Privacy Policy

How we collect, use, and protect your personal information

Last Updated: 3 March 2026 | Effective Date: 3 March 2026
ICO Registration Number: ZC087276

1. Data Controller

This Privacy Policy is provided by Magna Spero Ltd, the company that owns and operates Compliance Toolkit.

Detail Information
Company Name Magna Spero Ltd
Company Registration Number 16649166
ICO Registration Number ZC087276
Registered Office 1 Harland Road, Lincoln, LN2 4GW, United Kingdom
Website compliancetoolkit.co.uk
Data Protection Contact privacy@compliancetoolkit.co.uk

Our Data Processing Roles

As Data Controller

When you create an account and use Compliance Toolkit directly, Magna Spero Ltd is the data controller responsible for your personal information.

As Data Processor

Where you access Compliance Toolkit through a referring partner organisation (for example, a professional services firm directing its clients to a specific tool), that referring organisation is the data controller. In those cases, Magna Spero Ltd acts as a data processor on their behalf, governed by a separate Data Processing Agreement. Your referring organisation's own privacy policy will also apply to how they handle your data.

2. Introduction and Scope

This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use Compliance Toolkit. It applies to all processing activities we undertake and covers all users of our platform, including individual subscribers, consultants, and enterprise clients.

This policy is designed to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Data (Use and Access) Act 2025 (DUA Act 2025).

3. Information We Collect

3.1 Account Information

When you create an account or use our services, we collect:

  • Name, email address, and contact information
  • Company name and job title (for member accounts)
  • Account credentials and authentication data
  • Communication preferences

3.2 Assessment and Survey Data

Our platform includes a range of compliance assessment tools. When you complete a questionnaire or survey, we collect your responses for the purpose of generating your compliance report. This includes:

  • Health & Safety questionnaire responses and compliance evaluation data
  • Performance & Operational survey responses and maturity assessments
  • Charity Governance survey responses

Assessment responses are stored securely and retained in accordance with our Data Retention schedule (see Section 10).

3.3 Employment Contract Analysis

Our Employment Contract Clause Checker allows you to upload an employment contract for AI-powered statutory compliance analysis. This tool operates on a transient processing basis:

  • The document is transmitted securely to our AI analysis provider via encrypted API connection.
  • The analysis results are returned to you in real time.
  • The document is processed entirely in memory and is not written to disk, saved to any database, or retained in any persistent storage on our servers at any point.
  • Once the analysis is complete and the results are delivered, no copy of your document exists on our systems.

Important: You are advised not to upload documents containing personal identifiable information such as employee names, addresses, or salary details. If personal data is inadvertently included in an uploaded document, it will be processed transiently as described above and will not be retained. However, please note that our AI analysis provider (OpenAI) may retain API inputs for up to 30 days for safety and abuse monitoring purposes before permanent deletion (see Section 7 for further detail).

3.4 Usage Information

  • Platform usage patterns and feature interactions
  • Device information and browser details
  • IP address and general location data
  • Login activity for security purposes
  • Cookies and similar tracking technologies (see our Cookie Policy)

3.5 Analytics Data (With Consent)

With your consent, we use Microsoft Clarity to analyse how users interact with our platform. This includes page views, session duration, user behaviour patterns, and navigation paths. You can control analytics cookies through our cookie consent banner.

4. How We Use Your Information

We process your personal information for the following purposes, based on the legal grounds specified:

Purpose Data Processed Legal Basis (UK GDPR)
Service provision and account management Name, email, phone, account credentials Contract (Article 6(1)(b))
Assessment report generation Survey and questionnaire responses Contract (Article 6(1)(b))
Employment contract analysis (transient) Uploaded document content (not retained) Contract (Article 6(1)(b))
Account verification and security Email, IP address, login activity Legitimate Interest (Article 6(1)(f))
Platform improvement and analytics Usage patterns, analytics cookies Consent (Article 6(1)(a))
Legal compliance and dispute resolution All relevant personal data as required Legal Obligation (Article 6(1)(c))

5. AI Processing and Automated Decision-Making

How We Use AI

Compliance Toolkit uses artificial intelligence to provide compliance guidance, contract analysis, and report recommendations. When you interact with our AI features:

  • Your query and/or document data are transmitted to OpenAI via an encrypted API connection.
  • OpenAI processes your data to generate analysis and recommendations.
  • We use OpenAI's API under their enterprise data processing terms with data protection guarantees.
  • OpenAI does not use your data to train their models. However, OpenAI may retain API inputs for up to 30 days solely for safety and abuse monitoring, after which they are permanently deleted.

Automated Decision-Making

Important: Our AI provides advisory guidance only. It does not make automated decisions that have legal or similarly significant effects on you. All compliance assessments are recommendations that should be reviewed by qualified professionals.

Application Logging

Our application logs may record metadata relating to API requests (such as timestamps, response codes, and error messages) for the purposes of system monitoring and debugging. These logs do not capture the substantive content of documents uploaded for analysis or survey responses submitted by users. Logs are retained in accordance with our Data Retention schedule.

6. Data Sharing

We do not sell your personal data to third parties. We may share your personal information with the following categories of service provider, each of whom is engaged under appropriate contractual terms.

