Privacy notice
DRAFT - this privacy notice is a draft for review and is not yet in force. Details in [square brackets] are still to be confirmed.
This notice explains how Business Manager uses personal data about the people who use it. We follow UK GDPR and the Data Protection Act 2018.
Who we are
Business Manager is run by [company name, registered number and address]. Contact us at [privacy email address].
What we collect
- Account details: name, email address, role in your organisation, sign-in records and security settings.
- Company information from Companies House, including officers and people with significant control, which is public record.
- What you store with us: files, contracts, dates, questions to the assistant and to experts.
- Billing details: the Direct Debit mandate reference, payment history and invoices. Bank details are held by our Direct Debit provider [provider to be chosen], not by us.
- Technical records: IP address and time of sign-ins, and an audit log of changes.
Why we use it, and our lawful basis
- To provide the service you signed up for (contract).
- To collect payments and keep accounting records (contract and legal obligation).
- To keep accounts and files secure and investigate misuse (legitimate interests).
- To send reminders and service messages you ask for (contract); marketing only with your consent.
Who we share it with
Our hosting provider, our Direct Debit provider, and partner experts only when you send them a request. [An AI model provider when the AI assistant is switched on - to be confirmed.] We never sell personal data.
How long we keep it
While your organisation is a member, then [retention period] after it leaves; invoices for 6 years for tax purposes. You can export your organisation's data or ask us to delete it.
Your rights
You can ask to see, correct, export or delete your data, object to or restrict how we use it, and complain to the Information Commissioner's Office (ico.org.uk).
Version 0.1 draft, 29 September 2026.