Privacy Policy

Last updated: 22 March 2026

1. Who we are

ComplianceFix is operated by James at ComplianceFix. We are the data controller for the personal data described in this policy. You can contact us at info@compliancefix.co.uk.

2. What data we collect and why

DataPurposeLawful basis
Business name, domain, contact emailDelivering our compliance scanning and report serviceContract performance — Art.6(1)(b)
Website content (scanned pages)Analysing your site's compliance positionContract performance — Art.6(1)(b)
Questionnaire answers (data types, third parties, marketing practices)Customising your compliance documentsContract performance — Art.6(1)(b)
Payment details (card number, billing address)Processing your payment via StripeContract performance — Art.6(1)(b)
Companies House data (registered name, address, SIC codes)Populating your compliance documents accuratelyLegitimate interests — Art.6(1)(f)
Email delivery data (opens, bounces)Ensuring report and policy deliveryLegitimate interests — Art.6(1)(f)

We do not process any special category data (Art.9) about you. The website content we scan may contain such data — we process it solely to assess compliance and do not use it for any other purpose.

3. Who we share your data with

We share your data with the following third parties, all of whom act as data processors on our behalf unless otherwise stated:

RecipientPurposeLocation
Stripe (independent controller for fraud prevention)Payment processingUS — UK-US Data Bridge
Resend (processor)Email deliveryUS — UK-US Data Bridge
Netlify (processor)Website hosting and serverless functionsUS — UK-US Data Bridge
Render (processor)API hostingUS — UK-US Data Bridge
Turso (processor)Database storageEU (Ireland) — UK adequacy regulations
Companies House (public authority)Company data lookupUK
Google LLC (processor — Google Fonts)Font delivery. When your browser loads fonts from fonts.googleapis.com, your IP address is transmitted to Google.US — UK-US Data Bridge
Cloudflare Inc (processor — Turnstile)Bot protection on the free compliance scan form. Verifies visitors are real people.US — UK-US Data Bridge

We do not sell, rent, or share your personal data with any third parties for their own marketing purposes.

4. International transfers

Several of our service providers are based in the United States, including Stripe, Resend, Netlify, Render, Google (Google Fonts), and Cloudflare (Turnstile). For US-based providers certified under the EU-US Data Privacy Framework, transfers are covered by the UK Extension to the EU-US Data Privacy Framework (the "UK-US Data Bridge"), effective since 12 October 2023. For our EU-based provider (Turso, Ireland), transfers are covered by the UK's adequacy regulations for the EEA.

5. How long we keep your data

DataRetention periodReason
Customer records6 years from last serviceLimitation Act 1980 (contractual claims)
Payment records6 years from transactionHMRC requirements
Scan results and reportsDuration of service relationship plus 12 monthsEnabling re-scans and service continuity
Email delivery logs12 monthsTroubleshooting delivery issues

6. Your rights

Under UK GDPR, you have the right to:

To exercise any of these rights, email info@compliancefix.co.uk. We will respond within one month. If we need to extend this, we will tell you why within that first month.

7. Complaints

You have the right to complain to the Information Commissioner's Office (ICO) at any time. We would appreciate the opportunity to address your concerns first, but this is not a precondition.

ICO: ico.org.uk/make-a-complaint · 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

8. Changes to this policy

We will update this page when our data processing practices change. The "last updated" date at the top reflects the most recent revision.