Who we are

[Company legal name], company number [Company number], registered at [Registered address], is the controller for personal data processed through this website and the application. Questions about this policy, or a request to exercise your rights, go to [Data protection contact email].

What we collect

Account data. When you create an account we hold your name, email address, hashed password or authentication identifiers, the organisation you belong to and your role in it.

Content you enter. Product families, versions, configurations, components, performance claims, evidence records and uploaded files. This is your organisation's data, not ours. It may contain personal data if you choose to put it there — for example the name of the person who approved a version, which we record because an audit trail without a name is not an audit trail.

Enquiry data. If you submit a beta request or the evidence checklist, we hold what you entered on that form, including an email address where you gave one.

Technical data. Server logs generated by our hosting provider in the ordinary course of serving requests, including IP address and user agent, retained for a short period for security and diagnostics.

Analytics: what we do and do not do

We use first-party analytics only. Events are written to our own database, on our own infrastructure. There is no Google Analytics, no advertising pixel, no session recorder and no third-party tracking script anywhere on this site or in the application.

What an analytics event records is a name — for example "pricing_view", "evidence_checklist_started" or "public_record_view" — a timestamp, and a small set of coarse properties from a fixed allowed list such as a plan name or a result band. Free text is rejected before it is written, so product names, evidence references, characteristics and file names cannot reach analytics even by accident.

Cookies

We set one cookie: a session cookie that keeps you signed in. It is strictly necessary for the service to work and is removed when your session ends or you sign out.

We set no advertising, profiling or cross-site cookies, and we do not share identifiers with third parties. The public pages of this website — product records, resources, the tracker, pricing — set no cookies at all.

Where your data is processed

The application runs on Cloudflare's platform. Structured data is stored in Cloudflare D1 and uploaded evidence files in Cloudflare R2. Requests are served from Cloudflare's network, which means they may be handled at a location close to the person making the request.

Transactional email — sign-in links, invitations, alert notifications — is sent through Resend. Resend receives the recipient address and the content of the message.

We use no other processors for the operation of the service. [Confirm the current sub-processor list and any regional storage commitment before publication.]

Why we process it, and on what basis

To provide the service to you and your organisation: performance of a contract. To keep the service secure, prevent abuse and diagnose faults: our legitimate interests. To respond to a beta request or an enquiry you sent us: our legitimate interests in responding to you. To keep first-party product analytics: our legitimate interests in understanding which parts of the product are used, using data that does not identify individuals.

Sharing

We do not sell personal data and we do not share it for advertising. We share it with the processors named above, with professional advisers where necessary, and where we are required to by law.

Data you choose to publish — a public product record — is public by design. You control what is published: evidence records carry their own confidentiality setting and only what you mark for publication appears on a public record.

Retention

Account and content data are kept while your organisation has an account and for [retention period] after it closes, so that a record can be restored if an account is closed in error. Beta request and checklist submissions are kept for [retention period]. Server logs are kept for a short period set by our hosting provider.

Audit and revision history is deliberately not deletable while the record exists, because a record whose history can be edited is not an audit trail.

Your rights

You have the rights available under UK data protection law, including access, rectification, erasure, restriction, objection and portability. Contact [Data protection contact email] and we will respond within the statutory period.

You can also complain to the Information Commissioner's Office. We would rather you told us first, but that is your decision and not a precondition.

Changes

When this policy changes materially we will tell account holders by email. The date at the top of this page always reflects the current version.