Privacy Notice

Last updated 12 September 2026.

Kit and Ledger Limited ("Kit & Ledger", "we", "us", "our") provides a UK compliance-monitoring and deadline-reminder subscription for small businesses. This notice explains what personal data we collect, why, how we use it, and the rights you have over it under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This notice covers the Kit & Ledger website, the free eligibility check, the compliance product itself, and related email communications. It does not cover third-party websites we link to, including GOV.UK, Companies House, HMRC, ICO or The Pensions Regulator.

1. Who we are

Data controllerKit and Ledger Limited
Company number17418531
Registered officeSuite A, 82 James Carter Road, Mildenhall, IP28 7DE
Contact for privacy querieshello@kitandledger.com

2. Personal data we collect

Free eligibility check. If you use our free check, we collect the company number you search for and the answers you give to work out which compliance obligations apply. A short-lived, opaque cookie ties your answers to that one company while you complete the check; see Section 9 for detail. If you don't go on to subscribe, this data is deleted after 30 days (Section 8).

Account and sign-in. When you subscribe, we collect the email address you use to check out and sign in. Sign-in is passwordless: we email you a one-time link, and opening it establishes a short-lived, secure session. We don't store a password, and sign-in is handled entirely by our own application, not a third-party identity provider.

Company information. When you identify your business, we retrieve and store the record Companies House holds for it, including company name, company number, registered office address, company status, incorporation date, SIC codes, and, where relevant to a specific obligation, officer and person-with-significant-control (PSC) information. This is all publicly available information held on the Companies House register; we do not create or infer any of it ourselves.

Profile and questionnaire data. To work out which obligations apply to your business, we ask a short set of questions, for example whether you're VAT-registered, whether you employ staff, and similar facts about how your business operates. These answers are self-declared by you and stored against your company profile to personalise your compliance calendar. Each answer is recorded with when it was given, so we can show you exactly what a given deadline was calculated from, and so it can be updated if your circumstances change.

Billing data. Payments are processed by Stripe, our payment processor. We don't store your full card details; Stripe holds those under its own security standards. In our own database, we hold your subscription plan, subscription status, and the identifiers linking your account to the relevant Stripe records, for account administration, plus a durable record of which version of these Terms and this Privacy Notice you accepted at checkout and when, as evidence of what you agreed to. Stripe processes the payment, issues your receipt, and retains the associated transaction and payment-history records under its own privacy policy; we don't hold a copy of those records ourselves.

Technical data. Like any website, our hosting provider automatically logs standard technical data, such as IP address, browser and device type, and pages requested, for security and reliability. We do not run any analytics, advertising or tracking cookies or scripts on this site; everything we do run is described in full at Section 9 and our Cookies Notice.

Communications. If you contact us for support, or we send you a deadline or renewal reminder, we keep a record of that correspondence to respond to you, to operate the reminder service, and to improve it.

Bounce and spam-complaint suppression. If an email we send you is permanently rejected by your mail server, or you mark one of our emails as spam through your own email provider, our email provider (Postmark) tells us. We record a pseudonymised identifier for the affected address, being a one-way cryptographic hash generated with a private key only we hold, rather than the address itself, together with the reason (delivery failure or spam complaint) and when it happened. This lets us check, before sending you any further account or service email (a subscription confirmation, a deadline or renewal reminder, a replacement management-link email, or a compliance-change notification), whether we should hold off, without keeping the address itself in a form anyone could read back out of that record. See Section 8 for how long we keep this and how it can be removed.

3. Why we use your data and our legal basis

Running the free eligibility checkLegitimate interests (Art. 6(1)(f)): providing the free tool you've asked to use
Creating and administering your accountPerformance of a contract (Art. 6(1)(b))
Determining and personalising which obligations apply to youPerformance of a contract (Art. 6(1)(b))
Sending deadline and renewal reminder emailsPerformance of a contract (Art. 6(1)(b))
Processing payments and maintaining accounting recordsPerformance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax and accounting records
Recording what you agreed to at checkoutLegitimate interests (Art. 6(1)(f)): keeping evidence of the contract terms you accepted, including in the event of a dispute
Responding to a contact-form message or support requestLegitimate interests (Art. 6(1)(f))
Not sending further email to an address that has bounced or complainedLegitimate interests (Art. 6(1)(f)): keeping our service emails deliverable, and respecting your objection to further contact
Keeping the service secure and investigating misuseLegitimate interests (Art. 6(1)(f))

4. Companies House and public register data

Company information shown in your dashboard is sourced from the Companies House public register via its official API. Companies House is itself a separate data controller for that register. We display and store this data solely to operate the service for you; we do not use it for any other purpose, and we refresh it periodically, or on request, so it stays current. See the Companies House privacy notice at developer.company-information.service.gov.uk for how Companies House itself handles this data.

