Last updated 12 September 2026.
Kit and Ledger Limited ("Kit & Ledger", "we", "us", "our") provides a UK compliance-monitoring and deadline-reminder subscription for small businesses. This notice explains what personal data we collect, why, how we use it, and the rights you have over it under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This notice covers the Kit & Ledger website, the free eligibility check, the compliance product itself, and related email communications. It does not cover third-party websites we link to, including GOV.UK, Companies House, HMRC, ICO or The Pensions Regulator.
| Data controller | Kit and Ledger Limited |
|---|---|
| Company number | 17418531 |
| Registered office | Suite A, 82 James Carter Road, Mildenhall, IP28 7DE |
| Contact for privacy queries | hello@kitandledger.com |
Free eligibility check. If you use our free check, we collect the company number you search for and the answers you give to work out which compliance obligations apply. A short-lived, opaque cookie ties your answers to that one company while you complete the check; see Section 9 for detail. If you don't go on to subscribe, this data is deleted after 30 days (Section 8).
Account and sign-in. When you subscribe, we collect the email address you use to check out and sign in. Sign-in is passwordless: we email you a one-time link, and opening it establishes a short-lived, secure session. We don't store a password, and sign-in is handled entirely by our own application, not a third-party identity provider.
Company information. When you identify your business, we retrieve and store the record Companies House holds for it, including company name, company number, registered office address, company status, incorporation date, SIC codes, and, where relevant to a specific obligation, officer and person-with-significant-control (PSC) information. This is all publicly available information held on the Companies House register; we do not create or infer any of it ourselves.
Profile and questionnaire data. To work out which obligations apply to your business, we ask a short set of questions, for example whether you're VAT-registered, whether you employ staff, and similar facts about how your business operates. These answers are self-declared by you and stored against your company profile to personalise your compliance calendar. Each answer is recorded with when it was given, so we can show you exactly what a given deadline was calculated from, and so it can be updated if your circumstances change.
Billing data. Payments are processed by Stripe, our payment processor. We don't store your full card details; Stripe holds those under its own security standards. In our own database, we hold your subscription plan, subscription status, and the identifiers linking your account to the relevant Stripe records, for account administration, plus a durable record of which version of these Terms and this Privacy Notice you accepted at checkout and when, as evidence of what you agreed to. Stripe processes the payment, issues your receipt, and retains the associated transaction and payment-history records under its own privacy policy; we don't hold a copy of those records ourselves.
Technical data. Like any website, our hosting provider automatically logs standard technical data, such as IP address, browser and device type, and pages requested, for security and reliability. We do not run any analytics, advertising or tracking cookies or scripts on this site; everything we do run is described in full at Section 9 and our Cookies Notice.
Communications. If you contact us for support, or we send you a deadline or renewal reminder, we keep a record of that correspondence to respond to you, to operate the reminder service, and to improve it.
Bounce and spam-complaint suppression. If an email we send you is permanently rejected by your mail server, or you mark one of our emails as spam through your own email provider, our email provider (Postmark) tells us. We record a pseudonymised identifier for the affected address, being a one-way cryptographic hash generated with a private key only we hold, rather than the address itself, together with the reason (delivery failure or spam complaint) and when it happened. This lets us check, before sending you any further account or service email (a subscription confirmation, a deadline or renewal reminder, a replacement management-link email, or a compliance-change notification), whether we should hold off, without keeping the address itself in a form anyone could read back out of that record. See Section 8 for how long we keep this and how it can be removed.
| Running the free eligibility check | Legitimate interests (Art. 6(1)(f)): providing the free tool you've asked to use |
|---|---|
| Creating and administering your account | Performance of a contract (Art. 6(1)(b)) |
| Determining and personalising which obligations apply to you | Performance of a contract (Art. 6(1)(b)) |
| Sending deadline and renewal reminder emails | Performance of a contract (Art. 6(1)(b)) |
| Processing payments and maintaining accounting records | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax and accounting records |
| Recording what you agreed to at checkout | Legitimate interests (Art. 6(1)(f)): keeping evidence of the contract terms you accepted, including in the event of a dispute |
| Responding to a contact-form message or support request | Legitimate interests (Art. 6(1)(f)) |
| Not sending further email to an address that has bounced or complained | Legitimate interests (Art. 6(1)(f)): keeping our service emails deliverable, and respecting your objection to further contact |
| Keeping the service secure and investigating misuse | Legitimate interests (Art. 6(1)(f)) |
Company information shown in your dashboard is sourced from the Companies House public register via its official API. Companies House is itself a separate data controller for that register. We display and store this data solely to operate the service for you; we do not use it for any other purpose, and we refresh it periodically, or on request, so it stays current. See the Companies House privacy notice at developer.company-information.service.gov.uk for how Companies House itself handles this data.
