FreeholdMate

Privacy Policy

Last drafted: 25 July 2026.

1. Who we are

FreeholdMate (FreeholdMate [insert registered company name and number once incorporated]) is the data controller for the personal data described below. [ICO registration reference: not yet registered — see the README's "What's real vs. what's still a gap" for the £52/year Tier 1 fee this needs.]

2. What we collect

Account data: your name, email address, and a hashed (not plaintext) password.

Company data: directors, PSCs (people with significant control) and their correspondence addresses — pulled from the public Companies House register when you connect a company — plus whatever you enter yourself: members/shareholders, unit numbers, share counts, and the registered/reminder email addresses you set.

Documents: anything you upload — leases, insurance certificates, minutes, accounts, and so on.

"Ask AI" question content: if you use this feature, the document you're asking about and your question are sent to our AI provider to generate an answer (see section 4).

Technical data: a session cookie and a CSRF token, both strictly functional (keeping you logged in, and protecting against forged form submissions) — no advertising or analytics cookies are set by this app. Fonts are loaded from Google Fonts, which involves your browser contacting Google's servers directly to fetch them.

3. Why we process it, and on what legal basis

Mostly to perform our contract with you — running the account you signed up for, keeping your registers, preparing and (where enabled) submitting filings, sending you deadline reminders. Some processing (like security logging) relies on our legitimate interest in keeping the Service secure and working, balanced against your rights.

4. Who we share it with

We don't sell your data. It's shared only with the specific third parties that make the Service work, and only for that purpose:

5. International transfers

[Needs confirming: Anthropic is a US company. This section should name which transfer safeguard applies (e.g. the UK's International Data Transfer Addendum / a UK adequacy-adjacent mechanism) — don't guess this, check Anthropic's own data processing terms and get it right.]

6. How long we keep it

[Needs a real retention policy — e.g. how long data is kept after an account is closed, and whether/how it's deleted from backups too.]

7. Security

Documents, correspondence addresses, registered/reminder email addresses, and "Ask AI" question history are encrypted at rest (AES-256-GCM). Data in transit is encrypted (HTTPS). Passwords are hashed with scrypt, never stored in plain text. See the README's security section for full technical detail if you want it.

8. Your rights

Under UK GDPR you have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. You can export your full registers as a CSV any time from the Registers page — no request needed. For anything else, [insert a real contact email/process once one exists]. You also have the right to complain to the Information Commissioner's Office if you think we've got something wrong.

9. Children

The Service is intended for company directors and officers acting in a business capacity, not for children, and we don't knowingly collect data from anyone under 18.

10. Changes to this policy

We may update this policy from time to time. If we make a material change, we'll tell you before it takes effect.

11. Contact

[insert a real contact email once one exists]