Reinza Reminder — Privacy Policy
Last updated: 12 August 2026
Version: 1.0
1. Who we are
Reinza Limited ("we", "us") operates Reinza Reminder (the "Service").
- Registered in England and Wales, company number 11668166
- Registered office: 128 City Road, London, EC1V 2NX
- Contact for privacy matters: [email protected]
- ICO registration number: ZC221102
This policy explains how we handle personal data. It applies to visitors to our website and to account holders using the Service.
2. Two different roles — please read
Our responsibilities differ depending on whose data is involved:
(a) Data about you, our customer — we are the "controller".
This includes your name, email address, business details, login credentials and billing information. This policy explains how we handle it.
(b) Data you put into the Service about your own clients — you are the "controller", we are the "processor".
When you record the companies you act for, add notes, or enter contact details, you decide why and how that data is used; we simply store and process it on your instructions. Our obligations in that role are set out in our Data Processing Agreement (DPA), which forms part of our contract with you.
3. What we collect and why
| Data | Why | Lawful basis |
|---|---|---|
| Name, business name, email address | Create and administer your account; send service notices | Performance of a contract |
| Password (stored only as a cryptographic hash) | Secure access to your account | Performance of a contract |
| Billing records (subscription status, invoices, last four digits and card type) | Take payment; meet accounting and tax obligations | Contract; legal obligation |
| Technical logs (IP address, browser type, timestamps, actions taken in the Service) | Keep the Service secure, diagnose faults, prevent abuse | Legitimate interests (security and reliability) |
| Support correspondence | Answer your questions | Contract; legitimate interests |
| Optional email credentials you supply (e.g. an SMTP application password for your own mailbox) | Send reminders from your own email account on your instruction | Performance of a contract |
We do not use your data or your clients' data for advertising, and we do not sell it to anyone.
4. Company data from Companies House
The Service retrieves company information (company name, status, accounting reference date, filing due dates) from the Companies House public register. This is publicly available business information. Which companies you choose to monitor, however, is your confidential business information, and we treat it as such.
5. Cookies
At present we use only cookies that are strictly necessary to operate the Service: a session cookie to keep you logged in, and a security token to protect forms. We do not currently use advertising, tracking or analytics cookies. If we introduce technologies for which consent is legally required, we will obtain that consent before using them.
6. Payments
Payments are processed by Stripe Payments Europe, Ltd. We never see or store your full card number. Stripe processes your payment data as its own controller under its privacy policy (stripe.com/privacy). We receive only the information needed to manage your subscription (status, amounts, and card type and last four digits).
7. Who else may access data
We share data only with service providers acting on our instructions, and only as necessary:
| Provider | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | EU/UK, with international safeguards |
| Resend (Plus Five Five, Inc.) | Sending reminder and system emails from mail.reinza.com | US, with UK International Data Transfer Addendum in place |
| Cloudflare | Secure delivery of the website (traffic routing and protection) | Global network |
| Microsoft | Encrypted off-site backup storage (OneDrive for Business) | United Kingdom |
If you choose to send reminders through your own mailbox, your email provider acts under your own arrangements with them and is not our service provider.
We may also disclose data where required by law, or in connection with a sale or reorganisation of our business (in which case you will be informed).
8. Where data is stored
The Service and its database are hosted on our own equipment located in the United Kingdom. Backups are held in the United Kingdom. Where a provider listed in clause 7 processes data outside the UK, appropriate safeguards (such as the UK International Data Transfer Addendum) are in place.
9. How long we keep data
| Data | Retention |
|---|---|
| Account and service data (including data about your clients) | For as long as your account is active. After cancellation or suspension: 30 days, then permanently deleted |
| Billing and invoice records | 6 years after the end of the relevant financial year (UK tax law) |
| Technical logs | Up to 12 months |
| Support correspondence | Up to 2 years |
Online data is deleted according to the periods in the table above. Encrypted backups may retain deleted data for up to a further 90 days under the normal rotation cycle, after which it is permanently removed. Billing and invoice records are retained for six years as required by UK tax law and are not affected by those deletion periods.
You may request deletion earlier — see clause 11.
10. Security
We protect data by: encrypting traffic in transit (HTTPS); storing passwords only as bcrypt hashes; restricting access to the hosting environment to authorised personnel (currently the company director alone); taking regular backups with integrity checks; and applying the principle of least privilege to any third-party authorisation the Service requests.
No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the ICO within 72 hours and, where required, notify you without undue delay.
11. Your rights
Depending on the circumstances and subject to applicable law, you may have the right to: access your data; have inaccurate data corrected; have data erased; restrict or object to processing; receive your data in a portable format; and withdraw consent where processing is based on consent.
To exercise any right, email [email protected]. We will respond within one month. You may also export most of your data yourself at any time from within the Service.
If you are unhappy with how we handle your data, you can complain to us — see clause 12 — or to the Information Commissioner's Office (ico.org.uk, 0303 123 1113). We would appreciate the chance to resolve it first.
12. Data protection complaints
If you are unhappy with how we handle your personal data, you can complain to us directly. Please email [email protected] with details of your concern.
We will acknowledge your complaint within 30 days of receiving it, take appropriate steps to investigate it without undue delay, keep you informed of progress where appropriate, and tell you the outcome.
You can complain to us however you contact us — you do not need to use a particular form or wording.
You also have the right to complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113) at any time, including if you remain dissatisfied with our response.
13. Automated decision-making
We do not carry out automated decision-making that produces legal or similarly significant effects. Reminder emails are generated automatically from dates and rules, but they do not make decisions about any individual.
14. Children
The Service is for business use and is not directed at anyone under 18.
15. Changes to this policy
We may update this policy. Material changes will be notified by email at least 30 days in advance. The "last updated" date above always shows the current version.
Reinza Limited
128 City Road, London, EC1V 2NX
Company number 11668166 · ICO registration ZC221102
[email protected]