CompliantDocs Back to home
Legal

Privacy Policy

Last updated: June 2026

CompliantDocs is committed to protecting your personal data. This policy explains what data we collect, how we use it, and your rights under UK data protection law including the UK GDPR and the Data Protection Act 2018.

1. Who We Are

CompliantDocs is operated as a sole trader business based in Northampton, England. We are the data controller for the personal data you provide to us. Contact: Email us

2. What Data We Collect

When you place an order we collect the following information:

  • Your name and business name
  • Your email address
  • Your business address and postcode
  • Your phone number
  • Business information relevant to your document pack (such as number of staff, chemicals used, and use of sharp instruments)
  • Payment information (processed by Stripe, we do not store card details)
  • Your IP address
  • GDPR consent timestamp

3. How We Use Your Data

We use your data to:

  • Generate your compliance documents
  • Deliver your order confirmation and document-ready notification by email
  • Send reminder and renewal emails related to your purchase
  • Maintain records of transactions for legal and accounting purposes

4. Legal Basis for Processing

We process your data on the following legal bases:

  • Contract performance - to fulfil your order and deliver your documents
  • Legitimate interests - to send renewal reminders to existing customers, and to contact business owners and sole traders who may benefit from our compliance services (see Section 5)
  • Legal obligation - to retain financial records as required by HMRC

Where we rely on legitimate interests we have assessed that our use of data is proportionate, does not override your rights, and you would reasonably expect to be contacted in this way.

5. Direct Marketing and Prospecting

CompliantDocs may contact business owners and sole traders by email for the purpose of marketing our health and safety compliance document services. Business contact information used for this purpose is sourced from publicly available business directories and registers.

The lawful basis for this processing is legitimate interests. We consider that business owners operating in trades and industries with health and safety compliance obligations have a genuine interest in being made aware of services that help them meet those obligations.

Where we hold your data for prospecting purposes and you have not placed an order, we hold only your business name, email address, and trade or industry. This data is not shared with any third party for marketing purposes.

If you do not wish to receive marketing emails from us you can unsubscribe at any time by clicking the unsubscribe link in any email we send, or by contacting us at Email us. We will action your request within 5 working days.

6. Data Retention

Your documents and account data are stored securely in your account and remain accessible via your dashboard for as long as your account is active. If you delete your account, your personal data and documents are removed from our systems within 30 days. Financial transaction records may be retained for up to 7 years as required by HMRC.

7. Third Parties

We share your data with the following third party services solely to fulfil your order:

  • Stripe (payment processing)
  • Supabase (secure account and document data storage)
  • SendGrid (email delivery)
  • Anthropic (document generation via Claude API)

All third party providers are required to handle your data in accordance with applicable data protection law.

8. Your Rights

Under UK GDPR you have the right to access, correct, or delete your personal data. You also have the right to object to processing, to restrict processing, and to data portability. To exercise any of these rights, contact us at Email us. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your personal data has been processed unlawfully. The ICO can be contacted at ico.org.uk or by calling 0303 123 1113.

9. Cookies

We use cookies on our website. Please see our Cookie Policy for full details.

10. Changes to This Policy

We may update this policy from time to time. The current version will always be available on this page.

11. ICO Registration

CompliantDocs is registered with the Information Commissioner's Office (ICO) as a data controller. ICO Registration Number: C1910089.

Home Terms and Conditions Privacy Policy Cookie Policy Email us

CompliantDocs - compliantdocs.co.uk