5. Automated processing and "Check required"

Whether an obligation applies to your business, and its deadline, is worked out by rule-based logic applied to your company information and questionnaire answers. This is not profiling and doesn't produce a decision with a legal or similarly significant effect on you: it's an organisational aid, not a determination of your legal obligations. Where our confidence in an automated result is insufficient, we show "Check required" rather than presenting an uncertain result as fact. See our Disclaimer and our Source & Verification Framework for more detail on how this works.

6. Who we share data with

We share personal data with the following parties, solely to provide the service:

  • Companies House: to retrieve your company's public register data, a query rather than a disclosure about you to Companies House beyond your search terms.
  • Vercel: our application hosting provider.
  • Neon (provisioned through the Vercel Marketplace): our Postgres database provider, storing account, company and questionnaire data.
  • Stripe, our payment processor: to process subscription payments and issue your payment receipt. Stripe's own privacy policy governs its handling of payment details and receipts.
  • Postmark, our transactional email provider: to send account and reminder emails (not receipts, which Stripe sends directly), and to tell us when a message could not be delivered or was reported as spam, so we can act on it as described in Section 2.

We don't use a separate third-party authentication provider (Section 2). We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.

7. International data transfers

Our application runs on Vercel, our database is provisioned via Neon, and our transactional email is sent through Postmark. Postmark's own documentation states that message data is stored on servers in the United States. Wherever any supplier listed in Section 6 processes personal data outside the UK or European Economic Area, we ensure an appropriate safeguard, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, is in place before that transfer takes place. We do not claim that all infrastructure or personal data is hosted exclusively in the UK or EU.

8. How long we keep your data

Free eligibility checks that never convert to a paid account30 days, after which we delete or anonymise it
Account and company data, active accountFor as long as your account is active
Account and company data, after cancellation24 months, after which we delete or anonymise it
Raw Companies House source snapshotsFor the life of your subscription, plus 24 months
Billing and payment recordsUp to 6 years after the transaction, to meet UK accounting and tax record-keeping obligations
Checkout consent evidence (which Terms/Privacy version you accepted, and when)For as long as the related billing record is kept (up to 6 years)
Reminder and notification delivery records24 months
Support correspondenceUp to 2 years after resolution
Bounce and spam-complaint suppression record (pseudonymised)For as long as necessary to prevent further sending to that address, which in practice is indefinitely: a hard-bounce record is removed once we have confirmed the underlying issue is fixed (for example, you tell us the address had a typo and give us the corrected one), a spam-complaint record is not removed, and we keep this minimal, pseudonymised record even if you ask us to erase your data, so that we do not contact that address again by mistake

These are the periods we apply as a matter of policy and process today. You can ask us to delete your account data earlier; we will do so unless we are required to keep specific records (such as billing history) for a legal reason, or the record is subject to an unresolved complaint, payment dispute, fraud investigation, or legal hold, in which case it is retained until that matter is resolved. A minimal suppression record (the row above) is an exception we keep by design even after an erasure request, because deleting it would let us contact an address you have told us, directly or through a spam complaint, not to contact again.

9. Cookies

We set 2 cookies, both first-party and strictly necessary for the service to work: one remembers a free eligibility check you've started, and the other keeps you signed in for a short session after you open an emailed sign-in link. Neither is used for analytics, advertising or tracking, and we don't run any analytics, advertising or third-party tracking scripts anywhere on this site. Because every cookie we set is strictly necessary, we don't show a cookie consent banner: asking permission for a cookie the law doesn't require consent for would be a formality, not a real choice. If that ever changes, we'll add a proper consent banner before we add the cookie that needs it, not after. Full technical detail (exact name, provider, purpose and duration for each cookie) is at our Cookies Notice.

10. Keeping your data secure

We encrypt data in transit and at rest. Kit & Ledger has no general-purpose, browser-based administrative panel: the compliance rules that determine which obligations apply to a business are maintained as version-controlled code, reviewed and tested before deployment. They cannot be changed through a customer-facing or general-purpose administration screen, because no such screen exists. Access to the underlying hosting, database and email-provider dashboards used to run the service is restricted to authorised personnel of Kit and Ledger Limited. Because sign-in is passwordless, your email account forms part of the security perimeter for your Kit & Ledger account, so please keep it secure.

11. Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Have inaccurate data corrected.
  • Have your data erased, subject to our legal retention requirements (Section 8).
  • Restrict or object to certain processing, including processing based on legitimate interests.
  • Receive your data in a portable format.

To exercise any of these rights, contact hello@kitandledger.com. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, although we would welcome the chance to resolve any concern directly first. Kit and Ledger Limited is registered with the ICO as a data controller, registration reference ZC244204, rather than relying on an exemption.

12. Children

Kit & Ledger is a business-to-business service intended for use by adults acting on behalf of a company. It is not directed at, and we do not knowingly collect data from, children under 18.

13. Changes to this notice

We may update this notice as the service evolves or the law changes. We will post the updated version here with a new "last updated" date, and where a change is material, we will notify you by email.

14. Contact us

For any question about this notice or how we handle your data, contact hello@kitandledger.com or use our contact form.