Legal

Privacy Policy

Effective date: 13 July 2026 Version: 1.5 Data Controller: Ryburn Commercial Services Ltd

Data Controller: Ryburn Commercial Services Ltd (Company No. 13511979)
Registered Address: 2 Stones Drive, Ripponden, HX6 4NY
Contact: hello@notis.solutions

Ryburn Commercial Services Ltd ("we", "us", "our") operates the Notis platform at notis.solutions. This Privacy Policy explains how we collect, use, store, and protect personal data in connection with the Service where we act as a Data Controller. We are registered as a data controller under UK GDPR and the Data Protection Act 2018.

Where we process personal data on behalf of Subscribers as a Data Processor (for example, personal data contained within Contract Data such as project manager names and contact details), this is governed by our Data Processing Addendum available at notis.solutions/dpa.

1. What Data We Collect

1.1 Account Data

When you register for Notis, we collect:

1.2 Contract Data

When you use the Service, you may enter Contract Data which may include personal data relating to third parties such as project managers, employer representatives, and other named contacts. Our handling of such data as a Data Processor is governed by the Data Processing Addendum.

1.3 Usage Data

We automatically collect certain technical data via server logs and application telemetry for security, performance monitoring, and system administration purposes. This includes:

This data is collected at the server level and is used solely for operating and securing the Service.

Separately, our public marketing website (notis.solutions, excluding the authenticated Service itself) uses the following third-party tracking technologies:

Where these technologies rely on non-essential cookies or similar technologies, we will request your consent via a cookie banner before they are activated, in accordance with the Privacy and Electronic Communications Regulations (PECR). You can withdraw consent at any time using the "Cookie preferences" link in our website footer, or by contacting us at hello@notis.solutions.

The authenticated Notis application (i.e., once you are logged in and using the Service) does not use third-party advertising or analytics cookies beyond what is described above for the marketing site.

1.4 Support Communications

If you contact us for support or raise a support ticket, we collect the content of your communications and any attachments you provide.

2. How We Use Your Data

We use your personal data for the following purposes:

3. Legal Basis for Processing

We process your personal data on the following legal bases under UK GDPR:

4. AI Processing

Notis includes AI-assisted features for drafting notices and analysing compensation events. When you use these features, the content you submit is processed by Anthropic's Claude API.

Anthropic acts as our data processor in respect of this processing. Anthropic is bound by a data processing agreement with us and processes data solely on our instructions. Anthropic does not use data submitted via the API to train its AI models.

You should avoid entering special category personal data or confidential commercial information belonging to third parties beyond what is necessary to generate the relevant notice.

5. Third Party Processors

We use the following third party services to operate the platform. Each acts as a data processor under appropriate data processing agreements and is bound by confidentiality obligations. We do not sell your personal data to third parties.

Supabase (database and file storage) — Data location: UK (London)

Your Contract Data is stored in a Supabase PostgreSQL database hosted on Amazon Web Services in the EU West 2 (London) region. All data stored by Supabase remains within the UK. No international transfer occurs.

Clerk (authentication) — Data location: United States

User authentication, session management, and account security are managed by Clerk. Clerk stores your name, email address, and authentication credentials. Clerk's infrastructure is located in the United States. Transfers to the US are protected by the UK International Data Transfer Addendum (UK Addendum) to the EU Standard Contractual Clauses, as approved by the ICO. Note: Clerk processes account identity data only — your NEC4 contract documents and project data are not processed by Clerk and remain in the UK via Supabase.

Stripe (payment processing) — Data location: United States / EEA

Subscription billing and payment processing is managed by Stripe. We do not store payment card details — these are handled directly by Stripe. Stripe is PCI DSS compliant. Where Stripe's processing involves transfers outside the UK, such transfers are protected by the UK International Data Transfer Addendum or equivalent ICO-approved safeguards. Stripe processes billing data only — your contract data is not accessible to Stripe.

Anthropic (AI processing) — Data location: United States

AI-generated content is produced using Anthropic's Claude API. Content submitted for AI processing (event descriptions entered into the notice drafting wizards) is transmitted to Anthropic's servers in the United States. Anthropic acts as our data processor, does not use API data to train its models, and is bound by a data processing agreement. Transfers to the US are protected by the UK International Data Transfer Addendum (UK Addendum) to the EU Standard Contractual Clauses. Only the specific text you enter into AI drafting fields is transmitted — your stored contract data and documents are not sent to Anthropic.

