FilingPing

DRAFT: NOT FOR PUBLICATION. Prepared 28 September 2026 as general legal information, not regulated legal advice. Craig should have it reviewed before launch. Replace every {{PLACEHOLDER}}, make the decisions in the drafting notes, and delete the drafting notes before publishing.

FilingPing: Privacy Notice

Last updated: {{EFFECTIVE_DATE}}

This notice explains what personal data we collect when you use FilingPing (the Service), why we collect it, who we share it with, how long we keep it, and your rights. It is written to meet Articles 13 and 14 of the UK GDPR.

1. Who we are

The controller of your personal data is Craig Hallsworth, a sole trader trading as FilingPing, First Floor, Swan Buildings, 20 Swan Street, Manchester M4 5JW. Email: support@filingping.co.uk.

ICO registration number: ZC252957.

We are not required to appoint a Data Protection Officer. For any privacy question or request, email support@filingping.co.uk.

2. The short version

3. What we collect, why, and our lawful basis

Data Where it comes from What we use it for Lawful basis (UK GDPR Art. 6(1))
Email address You, when you sign up Sending your API key, the daily digest, service notices (for example, a paused webhook) and replies to your messages; identifying your account Contract (b): we need it to provide the Service
API key, stored only as a one-way SHA-256 hash plus a short prefix Generated by us Checking your requests come from you Contract (b)
Watchlist: company numbers, optional labels, the date each was added, and whether it is paused You Monitoring those companies and telling you about changes Contract (b)
Webhook endpoints: URL, signing secret and delivery status (attempts, errors) You and our systems Delivering and retrying alerts, and pausing endpoints that keep failing Contract (b)
Billing references: Stripe customer ID, subscription ID, subscription status, current period end date and plan Stripe Knowing which plan you are on, preventing double charging, and reconciling billing Contract (b); legal obligation (c) for records we must keep for tax
Account records: signup date, when your last key email was sent, which days a digest was sent, and an audit log of plan changes and account deletion (by account number) Our systems Running the Service, preventing duplicate emails, investigating billing problems and disputes Legitimate interests (f): running a reliable service and dealing with disputes
IP address Your device, when you call the signup endpoint Limiting how many signups can come from one address, to stop abuse Legitimate interests (f): preventing abuse and protecting our email reputation
Messages you send us (support, complaints, requests) You Answering you and keeping a record Legitimate interests (f); legal obligation (c) for data protection complaints and rights requests
Technical logs: error messages, which may include account or Stripe reference numbers Our systems Finding and fixing faults, and security Legitimate interests (f): keeping the Service working and secure

Legitimate interests. Where we rely on legitimate interests, we have judged that the use is expected, limited and low-risk, and that it does not override your rights. You can object (section 9).

Do you have to give us your data? You need an email address to use the Service. Without it we cannot send your API key. Labels are optional.

No marketing, and no automated decisions. We do not send marketing emails, and we do not make decisions about you by automated means that have legal or similarly significant effects.

Please do not put personal data in labels or webhook URLs. Use company names or your own reference codes.

4. Companies House data: about companies, not about people

The Service is built on public data from Companies House, used under the Open Government Licence v3.0. We deliberately keep company-level information only: company number, company name, status, whether accounts or the confirmation statement are overdue, and basic filing details (category, type, description code and dates). We do not collect or store the names, addresses or dates of birth of directors, other officers or persons with significant control. An alert about an officer or PSC filing says only that a filing of that type was made.

A company name can sometimes include a person's name (for example, "J Smith Plumbing Ltd"), and a small company can be closely linked to one person. Where company-level information does relate to an identifiable individual, we process it only as part of the public company record, to tell our customers about changes to companies they watch. Our lawful basis is legitimate interests (f): helping businesses manage credit and supplier risk using information that is already public. Companies House is the source. We keep events for 90 days. Snapshots of each watched company's current name and status are kept so that we can detect changes. You have the rights in section 9. Because we do not hold contact details for these individuals, it would be impossible or would involve disproportionate effort to contact them individually, so we publish this notice instead.

