Legal & compliance

Data Protection

What rights you have over your information, how to use them, and how we look after it in the meantime.

Your rights

  • See what we hold about you, and get a copy of it.
  • Correct anything that is wrong or incomplete.
  • Ask us to delete your information where we have no reason to keep it.
  • Withdraw consent — for marketing, for a bank connection, or for optional monitoring — at any time.
  • Object to processing based on our legitimate interests.
  • Ask us to restrict processing while a dispute is sorted out.
  • Take your information elsewhere in a portable format.
  • Not be subject to a decision made purely by automation that has a legal or similarly significant effect on you. Our comparisons are calculations you can inspect — we show you the maths — and a human will review any outcome on request.

How to use them

If you have an account, start at your privacy and data controls in your settings — you can download everything we hold, change each permission and delete your data yourself, without waiting on us. Otherwise write to the data protection contact below. We respond within one month.

Data protection enquiries
To be confirmed

Where to send a data request.

How we secure your information

  • Everything travels over encrypted connections (HTTPS/TLS) and is encrypted at rest in our database and file storage.
  • Row-level security is enforced in the database itself: every table holding customer data has policies tying each row to the account that owns it, so one customer's query cannot reach another's data even if application code has a bug.
  • Uploaded documents live in a private per-customer folder. Access is only ever through a short-lived signed link generated for you, and the path is checked against your account before anything is stored or served.
  • Privileged database access is never used to serve ordinary reads and never exposed to the browser.
  • Sign-in is handled by a managed authentication provider. We never see or store your password.
  • Bank connections are made through a regulated open banking provider. We receive read-only transaction data and never hold your banking credentials.
  • Secrets and API keys are held in a server-side secret store, not in the code or in the browser.
  • Access to customer data by our team is limited to the people who support customers, and only for that purpose.

International transfers

Our hosting, database and email suppliers may process data outside the UK and EEA. Where that happens we rely on the appropriate safeguards for those transfers. The full supplier list is being finalised and will be published here.

Registrations

We do not make any registration claim until it is confirmed in writing. These entries will be completed with numbers and register links at that point.

ICO data protection registration
To be confirmed

Registration number and register link, to be added once confirmed.

Insurance distribution status
To be confirmed

How insurance comparison is provided, and by whom, once confirmed in writing.

Professional indemnity insurance
To be confirmed

If you are unhappy with how we handled your data

Tell us first, through our complaints procedure. You also have the right to complain to the data protection supervisory authority for your country at any time.