Privacy policy

Report Kit 360 is a trading name of [Digital Depth Studio Ltd], a company registered in England and Wales under company number [company number] with its registered office at [registered office address] (“we”, “us”, “our”). This policy explains how we handle personal data when you use the Report Kit 360 website at reportkit360.com, the web application at portal.reportkit360.com and related services (together, the “Service”).

This policy is written for the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It is a draft prepared for review by a legal adviser before publication; items in square brackets must be completed or confirmed.

1. Who is responsible for your data

Our role depends on whose data it is.

We are the controller for personal data about you as a user of the Service and visitor to the website: your account details, billing records, support correspondence, usage and security logs, and website data.

We are a processor for personal data that our customers put into their workspace: the content of reports, photographs, client records, snippets, members’ details entered by the workspace, and data about people who open share links. For that data the customer (the workspace owner’s organisation) is the controller, and we act on its instructions under our terms of service and the data processing terms in section 13. If your data appears in a report produced by one of our customers, please contact that customer first; we will help them respond.

Contact for data protection matters: [[email protected]], or by post to the registered office. We have [not appointed / appointed] a data protection officer. [Insert ICO registration number if registered.]

2. Data we collect as controller

2.1 Account and profile

Name, email address, password (stored as a salted hash, never in plain text), company name, time zone, locale, avatar, marketing preference, two-factor authentication secret and recovery codes (stored encrypted), and the workspaces you belong to and your role in each.

2.2 Billing

Plan, subscription status, renewal date, seats, top-ups, invoice history and the billing address and VAT number you give us. Card payments are taken by Stripe through Stripe Checkout and the Stripe customer portal. We do not receive or store your full card number. Stripe’s own privacy notice applies to the payment itself.

2.3 Usage, security and audit

Sign-in events, IP address and user agent of each session, failed sign-in attempts, password reset and email change events, actions recorded in the workspace audit log (who did what and when), export jobs, API key and webhook activity, error logs and performance data. The audit log is retained for 30 days on the Basic plan and two years on the Pro plan.

2.4 Support

Emails and messages you send to [email protected] or [email protected], and notes of how we resolved them. If a platform administrator views your workspace to help with a request it is read-only, shown to you as a banner, and recorded in your audit log.

2.5 Website

Server logs for reportkit360.com. [If website analytics are used: state the tool, what it records and that non-essential cookies are set only with consent; see the cookie policy.] Contact form submissions.

2.6 Marketing

If you opt in, we may send product news by email. Every message carries an unsubscribe link and you can change the preference under Settings → Profile at any time.

3. Data we process on behalf of customers

When a customer uses the Service, we store and process on their instructions:

  • Report content: text, tables, findings, ratings, signatures, document-control entries and variables.
  • Media: photographs and documents uploaded to the workspace, including any EXIF data such as capture time and, if the workspace setting keeps it, GPS location.
  • Client records: names, contact details, addresses, references and notes about the customer’s own clients.
  • Workspace members: names, email addresses and roles of people the customer invites.
  • Share-page viewers: for each visit to a shared report, a hashed fingerprint, device class, country, time on page and whether the PDF was downloaded. We do not store the viewer’s raw IP address against the visit. If the customer enables the Pro viewer gate, the name and email address the viewer enters.
  • AI assistance: if a Pro customer adds their own API key for Anthropic (Claude), OpenAI (ChatGPT) or Google Gemini and asks for a task, the content of the relevant block or photograph is sent to that provider under the customer’s own account and terms. We log the provider, model, token counts and estimated cost of each call. We do not send any content to an AI provider unless a user requests it.

Customers are responsible for having a lawful basis for the personal data they put into the Service, for informing the people concerned where required, and for the content of their reports.

4. Why we use your data and the lawful basis

Purpose Lawful basis
Creating and running your account, providing the Service, billing and support Performance of a contract (our terms of service)
Security: sign-in protection, session management, fraud and abuse prevention, audit logs Legitimate interests in keeping the Service and its users safe, and legal obligation where applicable
Transactional emails: verification, password reset, invoices, export ready, invitations Performance of a contract
Product news by email Consent, which you may withdraw at any time
Improving the Service using aggregated usage data Legitimate interests in understanding how the Service is used
Complying with tax, accounting and legal obligations Legal obligation
Responding to legal requests and defending claims Legitimate interests and legal obligation

Where we rely on legitimate interests we have considered the impact on you and concluded the processing is proportionate. You can object; see section 9.

