1. Who is responsible
Drawbridges Business Services Ltd (England and Wales company 15260510) operates RegInspect. We act as controller for website enquiries, business contacts, account administration, billing, security and our own service records.
A subscribing firm normally acts as controller for its clients’, prospective clients’, staff members’ and beneficial owners’ information entered into RegInspect. For that processing we act as processor under the firm’s instructions and DPA. This notice does not replace the firm’s own privacy notice. Payment providers and public registries may separately act as controllers for their own purposes.
2. Information and sources
We receive business contact details and enquiry text directly from website visitors and prospective customers; account, role and billing contact details from users and firm administrators; and technical information such as IP address, session, device, request and security-event data when services are used.
Firms may submit identity and contact information, identification documents, ownership details, financial/source-of-funds evidence, screening results, risk assessments, correspondence and compliance records. Sources can include clients, authorised staff, public company registers and screening or identity providers. Some records may contain sensitive information or allegations of criminal activity. The firm must establish the additional conditions and safeguards required for that processing.
Please avoid including sensitive client or financial information in a general website enquiry. We request only what is needed for the relevant purpose.
3. Purposes and lawful bases
We use business contact and account information to answer enquiries, take steps towards a contract and deliver or administer the service. Where our contract is with a firm rather than the individual, our legitimate interests include managing that business relationship and providing secure support.
We process billing and accounting records to administer payment and meet applicable tax and record-keeping obligations. Our legitimate interests include protecting the platform, preventing abuse, investigating incidents and resolving disputes. We assess those interests against individuals’ rights.
Optional promotional communications and non-essential browser analytics use consent where required. Withdrawing that consent does not affect earlier lawful processing or necessary service messages. For customer-controlled compliance records, the firm determines the applicable lawful basis and provides instructions; we do not treat a platform checkbox as consent to every use of a client’s information.
4. Sharing and suppliers
Information is available to authorised personnel and service providers where needed for hosting, identity, screening, AI assistance, communications, billing, support and security. The provider list explains feature-dependent recipients. Not every provider receives every record.
We may disclose information when legally required, to protect legal rights or in connection with a business reorganisation subject to appropriate confidentiality and data-protection safeguards. We do not sell personal information or use client compliance records for third-party advertising.
5. Location and international transfers
The core production application and database are hosted in Google Cloud’s London region. That does not mean every supplier, support operation or processing activity is confined to the UK. International processing depends on the service, supplier and contract.
Where a restricted transfer is involved, the applicable adequacy decision or contractual safeguards and transfer assessment must be in place. Contact us for the arrangements relevant to your service. UK, Gibraltar and EU/Malta requirements are considered separately; a UK hosting location alone is not a transfer mechanism.
6. Retention
We retain controller records for the purpose for which they were collected, taking account of the business relationship, legal record-keeping duties, limitation periods and security needs. Enquiries that do not lead to a relationship should not be kept indefinitely. Contact us for the schedule applicable to a particular category.
Customer compliance records follow the firm’s instructions and applicable retention and legal-hold requirements. A five-year period can apply to AML records, but the start point, exceptions and duration depend on the jurisdiction and record. Subscription cancellation is not a promise that all regulated evidence can immediately be erased.
The DPA governs return and deletion of processor records. Backup expiry and legally retained records are handled separately from deletion of live records.
7. Your rights
Depending on the applicable law and processing, you may request access, correction, erasure, restriction or portability, object to processing, or withdraw consent. Rights have conditions and exceptions; we may need proportionate identity verification. There is normally no fee unless the law permits one.
For information controlled by your professional firm, contact that firm first. If you contact us as its processor, we will direct or pass the request to it and assist as required. For information we control, use our contact details below. We respond within the applicable statutory period and explain any lawful extension.
You may complain to the relevant supervisory authority, including the UK Information Commissioner’s Office, the Gibraltar Regulatory Authority or Malta’s Information and Data Protection Commissioner. You do not have to contact us first to exercise that right.
8. Automated assistance and security
Readiness scores, risk indicators and AI suggestions support human review. They are not a substitute for accountable professional decisions. The firm must assess any use that would amount to solely automated decision-making with legal or similarly significant effects.
We use access controls, protected transport, tenant scoping, audit records and operational safeguards. No system is risk free. Our Security Policy describes the controls without claiming that an independent certification or audit has been completed.
9. Cookies, communications and changes
See the Cookie Policy for cookies, local storage and optional browser monitoring. Website and app preferences are specific to their origin; changing one does not automatically change another.
Promotional messages include a way to withdraw. Essential messages about your account, payment or service security continue where appropriate. We update this notice when practices change and show a fixed document revision date.
Contact
Drawbridges Business Services Ltd · Company number 15260510
Townshend House, 30
Crown Road, Norwich NR1 3DT, United Kingdom
contact@reginspect.co.uk. For privacy or security matters, include “Privacy” or “Security” in the subject. Do not send sensitive client records in an initial enquiry.