KeepCert

Privacy policy

Last updated: 23 August 2026

This policy explains, in plain English, what personal data KeepCert holds about you, why we hold it, how long we keep it, and what you can ask us to do with it. It follows the UK GDPR and the Data Protection Act 2018. KeepCert is a trading name of Jaspal Sagoo, a sole trader based in England, and for the data described below Jaspal Sagoo (trading as KeepCert) is the "data controller". You can reach us at hello@keepcert.co.uk.

What we collect

  • Your account details — your name (if you give one) and email address, plus an encrypted version of your password. We never see or store your password in readable form.
  • Your property details — property names, addresses, postcodes, whether a property is an HMO, and any notes you add.
  • Your certificates — the type of certificate, issue and expiry dates, your notes, and any files you upload (gas safety records, EICRs, EPCs and similar). These files can contain the names of engineers, tenants or other people.
  • Your subscription details — if you take a paid plan, we keep your plan name, subscription status, renewal date and renewal amount, plus the customer and subscription reference given to us by our payment processor. Your card details are handled by Paddle (see below) and never reach us.
  • Basic technical data — limited security and error logs, such as the timing of sign-in attempts, used to protect accounts from abuse. We do not run advertising trackers.

Why we collect it and our lawful basis

  • To run your account and show your records — lawful basis: contract. We can't provide the service you signed up for without it.
  • To email you expiry reminders — lawful basis: contract. Reminders are the core purpose of KeepCert.
  • To keep accounts secure (rate limiting, abuse prevention, error monitoring) — lawful basis: legitimate interests in keeping the service safe and working.
  • To take payment and manage your subscription — lawful basis: contract. Payments are taken by Paddle as Merchant of Record.
  • To meet legal obligations where we must, for example responding to a lawful request — lawful basis: legal obligation.

We do not sell your data, and we do not use it to build advertising profiles. If you upload documents containing other people's details, you remain responsible for handling that information lawfully as a landlord.

Who can see it

Only you. Your properties, certificates and files are locked to your account at the database and storage level, so no other KeepCert user can read them. Uploaded files sit in a private store and are only ever served to you through short-lived links.

We use a small number of trusted service providers to host the database and files, send reminder emails, and take payment (Paddle, as our Merchant of Record). They process data on our instructions only, under contract.

Who processes your data for us

These are the third-party services (data processors) involved in running KeepCert. Each one only handles data on our written instructions.

  • Lovable Cloud — our backend and hosting provider. It runs the database holding your account details, properties and certificate records; the authentication system that stores your email address and a secure hash of your password and manages your login sessions; the private file storage holding your uploaded certificate documents; and the server-side functions that read and write that data, including the daily expiry check. Data is encrypted in transit and at rest.
  • Email delivery provider — used to send account emails (confirmation and password reset) and certificate expiry reminders. It receives your email address and the contents of the message, which may include a property label and the certificate type and expiry date. It does not receive your uploaded files or your password.
  • Paddle — our payment processor and Merchant of Record. Paddle.com Market Ltd sells KeepCert subscriptions to you as reseller of record, and handles checkout, payment, invoicing, VAT and tax compliance, subscription management, refunds and billing-related customer enquiries. When you subscribe, Paddle collects your billing details directly (name, email address, billing address or country, and payment card or PayPal details) and acts as controller of that payment data under its own privacy notice at paddle.com. We never see or store your full card details. We receive back from Paddle only your subscription status, plan, renewal date and renewal amount, so we can give you the right features. Lawful basis: contract.
  • AI provider (via Lovable Cloud) — where an AI-assisted feature runs, it receives only the minimum details for that request, as described in the AI section below. No training on your data.

We don't sell your data or share it with advertisers, and we don't use third-party advertising or profiling trackers.

Where it's stored

Data is hosted on secure cloud infrastructure and encrypted in transit and at rest. If any provider stores or processes data outside the UK, we rely on the UK's approved safeguards (such as the International Data Transfer Addendum) to protect it.

AI-assisted features

KeepCert was built with AI-assisted development tools, and some features in the app may use AI services — for example, to help draft the wording of a reminder email or to summarise certificate information.

Where an AI feature runs, only the minimum information needed is sent: things like a certificate type, its expiry date and a property label. We do not send uploaded certificate files, passwords or payment details to any AI service.

Your personal data is not used to train third-party AI models. Any AI provider we use processes data on our instructions only, for that single request, and is contractually prevented from using it for model training.

AI output is only ever a helper — no automated decision with legal or similarly significant effects is made about you.

How long we keep it

  • While your account is open — we keep your properties, certificates and files so they're there when you need them.
  • After you delete your account — we delete your account data and uploaded files within 30 days, apart from anything we're legally required to keep.
  • Inactive accounts — if you don't sign in for 24 months, we'll email you and then delete the account if we hear nothing back.
  • Security logs — kept for up to 12 months.

Your rights

Under UK GDPR you can ask us to:

  • give you a copy of the personal data we hold about you (access);
  • correct anything that's wrong or incomplete (rectification);
  • delete your data (erasure);
  • pause how we use it while a concern is resolved (restriction);
  • send you your data in a portable, machine-readable format (portability);
  • stop processing based on legitimate interests, where you have grounds to object.

You can correct most details yourself by editing a property or certificate, and you can remove a certificate or file at any time from the property page.

For anything else, email hello@keepcert.co.uk from your account address. We'll respond within one month and won't charge you.

Complaints

If you're unhappy with how we've handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.

Changes to this policy

If we make a meaningful change, we'll update the date at the top of this page and email you if it affects how your data is used.