5. Who we share data with

We do not sell your data. We share it only with these service providers:

Recipient Role What they receive Where
Render Services, Inc. (hosting and database) Processor, under Render's data processing addendum Everything we store (it runs our servers and database) Our servers and database are in the EU (Frankfurt, Germany). Render is a US company and uses sub-processors (for example AWS and Cloudflare), so some access or support may take place in the US
Resend (transactional email) Processor, under Resend's data processing addendum Your email address and the content of emails we send you (API key email, digests, service notices) EU (Ireland, eu-west-1 region). Resend is a US company, so US-based staff or sub-processors may have access; see transfers below
Stripe / Sold through Link, LLC ("Onelink") (payments) Independent controller. Onelink is the merchant of record and reseller for paid plans We give Stripe your email address and account number when you start checkout. Stripe collects your name, billing address and payment details directly United States and elsewhere. See Stripe's and Onelink's privacy notices

We may also disclose data where the law requires it, to protect our legal rights, or to a buyer if the Service is sold (and we would tell you).

Companies House is our data source, not a recipient. We do not send your personal data to Companies House. The only thing it receives from us is ordinary API requests about company numbers.

6. International transfers

7. How long we keep data

Data How long
Account (email, plan, Stripe references, signup date) Until you delete your account (or we close it). Free accounts with no subscription and no API activity for 12 months are deleted automatically.
API key hashes Until you delete your account
Watchlist and labels Until you remove the company or delete your account
Webhook endpoints and secrets Until you delete the endpoint or your account
Company change events, and webhook delivery records (including error messages) 90 days after we receive the event, then deleted automatically. Deleted sooner if you delete your account
Record of which days a digest was sent Until you delete your account
Audit log (account number, plan changes, Stripe subscription ID, account deletion) 6 years, then deleted automatically.
IP addresses used for rate limiting Held only in server memory, not written to our database or our application logs. Cleared when the server restarts, and periodically pruned
Technical logs held by our host 7 days on our current Render plan (up to 30 days on higher plans)
Emails held by Resend 30 days (Resend's standard retention), then deleted by Resend
Support messages and complaints 2 years after the matter is closed
Payment records Held by Stripe/Onelink as merchant of record, under their own retention policies. We keep financial records needed for tax for 6 years

When you delete your account through DELETE /v1/account, we immediately delete your account, API key hashes, watchlist, labels, webhook endpoints and delivery records. Stripe and Onelink keep their own payment records, and you can ask them to delete data as their privacy notices describe.

8. Cookies

The FilingPing API does not set cookies or use tracking technologies. Stripe's checkout pages are run by Stripe/Onelink and may use their own cookies, as their privacy notice explains. Our website (https://filingping.co.uk) also sets no cookies and uses no analytics or third-party scripts.

9. Your rights

You have the right to:

To use a right, email support@filingping.co.uk. We may need to confirm that the request comes from the account holder, for example by replying to your account email address. We will respond within one month. We can extend this by up to two further months for complex requests, and if we do, we will tell you why.

10. Complaints to us

If you are unhappy with how we have used your personal data, please complain to us first:

We will acknowledge your complaint within 30 days of receiving it (we aim to do so within 5 working days). We will look into it without undue delay, keep you updated, and tell you the outcome.

11. Complaints to the ICO

You also have the right to complain to the Information Commissioner's Office: https://ico.org.uk/make-a-complaint/, telephone 0303 123 1113. The ICO usually expects you to have raised the complaint with us first.

12. Security

We store only a hash of your API key. We accept webhook URLs only over HTTPS, we block private network addresses, and we sign every webhook. Data is encrypted in transit. Access to our systems is limited to the operator. If a breach is likely to put your rights at risk, we will tell you and the ICO as the law requires.

13. Changes to this notice

We will post any changes here and update the date at the top. If a change is significant, we will email you before it takes effect.