Data Handling and Compliance Policy
Last updated: 7 July 2026
1. Introduction
This Data Handling and Compliance Policy describes how Company Reminders manages, processes, protects, and complies with regulations governing data. This policy supplements our Privacy Policy with technical and operational details.
2. Data Classification
Company Reminders processes the following categories of data:
2.1 Personal Data (GDPR Classification)
- Email Addresses: Used as unique identifier and communication channel.
- Names: User display names and officer names from Companies House API.
- Phone Numbers: Stored only when users opt into SMS reminders (with consent).
2.2 Business Data
- Company Information: Registration numbers, company names, and related details you provide.
- Public Sector Data: Officer and PSC information retrieved from Companies House public API.
2.3 Technical Data
- IP Addresses: Logged for security (brute-force detection).
- Session Data: Anonymous session identifiers.
- User Preferences: Reminder timing, notification methods, and feature settings.
3. Data Collection Practices
3.1 Consent-Based Collection
- SMS Reminders: Only collected with explicit user opt-in; users can disable at any time via account settings.
- Magic-link Sign-in: Users can choose this authentication method; email addresses are required.
3.2 Implicit Collection
- Companies House Data: Retrieved automatically when you add a company; you retain control to delete companies at any time.
- Usage Metrics: Pages visited and features used are logged but not linked to third-party analytics.
3.3 Minimisation Practices
We collect only data necessary for the Service to function. We do not collect:
- Precise location data.
- Payment card information (the Service is free).
- Biometric data.
- Employment or educational history.
4. Storage and Infrastructure
4.1 Database Security
- Technology: MariaDB relational database with prepared statement queries (preventing SQL injection).
- Encryption at Rest: Database encryption enabled on the hosting platform.
- Access Control: Database access restricted to authenticated application users only.
- Backups: Regular automated backups with secure offsite storage.
4.2 Application Layer
- Server: Nginx web server running on isolated infrastructure.
- Programming Language: PHP 8.0+ with automatic input validation and output sanitisation.
- Transport Security: TLS 1.2+ for all connections (HTTPS).
4.3 Hosting Location
Data is processed and stored within the United Kingdom, ensuring compliance with UK Data Protection Act 2018 and UK GDPR.
5. Data Processing
5.1 Third-Party Data Processors
| Service | Data Type | Purpose | Legal Basis |
|---|---|---|---|
| Brevo | Email address, name, reminder content | Email delivery for reminders and account notifications | Data Processing Agreement (DPA) |
| Brevo SMS | Phone number, SMS reminder content | SMS delivery for deadline reminders (opt-in only) | Data Processing Agreement (DPA); User Consent |
| Companies House API | Company registration number | Retrieve public officer and PSC data | Public data access (no personal data sent) |
5.2 Data Processor Agreements
We have executed Data Processing Agreements (Standard Contractual Clauses) with Brevo in accordance with UK GDPR Article 28. These agreements ensure processors:
- Only process data as instructed by us.
- Maintain confidentiality and security.
- Implement appropriate technical and organisational measures.
- Assist with your data rights requests.
6. Data Retention and Deletion
6.1 Retention Schedule
| Data Type | Retention Period | Legal Reason |
|---|---|---|
| User Account Data | Duration of account + 30 days | Service provision; grace period for restoration |
| Email Log History | 12 months | Delivery verification; bounce handling |
| SMS Log History | 12 months | Delivery verification; troubleshooting |
| Failed Login Attempts | 24 hours | Brute-force attack prevention |
| Session Cookies | 1 hour idle / session close | Session management |
| Remember-me Tokens | 30 days or until logout | Persistent login functionality |
| Password Reset Tokens | 1 hour | Expiry prevents token reuse |
| Email Verification Tokens | 24 hours | Expiry prevents token abuse |
| Magic-link Tokens | 15 minutes | Single-use passwordless sign-in security |
6.2 Account Deletion
Users can delete their account at any time via account settings. Upon deletion:
- Personal data (email, name, phone number) is permanently deleted.
- Company tracking data is permanently deleted.
- Reminder records are anonymised.
- Email and SMS logs are retained for 12 months for auditing, then deleted.
- Session and authentication tokens are immediately revoked.
7. Security Measures
7.1 Encryption
- In Transit: TLS 1.2+ (HTTPS) for all connections.
- At Rest: Passwords hashed with PHP password_hash (bcrypt-equivalent).
- Sensitive Tokens: SHA-256 hashed for password resets, email verification, and magic-link sign-ins.
7.2 Access Control
- Authentication: Email + password, or magic-link single-use tokens.
- Session Security: HttpOnly, SameSite=Lax cookies; regenerated on login.
- Idle Timeout: Sessions expire after 1 hour of inactivity (configurable).
- API Access: Companies House API requests use basic authentication with credentials stored securely.
7.3 Fraud Prevention
- Brute-force Protection: Account lockout after 5 failed login attempts within 15 minutes.
- CSRF Protection: All state-changing operations require CSRF tokens.
- SQL Injection Prevention: Prepared statements used for all database queries.
- XSS Prevention: All user input sanitised with htmlspecialchars().
7.4 Ongoing Security
- Regular security reviews and updates.
- Vulnerability monitoring and patching.
- Server access restricted to authorised staff only.
- No public access to logs or sensitive files.
8. User Rights and Access
8.1 Data Subject Rights (UK GDPR)
You have the following rights, subject to legal limitations:
- Access (Article 15): Request all your personal data we hold.
- Rectification (Article 16): Correct inaccurate information via account settings or by contacting us.
- Erasure (Article 17): Delete your account and associated data (subject to retention obligations).
- Restrict Processing (Article 18): Limit how we use your data.
- Data Portability (Article 20): Export your data in a machine-readable format (reminders CSV export available in-app).
- Object (Article 21): Opt out of processing, including SMS reminders.
- Automated Decision-Making (Article 22): Not applicable (we do not use automated profiling).
8.2 Exercising Your Rights
To exercise any of the above rights, contact:
Email: dpo@company-reminders.obrienmedia.uk
Allow 30 days for a response.
8.3 Complaints to Supervisory Authority
If you believe we have violated your data protection rights, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Website: www.ico.org.uk
Telephone: 0303 123 1113
9. Compliance Commitments
9.1 UK GDPR (General Data Protection Regulation)
Company Reminders complies with the UK GDPR and UK Data Protection Act 2018. We:
- Base all processing on a lawful basis (contract, consent, legitimate interest, or legal obligation).
- Maintain privacy by design principles.
- Conduct Data Protection Impact Assessments (DPIA) for new processing.
- Implement data minimisation and purpose limitation.
- Maintain records of processing activities (Record of Processing Activities available on request).
9.2 Data Transfers
All data processing occurs within the UK. International transfers to processors (e.g., Brevo) are governed by Standard Contractual Clauses in compliance with UK GDPR Article 46.
9.3 Incident Response
In the event of a personal data breach, we will:
- Notify affected individuals without undue delay if high risk to their rights.
- Report to the ICO where legally required.
- Maintain detailed breach records and conduct post-incident reviews.
10. Policy Contact and Updates
For questions or concerns about this Data Handling Policy:
Pembroke Digital
Data Protection Officer: dpo@company-reminders.obrienmedia.uk
Support: support@company-reminders.obrienmedia.uk
Website: company-reminders.obrienmedia.uk
We may update this policy to reflect legal changes or operational improvements. Updates will be posted here with a revised date.
Version history
| Version | Date | Changes |
|---|---|---|
| 1.0 | 7 July 2026 | Initial publication |