Privacy policy
This page explains what personal data Audit Ready Solutions Limited collects when you visit audit-ready.care or use the AuditReady.care platform, how we use it, and the rights you have under UK data-protection law.
Last updated: 25 August 2026
1. Who we are
Audit Ready Solutions Limited ("we", "us", "our") is a company registered in the United Kingdom. We operate the website audit-ready.care and the SaaS platform AuditReady.care (the "Platform").
Contact for privacy matters: sales@audit-ready.org.
2. Our role
When you or your organisation use the Platform, we act as a data processor and your organisation is the data controller for any personal data you enter about your workers. When you visit our marketing site or book a demo, we act as a data controller for the personal data you give us in that flow.
3. What we collect on this website
- Contact details you provide — name, organisation, email, phone number, indication of your sponsored-worker headcount, and any free-text message — submitted through the “Book a demo” form. Our lawful basis is legitimate interests: you asked us to get in touch about our product.
- Basic access logs — IP address, browser type, page URL, referrer and timestamp, kept for a limited period for security and abuse-prevention purposes. Our lawful basis is legitimate interests in keeping the site secure.
- Analytics, but only if you agree — see the next section.
We do not use advertising cookies, retargeting pixels, or tag managers, and we do not sell or share your details with anyone for marketing purposes.
4. Cookies and analytics
The site sets no cookies at all until you tell us we may. When you first visit, a banner asks whether you are happy for us to use analytics cookies. Nothing is loaded while that question is unanswered, and choosing Decline means no analytics code runs on your visit at all — we do not simply load it and switch it off.
Your answer is stored in your browser’s local storage, not in a cookie, purely so we do not ask you again on every page. You can change your mind at any time using the Cookie settings link in the footer of any page. Declining after previously accepting also removes the analytics cookies already set.
Separately, if you reach us through a partner’s referral link, we note that partner’s code for the rest of your visit so we can credit the introduction. It is held only until you close the tab, is never shared with anyone, and is not used to track you across other sites. It is not a cookie and does not depend on the choice above.
If you accept, we use Google Analytics 4 to understand which pages people find useful. It sets cookies named _ga and _ga_<id> that last up to two years, and records the pages you view, roughly where in the world you are, your device and browser type, and how you arrived at the site. IP addresses are anonymised, and we have not enabled Google’s advertising or cross-device features. We keep this data for 14 months. Our lawful basis is your consent, which you can withdraw at any time.
Google acts as our processor for this data and may transfer it outside the UK under its standard contractual clauses. You can read Google’s privacy policy for more detail, or install Google’s opt-out browser add-on to block it across every site you visit.
None of this applies to the AuditReady.care platform itself. Once you sign in, the only cookies used are the strictly necessary ones that keep you logged in and keep the service secure. There is no analytics or advertising tracking inside the platform.
5. What the Platform collects
The Platform is a compliance tool for UK sponsor-licence holders. The kinds of personal data your organisation enters into it include:
- Worker details (name, contact details, address, nationality, passport / eVisa reference).
- Sponsorship details (Certificate of Sponsorship number, SOC code, salary, weekly hours, start / end dates).
- Compliance documents (right-to-work check, DBS / PVG, qualifications, references, employment contract).
- Absence records and reportable-event notes.
- Account credentials for your users (email address, hashed password, second-factor authenticator record).
The data your organisation enters is stored under your organisation’s tenant and is not visible to any other tenant.
6. Why we process it
- To provide the Platform to your organisation under the terms of the service agreement (contract).
- To respond to demo requests and account queries you submit through the website (legitimate interests).
- To send account-related emails such as invitations, password resets, security alerts and audit notifications (contract).
- To detect, investigate and prevent misuse of the Platform (legitimate interests).
7. Legal basis
We rely on Article 6(1)(b) UK GDPR (performance of a contract) for account and Platform operation, Article 6(1)(f) (legitimate interests) for website security and legitimate marketing responses to enquiries you initiate, and Article 6(1)(c) where we need to comply with a legal obligation. For analytics cookies on the marketing site we rely on Article 6(1)(a)(consent), which you give or refuse through the cookie banner and can change at any time.
8. Where your data is stored
All personal data is stored in the United Kingdom (Supabase Postgres, London eu-west-2 region). Backups are stored in the same region. We do not transfer personal data outside the UK / EU.
9. How long we keep it
- Website enquiries — 24 months from the last contact, unless you become a customer.
- Customer account data — for the duration of the service agreement plus 12 months, then deleted. Longer periods may apply where required by law (e.g. Home Office retention obligations that the controller must satisfy).
- Access logs — 90 days.
10. Sharing your data
We share personal data only with the sub-processors listed on our Security page, all of which are covered by written data-protection terms with us:
- Supabase (database, authentication and file storage; London, UK).
- Vercel (Next.js hosting and edge network; UK / EU).
- Brevo (transactional email delivery).
- Cloudflare (DNS and DDoS protection).
- Google Analytics (website analytics on the marketing site only, and only where you have accepted cookies).
We do not sell, rent or trade personal data to any third party.
11. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate personal data corrected.
- Request deletion of personal data where we no longer need it.
- Restrict or object to processing based on legitimate interests.
- Receive a copy of personal data in a portable format.
- Complain to the Information Commissioner’s Office (ICO).
To exercise any of these, email sales@audit-ready.org. Where you are a Platform user, some of these rights may need to be exercised through your organisation, which is the controller of that data.
12. Security
The technical and organisational security controls in place are described on our Security page. In brief: TLS in transit, encrypted Postgres at rest, mandatory two-factor authentication for admin users, database-level tenant isolation, automatic session timeout, immutable audit log, and UK / EU-only hosting.
13. Changes to this policy
We may update this policy from time to time. Material changes will be notified to Platform Account Owners by email.