5. Who we share data with

We do not sell personal data. We share it with:

  • Sub-processors who host and run the Service under contracts that require them to protect it: [hosting provider and data-centre location], [transactional email provider], [error monitoring provider, if any], Stripe (payments and invoicing). The current list is published at [reportkit360.com/legal/sub-processors] and we will give notice of changes.
  • AI providers chosen by a Pro customer, only for content the customer’s users submit for an AI task, under the customer’s own account.
  • Professional advisers such as accountants, lawyers and insurers where necessary.
  • Authorities where the law requires it or to protect the rights, property or safety of us, our customers or others.
  • A buyer or successor of the business, who would be bound by this policy.

6. International transfers

[State where data is hosted. If any sub-processor stores or accesses personal data outside the UK, state the country and the safeguard relied on, for example the UK International Data Transfer Agreement or an adequacy regulation.] AI providers chosen by a customer may process data outside the UK; the customer’s agreement with that provider governs the transfer.

7. How long we keep data

Data Retention
Account and workspace data For the life of the account or workspace
Workspace data after a subscription ends 30 days, during which the customer can export it, then purged
Account data after you delete your account Sign-in ends immediately; data purged after 30 days
Share-page analytics 30 days on Basic, two years on Pro
Workspace audit log 30 days on Basic, two years on Pro
AI keys after a downgrade from Pro Kept encrypted for 90 days, then removed
Sessions Up to 30 days with Remember me, otherwise 12 hours of inactivity
Invoices and billing records [6 years] after the end of the financial year, for tax and accounting purposes
Support correspondence [2 years] after the matter is closed
Server and security logs [90 days]

Backups are retained for [period] and are overwritten on a rolling basis; data deleted from the live Service remains in backups until they expire.

8. How we protect data

Passwords are at least 10 characters and stored hashed; five failed attempts lock the account for 15 minutes. Two-factor authentication is available to every user. AI provider keys and API secrets are encrypted at rest and shown once. Share links are 32-character secret addresses with optional password, expiry and view limit, and can be revoked or rotated. Uploaded files are checked by content, not by name. Access to production systems is restricted to [named roles] and logged. We do not describe the Service as certified under any security scheme; if that changes we will say which one.

No system is free of risk. If we become aware of a personal data breach that is likely to result in a risk to you, we will notify the ICO within 72 hours where required and tell affected customers without undue delay.

9. Your rights

Under UK GDPR you can ask us to: give you access to the personal data we hold about you; correct it; erase it; restrict or object to its processing; and provide it in a portable format. Where we rely on consent you may withdraw it at any time. We will respond within one month, extendable where a request is complex.

Many of these you can do yourself: Settings → Profile to change your name, email, password and marketing preference; Settings → Security for two-factor authentication and sessions; Settings → Profile → Export data for a copy of your workspaces (self-serve on Pro; on Basic, ask support and we will enable the button for you temporarily); Settings → Profile → Delete account.

If you are not satisfied with how we handle your data you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to address your concern first.

10. Cookies

See our cookie policy at /legal/cookies/ for the cookies and similar technologies we use and how to control them.

11. Children

The Service is for business use by people aged 18 or over. We do not knowingly collect data from children.

12. Changes to this policy

We will post changes here and update the effective date. For material changes we will email account holders or show a notice in the app at least [14 days] before they take effect.

13. Data processing terms for customers

For personal data we process on a customer’s behalf (section 3), the following terms form part of our agreement with the customer under Article 28 UK GDPR:

  1. Subject matter and duration. Hosting, rendering, storing, exporting and sharing inspection and survey reports and related records for the duration of the subscription plus the 30-day export period.
  2. Nature and purpose. Providing the Service as described in our documentation.
  3. Types of data and data subjects. As listed in section 3: the customer’s staff, clients, people named or shown in reports and photographs, and people who open share links.
  4. Instructions. We process the data only on the customer’s documented instructions, which are given through the Service’s settings and features, unless required by law.
  5. Confidentiality. Persons authorised to process the data are bound by confidentiality.
  6. Security. We maintain the measures described in section 8.
  7. Sub-processors. The customer authorises the sub-processors listed under section 5; we will give [30 days’] notice of additions and the customer may object on reasonable grounds.
  8. Assistance. We will assist the customer, by appropriate technical measures, in responding to data subject requests and in meeting its obligations on security, breach notification and impact assessments, taking into account the nature of the processing.
  9. Deletion and return. On termination the customer may export the data for 30 days, after which we delete it, subject to backups expiring as described in section 7.
  10. Audit. We will make available the information necessary to demonstrate compliance and allow audits, on reasonable notice and no more than once a year unless required by a supervisory authority.

[Legal review: confirm whether a separate signed DPA is to be offered to enterprise customers, and whether the standard contractual clauses or IDTA are needed for any sub-processor.]

14. Contact

[Digital Depth Studio Ltd], trading as Report Kit 360 [registered office address] [[email protected]]