Privacy
How we protect your data

Your relationships are private
The Social Gardener is useful because it can understand the context around the people who matter to you. That may include personal information you would not want exposed, shared or used for other purposes. We design the service accordingly.
Your data is yours
We use your information only to provide The Social Gardener to you. We do not sell it, use it for advertising, share it with other users, or use your private relationship data to train general-purpose AI models.
Your relationship data is kept separate
Your personal relationship information is stored within your own protected account environment. We do not build a shared social graph that connects information about the same person across different users.
If two Social Gardener users both know the same person, those remain two separate private relationships.
Sensitive information is protected
Relationship information is encrypted when stored and when transmitted. We also design the service so that access to sensitive data is tightly controlled and limited to what is required to provide the service.
The aim is not simply to protect a database, but to reduce the consequences of any single security failure.
We use context without unnecessarily spreading it
When The Social Gardener needs relationship context to make a recommendation or help you prepare for a conversation, we aim to use only the information required for that task and avoid creating unnecessary additional copies of sensitive data.
You remain in control
You decide what information you give The Social Gardener and which services you connect. You can review and remove your data, and disconnect connected services.
Our principle is simple: The Social Gardener should be able to know a great deal on your behalf without making that knowledge available to anyone else.
This section contains the more detailed legal information about how The Social Gardener handles personal data. It supplements the plain-English explanation above.
Last updated: 15 September 2026
1. Who we are
The Social Gardener is operated by Carothers Ltd, registered in England under company number 15065138, with its registered office at 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.
For privacy enquiries, contact hello@social-gardener.com.
2. Our role
The Social Gardener handles two different kinds of personal data, and our legal role differs between them.
Private Relationship Data
“Private Relationship Data” means the information that you provide, import, connect or create in order to build and use your private relationship memory.
It may include information about you and about people you know. You decide which relationships to include, which information sources to connect, what information to add, and what you want The Social Gardener to do with that information.
We process Private Relationship Data on your behalf and under your instructions, in order to provide The Social Gardener to you.
Where data-protection law applies to you as a controller, you are the controller of Private Relationship Data and Carothers Ltd acts as your processor.
If you use The Social Gardener solely for personal or household purposes and your own processing therefore falls outside applicable data-protection legislation, we nevertheless apply substantially the same restrictions: your Private Relationship Data is processed for you, not for independent purposes of our own.
We do not sell Private Relationship Data, use it for advertising, build a shared social graph between users, or use it to train general-purpose artificial intelligence models.
Service Data
Carothers Ltd acts as controller for the limited personal information we need in order to operate The Social Gardener as a service.
This may include:
- your name and contact information;
- account and authentication information;
- subscription and billing information;
- communications with us;
- device and technical information;
- security, audit and access logs; and
- limited product-usage information necessary to operate, secure and improve the Service.
We refer to this as “Service Data”.
3. Private Relationship Data we may process
Depending on the features you choose to use, Private Relationship Data may include:
- names, email addresses, telephone numbers and other contact details;
- address-book information;
- calendar events, attendees and meeting information;
- emails, correspondence and associated metadata;
- notes and memories about people and relationships;
- family, professional and social connections;
- organisations, roles and employment information;
- communication and interaction history;
- documents or other information you upload;
- information from services you choose to connect;
- relationship classifications, priorities, summaries and recommendations generated for you; and
- other contextual information contained within material you choose to make available to The Social Gardener.
Human relationships encompass many aspects of life. Information you make available to The Social Gardener may therefore sometimes contain legally protected or sensitive information, including information relating to health, religious or philosophical beliefs, political opinions, ethnicity, sexuality or other special-category information.
We do not collect such information for an independent purpose. Where it appears within Private Relationship Data, we process it on your behalf and in accordance with your instructions.
Where you are subject to data-protection law as a controller, you remain responsible for ensuring that your processing has any lawful basis or special-category condition required by that law.
4. Where Private Relationship Data comes from
Private Relationship Data may come from:
- information you enter directly;
- contacts or address books you connect;
- calendars you connect;
- email accounts you connect;
- documents or other material you upload;
- other services you explicitly choose to connect; and
- information generated for you by The Social Gardener from those sources.
Connecting a service is an instruction to The Social Gardener to access and process the information you authorise for the functionality described to you.
You can withdraw that instruction by disconnecting the relevant service.
5. How we use Private Relationship Data
We process Private Relationship Data only to provide and support functionality for you.
This may include:
- building and maintaining your private relationship map;
- organising, matching and deduplicating your contacts;
- summarising relationship history and context;
- helping you remember useful information;
- identifying relationships you may wish to sustain, revive, protect or deepen;
- generating relationship classifications and recommendations;
- preparing you for meetings or conversations;
- suggesting appropriate people to contact;
- suggesting potential conversation topics or actions;
- answering questions you ask about your relationship information;
- creating reminders and other features you request; and
- maintaining, securing and troubleshooting the Service.
