Privacy Policy
Version v1.0 · Last updated 12 June 2026 · Governed by the laws of England and Wales
This Privacy Policy explains how ChainPeace Ltd (“ChainPeace”, “we”, “us”) collects, uses, discloses and safeguards personal data when you use our website, web application and related services (the “Service”). It is written to comply with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 (“DPA 2018”), and the Privacy and Electronic Communications Regulations 2003 (“PECR”).
1. Who we are (Data Controller)
ChainPeace Ltd is a company registered in England and Wales. For the personal data described in this policy we act as the data controller. When you upload information about third parties (for example other parties in a property chain) you act as a controller and we act as your data processor under a separate Data Processing Agreement.
- Controller: ChainPeace Ltd, United Kingdom
- Privacy contact / Data Protection lead: privacy@chainpeace.com
- ICO registration: maintained at ico.org.uk
2. The personal data we collect
We collect only what we need to deliver the Service:
- Account data: name, email, hashed password (we never see your plaintext password), MFA enrolment status, profile photo, role.
- Transaction data: property addresses, chain positions, milestones, notes, documents and messages you upload.
- Communications: in-app messages, call metadata (participants, duration), voice notes and transcripts that you choose to create.
- Payment data: we use Stripe Payments UK Ltd as our PCI-DSS Level 1 processor; we never store full card numbers — only the last four digits, brand, country and a Stripe customer ID.
- Technical data: IP address, device, browser, operating system, language, time zone, pages viewed, referring URL, and security event logs.
- Consent records: a versioned audit trail of every consent you grant or withdraw in the Privacy Centre.
We do not knowingly collect special-category data (health, biometric, religion, political opinions). Please do not upload such data to the Service.
3. Lawful bases for processing (UK GDPR Art. 6)
- Contract (Art. 6(1)(b)) — to create your account, deliver the Service and bill you.
- Legitimate interests (Art. 6(1)(f)) — service security, fraud prevention, product analytics aggregated and pseudonymised, and direct B2B communications with existing customers.
- Legal obligation (Art. 6(1)(c)) — anti-money-laundering record-keeping (where applicable), tax records, responding to lawful requests.
- Consent (Art. 6(1)(a)) — non-essential cookies, marketing emails, optional features such as voice transcription. Consent can be withdrawn at any time without affecting prior lawful processing.
4. How we use your data
- Provide, secure and improve the Service.
- Authenticate you, enforce MFA, detect and block abuse.
- Process payments and issue invoices.
- Send transactional emails (password reset, security alerts, billing receipts).
- Send service updates and, where you have consented, marketing.
- Meet legal, regulatory and accounting obligations.
- Defend or bring legal claims.
We do not sell your personal data, and we do not use your transaction content to train AI models.
5. Sharing your data (sub-processors)
We share data with carefully vetted sub-processors who are bound by written contracts and UK GDPR-compliant safeguards. Current sub-processors include:
- Supabase (Lovable Cloud) — hosted database, authentication and storage (EU/UK regions).
- Cloudflare — content delivery, DDoS protection, edge compute.
- Stripe Payments UK Ltd — card processing.
- Resend / transactional email provider — outbound email delivery.
- OpenAI / Anthropic / Google AI (via the Lovable AI Gateway) — optional AI features, on a zero-retention basis; content is not used to train their models.
We may also disclose data to professional advisers, regulators, law enforcement, or in connection with a corporate transaction, where legally required or permitted.
6. International transfers
Where personal data is transferred outside the UK, we rely on UK adequacy regulations, the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK Addendum, together with appropriate technical safeguards (encryption in transit and at rest).
7. How long we keep data
- Account data: for the life of your account, then 30 days after closure (backups up to 35 days).
- Transaction & chain data: for the life of your account, plus 6 years (UK statute of limitations).
- Financial / tax records: 6 years from the end of the relevant accounting period.
- Security & audit logs: 13 months.
- Marketing consents: until withdrawn, plus 24 months suppression.
8. Security
We apply organisational and technical measures appropriate to the risk (UK GDPR Art. 32): TLS 1.2+ in transit, AES-256 at rest, MFA, role-based access control with row-level security, append-only audit logs, least-privilege keys, and an annually reviewed information security policy. See our Security overview for more.
9. Your rights (UK GDPR Art. 12–22)
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”) — subject to legal retention obligations.
- Restriction — limit how we process your data.
- Portability — receive your data in a structured, machine-readable format.
- Objection — to processing based on legitimate interests or for direct marketing.
- Withdraw consent — at any time via the Privacy Centre.
- Lodge a complaint with the Information Commissioner’s Office (ico.org.uk/make-a-complaint).
File any of these requests through the in-app Privacy Centre or by emailing privacy@chainpeace.com. We respond within one calendar month.
10. Cookies
See our Cookie Policy.
11. Automated decisions & profiling
We do not make decisions producing legal or similarly significant effects about you using solely automated processing. Optional AI features (e.g. transcription, summarisation) are advisory only and never determine eligibility, pricing or account status without human review.
12. Children
The Service is intended for users aged 18 and over. We do not knowingly collect data from children.
13. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email and/or an in-app notice at least 14 days before they take effect. The version and date appear at the top of this page.
14. Contact
ChainPeace Ltd, United Kingdom
Privacy: privacy@chainpeace.com
General: hello@chainpeace.com