SureMatters

Privacy notice

Version 0.2 (draft) · Pending legal review

Who we are

SureMatters Ltd (“SureMatters”, “we”, “our”, “us”) publishes the SureRedact and SurePrepare products and operates the website at surematters.com. For the personal data described below, we are the data controller.

You can contact us at privacy@surematters.com with any data-protection question. We aim to respond substantively within 5 working days, and within 1 working day where you only need a clarification.

What this notice covers

This notice covers personal data we process about visitors to our website and our customers and prospective customers.

It does not cover the personal data processed by SureRedact and SurePrepare themselves when you run them. For that processing your own organisation is the controller, and our position is set out in the AI Policy and in the DPIA template we provide on request.

In short: this notice is about the data we collect from you when you visit our website or buy our software. It is not about the disclosure material your organisation works on using it.

What we collect, why, and our lawful basis

Website visitors

Data Purpose Lawful basis Retention
Truncated IP address (no full IP stored), page viewed, browser family, referrer Site analytics via Plausible Analytics — cookieless, EU-hosted, no fingerprinting Legitimate interests (Article 6(1)(f)) — running and improving our website Aggregate statistics only; no per-session identifier is retained
Email address and optional name, if you sign up to the newsletter Sending product news, launch announcements and blog summaries Consent (Article 6(1)(a)) — opt-in on the signup form Until you unsubscribe; an unsubscribe link is in every email
Email address, name, organisation, message, if you use the contact form Responding to your enquiry Legitimate interests (Article 6(1)(f)) 24 months from last contact; deleted on request
Pilot-enquiry form submissions (organisation, role, request-volume estimate, contact details) Qualifying and responding to pilot enquiries Legitimate interests (Article 6(1)(f)) 24 months from last contact; deleted on request

Customers

Data Purpose Lawful basis Retention
Account-holder name, email, organisation, billing address, VAT number Issuing licences, invoicing, and supporting your account Contract (Article 6(1)(b)); legal obligation for invoice records (Article 6(1)(c)) While the account is active, plus 7 years for HMRC compliance
Licence metadata (seats, term, entitlements) Operating your licence Contract (Article 6(1)(b)) While the account is active, plus 24 months for billing reconciliation
Operator names and email addresses, where licences are issued to named operators Issuing and managing per-operator licences Contract (Article 6(1)(b)) While the operator is part of your account

Licences are currently issued by hand. There is no self-service portal and no automated issuance pipeline, so this data is held in our accounting system and our internal business records — Xero and Google Workspace, both listed below — rather than in a product database. If you buy by card in future, payment details will be handled by Stripe and never held by us.

Telemetry

We do not currently operate a telemetry service, and none has ever been transmitted to us.

Where the products record operational information about how they are being used, it stays on your own machine, where you can see it and clear it. Nothing is sent to us, so nothing is stored by us and no sub-processor receives it.

If that changes, we will say so before it does, under “Changes to this notice” below. The framework that would apply is a four-class scheme — operational counts, transformed artefacts, masked exemplars, and raw content — under which raw content is never permitted and the second and third classes would require your explicit opt-in with a preview before anything left your machine. The unconditional off-switch applies whether or not we ever collect anything. The detail is in the Telemetry Transparency Document.

Support and account correspondence

Data Purpose Lawful basis Retention
Support tickets, email exchanges, and any attachments you choose to send us Resolving your request Legitimate interests (Article 6(1)(f)); contract (Article 6(1)(b)) for paying customers 24 months from last contact; deleted on request, unless we need it for an unresolved dispute

Where a reply has been drafted with AI assistance, a named person reviews it before it is sent, and we label it — see the AI Policy.

What we do not collect

Cookies and consent

There is no cookie banner because we do not set anything that needs your consent.

If we ever introduce something that does need consent — third-party advertising, or embedded media that sets cookies — we will add a clear accept-or-reject control, with rejecting as easy as accepting, and set nothing until you choose.