Whether an obligation applies to your business, and its deadline, is worked out by rule-based logic applied to your company information and questionnaire answers. This is not profiling and doesn't produce a decision with a legal or similarly significant effect on you: it's an organisational aid, not a determination of your legal obligations. Where our confidence in an automated result is insufficient, we show "Check required" rather than presenting an uncertain result as fact. See our Disclaimer and our Source & Verification Framework for more detail on how this works.
We share personal data with the following parties, solely to provide the service:
We don't use a separate third-party authentication provider (Section 2). We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.
Our application runs on Vercel, our database is provisioned via Neon, and our transactional email is sent through Postmark. Postmark's own documentation states that message data is stored on servers in the United States. Wherever any supplier listed in Section 6 processes personal data outside the UK or European Economic Area, we ensure an appropriate safeguard, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, is in place before that transfer takes place. We do not claim that all infrastructure or personal data is hosted exclusively in the UK or EU.
| Free eligibility checks that never convert to a paid account | 30 days, after which we delete or anonymise it |
|---|---|
| Account and company data, active account | For as long as your account is active |
| Account and company data, after cancellation | 24 months, after which we delete or anonymise it |
| Raw Companies House source snapshots | For the life of your subscription, plus 24 months |
| Billing and payment records | Up to 6 years after the transaction, to meet UK accounting and tax record-keeping obligations |
| Checkout consent evidence (which Terms/Privacy version you accepted, and when) | For as long as the related billing record is kept (up to 6 years) |
| Reminder and notification delivery records | 24 months |
| Support correspondence | Up to 2 years after resolution |
| Bounce and spam-complaint suppression record (pseudonymised) | For as long as necessary to prevent further sending to that address, which in practice is indefinitely: a hard-bounce record is removed once we have confirmed the underlying issue is fixed (for example, you tell us the address had a typo and give us the corrected one), a spam-complaint record is not removed, and we keep this minimal, pseudonymised record even if you ask us to erase your data, so that we do not contact that address again by mistake |
These are the periods we apply as a matter of policy and process today. You can ask us to delete your account data earlier; we will do so unless we are required to keep specific records (such as billing history) for a legal reason, or the record is subject to an unresolved complaint, payment dispute, fraud investigation, or legal hold, in which case it is retained until that matter is resolved. A minimal suppression record (the row above) is an exception we keep by design even after an erasure request, because deleting it would let us contact an address you have told us, directly or through a spam complaint, not to contact again.
We set 2 cookies, both first-party and strictly necessary for the service to work: one remembers a free eligibility check you've started, and the other keeps you signed in for a short session after you open an emailed sign-in link. Neither is used for analytics, advertising or tracking, and we don't run any analytics, advertising or third-party tracking scripts anywhere on this site. Because every cookie we set is strictly necessary, we don't show a cookie consent banner: asking permission for a cookie the law doesn't require consent for would be a formality, not a real choice. If that ever changes, we'll add a proper consent banner before we add the cookie that needs it, not after. Full technical detail (exact name, provider, purpose and duration for each cookie) is at our Cookies Notice.
We encrypt data in transit and at rest. Kit & Ledger has no general-purpose, browser-based administrative panel: the compliance rules that determine which obligations apply to a business are maintained as version-controlled code, reviewed and tested before deployment. They cannot be changed through a customer-facing or general-purpose administration screen, because no such screen exists. Access to the underlying hosting, database and email-provider dashboards used to run the service is restricted to authorised personnel of Kit and Ledger Limited. Because sign-in is passwordless, your email account forms part of the security perimeter for your Kit & Ledger account, so please keep it secure.
Under UK GDPR, you have the right to:
To exercise any of these rights, contact hello@kitandledger.com. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, although we would welcome the chance to resolve any concern directly first. Kit and Ledger Limited is registered with the ICO as a data controller, registration reference ZC244204, rather than relying on an exemption.
Kit & Ledger is a business-to-business service intended for use by adults acting on behalf of a company. It is not directed at, and we do not knowingly collect data from, children under 18.
We may update this notice as the service evolves or the law changes. We will post the updated version here with a new "last updated" date, and where a change is material, we will notify you by email.
For any question about this notice or how we handle your data, contact hello@kitandledger.com or use our contact form.