6.1 Sub-Processors by Processing Activity

Different tools on our platform engage different sub-processors. The table below sets out which sub-processors are relevant to each processing activity:

Sub-Processor Purpose Applicable Tools Data Location
OpenAI AI-powered analysis and report generation All assessment tools; Contract Clause Checker USA
AWS (S3) Secure storage of generated reports Assessment tools (reports only) EU-West-2 (London, UK)
Neon Database hosting (accounts and platform data) Account management and platform operations EU
SendGrid Transactional email delivery Account notifications and report delivery USA
Microsoft Clarity Website analytics (with consent) Platform-wide (anonymised) USA

Note: The Employment Contract Clause Checker engages only OpenAI as a sub-processor. Uploaded documents are not stored in AWS S3, Neon, or any other persistent storage.

6.2 Partner Integrations

When you access Compliance Toolkit via a partner single sign-on (for example, SwiftHR.ai), limited account data may be shared as described in the partner's own privacy policy.

6.3 Legal Requirements

We may disclose personal data when required by law, court order, or regulatory authority.

7. International Data Transfers

Some of our service providers process data outside the United Kingdom. We ensure appropriate safeguards are in place for all international transfers in compliance with UK GDPR Chapter V:

Provider Transfer Destination Safeguard
OpenAI USA UK-US Data Bridge adequacy certification and Standard Contractual Clauses (SCCs)
SendGrid USA Standard Contractual Clauses (SCCs)
Microsoft Clarity USA Standard Contractual Clauses (SCCs)
AWS UK (EU-West-2, London) No international transfer — data stored in UK region
Neon EU UK adequacy decision for the EEA

OpenAI may retain API inputs for up to 30 days for safety and abuse monitoring purposes. During this retention period, the data is subject to the safeguards described above. After 30 days, all input data is permanently deleted by OpenAI.

8. Privacy Notices for Specific Tools

8.1 Charity Governance Assessment

When you access the Charity Governance assessment tool via a referring organisation (such as a law firm or professional advisor), the following applies:

  • The referring organisation is the data controller for any personal data you submit through the assessment.
  • Magna Spero Ltd acts as a data processor, processing your responses solely for the purpose of generating your governance gap analysis report.
  • Your survey responses are processed by OpenAI's API and the resulting report is stored securely in AWS S3 (UK region) for 12 months.
  • A separate Data Processing Agreement governs the relationship between Magna Spero Ltd and the referring organisation.

8.2 Employment Contract Clause Checker

When you use the Employment Contract Clause Checker:

  • Your uploaded document is processed in real time and is not stored on our servers at any point.
  • Document content is transmitted to OpenAI for analysis via encrypted API connection and results are returned directly to you.
  • No copy of your document is retained by Magna Spero Ltd after the analysis is complete.
  • OpenAI may retain API inputs for up to 30 days for safety and abuse monitoring only.
  • You are advised not to include personal identifiable information in uploaded documents. If personal data is inadvertently included, it is processed transiently and not retained by us.

9. Partner Referral Arrangements

Compliance Toolkit is used by some organisations to provide compliance tools to their own clients. Where you access a tool on our platform at the direction of a professional services firm, charity advisor, or other referring organisation:

  • The referring organisation is the data controller and determines the purposes for which your data is processed.
  • Magna Spero Ltd is the data processor, acting on the instructions of the referring organisation under a Data Processing Agreement compliant with UK GDPR Article 28.
  • Your referring organisation's privacy policy governs how they handle and protect your data.
  • You should direct any data subject rights requests to your referring organisation in the first instance.

10. Data Retention

Data Type Retention Period Reason
Account information Duration of account + 12 months Service provision and legal compliance
Assessment reports (stored) 12 months from generation User access and audit trail
Uploaded employment contracts Not retained (transient processing only) Data minimisation
Survey and questionnaire responses 12 months from submission Report generation and audit trail
Security and audit logs 12 months Security monitoring and incident response
Application logs (metadata only) 12 months System monitoring and debugging
Cookie consent records 12 months Demonstrate compliance

11. Your Rights Under UK GDPR

You have the following rights in relation to your personal data:

Right to Be Informed

Clear information about how we use your data (this policy)

Right of Access

Request a copy of personal data we hold about you

Right to Rectification

Request correction of inaccurate or incomplete data

Right to Erasure

Request deletion of your personal data

Right to Restrict Processing

Limit how we use your data in certain situations

Right to Data Portability

Receive your data in a machine-readable format

Right to Object

Object to processing for marketing or profiling purposes

Rights Related to Automated Decisions

Our AI provides advisory suggestions only — all decisions are made by you

To exercise your rights: Contact us at privacy@compliancetoolkit.co.uk with "GDPR Data Rights Request" in the subject line. We will respond within 30 days.

If you access Compliance Toolkit through a referring partner organisation, please direct your data rights request to that organisation in the first instance, as they are the data controller for your information.

12. Complaints Procedure

Step 1 — Contact Us

Email privacy@compliancetoolkit.co.uk with the subject line "Data Protection Complaint".

Step 2 — Investigation

We will acknowledge your complaint within 5 working days and provide a substantive response within 30 days.

Step 3 — Escalate to the ICO (If Unsatisfied)

If you are not satisfied with our response, you have the right to lodge a complaint with:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk

13. Cookies

We use cookies and similar tracking technologies. For detailed information about the cookies we use and how to manage your preferences, please see our Cookie Policy.

14. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, new features, or legal requirements. When we make material changes, we will update the "Last Updated" date at the top of this document and notify you via email or platform notification where appropriate.

15. Contact Us

Magna Spero Ltd

Company Registration Number: 16649166

ICO Registration Number: ZC087276

Registered Office: 1 Harland Road, Lincoln, LN2 4GW, United Kingdom

Email: privacy@compliancetoolkit.co.uk

We will respond to your enquiry within 30 days.