LEGAL
Privacy Policy
Last updated: 1 July 2026 · This policy is a draft and has not yet been reviewed by a solicitor.
1. Who We Are
Fidescore Ltd ("we", "us", "our") operates the Fidescore platform at fidescore.uk. We are the data controller for personal data collected through this platform.
For data protection queries: privacy@fidescore.uk
2. Data We Collect
Account data: When you register, we collect your name and email address. If you sign in via Google or LinkedIn, we receive your name and email from those providers.
Review data: When you submit a review, we collect your business email address domain (e.g. yourcompany.co.uk) and, for Ltd company reviewers, your Companies House registration number. We store this to verify your identity and prevent abuse. Your full email address is stored in hashed form and is never shown publicly.
Payment data: If you purchase credits, payments are processed by Stripe. We do not store your card details. We retain records of transactions for accounting purposes.
Usage data: We collect standard server logs including IP addresses, browser type, and pages visited. This is used for security and to improve the platform.
Cookies: We use essential cookies for authentication. We do not use advertising or tracking cookies.
3. How We Use Your Data
- To provide the service — verifying your identity, publishing your reviews, managing your credits
- To prevent abuse — detecting fake reviews, rate limiting, investigating complaints
- To communicate with you — sending verification emails, important account notices
- For legal compliance — responding to valid legal requests, maintaining audit trails
- To improve the platform — analysing usage patterns (in aggregate, not individually)
4. Legal Basis for Processing
We process your data under the following legal bases (UK GDPR):
- Contract — processing necessary to provide the service you signed up for
- Legitimate interests — fraud prevention, platform security, abuse detection
- Legal obligation — responding to court orders or regulatory requests
- Consent — for any optional marketing communications (which we do not currently send)
5. Who We Share Your Data With
We share data only with the following third-party processors, all of whom are bound by data processing agreements:
- Supabase — database and authentication hosting (EU servers)
- Vercel — web hosting and deployment (US, with EU data transfer safeguards)
- Stripe — payment processing
- Resend — transactional email delivery
- Companies House API — we query this to verify company details (no personal data sent)
We do not sell your data. We do not share your data with advertisers.
Legal disclosure: In the event of a valid court order or legal process relating to a defamation claim, we may be required to disclose reviewer identity information. We will always seek to notify affected users where legally permitted to do so.
6. Data Retention
We retain your account data for as long as your account is active plus 2 years after deletion.
Review data is retained indefinitely as it forms part of the public record of the platform. If a review is removed (e.g. following a valid complaint), we retain an audit record of the submission for legal purposes.
Transaction records are kept for 7 years for accounting and tax purposes.
7. Your Rights
Under UK GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your account and personal data (subject to legal retention obligations)
- Restriction — ask us to restrict processing of your data in certain circumstances
- Portability — receive your data in a machine-readable format
- Object — object to processing based on legitimate interests
To exercise any of these rights, contact privacy@fidescore.uk. We will respond within 30 days.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Security
We take reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), hashed storage of sensitive identifiers, and restricted access to production systems.
In the event of a data breach that poses a risk to your rights, we will notify affected users and the ICO as required by law.
9. Children
Fidescore is a B2B platform intended for use by businesses. We do not knowingly collect data from individuals under 18.
10. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes by email. The current version is always available at fidescore.uk/privacy.