Privacy Policy

Last updated: 2026-10-11

This policy explains what personal data NotchWork collects, why, who we share it with, how long we keep it, and the rights you have over it. It covers the website at notchwork.co.uk and the shadow-rating platform. It applies to the UK GDPR and the Data Protection Act 2018, and to the EU GDPR where we serve users in the EEA.

1. Who we are

1. Controller. NotchWork is a trading name of [CONFIRM: your name as sole trader, or the registered company name and number once incorporated], of [CONFIRM: service address — not a home address, because the ICO publishes the controller’s address], and is the data controller for the personal data described in this policy. You can reach us at hello@notchwork.co.uk. We are registered with the Information Commissioner’s Office under registration number [CONFIRM: ICO registration number].

2. What we collect

2. Account data. Your name, email address, and — where you provide it — your company name and role. We record whether you consented to marketing email; that choice defaults to off.

3. Documents you upload. Annual reports, financial statements, information memoranda, business plans and any other file you submit for analysis. These frequently contain commercially sensitive information about the subject company. They may also contain personal data about third parties — for example directors named in an annual report — for which you act as controller and we act as processor.

4. Analysis data. Financial figures extracted from your documents, the adjustments applied, the rating outputs generated, and the chat history of any questions you ask about a rating.

5. Billing data. Subscription and credit records. Card details are entered directly into Stripe and are never received or stored by NotchWork.

6. Technical data. Server logs including IP address, request paths, timestamps and error traces, retained for security and debugging.

3. Why we process it, and on what legal basis

7. To provide the service — contract. Creating your account, running ratings on the documents you submit, storing your sessions so you can return to them, and generating your deliverables. Without this data we cannot perform the service you asked for.

8. To take payment — contract and legal obligation. Processing subscriptions and credits, and keeping the accounting records UK law requires us to keep.

9. To keep the service secure — legitimate interests. Detecting and preventing unauthorised access, abuse of the rating endpoints, and fraud. Our interest is in running a service that does not leak one customer’s data to another; we consider this does not override your rights, since the data used is limited to logs and request metadata.

10. To send marketing — consent. Only if you ticked the box. You can withdraw at any time, through the unsubscribe link or by emailing us, without affecting the service.

11. What we do NOT do. We do not sell personal data. We do not use your uploaded documents, financial data or rating outputs to train any machine-learning model, ours or a third party’s. We do not use them to build a product dataset or to benchmark other customers.

4. Who we share it with

We use the following sub-processors. Each is bound by a data processing agreement and processes data only on our instructions.

  • Supabase — database, authentication and file storage. Holds your account record, your sessions and your uploaded documents.
  • Vercel — application hosting and the serving of every page and API request.
  • Anthropic— the Claude models that perform the analysis. The contents of your documents and your chat messages are sent to Anthropic’s API to produce the rating. Anthropic’s commercial terms state that inputs and outputs submitted through the API are not used to train its models.
  • Stripe — payment processing. Stripe acts as an independent controller for card data.
  • Render — the background worker that executes long-running rating jobs.

12. Others. We may disclose data where we are legally required to, or to professional advisers under duty of confidence. If NotchWork is ever acquired, data may transfer to the acquirer under this policy.

5. International transfers

13. Where data goes. Some sub-processors above operate outside the UK, principally in the United States. Where data leaves the UK we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on adequacy regulations where they apply. You can ask us for details of the safeguards in place for any specific transfer.

6. How long we keep it

14. Documents you upload. Ninety days from upload. After that the file is deleted from storage and the text extracted from it is deleted with it, automatically and without you having to ask. This is the shortest period of any category here, deliberately: your annual reports and business plans are the most sensitive thing we hold, and we only need them to produce the rating. A consequence worth knowing: re-running a rating more than ninety days after the upload requires the source document again.

15. Everything else. Ratings, the figures derived from your documents, and chat history are kept while your account is open — they are the work product you came for. Account data is kept while the account is open. Billing records are kept for six years from the end of the accounting period, which is what UK tax law requires of us. Our record that the copyright safeguard ran on a rating is kept for two years. Rate limiting counters are discarded after a day.

16. Deletion. Deleting your account removes your account record, your sessions, your chat history, the document records and the stored files themselves — the actual objects in the bucket, not only the rows that point at them. Billing records survive for the six years above, because we are required to keep them; they no longer identify a live account. You can also ask us to erase your data at any time without closing your account.

17. Backups. Deleted data can persist in encrypted database backups for up to [CONFIRM: your Supabase plan’s point-in-time-recovery window, 7 days on the default plan] before those backups roll off. It is not restored to the live service and is not otherwise accessible.

7. How we protect it

16. Measures. Data is encrypted in transit and at rest. Uploaded documents sit in a private storage bucket that is never publicly readable. Access to a rating session requires authentication and is checked against the owning account on every request. Card details never reach our servers.

17. Breach notification. If a breach occurs that is likely to result in a risk to your rights, we will notify the ICO within 72 hours of becoming aware of it, and notify you directly where the risk is high.

8. Your rights

Under the UK GDPR you have the right to access your data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent where processing rests on it. Exercising these rights is free and we will respond within one month.

18. How to exercise them. Email hello@notchwork.co.uk. If you are not satisfied with our response you can complain to the Information Commissioner’s Office at ico.org.uk, or to your local supervisory authority in the EEA.

9. Cookies

19. What we set. We set only the cookies required to keep you signed in and to maintain your session. These are strictly necessary and do not require consent. We do not run advertising or third-party analytics cookies. If that changes, we will add a consent banner before setting them.

10. Automated decision-making

20. Ratings are not decisions about you. The platform generates shadow credit ratings about companies using large language models. These are analytical outputs about a corporate entity, not automated decisions producing legal or similarly significant effects about you as an individual. Nothing on the platform makes an automated decision about your access to credit.

11. Children

21. Not for children. The service is for business users and is not directed at anyone under 18. We do not knowingly collect data from children.

12. Changes

22. Updates. We will post any changes on this page and update the date above. Where a change materially affects how we use your data, we will tell you directly.