Privacy Policy
Last updated: 7 July 2026
1. Introduction
Company Reminders ("we", "us", "our", or "the Service") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and otherwise process your personal information when you use our web application, including but not limited to compliance deadline tracking and reminder services.
The Service is operated by Pembroke Digital, a company registered in England and Wales.
2. Information We Collect
We collect information you provide directly, information collected automatically, and information from third parties.
2.1 Information You Provide
- Account Information: When you register, we collect your email address, name, and phone number (optional, for SMS reminders).
- Company Information: Company registration numbers and related details you provide when tracking companies.
- Reminder Settings: Your preferred reminder timing and notification methods.
- Login Information: We store password hashes for password-based authentication, or facilitate magic-link sign-in tokens.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, time spent on the Service, and interactions with reminders.
- Device Information: Browser type, operating system, IP address, and referring URLs.
- Cookies and Similar Technologies: Session cookies, remember-me tokens, and analytics identifiers.
2.3 Third-Party Information
- Companies House API: Officer and person with significant control data retrieved on your behalf.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Provision: To operate, maintain, and improve the Service.
- Reminders and Notifications: To send email and SMS reminders for compliance deadlines.
- Account Management: To manage your account, process requests, and provide customer support.
- Communication: To send service updates, security alerts, and policy changes.
- Analytics: To understand how users interact with the Service and identify improvements.
- Legal Obligations: To comply with legal requirements, prevent fraud, and enforce our terms.
4. Legal Basis for Processing (UK GDPR)
- Performance of a Contract: Providing the Service and sending reminders you have requested.
- Legitimate Interest: Improving the Service, preventing fraud, and business analytics.
- Consent: For SMS reminders and optional marketing communications.
- Legal Obligation: Compliance with data protection laws and law enforcement requests.
5. Third-Party Sharing
We do not sell your personal information. We share information only in these circumstances:
- Service Providers: Brevo (email and SMS service provider). Data is processed under data processing agreements.
- Companies House: Public company data is retrieved using your provided company registration numbers.
- Legal Requirements: When required by law, court order, or to protect rights and safety.
- Business Transfer: In the event of merger, acquisition, or sale of assets (you will be notified).
6. Data Retention
- Account Data: Retained for the duration of your account. You can delete your account at any time via account settings.
- Email and SMS Logs: Retained for 12 months for delivery verification and support.
- Login Attempts: Failed login records retained for 24 hours (brute-force protection).
- Remember-me Tokens: Valid for 30 days; deleted on logout or password change.
- Magic-link Tokens: Valid for 15 minutes; automatically expired.
- Password Reset and Email Verification Tokens: Valid for 1 and 24 hours respectively; automatically expired.
7. Your Rights
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal information.
- Rectification: Correct inaccurate or incomplete information.
- Erasure: Delete your account and associated data (subject to legal retention obligations).
- Restrict Processing: Limit how we use your information.
- Portability: Export your data in a portable format.
- Object: Opt out of certain processing, including marketing communications.
- Withdraw Consent: Withdraw consent for SMS reminders or magic-link authentication at any time via account settings.
To exercise these rights, contact us using the details in section 9.
8. Data Security
We implement industry-standard security measures:
- HTTPS encryption for all data in transit.
- Password hashing using PHP's password_hash (PASSWORD_DEFAULT algorithm).
- Single-use, time-limited tokens for sensitive operations (password reset, email verification, magic-link sign-in).
- Prepared statements and input validation against SQL injection.
- HttpOnly and SameSite session cookies.
- Regular security reviews and updates.
No system is absolutely secure. While we take comprehensive steps to protect your information, we cannot guarantee complete security.
9. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact:
Pembroke Digital
Email: support@company-reminders.obrienmedia.uk
Data Protection Officer: dpo@company-reminders.obrienmedia.uk
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk.
10. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of any material changes via email or by posting a notice on the Service. Your continued use of the Service constitutes acceptance of the updated policy.
Version history
| Version | Date | Changes |
|---|---|---|
| 1.0 | 7 July 2026 | Initial publication |