Privacy Policy
This notice explains how UKGovscan uses personal data when you create an account, take out a subscription, contact us, or use account features such as lists, alerts and Ask-AI. If you appear in the public records we publish and do not have an account, your notice is How we use public-record information.
On this page
1. Who we are
UKGovscan is operated by Elenchos Ltd, a company registered in England and Wales. Elenchos Ltd is responsible for the processing described in this notice.
Registered with the Information Commissioner’s Office, reference ZC251505.
Privacy enquiries and data requests: [email protected]. Our registered number and office are in our terms.
2. The information we collect
We hold your name and email address and the identifiers needed to sign you in; your saved lists, notes, alert rules and the notifications we have generated; your notification preferences and, if you link one, your Telegram chat identifier; your plan, subscription status and a Stripe customer reference; the questions you put to Ask-AI and the database queries generated from them; whether each email we sent you was delivered; what you send us when you get in touch and our reply, including a data request or a complaint; a record of sensitive actions our administrators take on an account, such as a refund, a suspension or a deletion you asked for; when your account was last active and whether it is suspended; and technical data, namely your IP address, held in memory to apply rate limits, and server logs kept for a limited period.
Payment is handled by Stripe. We do not receive or store card numbers.
An email address is necessary to hold an account: without one we cannot provide the service. Everything else is collected only when you use the feature it belongs to.
If you use UKGovscan without signing in, we do not build a profile of you. Your IP address is still processed briefly for rate limiting, and our cookieless analytics counts page views in aggregate. Section 9 lists everything stored on your device.
We keep the words typed into the search box, with the date and the number of results, so we can see what people look for and what the site fails to find. These records carry nothing that identifies you or your account, whether or not you are signed in, and they are deleted after 90 days.
3. How and why we use it
UK data protection law requires a lawful basis for each way we use personal data.
| What we use your information for | Lawful basis |
|---|---|
| Providing your account and its features, including lists, alerts and notifications | Necessary to perform our contract with you, under Article 6(1)(b) |
| Managing subscriptions and taking payment | Necessary to perform our contract with you, under Article 6(1)(b). Legal obligations for tax and accounting records, under Article 6(1)(c) |
| Sending the alerts you have chosen, by email or Telegram, and recording whether email was delivered | Necessary to provide the service you asked for, under Article 6(1)(b). You can switch alerts off at any time |
| Answering Ask-AI questions (section 4) | Necessary to provide a feature you chose to use, under Article 6(1)(b) |
| Applying plan limits and preventing misuse of Ask-AI and other features | Our legitimate interests in enforcing account limits and preventing abuse, under Article 6(1)(f) |
| Improving search: which terms people use, and which return nothing | Our legitimate interests in making the service find what people are looking for, under Article 6(1)(f) |
| Keeping the service secure: rate limiting, security logging, administrative audit records | Our legitimate interests in protecting the service and its users, under Article 6(1)(f) |
| Answering enquiries and providing support | Our legitimate interests in operating the service and helping its users, under Article 6(1)(f), or Article 6(1)(b) where the enquiry concerns our contract with you. Authorised people can view your account to fix a problem, and each such action is recorded |
| Handling privacy requests and complaints | Compliance with our legal obligations, under Article 6(1)(c), together with our legitimate interests in keeping a record of how a request was handled, under Article 6(1)(f) |
| Complying with the law, court orders and lawful requests from authorities | Compliance with a legal obligation, under Article 6(1)(c) |
We do not use your information for advertising, and we do not make solely automated decisions about you that produce legal or similarly significant effects.
4. Ask-AI
When you use Ask-AI, your question is turned into a database query and the result is turned back into an answer.
The question you type is sent to Anthropic, which provides the AI service behind this feature, along with the results the query returned so that an answer can be written from them. Nothing else about you goes with it: not your name, your email address, your lists or your notes.
Ask-AI reads the database through a separate account that can only read, and cannot change or delete anything.
We keep the record described in section 2 so the feature works, so plan limits can be applied, and so failures can be investigated. Investigating a failure means a member of our team can read the question that caused it, so please do not type anything into Ask-AI you would not want read. Whenever someone on our team opens that record we log who they were and what they looked at.
Your question and the query it produced are erased 90 days after you asked, as set out in section 7. Deleting your account erases them straight away.
5. Public-record information
Separately from your account, UKGovscan publishes information about people that forms part of the public record: Companies House, the Parliamentary registers of interests, the Electoral Commission, the Charity Commission and its Scottish and Northern Irish counterparts, individual councils, and government procurement and spending releases.
We process it under legitimate interests, Article 6(1)(f): the public interest in the scrutiny of public office, public money and political influence. A legitimate interests assessment has been recorded and is available on request.
Because the considerations are different from those that apply to an account holder, that information has its own notice: How we use public-record information. It covers the sources, the processing, the retention and the rights of the people in those records.