We do not use the contents of your Private Relationship Data as a general product-development dataset.
6. Artificial intelligence
The Social Gardener uses artificial intelligence to provide some of its functionality.
AI systems may, for example, summarise communications, identify relevant context, organise contacts, classify relationships, detect patterns, generate recommendations or draft suggested communications.
Information generated by AI should be treated as assistance rather than objective fact. In particular, an AI-generated description or classification of a person or relationship may be incomplete or incorrect.
Where an AI provider processes Private Relationship Data for us, it does so as a service provider or sub-processor for the purpose of delivering the relevant functionality.
We do not permit Private Relationship Data to be used to train general-purpose AI models.
The Social Gardener does not use Private Relationship Data to make decisions about people that produce legal or similarly significant effects upon them.
7. Google-connected services
If you choose to connect Google services, The Social Gardener may access information from services such as Google Contacts, Google Calendar and Gmail after you authorise the relevant access.
The information accessed depends upon the permissions you grant and the features you choose to use.
Google information may be used, for example, to:
- identify people you know;
- understand your interaction history;
- identify meetings and communications;
- construct your private relationship context;
- help organise and classify relationships; and
- provide personalised relationship assistance.
We request only access reasonably necessary for the functionality being provided.
We do not sell Google user data, use it for advertising, or allow it to be used to train general-purpose AI models.
The Social Gardener's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Our personnel will not access Google user data except where necessary and permitted, such as where you have explicitly requested support requiring such access, where access is necessary for security or abuse investigation, or where required by law.
Disconnecting a Google account stops future access through that connection. Information already incorporated into your private Social Gardener data can be deleted through the Service or by closing your account.
8. How we use Service Data
Where Carothers Ltd acts as controller, we process Service Data for the following purposes.
Providing the Service. We process account, authentication and subscription information where necessary to perform our contract with you.
Security and prevention of abuse. We process appropriate technical and security information for our legitimate interests in protecting our users, systems and Service.
Customer support and administration. We process information necessary to respond to requests and administer accounts, either to perform our contract with you or for our legitimate interests in operating the Service.
Legal obligations. We process information where necessary to comply with applicable law or binding legal requirements.
Operating and improving the Service. We may use limited Service Data to understand performance, reliability and use of the Service where necessary for our legitimate interests and where those interests are not overridden by your rights.
Where consent is legally required for a particular form of processing, including certain cookies or similar technologies, we will request it separately.
9. Service providers and sub-processors
We use selected suppliers to provide infrastructure and specialist services necessary to operate The Social Gardener.
These may include providers of:
- cloud hosting and storage;
- database and application infrastructure;
- artificial intelligence services;
- authentication;
- email and communications;
- payment processing;
- security and monitoring; and
- customer-support and operational tools.
Where a supplier processes Private Relationship Data, it acts as our sub-processor and is required to process the information only for the purposes for which we engage it and to apply appropriate confidentiality and security protections.
We remain responsible for our sub-processors' performance of their applicable data-protection obligations.
A current list of material sub-processors is available on request from hello@social-gardener.com.
We do not authorise sub-processors to use Private Relationship Data for advertising, unrelated profiling or their own independent commercial purposes.
10. International transfers
Some of the service providers we use may process information outside the United Kingdom.
Where UK data-protection law applies and personal information is transferred to a country without applicable UK adequacy regulations, we use an appropriate lawful transfer mechanism, such as approved contractual safeguards or another mechanism permitted by applicable law.
11. Security
We apply technical and organisational safeguards designed to protect personal information from accidental or unlawful loss, alteration, disclosure, destruction or unauthorised access.
Depending upon the relevant system, these include measures such as:
- encryption in transit and at rest;
- separation of users' private relationship information;
- access controls and authentication;
- restrictions on staff and contractor access;
- system monitoring and logging;
- secure development and operational practices; and
- security-incident procedures.
No internet-based system can guarantee absolute security.
12. Retention and deletion
We retain Private Relationship Data for as long as necessary to provide The Social Gardener to you and in accordance with your instructions.
You can remove information, disconnect supported data sources and request deletion of your account.
When Private Relationship Data is deleted or your account is closed, we will delete the relevant information from our active systems, except where retention is required by law.
Residual encrypted copies may remain temporarily within backups until those backups are overwritten or destroyed in the ordinary backup cycle. During that period they will not be used for ordinary processing.
We retain Service Data only for as long as reasonably necessary for the purpose for which it was collected, taking account of operational, security, accounting and legal requirements.
13. Your rights
Where Carothers Ltd acts as controller of your Service Data, applicable data-protection law may give you rights including the right to:
- access your personal information;
- correct inaccurate information;
- request deletion;
- restrict certain processing;
- object to certain processing; and
- receive applicable information in a portable format.
To exercise these rights, contact hello@social-gardener.com.
Where a request relates to Private Relationship Data for which we act as processor, responsibility for deciding how to respond rests with the relevant controller. We will provide reasonable assistance as required by applicable law.
