Privacy Policy
Last updated 28 August 2026
This Privacy Policy explains how [REGISTERED COMPANY NAME] (“we”, “us”, “arx Partners”), company number [COMPANY NUMBER], registered in England & Wales at [REGISTERED ADDRESS], collects and uses your personal data when you use the arx Partners Martyn's Law self-assessment and workbook (the “Service”). We are the data controller for that personal data. We are registered with the Information Commissioner’s Office (ICO), registration number [ICO REGISTRATION NUMBER].
1. The personal data we collect
Depending on how you use the Service, we collect:
- Account details — your name, email address, role, and a securely hashed password.
- Self-assessment details — the name of the person completing it, the site/premises or event name, the responsible legal entity, address, contact email and phone, your answers, and the assessment outcome.
- Workbook content — the information, documents, floor plans and images you add to your workbook, including details of responsible people and your protection plans.
- Communications — emails we send you (verification, reminders, plan documents) and any support correspondence.
- Payment information — taken and processed by Stripe. We do not see or store your full card details; we keep limited transaction records (such as a payment reference, amount and status).
- Technical data — IP address, browser/user-agent, and server logs, collected automatically for security and to run the Service.
2. How and why we use it (lawful bases)
- To provide the Service — create and secure your account, run the assessment, host your workbook, take payment, and send service emails. Lawful basis: performance of a contract.
- To keep the Service secure and prevent fraud/misuse, and to improve and support it. Lawful basis: our legitimate interests (balanced against your rights).
- To meet legal and regulatory obligations. Lawful basis: legal obligation.
- Where we ask for it (for example optional communications). Lawful basis: consent, which you can withdraw at any time.
We do not sell your personal data, and we do not use it for advertising.
3. Who we share it with
We share personal data only with service providers who process it on our behalf under contract, and only as needed to run the Service:
- Stripe — payment processing.
- Twilio SendGrid — sending our transactional emails.
- [HOSTING PROVIDER] — hosting and infrastructure.
- Professional advisers and authorities — where we are required to by law, or to establish or defend legal claims.
Each provider is bound to protect your data and use it only for the purpose we specify.
4. International transfers
Some providers (for example Stripe and SendGrid) may process data outside the UK. Where they do, we rely on appropriate safeguards — such as UK adequacy regulations or the UK International Data Transfer Agreement / addendum to the EU Standard Contractual Clauses — so your data stays protected.
5. How long we keep it
We keep your account and workbook data for as long as your account is active and for [RETENTION PERIOD, e.g. 12 months] afterwards, unless you ask us to delete it sooner or we must keep it longer to meet a legal obligation. Limited payment records are kept for the period required by law (typically six years for financial records). Server logs are kept for a short period for security.
6. How we protect it
We take security seriously. We hold Cyber Essentials and Cyber Essentials Plus certification and follow National Cyber Security Centre (NCSC) guidance. Practical measures include encryption of data in transit (HTTPS), passwords stored only as salted hashes, parameterised database access, hardened session handling, access controls on the limited staff who can see data, and regular review. No system is ever completely secure, but we work to protect your data proportionately to its sensitivity.
7. Cookies
The Service uses a single essential session cookie to keep you signed in and to protect the security of forms. It is not used for tracking or advertising, so no consent banner is required. We do not currently use analytics or third-party tracking cookies; if that changes we will update this policy and ask for consent where needed.
8. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to certain processing;
- data portability; and
- withdraw consent where we rely on it.
To exercise any of these, email support@arxpartners.co.uk. We will respond within the time limits set by law. You also have the right to complain to the ICO (ico.org.uk), though we would appreciate the chance to put things right first.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will publish the updated version here and change the “last updated” date above; significant changes will be communicated to account holders.
10. Contact
Questions about your data or this policy? Email support@arxpartners.co.uk, or write to us at [REGISTERED ADDRESS].