Privacy Policy
Last updated: August 2026 · UK GDPR & Data Protection Act 2018
UK GDPR compliance summary
- AI prompts are processed transiently and not retained; saved documents and project registers are kept while your account is active
- Account data stored on Supabase EU servers (Ireland, eu-west-1)
- Cookieless Vercel Web Analytics only, no advertising or third-party tracking cookies
- Authentication uses a single HttpOnly cookie (no personal data), persistent for up to 30 days
- API inputs are not used by Anthropic to train AI models
- You have the right to access, correct, or erase any personal data we hold
1. Who We Are
FitOut Insider is operated by Dariusz Kubies Services (JDG), al. Solidarnosci 68 lok. 121, 00-240 Warszawa, Poland. NIP 7532202127, REGON 544086256 ("we", "us", "our"). For data protection enquiries, contact: hello@fitoutinsider.com. As the data controller, we are responsible for any personal data processed by this Service.
2. What Data We Collect
We collect minimal data:
• Account data: When you subscribe, Stripe collects your email, billing name, billing address, tax/VAT ID and payment card details via its own hosted checkout. We receive only your email address to create your account - your billing name, address and tax ID are held by Stripe, not by us.
• Registration IP address: Recorded at account creation as part of our terms-of-service acceptance record, retained solely as legal evidence of agreement under UK GDPR Article 6(1)(f). Never used for tracking or marketing.
• Session authentication: A single encrypted session cookie set at login, contains only a session token, no personal data.
• Tool inputs and AI processing. Text you enter into a tool is sent to the Anthropic Claude API to generate the document. The prompt and the AI response are transmitted securely and are not retained by us once the response is generated.
• Saved documents. When you save or export a document, both the document and the form inputs used to create it are stored in your account, so you can reopen, edit, print and complete it later. This includes anything you typed or uploaded into the form, which may include names, job titles, contact details, training certificates and incident details. Retained for as long as your account is active. See Data retention.
• Project registers. Some tools, including the Site Diary and the Visitor and Site Access Register, save entries automatically as you type, because they are continuous project records rather than one-off documents. The same retention applies.
• Data about other people. Many of these tools are designed to record information about your staff, subcontractors and site visitors. Where you enter data about other people, you are the controller of that data and we act as your processor. You are responsible for informing those people and for having a lawful basis to record it.
• Usage tracking: We record the number of AI requests you make. We record counts only, never the content of a request or a response. Your count is shown back to you in your account so you can see your own usage. No plan has a request limit, and this count is not used to restrict your access to any feature.
• Feedback / support messages and technical error logs: stored to diagnose issues and improve the Service (EU region, Ireland eu-west-1), never shared with third parties.
3. AI Processing, Anthropic Claude API
Tool inputs are processed by Anthropic's Claude API to generate outputs. By Anthropic's policy, API inputs are not used to train AI models. The prompt and the AI response are transmitted securely and are not retained by us once the response is generated. We recommend you do not input sensitive personal data unless necessary for the specific document being generated.
4. Health and Incident Data
The Near Miss and Incident Reporting tool may record information about injuries, including RIDDOR classifications. Where that identifies an individual it is special category data under Article 9. We process it solely as your processor, on your instructions, so that you can meet your own obligations under health and safety law. We use it for no other purpose. You remain the controller.
5. Vetting and Clearance Data
Vetting and clearance data. The Training Matrix and Competency Tracker allows you to record that an individual holds a security check or clearance, including BPSS, DBS, CTC, SC and DV, with completion and expiry dates. Data about the outcome of a DBS check is criminal offence data under Article 10. We process it solely as your processor, on your instructions. You remain the controller and are responsible for having a lawful basis and a Schedule 1 condition. The Service is designed to record that a check exists and when it expires, not the detail of any conviction, caution or vetting finding.
6. Data Storage
Account data and saved outputs are stored in Supabase (PostgreSQL), hosted in the EU (Ireland, eu-west-1). All connections are encrypted end-to-end (TLS 1.3). Your data is never used to train AI models. We do not share or sell your data. Hosting runs on Vercel for serverless functions and CDN delivery.