7. How long we keep it
| Information | How long we keep it |
|---|---|
| Account and workspace | While your account is open. Deleting your account erases it, including your Ask-AI history, and we instruct our sign-in and payment providers to do the same. |
| Ask-AI questions | The question you typed and the database query it produced are erased 90 days after you asked. The usage record behind it, which is a count of queries and tokens with no question text, is kept for 24 months so plan limits and billing can be checked. Deleting your account erases both straight away. |
| Billing and financial records | Stripe retains transaction, tax and regulatory records for as long as the law requires it to, and for its own purposes where it acts as a controller in its own right. WorkOS retains what it needs to operate authentication. |
| Email delivery records | While they are needed to keep alerts reaching you, and to stop us emailing addresses that reject mail. |
| Support, requests and complaints | While the matter is open, and afterwards for as long as we need a record of how it was handled. |
| Administrative audit records | Kept after an account is deleted, because they exist to show what a person acting for us did, and for no longer than that purpose requires. They hold the action, the date and the account’s email address. |
| Technical | IP addresses used for rate limiting are held in memory for a rolling window of about a minute, and are never written to our database. Server logs are kept for a limited period. |
| Public-record data | While it serves the purpose in section 5, and while its official source continues to publish it. A record withdrawn at source is marked withdrawn. |
Deleting your account removes the account information we no longer need. It does not remove what we, or another controller such as Stripe, are required to keep.
8. International transfers
Our servers are in Germany.
Several of the providers in section 6, and companies they in turn rely on, process data in the United States or elsewhere outside the UK. Where a country is named there it is where the processing we know about happens; it is not a representation that no affiliate or supplier of theirs is anywhere else.
Where UK law treats that as a restricted transfer, we use an appropriate transfer mechanism: the UK’s adequacy regulations, the UK Extension to the EU–US Data Privacy Framework (the UK–US Data Bridge) where the recipient is certified under it, or the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, with a transfer risk assessment where one is required.
You can ask us at [email protected] for the safeguards used for a particular transfer.
9. Cookies and what we store on your device
The law treats anything stored on or read from your device the same way it treats cookies. This is all of it.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| wos-session | Cookie (necessary) | Keeps you signed in. Set by WorkOS, our sign-in provider, only when you sign in, and removed when you sign out. | Up to 400 days, refreshed as you use the site |
| wos-auth-verifier-… | Cookie (necessary) | Protects the sign-in exchange. Set by WorkOS when sign-in starts and cleared when it completes. One is set per attempt, so opening sign-in in more than one tab can leave several at once; the oldest are removed automatically. | About 10 minutes |
| wos-callback-restart | Cookie (necessary) | Set only when sign-in returns without the security token it expects, so the attempt restarts once rather than looping. It records nothing about you. | 2 minutes |
| ukgs_intent | Cookie (necessary) | Set when you save or track something before signing in, so it is done once you have. Sent only to the page that finishes it. | 24 hours |
| ukgs-theme | Local storage (preferences) | Your light or dark theme choice. | Until you clear it |
| ukgs-fav-lists | Local storage (preferences) | Which of your lists are pinned to your dashboard. | Until you clear it |
| uks:recent-searches | Local storage (preferences) | Your recent searches, shown when the search box is empty. | Until you clear it |
| umami.disabled | Local storage (preferences) | Records that you have turned analytics off on this device. | Until you clear it |
| ask-ai:thread | Session storage (necessary) | Your recent Ask-AI questions and answers, so returning to the page restores them. | Until you close the tab |
| cp:… and acc-fetch:… | Session storage (necessary) | A company profile you have already loaded, so returning to it does not fetch it again. | Until you close the tab |
Local and session storage stay in your browser and are not sent to us. You can clear or block any of it in your browser settings. Blocking the session cookie signs you out.
Analytics
We count page views using Umami, which runs on our own server. It sets no cookie, stores no identifier on your device, and cannot track you across other websites. It records the page viewed, the site that linked to it, and your browser language, screen size and country.
You can object at any time. This applies to the device and browser you are using.
Analytics is on for this device.
10. Your rights
Depending on the circumstances and the basis we rely on, you have the right to:
- Access. A copy of the personal data we hold about you.
- Rectification. Correction of inaccurate or incomplete data.
- Erasure. Deletion of your data, in certain circumstances.
- Restriction. Ask us to pause our use of your data, in certain circumstances.
- Object. Object to processing based on legitimate interests.
- Portability. Data you gave us, in a portable format. This covers account data processed under our contract with you, not the public-record database.
- Withdraw consent. Where consent is the basis we rely on.
- Complain. To us, and to the ICO. See section 11.
You can delete your account at any time from Profile & privacy. For anything else, email [email protected]. An access request returns everything we hold, including your notes, your Ask-AI history and our record of emails we sent you; the records held by WorkOS and Stripe, and our administrative audit trail, come on request too. The same route covers public-record data.
We respond within one month of receiving a request. Where a request is complex, or where you have made several, the law allows more time; if that applies we will tell you within the first month and explain why.
We may ask for what is reasonably necessary to confirm your identity, or your authority to act for someone else, before we act on a request. We will not ask for more than the request requires.
No fee is charged. Article 12(5) of the UK GDPR permits a reasonable fee, or a refusal, where a request is manifestly unfounded or excessive, or where further copies are requested. If we rely on that, we will say why and how to challenge it.
11. Complaints
Section 164A of the Data Protection Act 2018 gives you the right to complain to us about our processing of your personal data. You can complain by emailing [email protected].
We will acknowledge receipt of your complaint within 30 days. Without undue delay, we will then take appropriate steps to respond to it and tell you the outcome.
You can complain at any time to the Information Commissioner’s Office, the UK’s data protection regulator, at ico.org.uk/make-a-complaint. The ICO recommends giving us an opportunity to complete our complaints process first.
12. Changes to this notice
We may update this notice, including where our service, our providers or our legal obligations change. The current version and its effective date are always at ukgovscan.com/privacy.
Where a change materially affects how we use account holders’ personal data, we will email them before it takes effect.