Last updated 20 July 2026
Privacy Policy
This explains what personal data Workscribe collects, why we need it, who else sees it and what rights you have. We've kept it specific — no vague statements about valuing your privacy.
Who controls your data
Aaran Wahie, trading as Workscribe of 1 The West Rig, Newcastle upon Tyne, [POSTCODE], United Kingdom is the data controller for the personal data described here, under the UK GDPR and the Data Protection Act 2018.
For anything to do with your data, email A.WVentures@hotmail.com.
What we collect
When you create an account
- Your name and email address
- An encrypted version of your password — we never see the password itself
- The profession you select
Your business details, if you add them
- Business name, address, phone, email, VAT number and hourly rate
- These are added to the documents you generate, which is the only reason we hold them
When you use a tool
- Whatever you type into the fields, which may include your customers’ names and addresses
- The document that gets generated, if you choose to save it
- A usage record: which tool, when, how long it took, how many tokens it used and what it cost us
If you subscribe
- Your Stripe customer and subscription identifiers, your plan and its status
- We do not receive or store your card number. Stripe handles that.
Automatically
- Standard server logs from our hosting provider — IP address, browser type, pages requested, timestamps — kept briefly for security and debugging
Data about your customers
We process that information only to generate and store your document. We don’t use it for anything else, we don’t contact the people it describes, and we don’t use it to train any AI model.
Our commitments as your processor. Where we act as processor for personal data you have entered about other people, we commit to the following, which together with these terms form our processing agreement with you under Article 28 of the UK GDPR:
- We process that data only on your documented instructions — in practice, to generate, store and return the document you asked for — unless the law requires otherwise.
- We keep it confidential and ensure anyone with access is bound by confidentiality.
- We apply the security measures set out in section 8.
- We use only the sub-processors listed in section 5. We’ll give you notice before adding another, and you can object by closing your account.
- We’ll help you respond to requests from the people whose data it is, and with your own security, breach-notification and impact-assessment obligations.
- We’ll tell you without undue delay if we become aware of a breach affecting your data.
- On request, or when your account closes, we delete or return the data — see section 7 for timings.
- We’ll make available the information you reasonably need to demonstrate we’re meeting these obligations.
If your organisation needs a separate signed data processing agreement, email A.WVentures@hotmail.com and we’ll sort one out.
Why we're allowed to use it
- To provide the service (contract). Your account details, business details, tool inputs and saved documents. Without them the service can’t function.
- To take payment (contract). Your subscription and billing identifiers.
- To enforce usage limits and understand our costs (legitimate interests). The usage records. We need to know what we’re spending and to stop the service being abused.
- To keep the service secure (legitimate interests). Server logs and authentication records.
- To meet legal obligations. Financial records, which tax law requires us to keep.
We don’t send marketing emails. If that ever changes, we’ll ask your consent first and you can withdraw it at any time.
Who else processes it
We use a small number of service providers. Each one only receives what it needs, and each is bound by a data processing agreement.
Generates the documents you create. Receives the details you type into a tool, plus your business details.
Database and account authentication. Stores your profile, saved documents and usage records.
Hosting and content delivery. Processes requests and server logs.
Payment processing and subscription billing. Holds your payment details — we never see your card number.
On AI processing: when you generate a document, the details you entered are sent to Anthropic to produce it. Anthropic does not use data submitted through its API to train its models. We don’t use your documents to train anything either.
We don’t sell your data. We’d only disclose it otherwise if the law required it, or to establish or defend a legal claim.
Data leaving the UK
Some of our providers are in the United States. Those transfers are covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or by the UK extension to the EU–US Data Privacy Framework where the provider is certified under it.
How long we keep it
- Account and business details — while your account is open, then deleted within 30 days of closure.
- Saved documents and templates — until you delete them, or 30 days after your account closes.
- Usage records — 24 months, so we can understand costs and abuse patterns over time. These contain no document content.
- Payment records — 7 years, as UK tax law requires.
- Server logs — typically 30 days.
Security
- Everything is encrypted in transit (HTTPS) and at rest.
- Passwords are hashed by our authentication provider and are never visible to us.
- Our database enforces row-level security, so each account can only ever read its own rows — even if there were a bug in our application code.
- Card details never reach our servers.
No system is perfectly secure. If a breach ever affected your rights, we’d tell you and the ICO as the law requires.
Your rights
Under UK data protection law you can ask us to:
- Give you a copy of the personal data we hold about you
- Correct anything inaccurate — most of it you can edit yourself in your account settings
- Delete your data, subject to records we’re legally required to keep
- Restrict or object to certain processing
- Port your data to another provider in a machine-readable format
Email A.WVentures@hotmail.com and we’ll respond within one month. There’s no charge.
If you’re unhappy with how we’ve handled your data you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We’d appreciate the chance to put it right first.
Cookies
We only use cookies that are strictly necessary for the service to work — keeping you signed in and securing your session. These don’t require consent under the Privacy and Electronic Communications Regulations, which is why you don’t see a cookie banner.
We use no advertising or tracking cookies. If we ever add analytics, we’ll ask for consent before setting anything non-essential.
Children
This service is for people aged 18 and over and isn’t designed for children. We don’t knowingly collect data from anyone under 18. If you believe a child has given us personal data, email us and we’ll delete it.
Changes
If we change this policy we’ll update the date at the top. If a change materially affects how we use your data, we’ll email you before it takes effect.