Sharing and sub-processors

We do not sell, rent or trade your personal data.

Sub-processors

These organisations process personal data on our behalf. The full list, with the transfer basis for each, is at surematters.com/subprocessors, which is the authoritative version.

Other recipients

We do not share your personal data with marketing or advertising networks.

International transfers

Most of the personal data covered by this notice is processed in the UK or the EEA, where the UK adequacy decision for the EEA is the transfer basis and no additional safeguards are needed.

Two sub-processors process data outside that area. Anthropic processes in the United States under Standard Contractual Clauses. Cloudflare serves static content from a global edge network under Standard Contractual Clauses and the UK International Data Transfer Addendum. Google Workspace is EU-primary with some sub-processing in the United States under Google’s published terms.

The transfer basis for each sub-processor is set out at surematters.com/subprocessors. We tell you if it materially changes.

Your rights

Under UK GDPR you have rights to access, rectify, erase, restrict, object to and port your personal data, and rights concerning automated decision-making. To exercise any of them, write to privacy@surematters.com.

We respond within one calendar month, extendable to three months for complex requests, and we tell you if we extend. Where we need you to clarify or narrow your request before we can find your data, the time we spend waiting for your answer does not count against that deadline — a change made by the Data (Use and Access) Act 2025.

Right of access (Article 15)

You can ask for a copy of the personal data we hold about you. We provide it in a commonly-used electronic format.

Right to rectification (Article 16)

You can ask us to correct data that is inaccurate or incomplete.

Right to erasure (Article 17)

You can ask us to delete your data where one of the Article 17 grounds applies. We keep what we must to meet legal obligations — invoice records for HMRC, for example — where Article 17(3) permits.

Right to restrict processing (Article 18)

You can ask us to restrict processing while we resolve a rectification or erasure request.

Right to object (Article 21)

You can object to processing we carry out on the basis of legitimate interests. We weigh your objection against those interests as described above.

Right to data portability (Article 20)

You can ask for your data in a structured, commonly-used, machine-readable format, where we process it by automated means on the basis of consent or contract.

Automated decision-making (Articles 22A–22D)

We do not make decisions about you by automated means alone that produce legal or similarly significant effects.

The Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR with new Articles 22A to 22D. You will still see “Article 22” cited in older notices; it is the provision that was replaced.

How our products handle automated suggestions to their operators is a separate question, and is covered in the AI Policy.

Right to complain

You can complain to the Information Commissioner’s Office at any time, and you do not have to raise it with us first — though we would rather have the chance to put it right. Their contact details are at ico.org.uk.

Security

We protect your data with appropriate technical and organisational measures, described more fully in our Security overview.

Changes to this notice

We update this notice when our processing changes. A material change — a new category of personal data, a new sub-processor, a new lawful basis, or a new international-transfer arrangement — is notified on our website within 10 working days, and by email to current customers where it affects them. Editorial changes are made in place and recorded here.

Change history

Date Version Change
2026-05-09 v0.1 Initial draft.
2026-08-12 v0.2 Correction and refresh. The telemetry section previously said we receive telemetry, with retention periods for each class. We do not operate a telemetry service and none has ever been transmitted to us; the section now says so. References to a customer portal, and to control-plane services we do not run, were removed. The customer section no longer treats customer data as something we will process in future — we process it now, by hand. Updated for the replacement of Article 22 by Articles 22A–22D, and for the change to how the response deadline is counted, both under the Data (Use and Access) Act 2025. Three links that pointed to pages that do not exist were corrected. Registered office added.

How to contact us

SureMatters Ltd, Ground Floor, 108–112 Main Road, Sundridge, Sevenoaks, TN14 6ES.

We aim to respond within 5 working days for substantive enquiries, and within 1 working day for clarifications. The DPIA template and the processor agreement are available on request from policy@surematters.com; neither is published.

Drafted with AI assistance and reviewed by a named person, per our AI Policy.