Privacy Policy
Last updated: May 2026
1. Who We Are
Proven Duty ("we", "us", "our") is a software-as-a-service platform that provides automated document analysis, compliance tracking, and reporting features for FCA-regulated financial advice firms. We are the data controller for the personal data we process in providing our service.
2. What Data We Process
We process the following categories of data:
- Account data: Firm name, adviser names, email addresses, and login credentials.
- Client data uploaded by firms: Client names, contact details, dates of birth, financial circumstances, product types, and service levels. This data is uploaded by the firm and processed on their behalf.
- Document data: Uploaded suitability reports, meeting notes, and correspondence in PDF format. Text is extracted for AI analysis and stored for audit purposes.
- Special category data: Vulnerability indicators detected in uploaded documents, which may include health data, bereavement information, and financial stress indicators. This processing is necessary for reasons of substantial public interest (the firm's FCA Consumer Duty obligation to identify vulnerable customers).
- AI assessment data: Compliance scores, file review results, vulnerability signals, and suitability report drafts generated by our AI systems.
- Billing data: Payment information processed by Stripe. We do not store card details on our servers.
- Usage data: Audit log entries recording user actions within the platform for compliance and security purposes.
3. Lawful Basis for Processing
Under Article 6 of the UK GDPR, we rely on the following lawful bases:
- Contract (Article 6(1)(b)): Processing client data, generating compliance scores and reports, and providing the subscribed service features.
- Legitimate interests (Article 6(1)(f)):Vulnerability detection (the firm's legitimate interest in meeting FCA Consumer Duty obligations), sending regulatory digest emails, and platform security monitoring.
- Consent (Article 6(1)(a)): Where required for specific features such as optional email notifications.
For special category data (vulnerability indicators including health data), we rely on Article 9(2)(b) of the UK GDPR — processing is necessary for reasons of substantial public interest, specifically the firm's legal obligation under FCA rules (PRIN 2A Consumer Duty and FG21/1 Vulnerable Customers).
4. How We Use AI
We use Google Gemini AI to analyse uploaded documents and generate compliance assessments, vulnerability indicators, regulatory summaries, and suitability report drafts. Client data sent to Gemini is processed under Google's data processing terms and is not used for model training. All AI outputs require human review before having any compliance effect.
5. Data Retention
Data is retained for the duration of the subscription plus 7 years following termination, in accordance with FCA record-keeping requirements for advised business (COBS 9.1 and SYSC 9). Firms may request earlier deletion of client data, subject to their own regulatory obligations. Account data is deleted within 30 days of account closure, unless retention is required by law.
6. Data Sharing and Sub-Processors
We share personal data with the following sub-processors:
- Supabase (EU region): Database hosting, authentication, and file storage.
- Vercel: Application hosting and deployment.
- Google (Gemini API): AI processing. Data is not used for model training.
- Stripe: Payment processing. Card details are never stored on our servers.
- Resend: Transactional email delivery.
We will notify all subscribed firms of any new sub-processors with an opportunity to object before the new sub-processor begins processing data.
7. International Data Transfers
Where data is processed outside the UK (e.g., Google Gemini API in the US), we ensure appropriate safeguards are in place, including Standard Contractual Clauses or UK adequacy decisions. Our primary infrastructure (Supabase) is hosted in the EU.
8. Your Rights
Under the UK GDPR, you have the following rights:
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten"), subject to regulatory retention requirements
- Right to restriction of processing
- Right to data portability
- Right to object to processing based on legitimate interests
- Rights related to automated decision-making and profiling
To exercise any of these rights, contact us at the details below. We will respond within 30 days.
9. Data Security
We implement appropriate technical and organisational measures to protect personal data, including encryption at rest and in transit, row-level security to ensure firm data isolation, access controls, and regular security reviews.
10. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will notify the ICO within 72 hours and notify affected individuals without undue delay, as required by the UK GDPR.
11. Contact
For data protection enquiries, to exercise your rights, or to make a complaint:
Email: support@proven-duty.co.uk
You also have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk).