Privacy policy
This page explains what personal data Audit Ready Solutions Limited collects when you visit audit-ready.care or use the AuditReady.care platform, how we use it, and the rights you have under UK data-protection law.
Last updated: 21 August 2026
1. Who we are
Audit Ready Solutions Limited ("we", "us", "our") is a company registered in the United Kingdom. We operate the website audit-ready.care and the SaaS platform AuditReady.care (the "Platform").
Contact for privacy matters: sales@audit-ready.org.
2. Our role
When you or your organisation use the Platform, we act as a data processor and your organisation is the data controller for any personal data you enter about your workers. When you visit our marketing site or book a demo, we act as a data controller for the personal data you give us in that flow.
3. What we collect on this website
- Contact details you provide — name, organisation, email, phone number, indication of your sponsored-worker headcount, and any free-text message — submitted through the "Book a demo" form.
- Basic access logs — IP address, browser type, page URL, referrer and timestamp, kept for a limited period for security and abuse-prevention purposes.
- We do not use analytics cookies, advertising trackers, or third-party tag managers on the marketing site.
4. What the Platform collects
The Platform is a compliance tool for UK sponsor-licence holders. The kinds of personal data your organisation enters into it include:
- Worker details (name, contact details, address, nationality, passport / eVisa reference).
- Sponsorship details (Certificate of Sponsorship number, SOC code, salary, weekly hours, start / end dates).
- Compliance documents (right-to-work check, DBS / PVG, qualifications, references, employment contract).
- Absence records and reportable-event notes.
- Account credentials for your users (email address, hashed password, second-factor authenticator record).
The data your organisation enters is stored under your organisation’s tenant and is not visible to any other tenant.
5. Why we process it
- To provide the Platform to your organisation under the terms of the service agreement (contract).
- To respond to demo requests and account queries you submit through the website (legitimate interests).
- To send account-related emails such as invitations, password resets, security alerts and audit notifications (contract).
- To detect, investigate and prevent misuse of the Platform (legitimate interests).
6. Legal basis
We rely on Article 6(1)(b) UK GDPR (performance of a contract) for account and Platform operation, Article 6(1)(f) (legitimate interests) for website security and legitimate marketing responses to enquiries you initiate, and Article 6(1)(c) where we need to comply with a legal obligation.
7. Where your data is stored
All personal data is stored in the United Kingdom (Supabase Postgres, London eu-west-2 region). Backups are stored in the same region. We do not transfer personal data outside the UK / EU.
8. How long we keep it
- Website enquiries — 24 months from the last contact, unless you become a customer.
- Customer account data — for the duration of the service agreement plus 12 months, then deleted. Longer periods may apply where required by law (e.g. Home Office retention obligations that the controller must satisfy).
- Access logs — 90 days.
9. Sharing your data
We share personal data only with the sub-processors listed on our Security page, all of which are covered by written data-protection terms with us:
- Supabase (database, authentication and file storage; London, UK).
- Vercel (Next.js hosting and edge network; UK / EU).
- Brevo (transactional email delivery).
- Cloudflare (DNS and DDoS protection).
We do not sell, rent or trade personal data to any third party.
10. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate personal data corrected.
- Request deletion of personal data where we no longer need it.
- Restrict or object to processing based on legitimate interests.
- Receive a copy of personal data in a portable format.
- Complain to the Information Commissioner’s Office (ICO).
To exercise any of these, email sales@audit-ready.org. Where you are a Platform user, some of these rights may need to be exercised through your organisation, which is the controller of that data.
11. Security
The technical and organisational security controls in place are described on our Security page. In brief: TLS in transit, encrypted Postgres at rest, mandatory two-factor authentication for admin users, database-level tenant isolation, automatic session timeout, immutable audit log, and UK / EU-only hosting.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified to Platform Account Owners by email.