Privacy Policy
1. Introduction
This Privacy Policy explains how BonafideCheck ("we", "us", "our") collects, uses, stores, and protects personal data when you access or use bonafidecheck.co.uk (the "Website") and any associated services, tools, reports, or outputs (the "Service").
We are committed to protecting personal data and complying with all applicable data protection legislation, including:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- ICO guidance and best practice
2. Data Controller and Processor Roles
BonafideCheck acts as:
- A Data Controller for personal data processed for its own operational, security, legal, and administrative purposes; and
- A Data Processor where personal data is processed strictly on behalf of customers using the Service.
Responsibility for determining the lawful basis and purpose of processing customer-submitted data remains with the customer.
3. Data Hosting, Location, and Sovereignty
3.1 UK-Only Data Processing
All personal data processed through the Service is:
- Stored exclusively on UK-based servers
- Processed solely within the United Kingdom
- Subject only to UK data protection law
3.2 No International Transfers
BonafideCheck does not:
- Transfer personal data outside the UK
- Process data in non-UK jurisdictions
- Rely on international data transfer mechanisms
All infrastructure, hosting, backups, and processing environments are UK-resident.
4. Categories of Personal Data We Process
4.1 Data Provided Directly by Users
- Name, job title, organisation
- Email address, telephone number
- Account credentials and access details
- Billing and payment information
- Communications, enquiries, and support requests
- User-submitted due diligence or verification data
4.2 Data Collected Automatically
- IP address
- Browser and device information
- Access logs, timestamps, and usage patterns
- Referrer URLs
- Cookies and similar technologies
4.3 Third-Party and Publicly Available Data
We may process personal data obtained from:
- Public registers (e.g. Companies House)
- Government or regulatory sources
- Licensed third-party data providers
- Open-source and publicly available materials
5. Special Category and Criminal Offence Data
BonafideCheck does not intentionally process:
- Special category personal data
- Criminal offence data
unless:
- Explicitly submitted by a customer
- Lawfully permitted
- Strictly necessary for a documented purpose
- Appropriate safeguards are in place
Customers must not submit such data unless legally authorised.
6. Purposes of Processing
Personal data is processed for the following purposes:
- Providing, operating, and maintaining the Service
- Conducting bona fide checks and due diligence support
- User authentication and access control
- Customer relationship management and support
- Billing, invoicing, and payment processing
- Platform security, fraud prevention, and monitoring
- Legal, regulatory, and compliance obligations
- Internal analytics and service improvement
7. Lawful Bases for Processing
We rely on one or more of the following lawful bases under UK GDPR:
- Contractual necessity - to deliver the Service
- Legal obligation - compliance with UK law
- Legitimate interests - security, fraud prevention, service operation
- Consent - where expressly obtained
- Public task - where processing involves public registers
Customers are responsible for establishing their own lawful bases for customer-submitted data.
8. Data Accuracy and Relevance
We take reasonable steps to ensure data accuracy; however:
- Data sourced from third parties or public records may be inaccurate or outdated
- Information relevance may vary depending on context and timing
Users must independently assess relevance and accuracy before reliance.
9. Data Sharing and Disclosure
Personal data may be shared with:
- Authorised BonafideCheck personnel
- UK-based cloud hosting and infrastructure providers
- UK-based payment processors
- Security, monitoring, and analytics providers
- Sub-processors operating solely within the UK
- Legal or regulatory authorities where required by law
We do not sell personal data.
10. Records of Processing Activities (RoPA)
BonafideCheck maintains internal Records of Processing Activities in accordance with Article 30 UK GDPR, documenting:
- Processing purposes
- Data categories
- Retention periods
- Security measures
- Lawful bases
These records are available to regulators upon lawful request.
11. Data Retention
Personal data is retained only for as long as necessary, based on:
- Contractual requirements
- Legal and regulatory obligations
- Operational necessity
Retention periods vary by data type and are reviewed regularly. Data is securely deleted or anonymised when no longer required.
12. Security Measures
We implement appropriate technical and organisational measures, including:
- Role-based access controls
- Encryption where appropriate
- Secure UK-based hosting environments
- Monitoring, logging, and audit trails
- Staff confidentiality and training obligations
No system is entirely risk-free; residual risk remains inherent.
13. Automated Processing and Profiling
The Service may include automated processing or scoring mechanisms to support due diligence activities.
Such processing:
- Is designed to assist internal assessment
- Does not produce legally binding or significant decisions without human review
14. Data Subject Rights
Individuals have the right to:
- Access personal data
- Rectify inaccuracies
- Request erasure (subject to legal limits)
- Restrict processing
- Object to processing
- Data portability
Requests must be submitted via the contact details on the Website and will be handled in accordance with statutory timelines.
15. Cookies and Tracking
We use cookies and similar technologies to:
- Operate and secure the Website
- Improve functionality
- Analyse usage
A separate Cookie Policy provides full details and consent mechanisms.
16. Children's Data
The Service is not intended for individuals under 18. We do not knowingly process children's personal data.
17. Data Protection Impact Assessments (DPIAs)
Where processing is likely to result in high risk, BonafideCheck conducts DPIAs in line with ICO guidance to assess and mitigate risk.
18. Complaints
If you have concerns regarding data processing:
- Contact us directly using the details on the Website
- You may also lodge a complaint with the Information Commissioner's Office (ICO)
19. Changes to This Policy
This Privacy Policy may be updated at any time. Changes take effect upon publication on the Website.
20. Contact
For data protection, privacy, or rights-related enquiries, contact details are published on bonafidecheck.co.uk