Decised

Legal

Privacy policy

Last updated 1 September 2026.

This Privacy Policy explains how Decised (“we”, “us”) processes personal data when you use our websites, accounts and related features (the “Service”). It is written for users in the United Kingdom and is intended to meet transparency requirements under UK GDPR and the Data Protection Act 2018.

1. Controller identity and contact

Controller. The controller of personal data processed for Decised accounts and related Service operation is the operator of Decised (trading as “Decised”).

Registered company name, company number and registered office will be stated on this page before Decised processes personal data of production users at scale. Until then, use the contacts above for all privacy enquiries.

2. Personal data we process

Account and identity

First name, last name, email address, hashed password, email-verification and password-reset challenge records (we store a one-way digest, not the raw emailed link), session records, and optional pending email-change details.

We use your name to operate and personalise your account, address transactional emails, and identify Workspace inviters and members. Email remains your unique sign-in identifier.

Service content you create

Saved reports, decision cases and alternatives, assumptions and ranges, evidence items, product feedback, uploads (for example CSV financials), and Workspace (Beta) membership and invitation records.

Technical and security data

IP address and user-agent as recorded in server logs; CSRF and session cookies; request identifiers; security and audit events (for example login, invite, export, deletion). Audit metadata is designed not to store assumption amounts.

What we do not intentionally collect

Special-category data, children’s data, payment card details, or non-essential marketing tracking. The Service is not directed at anyone under 18. Do not upload health, biometric or other special-category data.

3. Purposes and lawful bases

PurposeLawful basis (UK GDPR)
Create and operate your account; save reports and casesContract (Art. 6(1)(b))
Authentication, CSRF protection, abuse prevention, backupsLegitimate interests (Art. 6(1)(f)) — security and integrity
Email verification, password reset, email changeContract; legitimate interests — account security
Workspaces (Beta) membership and invitationsContract; legitimate interests — collaboration you requested
Optional product feedback you submitConsent or legitimate interests — product improvement
Respond to support, legal claims, regulator requestsLegal obligation (Art. 6(1)(c)) and/or legitimate interests

We do not use automated decision-making that produces legal or similarly significant effects about you (UK GDPR Art. 22). Financial and model outputs are tools for your own review, not credit or underwriting decisions by Decised.

4. Recipients and sharing

We may share personal data with:

  • Subprocessors that host or operate parts of the Service — see Subprocessors.
  • Public data providers when you run a signed-in search or report (for example Companies House, Nomis/ONS endpoints, police.uk, OpenStreetMap Overpass, news search). Query text needed to resolve a place or company may be sent to those providers.
  • Workspace (Beta) members for content associated with a shared workspace, according to role.
  • Professional advisers or authorities where required by law or to protect rights, safety or security.

We do not sell personal data.

5. International transfers

Primary account storage is intended to run in the United Kingdom or European Economic Area where practicable. Some public API calls and infrastructure providers may process data in other countries (including the United States). Where a transfer of personal data outside the UK requires a safeguard, we rely on an adequacy regulation or standard contractual clauses (or UK international data transfer addendum) with the relevant provider, as described in their documentation and our Data Processing Agreement for organisational customers.

6. Retention

See the Data retention notice. In summary: account content remains until you delete it or your account; deleting your account removes your first name, last name and other profile fields with the User record; security audit records may be kept in limited or anonymised form after deletion; public city snapshots are not personal data.

7. Cookies and similar technologies

We use essential authentication and security cookies. We do not currently set non-essential analytics or advertising cookies. Details are in the Cookie policy. A consent control will be introduced before any non-essential tracking.

8. Your rights

Under UK GDPR you may have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase data in certain circumstances
  • Restrict or object to certain processing
  • Data portability for data you provided where processing is based on contract or consent
  • Withdraw consent where processing is consent-based
  • Complain to the Information Commissioner’s Office (ICO)

To exercise rights, email [email protected]. We may need to verify your identity. You can also delete your account from account settings where that feature is available.

9. Complaints to the ICO

If you are unhappy with how we handle your personal data, you can complain to the UK Information Commissioner’s Office:

We would appreciate the chance to resolve concerns first via [email protected].

10. Security

We use hashed passwords, HttpOnly session cookies, CSRF protection, and access controls between accounts and workspaces. No method of transmission or storage is perfectly secure. Report suspected vulnerabilities via Reporting abuse.

11. Changes

We may update this Policy by posting a revised version with a new “Last updated” date. Material changes will be highlighted on this page.