Privacy Policy

Last updated: 22 July 2026

This Privacy Policy explains how CertMinder UK collects, uses, stores, and shares personal data when you use our website and services.

1. Who we are

CertMinder UK is operated by Rooted Networks Ltd, a company registered in England and Wales under company number 17338886. We are registered with the UK Information Commissioner's Office (ICO registration reference ZC179658).

If you have any questions about this Privacy Policy or how we use your data, please contact us by email at privacy@certminder.co.uk. Our registered office address is held on the public Companies House register.

2. What this policy covers

This policy applies when you:

  • visit our website;
  • create an account;
  • use our compliance tracking service;
  • upload or enter property or document information;
  • receive email, text, or phone reminders from us;
  • contact us for support.

3. What personal data we collect

Account and contact details: name; email address; phone number; business name; login details; account preferences.

Compliance and property data: property address; certificate details; expiry dates; compliance notes; reminder settings; document status; tenancy-related information.

Technical data: IP address; browser type; device information; user agent; log data; cookies and analytics information.

Communication data: messages sent to us; support requests; feedback; records of reminders sent by email, SMS, or phone.

Payment data: If you pay for our services, we may collect billing details and payment records. Payment card details are handled by our payment provider (Stripe) and are not stored by us directly.

4. Why we use your data

  • to create and manage your account;
  • to provide our tracking and reminder service;
  • to store and display compliance information you enter;
  • to send reminders and alerts;
  • to respond to support queries;
  • to improve our website and services;
  • to protect our platform from misuse or fraud;
  • to comply with legal obligations;
  • to manage billing, invoicing, and payments.

5. Lawful basis for processing

Under UK GDPR we must have a lawful basis to use your data. Depending on the data and purpose, we may rely on:

Contract — where we need the data to provide the CertMinder UK service you have requested (including sending the compliance reminders you have switched on).

Legitimate interests — to operate and secure the platform, send service reminders, improve our systems, prevent abuse or fraud, and keep records of use.

Legal obligation — where we need to keep records or comply with legal requirements.

Consent — where we rely on your consent for optional processing, such as marketing emails, optional promotional messages, and non-essential cookies. You can withdraw consent at any time where consent is the lawful basis.

6. Reminder messages

We may send you reminder messages by email, SMS/text, phone, and in-app notifications. These reminders are service notifications provided as part of the CertMinder UK service you have signed up for and switched on — they are not marketing. Our lawful basis is performance of our contract with you and our legitimate interest in providing the service.

If you use our free compliance risk score or join an early-access waiting list, we email you the result or update you asked for. We only send you tips, product news, or other marketing where you have ticked the optional consent box, and you can withdraw that consent or unsubscribe at any time using the link in every email.

Important: CertMinder UK does not guarantee that any reminder will be delivered, received, or acted on. You remain responsible for your own compliance obligations.

7. Sharing your data

We may share your personal data with: our hosting and database provider; our email and SMS providers; our payment processor; customer support tools; analytics providers; professional advisers; and regulators, courts, or law enforcement where required by law. We do not sell your personal data. Any third-party service providers must only process your data on our instructions and with appropriate safeguards.

8. International transfers

Some of our service providers may be located outside the UK. Where this happens, we will make sure appropriate safeguards are in place, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK addendum to the EU standard contractual clauses, or other lawful transfer safeguards.

9. How long we keep your data

We keep personal data only for as long as needed for the purposes we collected it for, including to meet legal, accounting, or reporting requirements. Typical retention: active account data while your account is open; billing records for the period required by law; support records for a reasonable period after the issue is resolved; log data for a limited period for security and troubleshooting; deleted account data removed or anonymised after a reasonable retention period, subject to legal exceptions. We may keep some data longer where needed for dispute resolution, fraud prevention, legal claims, or compliance with legal obligations.

10. Cookies

Our website uses cookies and similar technologies.

Essential cookies are needed for login, security, account functionality, and basic site operation.

Non-essential cookies may be used for analytics, performance monitoring, and marketing. Where required by law, we will ask for your consent before placing non-essential cookies.

11. Your rights

Under UK GDPR you may have the right to:

  • access your personal data;
  • correct inaccurate data;
  • erase your data in certain cases;
  • restrict processing in certain cases;
  • object to processing in certain cases;
  • data portability in certain cases; and
  • withdraw consent where consent is the lawful basis.

To exercise any of these rights, contact us at privacy@certminder.co.uk. You also have the right to complain to the Information Commissioner's Office (ICO) if you are unhappy with how we handle your data.

12. Security

We use appropriate technical and organisational measures to protect your data, including access controls, encryption, secure hosting, authentication measures, audit logging, backups, and staff access restrictions. However, no system is completely secure, and we cannot guarantee absolute security.

13. Children

CertMinder UK is not intended for children. We do not knowingly collect personal data from children under 18.

14. Automated decision-making

We do not use your personal data to make solely automated decisions that have legal or similarly significant effects on you. If we ever introduce such processing, we will update this policy and explain your rights.

15. Changes to this policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with a new "last updated" date.

16. Contact us

If you have questions about this Privacy Policy, contact Rooted Networks Ltd (company no. 17338886) by email at privacy@certminder.co.uk. Our registered office address is held on the public Companies House register.