Data Controller: Ryburn Commercial Services Ltd (Company No. 13511979)
Registered Address: 2 Stones Drive, Ripponden, HX6 4NY
Contact: hello@notis.solutions
Ryburn Commercial Services Ltd ("we", "us", "our") operates the Notis platform at notis.solutions. This Privacy Policy explains how we collect, use, store, and protect personal data in connection with the Service where we act as a Data Controller. We are registered as a data controller under UK GDPR and the Data Protection Act 2018.
Where we process personal data on behalf of Subscribers as a Data Processor (for example, personal data contained within Contract Data such as project manager names and contact details), this is governed by our Data Processing Addendum available at notis.solutions/dpa.
1. What Data We Collect
1.1 Account Data
When you register for Notis, we collect:
- Your name and email address
- Your organisation name
- Authentication data (managed by Clerk — see Section 5)
- Billing information (managed by Stripe — see Section 5)
1.2 Contract Data
When you use the Service, you may enter Contract Data which may include personal data relating to third parties such as project managers, employer representatives, and other named contacts. Our handling of such data as a Data Processor is governed by the Data Processing Addendum.
1.3 Usage Data
We automatically collect certain technical data via server logs and application telemetry for security, performance monitoring, and system administration purposes. This includes:
- IP address and browser type
- Pages visited and features used within the Service
- Session duration and login timestamps
- Error logs and performance data
This data is collected at the server level and is used solely for operating and securing the Service.
Separately, our public marketing website (notis.solutions, excluding the authenticated Service itself) uses the following third-party tracking technologies:
- PostHog — to understand how visitors use our marketing site and product, and to improve the Service. See Section 5 for details of PostHog as a processor.
- LinkedIn Insight Tag — to measure the effectiveness of our advertising and understand which channels bring visitors to our site.
Where these technologies rely on non-essential cookies or similar technologies, we will request your consent via a cookie banner before they are activated, in accordance with the Privacy and Electronic Communications Regulations (PECR). You can withdraw consent at any time using the "Cookie preferences" link in our website footer, or by contacting us at hello@notis.solutions.
The authenticated Notis application (i.e., once you are logged in and using the Service) does not use third-party advertising or analytics cookies beyond what is described above for the marketing site.
1.4 Support Communications
If you contact us for support or raise a support ticket, we collect the content of your communications and any attachments you provide.
2. How We Use Your Data
We use your personal data for the following purposes:
- Providing and operating the Service — including storing your contract data, generating notices, and sending deadline alerts
- Account management — creating and maintaining your account, processing authentication, and managing your subscription
- Billing — processing subscription payments and managing invoicing via Stripe
- Service communications — sending deadline alerts, product updates, and important notices by email via Resend
- Support — responding to support requests and troubleshooting issues
- Security and system administration — detecting and preventing fraud, abuse, and unauthorised access; monitoring system performance and stability
- Legal compliance — complying with applicable laws and regulations
- Service improvement — analysing aggregated, anonymised usage patterns to improve the Service
3. Legal Basis for Processing
We process your personal data on the following legal bases under UK GDPR:
- Contract performance — processing necessary to provide the Service under your subscription agreement (Article 6(1)(b))
- Legitimate interests — processing necessary for our legitimate business interests including security, fraud prevention, system administration, and service improvement, where these interests are not overridden by your rights (Article 6(1)(f))
- Legal obligation — processing necessary to comply with applicable law (Article 6(1)(c))
- Consent — where you have given specific consent, for example for non-essential communications (Article 6(1)(a))
4. AI Processing
Notis includes AI-assisted features for drafting notices and analysing compensation events. When you use these features, the content you submit is processed by Anthropic's Claude API.
Anthropic acts as our data processor in respect of this processing. Anthropic is bound by a data processing agreement with us and processes data solely on our instructions. Anthropic does not use data submitted via the API to train its AI models.
You should avoid entering special category personal data or confidential commercial information belonging to third parties beyond what is necessary to generate the relevant notice.
5. Third Party Processors
We use the following third party services to operate the platform. Each acts as a data processor under appropriate data processing agreements and is bound by confidentiality obligations. We do not sell your personal data to third parties.
Supabase (database and file storage) — Data location: UK (London)
Your Contract Data is stored in a Supabase PostgreSQL database hosted on Amazon Web Services in the EU West 2 (London) region. All data stored by Supabase remains within the UK. No international transfer occurs.
Clerk (authentication) — Data location: United States
User authentication, session management, and account security are managed by Clerk. Clerk stores your name, email address, and authentication credentials. Clerk's infrastructure is located in the United States. Transfers to the US are protected by the UK International Data Transfer Addendum (UK Addendum) to the EU Standard Contractual Clauses, as approved by the ICO. Note: Clerk processes account identity data only — your NEC4 contract documents and project data are not processed by Clerk and remain in the UK via Supabase.
Stripe (payment processing) — Data location: United States / EEA
Subscription billing and payment processing is managed by Stripe. We do not store payment card details — these are handled directly by Stripe. Stripe is PCI DSS compliant. Where Stripe's processing involves transfers outside the UK, such transfers are protected by the UK International Data Transfer Addendum or equivalent ICO-approved safeguards. Stripe processes billing data only — your contract data is not accessible to Stripe.