Resend (transactional email) — Data location: United States

Deadline alert emails, account notifications, and support ticket confirmations are sent via Resend. Resend processes your email address and the content of transactional emails on our behalf under a data processing agreement. Transfers outside the UK are protected by appropriate safeguards including Standard Contractual Clauses.

PostHog (product and marketing analytics) — Data location: European Union

Our public marketing website uses PostHog to understand how visitors use the site and product, including aggregated usage analytics and session replay of marketing pages (with all form inputs masked so typed data such as your email is not recorded). PostHog data is hosted in PostHog's EU cloud (eu.i.posthog.com), so no transfer outside the UK/EEA occurs. PostHog acts as our data processor under a data processing agreement and does not use the data for its own purposes. These analytics cookies are non-essential and load only after you consent via our cookie banner (see Section 10). PostHog is not used to record any activity within the authenticated Service, and no data relating to your NEC4 contracts is processed by PostHog.

LinkedIn Insight Tag (advertising measurement) — Data location: United States / Ireland

Our public marketing website uses the LinkedIn Insight Tag to measure the effectiveness of our advertising and understand which channels bring visitors to our site. LinkedIn (LinkedIn Ireland Unlimited Company) processes this data in accordance with its own terms and privacy policy. This advertising cookie is non-essential and loads only after you consent via our cookie banner (see Section 10). Where LinkedIn's processing involves transfers outside the UK/EEA (including to the United States), such transfers are protected by the UK International Data Transfer Addendum or Standard Contractual Clauses. The LinkedIn Insight Tag operates only on our marketing website, not within the authenticated Service.

6. Data Retention

We retain your personal data for as long as your subscription is active and for a period of 90 days following termination, during which you may export your Contract Data. After 90 days, your data is securely deleted.

Server logs and technical data are retained for up to 12 months for security and system administration purposes. Billing records are retained for 7 years in accordance with HMRC requirements.

7. International Data Transfers

Some of our third party processors operate outside the UK. The table below summarises where each processor is located and the safeguard in place:

ProcessorLocationSafeguard
SupabaseUK (London, AWS eu-west-2)No international transfer
ClerkUnited StatesUK International Data Transfer Addendum (UK Addendum) to EU SCCs
StripeUnited States / EEAUK International Data Transfer Addendum or IDTA
AnthropicUnited StatesUK International Data Transfer Addendum (UK Addendum) to EU SCCs
ResendUnited StatesStandard Contractual Clauses / UK Addendum
PostHogEuropean UnionUK adequacy regulations (EU/EEA)
LinkedIn Insight TagUnited States / IrelandUK International Data Transfer Addendum / Standard Contractual Clauses

Your NEC4 contract documents, notices, and project data are stored exclusively in the UK via Supabase and are not transferred internationally. Only account identity data (Clerk), payment data (Stripe), AI drafting inputs (Anthropic), email addresses (Resend), and consent-based marketing-site analytics data (PostHog, LinkedIn Insight Tag) involve transfers outside the UK.

8. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

Note: The Service provides contract administration tools that require human review before any notice or communication is issued (as set out in our Terms of Service). We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects on individuals within the meaning of Article 22 of UK GDPR.

To exercise any of these rights, please contact us at hello@notis.solutions. We will respond within one calendar month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

9. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, disclosure, or destruction. These measures include encrypted data storage, secure HTTPS connections, access controls, and regular security reviews.

Despite these measures, no system is completely secure. You should use a strong password and keep your account credentials confidential. Notify us immediately at hello@notis.solutions if you suspect any unauthorised access to your account.

10. Cookies

The Service uses essential cookies required for authentication and session management. These cannot be disabled, as they are required for the Service to function.

Our public marketing website also uses non-essential cookies and tracking technologies for analytics (PostHog) and advertising measurement (LinkedIn Insight Tag), as described in Section 1.3. We request your consent for these via a cookie banner on your first visit, and you may withdraw consent at any time using the "Cookie preferences" link in our website footer.

We do not use third-party advertising or tracking cookies within the authenticated Service itself.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or via an in-app notification before they take effect. The current version will always be available at notis.solutions/privacy. Your continued use of the Service following notification of changes will signify that you have acknowledged the updated Policy. Where changes affect the legal basis on which we process your data, we will seek fresh consent where required by law.

12. Contact Us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at hello@notis.solutions.

Ryburn Commercial Services Ltd
2 Stones Drive, Ripponden, HX6 4NY
Company No. 13511979
hello@notis.solutions
Ryburn Commercial Services Ltd | Company No. 13511979 | 2 Stones Drive, Ripponden, HX6 4NY | hello@notis.solutions | Version 1.5 — 13 July 2026