Privacy notice
Last updated 8 October 2026.
Who we are
Certlog is the controller of the information described here. You can contact us at hello@certlog.uk.
What we collect
If you ask for an email when your region opens (the form on our home page), we collect your email address, your region and roughly how many properties you let.
If you create an account, we collect:
- your email address and a scrambled (hashed) version of your password. We never store your password itself;
- the properties you add: their name, and any address and region you choose to enter;
- the certificates you add: the type, the dates, any reference, and the file you upload;
- a record that you used the "Read dates from file" feature, with the time but not the content, so we can limit how often it is used;
- your reminder preference, and a record of which reminder emails we have sent for which certificate (the type of reminder and the date, not the text);
- if you ask to reset your password, a one-time code (stored scrambled) that stops working after one hour;
- if you subscribe to the paid plan, your Stripe customer reference, the state of your subscription and the date it renews. We never see or store your card number: you enter it on Stripe's own page.
Certificate files can contain other people's details, such as a tenant's name. Only upload documents you are entitled to hold. We use them only to show you your dates and give you your files back.
Why we use it, and our lawful basis
- To run your account and show your certificates and dates. This is needed to provide the service you asked for (contract).
- To email you when the register opens in your region, if you asked for that on our home page (your consent, which you can withdraw at any time).
- To email you reminders as a certificate approaches its expiry date, and to email you a password reset link when you ask for one. These are part of the service you asked for (contract). You can switch reminders off in the dashboard or with the link in every reminder email.
- To take payment for the paid plan and keep the records the law requires us to keep (contract, and legal obligation for accounting records).
- To keep the service secure and prevent abuse, such as limiting repeated failed sign-ins (our legitimate interest).
We do not sell your information, use it for advertising, or share it with anyone for their own purposes.
Who handles it for us
- Cloudflare hosts the website and stores account data and uploaded files.
- Formspree receives the details you enter on that region form.
- Namecheap Private Email handles the emails we send and receive, including reminder and password reset emails. Those emails contain your property names and certificate dates.
- Stripe takes payment for the paid plan. It receives your email address and your payment details and tells us whether the payment worked. Stripe also uses this information for its own fraud prevention and legal duties, and explains how in its own privacy policy.
- Anthropic provides the AI service that reads dates from a certificate. We send a file to Anthropic only when you click "Read dates from file", and we receive suggested details back. We send nothing else to them.
Anthropic's published terms for its API say that content sent through it is not used to train its models and is deleted from its systems within about 30 days, with limited exceptions such as enforcing its usage policies or complying with the law. The suggestions are never saved until you have checked and confirmed them.
Some of these providers process information outside the UK. We choose providers that publish data protection commitments and use recognised safeguards for transfers.
How long we keep it
- Account information and files: until you delete them. Deleting a certificate or property removes its files. Deleting your account removes your account, all your properties, certificates and every uploaded file straight away.
- Sign-in sessions: 30 days, or until you sign out.
- Records that you used the "Read dates from file" feature: deleted after 7 days.
- Reminder records: deleted with your account, and reset whenever you change a certificate's date.
- Password reset codes: stop working after one hour, and are deleted when used or when you delete your account.
- Payment records: deleting your account cancels any subscription at once. Stripe and we keep invoices and payment records for as long as UK tax and accounting rules require, even after your account is deleted. We keep nothing else about you for this.
- Records of failed sign-in attempts: removed after a successful sign-in, and not used for anything else.
- Region email list: until the opening email for your region has been sent and for up to 12 months after, unless you ask us to delete it sooner.
Your rights
You can ask to see, correct or delete your information, object to how we use it, or ask for a copy. You can delete your account yourself from the Certlog dashboard, or email hello@certlog.uk. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office at ico.org.uk.
Cookies
We use one cookie, only after you sign in, to keep you signed in. It is needed for the service to work. We do not use advertising or analytics cookies.
When this changes
If we change how we use your information we will update this page and tell account holders by email.