7. Cookies
We use one essential cookie, fitout-snonce: an authentication cookie (HttpOnly, Secure, SameSite=Strict, persistent for up to 30 days). For usage statistics we use Vercel Web Analytics, a cookieless analytics tool provided by Vercel, Inc. that collects no personal data and sets no cookies - no consent is required under GDPR, UK GDPR or PECR. We do not use advertising or third-party tracking cookies. See our Cookie Policy for full details.
8. Legal Basis for Processing (UK GDPR)
• Contract performance (Art. 6(1)(b)): processing account and usage data to deliver the subscription.
• Legitimate interests (Art. 6(1)(f)): session authentication, transient processing of tool inputs, registration-IP record, error logging.
• Consent (Art. 6(1)(a)): for any optional feedback or support messages.
9. Data Retention
Authentication cookie (fitout-snonce): persists up to 30 days, cleared on sign-out.
AI prompts (the exact text sent to Anthropic): not retained after response generation.
Billing, invoice and transaction records: retained for 7 years, as required by UK and Polish tax and accounting law. This applies regardless of when you cancel your subscription.
Saved documents and project registers: retained for as long as your subscription is active. If you cancel, your data remains available for 90 days so that you can export it, and is then permanently deleted. You can delete any document or entry yourself at any time, and deletion is permanent.
Registration IP: account duration + 90 days.
Usage records: 13 months.
Feedback: up to 12 months.
Technical error logs: 90 days.
10. Your Rights Under UK GDPR
You have the right to: Access, Rectification, Erasure ("right to be forgotten"), Restriction, Portability, and Objection. To exercise any of these, contact hello@fitoutinsider.com, we respond within 30 days. You may also complain to the Information Commissioner's Office (ICO) at ico.org.uk.
11. Security
We implement appropriate technical and organisational measures: TLS 1.3 in transit, AES-256 at rest (Supabase), HttpOnly + Secure auth cookies, and Row Level Security so users can only access their own data. In the event of a breach likely to risk your rights, we notify the ICO within 72 hours and affected individuals without undue delay.
12. Sub-Processors & International Transfers
Supabase (EU, Ireland), database/auth · Anthropic (USA), transient AI processing via your own connected API key (BYOK) · Vercel (USA/UK/EU), hosting and cookieless analytics (Vercel Web Analytics, which collects no personal data and sets no cookies), functions run in London (UK) · Stripe (USA/EU), payment processing - Stripe collects and holds your billing name, address, tax/VAT ID and card details, we receive only your email · Resend (USA), transactional email - processes the name, email and message you submit via the contact form · Upstash (USA), rate limiting - processes your IP address only, to protect public forms against abuse. Transfers to the USA are governed by standard contractual clauses (SCCs) under UK & EU GDPR.
13. Data Processing Agreement
DPAs are in place with each sub-processor via their standard contractual terms. A Data Processing Agreement between you and FitOut Insider forms part of the standard terms accepted by every customer on every plan, not something available only on request to some. The full Data Processing Agreement is published on this Legal page, alongside this Privacy Policy.
14. EU GDPR and RODO
FitOut Insider is operated by Dariusz Kubies Services, established in Poland (EU), and is therefore also subject to EU GDPR (RODO). As a Polish-registered business, our primary supervisory authority is the Urzad Ochrony Danych Osobowych (UODO), the Polish data protection authority (uodo.gov.pl). If you are based in the United Kingdom, you also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, in respect of processing that affects you as a UK resident.
15. Changes to This Policy
We may update this Policy from time to time. Where changes are significant, we notify subscribers by email at least 14 days before they take effect. The most recent revision date is shown at the top of this page.
16. Contact
Data controller: Dariusz Kubies Services (JDG), al. Solidarnosci 68 lok. 121, 00-240 Warszawa, Poland. NIP 7532202127, REGON 544086256 (trading as FitOut Insider)
Email: hello@fitoutinsider.com
ICO complaints: ico.org.uk · UODO complaints (EU): uodo.gov.pl