Privacy Notice
Last updated: 18 July 2026
This notice explains how Compliance Vault handles personal data under UK GDPR and the Data Protection Act 2018. The Service is operated by Compliance Vault, an independent software business based in England. Contact: hello@compliancevaultapp.com or by post: 61 Bridge Street, Kington, HR5 3DJ.
1. The two roles we play
We are the controller for account and billing data
When you sign up we collect your name, email address, hashed password, workspace name, and (when you subscribe) billing details handled by Stripe. We use these to provide the Service, take payment, send service emails, and keep the Service secure. Legal bases: performance of a contract and our legitimate interest in running the Service securely.
We are a processor for your portfolio data
The properties, landlords, tenancies and documents you upload may contain personal data about landlords and tenants. For that data your agency is the controller and we process it only on your instructions to provide the Service. It is never used for marketing, profiling, or training AI models.
2. AI document reading
When you upload a compliance document, its text or image is sent to Anthropic's Claude API to suggest the document type and dates. Suggestions are held in a review queue until a person in your workspace confirms them. We use API settings under which Anthropic does not use your data to train models.
3. Who we share data with (subprocessors)
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Application hosting | EU/US (EU edge for app traffic) |
| Neon (on AWS) | Database | London, UK (eu-west-2) |
| Vercel Blob | Document storage (private access) | London, UK (lhr1) |
| Resend (on Amazon SES) | Transactional email | EU (eu-west-1, Ireland) |
| Anthropic | AI document reading | US, with contractual safeguards |
| Stripe | Payments and billing | EU/US, with contractual safeguards |
Where data leaves the UK, transfers rely on adequacy regulations or standard contractual clauses with the UK addendum. We do not sell personal data to anyone.
4. Cookies and analytics
We use only essential cookies: a session cookie to keep you signed in and a CSRF token to protect forms. No advertising or cross-site tracking cookies, no email open-tracking pixels.
We measure aggregate page traffic using Vercel Web Analytics, which sets no cookies and stores nothing on your device. It records the page visited, referring site and coarse country-level location, and does not build a profile of you or follow you across other websites.
If you tell us how you heard about us when creating an account, we store that answer against your workspace so we know which channels are worth our time. The field is optional, and the answer is never linked to your browsing.
5. How long we keep data
Set out in the Retention Schedule. In short: your data stays while your workspace is active; deleting the workspace permanently removes it, with residual copies leaving encrypted backups within 30 days.
6. Your rights
You can ask us for access to, correction of, deletion of, or a portable copy of personal data we hold about you as controller — email hello@compliancevaultapp.com and we will respond within one month. For landlord or tenant data in an agency's workspace, contact the agency (the controller); we will assist them. You can complain to the Information Commissioner's Office (ico.org.uk) if you are unhappy with how we handle your data.
7. Security
Data is encrypted in transit (TLS) and at rest. Documents are stored in a private bucket readable only through authenticated, workspace-scoped requests. Passwords are stored as bcrypt hashes. Access to production systems is limited to the operator. Every change to compliance records is written to an audit log.
8. Changes
We will notify account holders by email of material changes to this notice at least 14 days before they take effect.