Back to Home
Privacy & Data Protection

Privacy Policy

We're committed to protecting your privacy and being transparent about how we handle your data.

Effective: January 1, 2024
UK GDPR Compliant

Controller Information

Effective date: January 1, 2024
Controller: Letsy Formation Ltd ("Letsy", "we", "us")
Registered office: [Insert registered office address]
Company number: [Insert number]
Contact (privacy/DPO): [Insert DPO or privacy email]
Scope: UK GDPR and Data Protection Act 2018

This Policy explains how we collect, use, disclose, and protect personal data when you use Letsy's websites, APIs, dashboard, and services.

1. What We Collect

Personal Information

  • Identity: name, DOB, nationality
  • Contact: email, phone, addresses
  • Verification: ID documents (passport/driving licence), proof of address

Business & Technical

  • Company: name, SIC codes, shareholdings, PSC status
  • Technical: IP, device, logs
  • Billing: payment details via processor
  • Communications: support requests

2. How We Collect

Directly from you

Account creation, dashboard usage, and support requests

From your platform

When you are a Partner, you send officer/PSC data to Letsy

Automatically & from third parties

Cookies, logs, analytics, service providers (IDV vendors), and public sources (Companies House)

3. Purposes & Legal Bases

PurposeLegal basis
Provide the Services (formations, webhooks, VO services)Contract necessity
Identity verification & AML/ECCTA obligationsLegal obligation; substantial public interest where applicable
Security, fraud prevention, audit logsLegitimate interests; legal obligation
Billing, invoicing, account managementContract necessity; legitimate interests
Improve Services (analytics, troubleshooting)Legitimate interests
Marketing communicationsConsent (you can withdraw anytime)
Legal claims & complianceLegitimate interests; legal obligation

Important: We do not routinely process special category data. Do not submit such data unless requested for compliance and permitted by law.

4. Sharing Your Data

We may share personal data with:

Companies House (to file formations/updates)
ID verification providers (to verify officers/PSCs)
Infrastructure & security providers (cloud, email, logging)
Payment processors (for fees)
Professional advisors (legal/accounting)
Regulators/law enforcement (where required by law)
Your platform (when we are engaged by a Partner on your behalf)

We do not sell personal data.

5. International Transfers

Where data is transferred outside the UK/EEA, we use approved safeguards (UK adequacy regulations, ICO-approved Standard Contractual Clauses, or equivalent). Details available on request.

6. Retention

We keep personal data only as long as necessary:

Formation/KYC records

At least 5 years after the end of the business relationship (AML requirement)

Account/contract data

Duration of contract + statutory limitation periods

Logs/analytics

Per our internal retention schedules

7. Security

We implement technical and organisational measures appropriate to risk (encryption in transit, access controls, least privilege, monitoring, backups). No system is 100% secure.

8. Your Rights (UK GDPR)

Access
Rectification
Erasure (subject to AML/legal retention)
Restriction
Objection
Portability
Withdraw consent for marketing

Contact: [Insert privacy/DPO email]. We may need to verify your identity.

9. Cookies & Analytics

We use necessary cookies and, with consent, analytics cookies to improve the site. See our Cookie Policy: [Insert URL]. You can manage preferences via our banner or your browser.

10. Children

Our Services are for businesses and are not directed to children under 16. Do not submit children's data.

11. Automated Decision-Making

We do not rely on solely automated decisions producing legal effects. Where automated risk scoring is used, human review is available.

12. Acting as Processor

Where we process personal data on behalf of Partners, we act as processor under a Data Processing Addendum (DPA). Partners are responsible for providing privacy notices and obtaining required consents from their users.

13. Subprocessors

We use vetted subprocessors to deliver the Services. Current list: [Insert URL to subprocessor list]. We impose contractual obligations and security requirements on all subprocessors.

14. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new effective date. Significant changes may be notified by email or dashboard notice.

15. Contact & Complaints

Data protection contact / DPO: [Insert name/email]

Postal: [Insert address]

You may complain to the UK ICO if you believe we have not complied with data protection law: https://www.ico.org.uk

Questions about your privacy?

If you have any questions about this Privacy Policy or how we handle your data, please don't hesitate to contact us.