month.
If you think we have mishandled your data, complain to us at the same address: we acknowledge a complaint within 30 days and tell you the outcome. You can also complain to the Information Commission (the ICO) at ico.org.uk, or to the data protection authority where you live.
Changes
We email the contacts ticked for Account emails before a material change to this policy takes effect. It was last updated on 7 October 2026.