Skip to main content

Last updated: 13.07.2026

This Privacy Policy explains how Policy Now Ltd (“we”, “us”, “our”) collects, uses, stores, and protects personal data when you use Policy Now, a software-as-a-service policy management system for independent health and social care providers in the United Kingdom (the “Platform”). It should be read together with our Terms and Conditions.

  1. Who We Are

Policy Now Ltd is a company incorporated in England and Wales with registered number 16942214 and registered office at Suite 155, 1 Silk House, Park Green, Macclesfield, SK11 7QJ, UK.

For the purposes of UK data protection law, we act as a data controller for personal data relating to our business operations and Platform users, and as a data processor for personal data uploaded to the Platform by our customers.

  1. Scope of This Policy

This Privacy Policy applies to visitors to our website, users of the Platform, and representatives of organisations that subscribe to the Platform. It does not cover third-party services, which have their own privacy policies.

  1. Personal Data We Collect

3.1 Information you provide: name, job title, and organisation name; email address and contact details; account login credentials; support requests and correspondence.

3.2 Information processed on behalf of customers: when you upload or manage content on the Platform, this may include personal data relating to staff members, contractors, and service users or patients (where included within policies or procedures). In these cases you are the data controller and we act as your data processor.

3.3 Technical and usage data: IP address (which, for some security and analytics logs, we store only in a hashed/pseudonymised form); device and browser information; usage logs and activity data; and cookies and similar technologies (see section 11).

  1. How We Use Personal Data

We use personal data to provide and operate the Platform; manage accounts and subscriptions; communicate with users and provide support; improve and secure the Platform; and comply with legal and regulatory obligations. We do not use personal data for automated decision-making that produces legal or similarly significant effects, and we do not carry out profiling.

  1. Legal Bases for Processing

Under the UK GDPR we rely on: contract (to provide the Platform); legitimate interests (platform security, improvement, and business operations); legal obligation (where required by law); and consent (for marketing communications and for non-essential analytics cookies — see section 11). You may withdraw consent at any time.

  1. Data Sharing and Disclosure

We share personal data with the sub-processors listed in section 6a; professional advisers (legal, accounting); and regulators or authorities where required by law. All sub-processors are bound by written data processing terms. We do not sell personal data.

6a. Sub-processors

We engage the following sub-processors to operate the Platform. Each processes personal data only on our documented instructions and under a data processing agreement. We give reasonable advance notice of any intended change and an opportunity to object.

  • Supabase — database hosting and storage of Platform data. Location: United Kingdom (AWS London, eu-west-2). Platform data is stored in the UK; where Supabase’s US operations require access for support, this is covered by Supabase’s DPA incorporating the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
  • Vercel — application hosting, serverless functions, and content delivery. Location: United Kingdom (London, lhr1) for application compute. Vercel Inc. is US-incorporated; any resulting US access is covered by Vercel’s DPA incorporating the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
  • Anthropic — AI processing for the “Ask” features and policy analysis (Claude). Location: United States. Safeguards: Anthropic’s DPA incorporating the EU Standard Contractual Clauses (Modules Two and Three) as adapted by the UK International Data Transfer Addendum, with the EU–US Data Privacy Framework (Anthropic is certified) as a secondary basis. Anthropic does not use data submitted through its API to train its models.
  • OpenAI — AI processing for search embeddings. Location: United States. Safeguards: OpenAI’s DPA incorporating the EU Standard Contractual Clauses as adapted by the UK International Data Transfer Addendum, with the EU–US Data Privacy Framework (OpenAI is certified) as a secondary basis. OpenAI does not use data submitted through its API to train its models.
  • Stripe — payment processing. Location: United States. Safeguards: Stripe is certified under the EU–US Data Privacy Framework and its UK Extension, with the EU Standard Contractual Clauses and the UK International Data Transfer Addendum incorporated into Stripe’s data processing terms. We do not receive or store full payment card details.
  • Twilio (SendGrid) — transactional email delivery. Location: United States. Safeguards: Twilio’s DPA incorporating the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
  • Google (Google Analytics) — website and app usage analytics, used only where you have consented (see section 11). Location: United States. Safeguards: Google LLC is certified under the EU–US Data Privacy Framework, with the EU Standard Contractual Clauses and the UK International Data Transfer Addendum incorporated into Google’s data processing terms.
  1. International Data Transfers

Platform data — your account information and the content you upload — is stored within the United Kingdom (Supabase, London; application compute on Vercel, London).

Some processing necessarily takes place outside the UK, in the United States: the AI-powered “Ask” features, policy analysis, and search embeddings (Anthropic and OpenAI), and email, payments, and consented analytics (Twilio, Stripe, Google). Each of these transfers is protected by an appropriate safeguard — the EU–US Data Privacy Framework and its UK Extension where the recipient is certified, and/or the EU Standard Contractual Clauses as adapted by the UK International Data Transfer Addendum — as set out for each provider in section 6a.

  1. Data Security

We implement appropriate technical and organisational measures, including role-based access controls, encryption in transit, logical separation of customer data, and regular security reviews. No system can be guaranteed to be completely secure.

8a. Artificial Intelligence Features

The Platform uses AI to power its “Ask” features (staff, manager, and inspector question-answering) and to analyse and map policies. When these features are used, the question and the relevant extracts of the organisation’s own policies are sent to our AI sub-processors — Anthropic, and OpenAI for search embeddings — to generate a response or mapping. Both providers act as our sub-processors and do not use data submitted through their APIs to train their models. Answers are generated only from the organisation’s own policy content and are not a source of clinical advice.

  1. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements. Customer data processed on behalf of subscribers is retained in accordance with our contractual arrangements. Our summary retention schedule is available on request.

  1. Your Data Protection Rights

Under UK data protection law you have the right to access your personal data; request rectification or erasure; restrict or object to processing; data portability; withdraw consent at any time (where applicable); and lodge a complaint with the Information Commissioner’s Office (ICO). Requests can be made using the contact details below.

  1. Cookies and Similar Technologies

We use cookies in two categories:

  • Essential (strictly necessary) cookies keep you signed in, protect your session, manage inactivity time-outs, and support offline access. These do not require consent and are always active.
  • Analytics cookies — we use Google Analytics to understand how the Platform is used so we can improve it. These are non-essential and are set only after you consent via our cookie banner. If you select “Reject non-essential”, Google Analytics is not loaded.

You can accept or reject non-essential cookies using the banner shown on first use, and change your choice at any time by clearing the pn_cookie_consent cookie in your browser. Rejecting analytics cookies does not affect your ability to use the Platform.

  1. Payments

Payments and subscriptions are processed by Stripe (see section 6a). We do not receive or store full payment card details. Please refer to Stripe’s privacy policy for further information.

  1. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes are effective when published on our website or within the Platform. Where changes materially affect how we process personal data, we will provide reasonable notice.

  1. Contact Us

Email: admin@policynow.uk Company: Policy Now Ltd