Privacy policy
Last updated 1 September 2026.
This Privacy Policy explains how Decised (“we”, “us”) processes personal data when you use our websites, accounts and related features (the “Service”). It is written for users in the United Kingdom and is intended to meet transparency requirements under UK GDPR and the Data Protection Act 2018.
1. Controller identity and contact
Controller. The controller of personal data processed for Decised accounts and related Service operation is the operator of Decised (trading as “Decised”).
- Privacy requests: [email protected]
- General support: [email protected]
Registered company name, company number and registered office will be stated on this page before Decised processes personal data of production users at scale. Until then, use the contacts above for all privacy enquiries.
2. Personal data we process
Account and identity
First name, last name, email address, hashed password, email-verification and password-reset challenge records (we store a one-way digest, not the raw emailed link), session records, and optional pending email-change details.
We use your name to operate and personalise your account, address transactional emails, and identify Workspace inviters and members. Email remains your unique sign-in identifier.
Service content you create
Saved reports, decision cases and alternatives, assumptions and ranges, evidence items, product feedback, uploads (for example CSV financials), and Workspace (Beta) membership and invitation records.
Technical and security data
IP address and user-agent as recorded in server logs; CSRF and session cookies; request identifiers; security and audit events (for example login, invite, export, deletion). Audit metadata is designed not to store assumption amounts.
What we do not intentionally collect
Special-category data, children’s data, payment card details, or non-essential marketing tracking. The Service is not directed at anyone under 18. Do not upload health, biometric or other special-category data.
3. Purposes and lawful bases
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Create and operate your account; save reports and cases | Contract (Art. 6(1)(b)) |
| Authentication, CSRF protection, abuse prevention, backups | Legitimate interests (Art. 6(1)(f)) — security and integrity |
| Email verification, password reset, email change | Contract; legitimate interests — account security |
| Workspaces (Beta) membership and invitations | Contract; legitimate interests — collaboration you requested |
| Optional product feedback you submit | Consent or legitimate interests — product improvement |
| Respond to support, legal claims, regulator requests | Legal obligation (Art. 6(1)(c)) and/or legitimate interests |
We do not use automated decision-making that produces legal or similarly significant effects about you (UK GDPR Art. 22). Financial and model outputs are tools for your own review, not credit or underwriting decisions by Decised.
4. Recipients and sharing
We may share personal data with:
- Subprocessors that host or operate parts of the Service — see Subprocessors.
- Public data providers when you run a signed-in search or report (for example Companies House, Nomis/ONS endpoints, police.uk, OpenStreetMap Overpass, news search). Query text needed to resolve a place or company may be sent to those providers.
- Workspace (Beta) members for content associated with a shared workspace, according to role.
- Professional advisers or authorities where required by law or to protect rights, safety or security.
We do not sell personal data.
5. International transfers
Primary account storage is intended to run in the United Kingdom or European Economic Area where practicable. Some public API calls and infrastructure providers may process data in other countries (including the United States). Where a transfer of personal data outside the UK requires a safeguard, we rely on an adequacy regulation or standard contractual clauses (or UK international data transfer addendum) with the relevant provider, as described in their documentation and our Data Processing Agreement for organisational customers.
6. Retention
See the Data retention notice. In summary: account content remains until you delete it or your account; deleting your account removes your first name, last name and other profile fields with the User record; security audit records may be kept in limited or anonymised form after deletion; public city snapshots are not personal data.
7. Cookies and similar technologies
We use essential authentication and security cookies. We do not currently set non-essential analytics or advertising cookies. Details are in the Cookie policy. A consent control will be introduced before any non-essential tracking.
8. Your rights
Under UK GDPR you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data in certain circumstances
- Restrict or object to certain processing
- Data portability for data you provided where processing is based on contract or consent
- Withdraw consent where processing is consent-based
- Complain to the Information Commissioner’s Office (ICO)
To exercise rights, email [email protected]. We may need to verify your identity. You can also delete your account from account settings where that feature is available.
9. Complaints to the ICO
If you are unhappy with how we handle your personal data, you can complain to the UK Information Commissioner’s Office:
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
We would appreciate the chance to resolve concerns first via [email protected].
10. Security
We use hashed passwords, HttpOnly session cookies, CSRF protection, and access controls between accounts and workspaces. No method of transmission or storage is perfectly secure. Report suspected vulnerabilities via Reporting abuse.
11. Changes
We may update this Policy by posting a revised version with a new “Last updated” date. Material changes will be highlighted on this page.