If someone whose information appears within a user's Private Relationship Data contacts us directly, we will handle that request in a way that respects both our processor obligations and the confidentiality of the user's private account.
14. Complaints
If you have concerns about how Carothers Ltd processes personal information for which we act as controller, please contact us at hello@social-gardener.com.
Where applicable, you also have the right to complain to the Information Commissioner's Office (ICO), the UK's data-protection supervisory authority, at ico.org.uk.
15. Changes to this notice
We may update this notice to reflect changes to The Social Gardener, our suppliers, applicable law or our processing practices.
If a change materially affects the way we process personal information, we will take reasonable steps to bring it to users' attention.
These additional terms apply where you use The Social Gardener as a controller of personal data and Carothers Ltd processes that data on your behalf.
1. Processing on your instructions
Carothers Ltd (“Processor”) will process Private Relationship Data only on the documented instructions of the user (“Controller”), including instructions arising from the Controller's use and configuration of The Social Gardener.
We may process such information otherwise where required by applicable law. Where legally permitted, we will inform the Controller before doing so.
If we believe an instruction infringes applicable data-protection law, we may inform the Controller and suspend the affected processing while the matter is resolved.
2. Details of processing
Subject matter: provision of The Social Gardener and its relationship-management, memory, recommendation and related functionality.
Duration: for the period during which the Controller uses the Service, together with any limited period necessary for secure deletion or lawful retention.
Nature and purpose: collection, retrieval, organisation, storage, analysis, summarisation, inference, generation, transmission and deletion necessary to provide the functionality requested by the Controller.
Categories of personal data: contact information, correspondence, calendar and meeting information, relationship information, notes, uploaded material, contextual information and relationship information generated through the Service.
Categories of data subjects: the Controller; people known to or connected with the Controller; participants in communications or meetings; and individuals whose information appears in material made available by the Controller.
Private Relationship Data may include special-category personal data where such information is contained within material supplied or connected by the Controller.
3. Confidentiality
We will ensure that people authorised to process Private Relationship Data are subject to appropriate confidentiality obligations and have access only where required for their authorised functions.
4. Security
We will maintain technical and organisational measures appropriate to the nature of the processing and the risks to individuals, having regard to the state of the art and costs of implementation.
5. Sub-processors
The Controller gives us general authorisation to appoint sub-processors necessary to provide The Social Gardener.
We will require sub-processors with access to Private Relationship Data to be bound by appropriate written data-protection obligations.
We remain responsible to the Controller for the performance of our sub-processors' applicable data-protection obligations.
We will maintain a list of material sub-processors and give reasonable notice of material additions or replacements where required by applicable law.
Where the Controller has a statutory right to object to a new sub-processor, an objection must be based on reasonable data-protection grounds.
6. International transfers
We will not make a restricted international transfer of Private Relationship Data except in accordance with the Controller's instructions and using a transfer mechanism permitted by applicable data-protection law.
Use of The Social Gardener constitutes an instruction to make transfers reasonably necessary to provide the Service using our disclosed sub-processors, subject to appropriate safeguards.
7. Data-subject rights
Taking account of the nature of the processing, we will provide reasonable assistance to enable the Controller to respond to applicable data-subject rights requests.
We will not independently respond substantively to a request concerning Private Relationship Data except on the Controller's instructions or where required by law.
8. Compliance assistance and data breaches
Taking account of the nature of the processing and the information available to us, we will provide reasonable assistance with applicable obligations concerning:
- security of processing;
- personal-data breaches;
- data-protection impact assessments; and
- consultation with supervisory authorities.
Where required by applicable law, we will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Private Relationship Data.
9. Deletion or return
At the end of the relevant processing services, we will delete or return Private Relationship Data in accordance with the Controller's instructions and insofar as the requested option is reasonably available through the Service, unless applicable law requires continued storage.
Information remaining temporarily within secure backups will remain protected from ordinary processing and will be deleted through the normal backup-retention cycle.
10. Demonstrating compliance
We will make available information reasonably necessary to demonstrate compliance with these Data Processing Terms and our applicable obligations as processor.
Where required by applicable law, we will permit and contribute to reasonable audits by the Controller or an independent auditor acting on its behalf, subject to appropriate confidentiality, security and reasonable-notice requirements.
Where reasonably possible, the parties will first seek to satisfy audit requirements using existing compliance documentation, reports or certifications rather than intrusive inspection of systems or facilities.
11. Controller responsibilities
Where the Controller is subject to applicable data-protection law, the Controller remains responsible for:
- determining the purposes for which Private Relationship Data is processed;
- ensuring its instructions are lawful;
- establishing any required lawful basis or special-category condition;
- determining what information it is appropriate to make available to the Service;
- providing privacy information to data subjects where legally required; and
- responding to data subjects and supervisory authorities.
Nothing in these Data Processing Terms permits Carothers Ltd to use Private Relationship Data for independent purposes inconsistent with its role as Processor.
