LEGAL

Privacy Notice

How Reffolio collects and uses personal data. Last updated: [DATE] · Version 1.0

This notice is being finalised. Some details shown in [brackets] are placeholders pending registration and legal review.

1. Who we are

This privacy notice explains how [LEGAL ENTITY NAME] (“Reffolio”, “we”, “us”), company number [COMPANY NUMBER], registered at [REGISTERED ADDRESS], collects and uses personal data when you use the Reffolio platform at reffolio.co.uk and related services.

For the platform and our own business operations, Reffolio is a data controller. When we process reference content on behalf of an employer or agency that issues or requests references through Reffolio, we generally act as a data processor on that organisation’s behalf (see section 9).

We are registered with the UK Information Commissioner’s Office (ICO), registration number [ICO REGISTRATION NUMBER]. For any privacy question or to exercise your rights, contact [PRIVACY CONTACT EMAIL].

2. Who this notice covers

  • Workers — people who are the subject of references.
  • Referees — people asked to provide or confirm a reference.
  • Organisation users — staff at employers and agencies who request, issue or manage references.
  • Website visitors — people who browse our public website.

3. The personal data we collect

CategoryExamplesSource
Account dataName, email, role, organisation, job title, login identifiersYou / your organisation
Worker identity & verificationFull name, professional registration body and number, DBS certificate number, a tamper-evident identity hashYou / your organisation
Reference contentEmployment dates, role, conduct, attendance, disciplinary and capability matters, safeguarding information, suitability assessmentsThe issuing or requesting organisation / referee
Referee dataName, job title, work email, confirmation statusThe organisation
Sharing & access dataRequest and share links, verification codes, when a reference was opened and by whomGenerated by the platform
Billing dataPlan, seats, payment status (card details handled by Stripe, not stored by us)You / Stripe
Technical dataIP address, device/browser information, usage logsAutomatically collected

4. Special-category and criminal-offence data

References in regulated sectors can include information needing extra protection under UK data-protection law:

  • Criminal-offence data (Article 10 UK GDPR / DPA 2018) — such as DBS details and information about safeguarding allegations or disciplinary matters.
  • Potentially special-category data (Article 9) — where a reference incidentally reveals health or other protected information.

We process this only where a condition in Schedule 1 of the Data Protection Act 2018 applies — in particular safeguarding of children and individuals at risk, and employment purposes — and we keep an appropriate policy document. [CONFIRM SCHEDULE 1 CONDITIONS WITH YOUR ADVISER]

5. How we use your data and our lawful bases

PurposeLawful basis
Providing the platform and your accountContract
Verifying worker identity and registrationLegitimate interests; legal obligation where applicable
Creating, requesting, assessing and storing referencesLegitimate interests of the organisation; safeguarding
Letting workers share references by consentConsent for the share itself
AI fairness and sector analysis of referencesLegitimate interests
Billing and fraud preventionContract; legal obligation
Security, logging and service improvementLegitimate interests

6. Who we share data with

  • Recipients of a reference — the requesting organisation, and (in the worker-held model) anyone the worker chooses to share with after they verify their email.
  • The organisation and its authorised users — for references they create, request or manage.
  • Our service providers (processors) — listed in section 7.
  • Authorities or advisers — where legally required, or to establish or defend legal claims.

We do not sell personal data, and we do not use it for advertising.

7. Our processors and sub-processors

ProviderPurposeLocation
SupabaseDatabase and authentication hosting[CONFIRM REGION]
RailwayBackend application hosting[CONFIRM REGION]
VercelFrontend website hosting[CONFIRM REGION]
ResendTransactional email delivery[CONFIRM REGION]
StripePayment processingEU / US
AnthropicAI analysis of reference contentUS

8. International transfers

Some providers process data outside the UK, including in the United States. Where that happens, we rely on appropriate safeguards — such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses — together with the provider’s own measures. [CONFIRM THE MECHANISM FOR EACH PROVIDER WITH YOUR ADVISER.]

9. Controller and processor roles

Reffolio is the controller for your account, billing, security and the operation of the platform. When an organisation requests or issues a reference through Reffolio, that organisation is the controller for the reference content and Reffolio acts as its processor under a data-processing agreement. [HAVE YOUR ADVISER CONFIRM THE ANALYSIS FOR THE WORKER-HELD MODEL.]

10. How long we keep data

  • Account data — while your account is active, then [RETENTION PERIOD] after closure.
  • References and verification records — [RETENTION PERIOD], reflecting safeguarding and regulatory expectations.
  • Billing records — as required by law (typically six years).
  • Logs — [RETENTION PERIOD].

11. Your rights

Under UK data-protection law you have the right to access your data; to have it corrected or erased; to restrict or object to processing; to data portability; and to withdraw consent where we rely on it. To exercise any of these, contact [PRIVACY CONTACT EMAIL]; we will respond within one month. Where a reference about you was issued or requested by an organisation (Reffolio as processor), we may direct your request to that organisation as the controller and help you do so.

You also have the right to complain to the ICO (ico.org.uk, helpline 0303 123 1113), though we hope you will contact us first.

12. Cookies

We use only the cookies and local storage needed to keep you signed in and the service secure. We do not use advertising or third-party tracking cookies.

13. Changes to this notice

We may update this notice from time to time. We will change the “last updated” date above and, for significant changes, tell you directly where appropriate.

14. Contact

[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Email: [PRIVACY CONTACT EMAIL]. ICO registration: [ICO REGISTRATION NUMBER].

Our Data Processing Agreement for organisations is available on request — request a copy.

Questions about your data?

We’re happy to help. Get in touch and we’ll respond promptly.

Contact us