Legal and trust

Privacy notice

Last updated 22 July 2026

Controller

DIGIDENT LTD is controller for account, support, billing and service-use data. Contact digidentAI@proton.me at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

Data we collect

We collect account names, business names, email addresses, password hashes, acceptance records, security logs, preferences, notes, pipeline status, subscription identifiers and service usage. GoCardless receives bank details directly; FoodStart Radar does not store bank-account numbers.

Public-source data

We process establishment records published by the Food Standards Agency and local authorities. These usually describe businesses, but names or addresses may sometimes constitute personal data for sole traders. The source is identified on each record.

Purposes and lawful bases

We process account and billing data to perform the contract; security, service improvement, source monitoring and limited public-record organisation for our legitimate interests in operating a safe business information service; legal records to meet legal obligations; and optional marketing only with the applicable permission or another valid legal basis.

Recipients

Cloudflare provides hosting and databases; GoCardless processes payments; Resend delivers service emails; and professional advisers or authorities may receive information where necessary. Each receives only information needed for its role.

International transfers

Some suppliers may process data outside the UK. We require an applicable transfer mechanism and safeguards where UK adequacy regulations do not cover the destination.

Retention

Active account data is retained for the subscription. Core billing and contract records are normally retained for six years after the relevant accounting period or relationship. Security logs are normally retained for up to 12 months, reset tokens for no more than one hour, verification tokens for 24 hours, and expired sessions for no more than 14 days. Public-source snapshots are replaced or minimised as described in the data-source notice.

Your rights

Depending on the processing, you may request access, correction, erasure, restriction, portability or objection. The right to object to legitimate-interest processing is specifically available. Contact digidentAI@proton.me. You may complain to the Information Commissioner's Office at ico.org.uk.

Automated scoring

The platform calculates an opportunity score to help customers prioritise public business events. It does not make legal or similarly significant decisions about individuals, and customers can see the trigger and reason supporting each score.

Security

We use password hashing, short-lived reset links, secure cookies, CSRF controls, signed payment webhooks, role checks, source separation and operational logging. No online system is risk-free.

Updates

We review this notice when processing, suppliers or law changes. Material changes are shown in the service and, where appropriate, emailed before taking effect.

Pre-launch review

This notice reflects the planned unpublished system and must be checked against the final supplier contracts, ICO status and live data flow before launch.