How we collect, use, and protect your personal information
Version 1.0 | Last Updated: 1 February 2026 | Effective Date: 1 February 2026
ICO Registration Number: ZC087276
This Privacy Policy is provided by:
Magna Spero Ltd
Company Registration Number: 16649166
ICO Registration Number: ZC087276
Registered Office: 1 Harland Road, Lincoln, LN2 4GW, United Kingdom
Website: compliancetoolkit.co.uk
Email: privacy@compliancetoolkit.co.uk
Data Protection Contact: privacy@compliancetoolkit.co.uk
Magna Spero Ltd operates Compliance Toolkit, a comprehensive employment compliance assessment platform. We are committed to protecting your privacy and ensuring the security of your personal information. This policy applies to all users of our platform, including individual subscribers, consultants, and enterprise clients.
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use Compliance Toolkit. It applies to all processing activities we undertake as a data controller and describes our practices when handling employee or client data on behalf of our enterprise and consultant customers.
This policy is designed to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Data (Use and Access) Act 2025 (DUA Act 2025).
When you create an account or use our services, we collect:
With your consent, we use Microsoft Clarity to analyze how users interact with our platform. This includes page views, session duration, user behavior patterns, and navigation paths. You can control analytics cookies through our cookie consent banner.
We process your personal information for the following purposes, based on the legal grounds specified:
| Purpose | Data Processed | Legal Basis (UK GDPR) |
|---|---|---|
| Service provision and account management | Name, email, phone, account credentials | Contract (Article 6(1)(b)) |
| Contract analysis and report generation | Uploaded documents, assessment responses | Contract (Article 6(1)(b)) |
| Account verification and security | Email, IP address, login activity | Legitimate Interest (Article 6(1)(f)) |
| Platform improvement and analytics | Usage patterns, feature interactions, analytics cookies | Consent (Article 6(1)(a)) - via cookie consent |
| Legal compliance and dispute resolution | All relevant personal data as required | Legal Obligation (Article 6(1)(c)) |
Compliance Toolkit uses artificial intelligence to provide compliance guidance, contract analysis, and report recommendations. When you interact with our AI features:
Important: Our AI provides advisory guidance only - it does not make automated decisions that have legal or similarly significant effects on you. All compliance assessments are recommendations that should be reviewed by qualified professionals.
We may share your personal information with:
We do not sell your personal data to third parties.
Some of our service providers process data outside the UK. We ensure appropriate safeguards are in place:
All international transfers comply with UK GDPR Chapter V requirements.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account information | Duration of account + 12 months | Service provision and legal compliance |
| Assessment reports | 12 months from generation | User access and audit trail |
| Uploaded contracts | Deleted immediately after analysis | Data minimization |
| Security and audit logs | 12 months | Security monitoring |
| Cookie consent records | 12 months | Demonstrate compliance |
Clear information about how we use your data (this policy)
Request a copy of personal data we hold about you
Request correction of inaccurate or incomplete data
Request deletion of your personal data
Limit how we use your data in certain situations
Receive your data in a machine-readable format
Object to processing for marketing or profiling
Our AI provides advisory suggestions only - all decisions are made by you
To exercise your rights: Contact us at privacy@compliancetoolkit.co.uk with "GDPR Data Rights Request" in the subject line. We will respond within 30 days.
Under the Data (Use and Access) Act 2025, we have a formal procedure for handling data protection complaints:
Email: privacy@compliancetoolkit.co.uk with subject "Data Protection Complaint"
We will acknowledge your complaint within 5 working days and provide a substantive response within 30 days.
If you are not satisfied with our response, you can lodge a complaint with:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
We use cookies and similar tracking technologies. For detailed information about the cookies we use and how to manage your preferences, please see our Cookie Policy.
We may update this Privacy Policy periodically to reflect changes in our practices, new features, or legal requirements. When we make material changes, we will update the "Last Updated" date and notify you via email or platform notification where appropriate.
Magna Spero Ltd
Company Registration Number: 16649166
Registered Office: 1 Harland Road, Lincoln, LN2 4GW, United Kingdom
We will respond to your inquiry within 30 days.