PolicyMind

Privacy Notice

Last updated: 9 July 2026

1. Who we are

PolicyMind(“we”, “us”) is an AI-assisted governance and compliance policy platform for UK organisations, available at app.policy-mind.com. The Service is operated by PolicyMind Ltd, a company registered in England and Wales (company number 17321550) with its registered office at 30 Osprey Avenue, Chatham, England, ME5 7HY. You can contact us about anything in this notice at privacy@policy-mind.com.

This notice is provided under the UK GDPR and the Data Protection Act 2018. We operate in the UK and the Information Commissioner's Office (ICO) is our supervisory authority.

Controller and processor roles. For your account, billing, security, and usage data we are the data controller. For the content your organisation puts into PolicyMind — its company profile, uploaded documents, policies, and assistant conversations — your organisation decides why that data is processed, so it is the controller and we act as its processor, on the data processing terms in our Terms of Service.

2. The personal data we process

  • Account data — your name, email address, and password (stored only as an Argon2id hash; we never see or store the password itself). If you enable SMS notifications, your phone number.
  • Organisation & team data — your role, the organisation you belong to, and team invitations (including the email address an invite was sent to and who sent it).
  • Company profile — the business details your organisation enters to drive policy recommendations (for example company number, sector, workforce make-up, and what kinds of personal data your business handles).
  • Content you create or upload — policies and their version history, documents you upload for checking (we extract and keep the text, not the file), assessments, approvals and review comments, and policy acknowledgements.
  • Assistant conversations — the messages you exchange with the Compliance Assistant, and a working-memory profile of the priorities and decisions you state to it.
  • Usage & audit data — an audit log of significant actions, AI usage records (which features you ran and the tokens they used), session records, and short-lived rate-limiting counters that may include your IP address.
  • Billing data— your organisation's plan, subscription status, and billing interval. Card details are collected and held by Stripe; they never touch our servers.

3. Where the data comes from

Almost all of it comes directly from you or your organisation's team. Three exceptions:

  • An organisation admin may give us your email address to send you an invitation.
  • If you use the company lookup during onboarding, we fetch public company details from the Companies House register.
  • If you run a website or repository scan, we fetch the content of the site or repository you point us at, on your instruction.

4. Why we process it, and our lawful bases

  • To provide the service (accounts, organisations, policies, the assistant, billing) — performance of a contract.
  • To secure the service (authentication, audit logging, rate limiting, abuse prevention) — legitimate interests in keeping the platform and your data safe.
  • To send you service email (invites, password resets, billing and compliance alerts) — performance of a contract and legitimate interests. We do not send marketing email.
  • To send SMS notifications — only if you opt in: consent, which you can withdraw at any time in your notification settings.
  • To meet legal obligations (e.g. tax and accounting records) — legal obligation.

5. AI processing — what is sent where

PolicyMind's AI features are powered by Anthropic's Claude models via the Anthropic API. Nothing is sent to any AI provider passively — only when you run a feature:

  • Generate sends your company profile and policy requirements.
  • Check sends the text of the document you upload or paste.
  • Recommendations sends your company profile.
  • Assistant sends your chat messages, its working memory of your stated priorities, and relevant knowledge-base excerpts.
  • Scan sends the content of the website or repository you asked us to scan.

The outputs (drafted policies, findings, recommendations, conversation replies) are stored in your organisation's workspace. Under Anthropic's commercial API terms, data sent to the API is not used to train Anthropic's models.

No automated decisions with legal effect. AI outputs in PolicyMind are drafts and recommendations for your team to review; we make no solely automated decisions about you that have legal or similarly significant effects (UK GDPR Article 22).

6. Who we share it with (sub-processors)

We use a small number of processors to run the service, and we do not sell personal data. The current list:

  • Fly.io — application hosting and our managed Postgres database, in London (UK). All data at rest lives here.
  • Northbytes (UK) — manages our hosting infrastructure and deployments on our behalf.
  • Anthropic (US) — AI model provider, as described in section 5.
  • Stripe (US/global) — payments, subscriptions, and card handling.
  • Resend (US) — transactional email delivery (invites, password resets, alerts).
  • The SMS Works (UK) — SMS delivery, only if you opt in to SMS notifications.
  • Companies House (UK) — public register lookups, only if you use the company search.
  • GitHub (US) — repository access, only if you connect a repository for scanning. We do not store your GitHub access token.

If we add or replace a sub-processor we will update this page before the change takes effect.

7. International transfers

Your data is hosted in the UK (London). Some processors above (Anthropic, Stripe, Resend, GitHub) process data in the United States. Where that happens, we rely on appropriate safeguards under Chapter V of the UK GDPR — the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses — and UK adequacy regulations where they apply.

8. How long we keep it

We keep your personal data for as long as your account is active, with these specifics:

  • Sign-in sessions expire after 30 days of inactivity and are then purged.
  • Rate-limiting counters (which may include an IP address) are deleted within 24 hours.
  • Payment webhook records are deleted after 30 days.
  • Personal identifiers are automatically removed from audit-log entries older than 24 months; the anonymised trail is kept for accountability.

When you delete your account (or an owner deletes the organisation), we erase your personal data — including your assistant conversations and working memory — cancel any Stripe subscription, and strip your identifiers from retained audit records. Residual copies in encrypted database backups age out on the backup rotation schedule.

9. Your rights

Under the UK GDPR you have the right to:

  • Access a copy of your data and port it — download a full JSON export in-app under Settings → Data & privacy.
  • Eraseyour data (“right to be forgotten”) — delete your account in the same place, no email required.
  • Rectify inaccurate data — edit it in your profile and settings.
  • Restrict or object to processing based on legitimate interests.
  • Withdraw consent at any time where we rely on it (SMS notifications).

To exercise a right you can't complete in-app, email privacy@policy-mind.com. We respond within one month.

10. Cookies

PolicyMind sets a single cookie, policymind_session, which keeps you signed in. It is httpOnly, sent only over HTTPS in production, and lasts up to 30 days. It is strictly necessary for the service, so under the Privacy and Electronic Communications Regulations (PECR) it does not require consent. We use no analytics, advertising, or tracking cookies of any kind. Your browser's local storage holds only interface preferences (theme, sidebar state) that never leave your device. If any of this changes, we will ask for your consent first.

11. How we protect your data

We apply technical and organisational measures appropriate to the risk (UK GDPR Art. 32): encryption in transit, Argon2id password hashing, strict per-organisation access controls and tenant isolation, a Content Security Policy and related security headers, brute-force and rate-limit protection, audit logging, and automatic encrypted database backups in the UK.

12. Children

PolicyMindis a business tool and is not intended for, or directed at, anyone under 18. We do not knowingly process children's data.

13. Changes to this notice

If we make material changes we will update the date at the top and, where the change affects how we use your personal data, tell you by email or in-app notice before it takes effect.

14. Complaints

If you have a concern, please contact us first at privacy@policy-mind.com. You also have the right to complain to the ICO at ico.org.uk/make-a-complaint or 0303 123 1113.

Terms of Service · ← Back to PolicyMind