Privacy notice
Last updated: 1 September 2026
Who we are
Kept provides compliance software to businesses in the United Kingdom. We are the data controller for the personal data described in this notice. Contact us at privacy@keptcompliant.co.uk.
What we collect
- Account details: name, work email address and password credentials.
- Company details: organisation name, headcount and certification dates.
- Compliance records: the cloud services you list, their multi-factor status, generated policies and evidence snapshots.
- Billing details, processed by our payment provider. We do not store card numbers.
- Basic technical logs needed to keep the service secure and available.
Why we use it
We process this data to deliver the service you have asked for (performance of a contract), to keep the service secure, and to meet our legal obligations. Where we send marketing email, we rely on your consent and you may withdraw it at any time.
How long we keep it
Compliance records are retained while your account is active and for 12 months afterwards, so you can retrieve evidence for a previous certification cycle. You may ask us to delete them sooner.
Your rights
Under UK GDPR you may request access to your data, correction, deletion, restriction or portability, and you may object to certain processing. You also have the right to complain to the Information Commissioner's Office.
Sharing
We share data only with the suppliers needed to run the service, such as our hosting and payment providers, under written data processing terms. We do not sell personal data.