Anthropic (AI processing) — Data location: United States
AI-generated content is produced using Anthropic's Claude API. Content submitted for AI processing (event descriptions entered into the notice drafting wizards) is transmitted to Anthropic's servers in the United States. Anthropic acts as our data processor, does not use API data to train its models, and is bound by a data processing agreement. Transfers to the US are protected by the UK International Data Transfer Addendum (UK Addendum) to the EU Standard Contractual Clauses. Only the specific text you enter into AI drafting fields is transmitted — your stored contract data and documents are not sent to Anthropic.
Resend (transactional email) — Data location: United States
Deadline alert emails, account notifications, and support ticket confirmations are sent via Resend. Resend processes your email address and the content of transactional emails on our behalf under a data processing agreement. Transfers outside the UK are protected by appropriate safeguards including Standard Contractual Clauses.
PostHog (product and marketing analytics) — Data location: European Union
Our public marketing website uses PostHog to understand how visitors use the site and product, including aggregated usage analytics and session replay of marketing pages (with all form inputs masked so typed data such as your email is not recorded). PostHog data is hosted in PostHog's EU cloud (eu.i.posthog.com), so no transfer outside the UK/EEA occurs. PostHog acts as our data processor under a data processing agreement and does not use the data for its own purposes. These analytics cookies are non-essential and load only after you consent via our cookie banner (see Section 10). PostHog is not used to record any activity within the authenticated Service, and no data relating to your NEC4 contracts is processed by PostHog.
LinkedIn Insight Tag (advertising measurement) — Data location: United States / Ireland
Our public marketing website uses the LinkedIn Insight Tag to measure the effectiveness of our advertising and understand which channels bring visitors to our site. LinkedIn (LinkedIn Ireland Unlimited Company) processes this data in accordance with its own terms and privacy policy. This advertising cookie is non-essential and loads only after you consent via our cookie banner (see Section 10). Where LinkedIn's processing involves transfers outside the UK/EEA (including to the United States), such transfers are protected by the UK International Data Transfer Addendum or Standard Contractual Clauses. The LinkedIn Insight Tag operates only on our marketing website, not within the authenticated Service.
6. Data Retention
We retain your personal data for as long as your subscription is active and for a period of 90 days following termination, during which you may export your Contract Data. After 90 days, your data is securely deleted.
Server logs and technical data are retained for up to 12 months for security and system administration purposes. Billing records are retained for 7 years in accordance with HMRC requirements.
7. International Data Transfers
Some of our third party processors operate outside the UK. The table below summarises where each processor is located and the safeguard in place:
| Processor | Location | Safeguard |
|---|---|---|
| Supabase | UK (London, AWS eu-west-2) | No international transfer |
| Clerk | United States | UK International Data Transfer Addendum (UK Addendum) to EU SCCs |
| Stripe | United States / EEA | UK International Data Transfer Addendum or IDTA |
| Anthropic | United States | UK International Data Transfer Addendum (UK Addendum) to EU SCCs |
| Resend | United States | Standard Contractual Clauses / UK Addendum |
| PostHog | European Union | UK adequacy regulations (EU/EEA) |
| LinkedIn Insight Tag | United States / Ireland | UK International Data Transfer Addendum / Standard Contractual Clauses |
Your NEC4 contract documents, notices, and project data are stored exclusively in the UK via Supabase and are not transferred internationally. Only account identity data (Clerk), payment data (Stripe), AI drafting inputs (Anthropic), email addresses (Resend), and consent-based marketing-site analytics data (PostHog, LinkedIn Insight Tag) involve transfers outside the UK.
8. Your Rights
Under UK GDPR, you have the following rights in relation to your personal data:
- Right of access — you may request a copy of the personal data we hold about you
- Right to rectification — you may ask us to correct inaccurate personal data
- Right to erasure — you may ask us to delete your personal data in certain circumstances
- Right to restriction — you may ask us to restrict processing of your personal data
- Right to data portability — you may request your data in a machine-readable format
- Right to object — you may object to processing based on legitimate interests
- Rights relating to automated decision-making — you have rights in relation to decisions made solely by automated means
Note: The Service provides contract administration tools that require human review before any notice or communication is issued (as set out in our Terms of Service). We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects on individuals within the meaning of Article 22 of UK GDPR.
To exercise any of these rights, please contact us at hello@notis.solutions. We will respond within one calendar month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
9. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, disclosure, or destruction. These measures include encrypted data storage, secure HTTPS connections, access controls, and regular security reviews.
Despite these measures, no system is completely secure. You should use a strong password and keep your account credentials confidential. Notify us immediately at hello@notis.solutions if you suspect any unauthorised access to your account.
10. Cookies
The Service uses essential cookies required for authentication and session management. These cannot be disabled, as they are required for the Service to function.
Our public marketing website also uses non-essential cookies and tracking technologies for analytics (PostHog) and advertising measurement (LinkedIn Insight Tag), as described in Section 1.3. We request your consent for these via a cookie banner on your first visit, and you may withdraw consent at any time using the "Cookie preferences" link in our website footer.
We do not use third-party advertising or tracking cookies within the authenticated Service itself.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or via an in-app notification before they take effect. The current version will always be available at notis.solutions/privacy. Your continued use of the Service following notification of changes will signify that you have acknowledged the updated Policy. Where changes affect the legal basis on which we process your data, we will seek fresh consent where required by law.
12. Contact Us
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at hello@notis.solutions.
2 Stones Drive, Ripponden, HX6 4NY
Company No. 13511979
hello@notis.solutions