Privacy Policy
Last updated: [DATE] · Draft — pending legal review
1. Who we are
[Company name], the data controller for your account data. ICO registration: [NUMBER].
2. What we collect
Account data (name, email, hashed password, optional two-factor secrets, encrypted at rest); the documents and emails you add — which can include identity documents and financial records; access-log data for shared documents (recipient activity, IP address, browser); and technical logs needed to run the service.
3. Why we process it (lawful bases)
Performing our contract with you (storing and organising your record); your consent (notification emails, which you control in Settings); and legitimate interests (security logging, abuse prevention).
4. The mobile app: device permissions
Camera and photos are used only when you choose to add a picture to a viewing; photos are uploaded to your own record. Face ID / biometrics unlock the app locally — your biometric data never leaves your device and is never sent to us. Notifications, if you enable them, alert you to new messages, documents and due dates; we store a device push token for this and nothing more. You can change any of these in your device Settings at any time.
5. AI processing
Document text is sent to our AI provider ([provider], under a no-training-on-inputs agreement) to generate summaries and answer your questions. Your documents are not used to train models.
6. Email
Emails sent to your transaction’s own address — whether written to it directly or forwarded in — are stored in your record along with their safe attachments, and we retain the raw message as received. Emails sent via Chainkeep on your behalf carry your name and set replies to your own address.
7. Usage measurement
We record a short list of named events about how the product is used — that an account was created, that a transaction was created, that an introduction was sent, that mail arrived and filed itself. Each is stored in our own database, with no third-party analytics service involved and no additional cookies set beyond the session cookie that signs you in. These records carry counts and fixed labels only; the address, the people and the contents of your record are never part of them. Lawful basis: legitimate interests in understanding whether the product works. Deleting your account removes the link between you and these events.
8. Sharing and processors
We never sell your data. Processors: [hosting provider], [object storage provider], [email provider], [AI provider] — each under a data processing agreement.
9. Retention
[Retention schedule — for review. Deleted accounts are purged within N days, including backups.]
10. Your rights
Access and portability: Settings → Export gives you everything as a zip. Erasure: delete your account in the mobile app under Account → Delete my account, or on the web under Settings → Delete account — this permanently erases your transactions, documents, viewings and messages. You can also contact contact@chainkeep.uk for any UK GDPR right, and you may complain to the ICO.
11. Security
Encryption in transit and at rest, hashed share tokens, mandatory link expiry, an append-only tamper-evident access log, optional two-factor authentication, and malware scanning of incoming files.