Draft — not legally reviewed.These documents are placeholder text pending solicitor review and completion of the company's trading details. They do not form a binding agreement in their current state, and must not be relied on in any commercial relationship until an executed, reviewed version is published.

Privacy Notice

Privacy Notice

⚠ DRAFT — NOT LEGALLY REVIEWED. Placeholder drafted to common UK-SaaS practice under UK GDPR / DPA 2018. It has not been reviewed by a qualified solicitor. The [PLACEHOLDER] fields (company details, ICO registration, contact addresses) and the precise list of sub-processors must be confirmed and the document signed off by legal counsel before publication to real end users.

Effective date: [EFFECTIVE_DATE] Version: 0.1 — draft pending legal review.

This notice explains how [LEGAL_ENTITY_NAME] ("we", "us", "our") handles personal data when you use the Tracker SaaS application or visit our website. It is written for the hosted service at app.tracker.[DOMAIN]; self-hosters run their own copy and are their own data controllers.

1. Who we are

[LEGAL_ENTITY_NAME] is the data controller for personal data we collect about you when you use the Tracker SaaS service. We are registered in [the United Kingdom], [company number [COMPANY_NUMBER]], registered address [REGISTERED_ADDRESS]. Our ICO registration number is [ICO_REGISTRATION_NUMBER].

If you have any questions, write to us at [PRIVACY_CONTACT_EMAIL].

Where our customers use Tracker to process personal data about their own staff, contacts, or end users, the customer is the controller of that data and we act as the processor under our Data Processing Addendum.

2. Personal data we collect

Data you give us

  • Account data when you register: email address, name, and a bcrypt hash of your chosen password.
  • Profile content that you add: display name, timezone, any optional fields you supply.
  • Organisation membership data: the organisations, projects, and departments you belong to, and the role you hold in each.
  • Customer content you enter into Tracker: compliance requirements, evidence, gaps, tasks, notes, and any file paths or URLs you supply. To the extent this content contains personal data about others, our customer is the controller and our DPA applies.

Data collected automatically

  • Technical data: IP address, browser user-agent, timestamps of requests, server-generated request IDs, coarse-grained geolocation inferred from IP for abuse-protection purposes.
  • Session tokens and API-token hashes we issue for authentication.
  • Audit events describing actions taken in the application — who did what, when, and which object was affected. The audit log is append-only by design and cannot be edited after the fact.

We do not use third-party analytics cookies, advertising pixels, or cross-site tracking technologies.

3. Purposes and legal bases

Purpose Legal basis (UK GDPR Article 6)
Provide and operate the Service Performance of a contract — Art. 6(1)(b)
Keep the Service secure, investigate abuse Legitimate interests — Art. 6(1)(f)
Comply with legal obligations (tax, accounting, requests) Legal obligation — Art. 6(1)(c)
Respond to your support queries Performance of a contract — Art. 6(1)(b)
Send operational notices (security, billing, outages) Performance of a contract — Art. 6(1)(b)
Send product or marketing updates Consent — Art. 6(1)(a); you can opt out anytime

We do not make automated decisions producing legal or similarly significant effects about you.

4. Retention

  • Account data: kept for the life of your account plus 30 days after you delete it, after which it rotates out of our backups within a further 30 days.
  • Audit events: retained for at least 7 years for accountability and compliance evidence. This is a deliberate design decision — the audit log is the core of a compliance product and must outlive the activity it describes.
  • Authentication tokens: password-reset tokens expire after 1 hour; email-verification tokens after 24 hours; consumed tokens are retained for 7 days then pruned.
  • Backups: database backups rotate on a 14-day cycle by default; deleted records persist in a backup for up to that period.
  • Request logs: 30 days.

Where we are required by law to keep data longer (tax, dispute), we retain only the minimum necessary.

5. Recipients and sub-processors

We share personal data with the following categories of recipient:

  • Our staff and contractors, under confidentiality and need-to-know obligations.
  • Sub-processors we engage to deliver the Service, listed in Annex C of our Data Processing Addendum. Current sub-processors include our SMTP-relay provider and the hosting platform on which our production cluster runs.
  • Professional advisers (lawyers, auditors, accountants) where necessary and under confidentiality.
  • Authorities if we are legally required to disclose (e.g. court order) — we will notify you where lawful.

We do not sell personal data.

6. International transfers

Our production hosting is located in the United Kingdom. Where any sub-processor processes data outside the United Kingdom, we rely on the UK International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses, or equivalent safeguards, to ensure your data continues to enjoy protection comparable to UK law.

A copy of the relevant safeguards is available on request to [PRIVACY_CONTACT_EMAIL].

7. Your rights

Under UK GDPR you have the right to:

  • access the personal data we hold about you (Article 15);
  • rectify inaccurate or incomplete data (Article 16);
  • erase your data, subject to legal retention obligations (Article 17);
  • restrict processing in certain circumstances (Article 18);
  • data portability — receive your data in a structured, commonly used, machine-readable format (Article 20);
  • object to processing based on our legitimate interests (Article 21);
  • withdraw consent where we rely on consent — this does not affect the lawfulness of earlier processing (Article 7(3));
  • lodge a complaint with the Information Commissioner's Office (ico.org.uk) if you believe we have not handled your data lawfully. We would appreciate the chance to address your concern first.

To exercise any of these rights, write to [PRIVACY_CONTACT_EMAIL]. We will respond within one month, or explain within that month why we need an extension (up to two further months for complex requests).

8. Cookies

We set only first-party cookies strictly necessary for the Service to function:

  • next-auth.session-token — authenticates your signed-in session.
  • sid (where present) — server-side session identifier.

We do not use cookies for analytics, advertising, or cross-site tracking. Session cookies expire when your session ends or is terminated.

9. Security

We apply commercially reasonable technical and organisational measures to protect personal data, including: TLS in transit, encryption at rest for the underlying storage, role-based access controls, row-level security in the database enforcing tenant isolation, pinned and CVE-scanned container images, and an append-only audit log. Further detail is set out in Annex B of the Data Processing Addendum.

No system is perfectly secure. If a breach affecting your personal data occurs, we will notify you and, where required, the ICO without undue delay.

10. Children

The Service is intended for use by adults in a professional context. We do not knowingly collect personal data from people under the age of 16. If you believe we hold such data, contact [PRIVACY_CONTACT_EMAIL] and we will delete it.

11. Changes to this notice

We may update this notice. The version number and effective date are shown at the top. We will notify account holders of material changes by email or in-app notice at least 14 days before they take effect.

12. Contact

  • Privacy contact: [PRIVACY_CONTACT_EMAIL]
  • Postal: [REGISTERED_ADDRESS]
  • Supervisory authority: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — ico.org.uk.