Privacy
Privacy policy
Last updated: 28 July 2026
RepoLogic Limited (company no. 05969213, registered in England & Wales; "we", "us") provides financial modelling and group reporting consultancy through this website, repologic.uk. This policy explains what personal data we handle, why, how long we keep it, and the rights you have over it. We've kept it in plain language because that's how we write everything.
Who is responsible for your data
RepoLogic Limited is the data controller for personal data collected through this site. Our registered office is 128 City Road, London EC1V 2NX. You can reach us about anything in this policy at hello@repologic.uk.
We are not required to appoint a Data Protection Officer, and have not appointed one. Data protection matters are handled by the principal directly.
What we collect, and why
The enquiry form. If you complete the enquiry form on our home page, we collect your name, work email address, the enquiry category you select, and anything you type into the free-text fields (systems involved, number of legal entities, and your description of the situation). We use this solely to respond to your enquiry and, if an engagement follows, to deliver it. Submissions are received and stored by Netlify Forms on our behalf, and forwarded to our Microsoft 365 mailbox.
Please do not include confidential or sensitive information in the form. Send us enough to start a conversation, not your actual data. Do not paste client-identifying details, live financial data, personal data about other people, or anything falling into a special category under UK GDPR. If a matter is sensitive, choose "Confidential — prefer to discuss" and we will arrange a secure channel.
Email correspondence. If you write to us directly, we hold your name, email address and whatever you send, including Model Health Check results if you use the "send my results" button. Same purpose, same basis.
The Model Health Check. The health check runs entirely in your browser. Your answers and score are not transmitted to us, stored, or tracked unless you choose to email them to us.
Hosting logs. Our site is hosted by Netlify, whose servers keep standard technical logs (IP address, pages requested, timestamps) for security and reliability. We don't use these to identify visitors.
Fonts. Typefaces are served directly from repologic.uk. No request leaves this site to load them, and no third party sees your visit.
We use no analytics, no advertising trackers, and no cookies set by us. Netlify may set a strictly necessary cookie in connection with form submission and spam prevention; we set none.
Our lawful bases
- Legitimate interests (Article 6(1)(f)) — responding to business enquiries and maintaining a record of them. Our interest is in operating a professional services firm; the data is business contact information, volunteered by you, for a purpose you initiated. We have assessed the balance and consider the impact on your privacy to be minimal. Ask and we'll share our legitimate interests assessment.
- Contract (Article 6(1)(b)) — where an engagement follows, to take steps at your request and to perform it.
- Legal obligation (Article 6(1)(c)) — retaining records required by company, tax and accounting law.
We do not rely on consent for anything on this site, so there is nothing here for you to consent to or withdraw.
Who we share it with
Nobody, except the service providers that operate the site and our email:
- Netlify, Inc. — website hosting and form submission handling (processor)
- Microsoft Ireland Operations Limited — Microsoft 365 email (processor)
Both are engaged under written data processing terms that meet Article 28 of the UK GDPR. We do not sell, rent or trade personal data, and we never will. We will disclose personal data where the law requires it, and will tell you unless we are prohibited from doing so.
Where your data goes
Microsoft 365 email is contracted through Microsoft's Irish entity, and the EU benefits from a UK adequacy decision, so no additional transfer safeguard is required.
Netlify, Inc. is based in the United States. Netlify is certified under the EU–US Data Privacy Framework and has opted into the UK Extension to it (the "UK–US Data Bridge"), which the UK government recognises as providing an adequate level of protection. That is the mechanism we rely on for enquiry form data. We monitor the status of that framework, and hold the UK International Data Transfer Addendum as a contractual fallback should it be suspended or withdrawn.
How long we keep it
- Enquiry form submissions — deleted from Netlify within 90 days of the enquiry being answered or closed.
- Enquiries that don't lead to an engagement — email correspondence deleted within 12 months.
- Engagement records — kept for six years from the end of the engagement, which is the period we need for tax, accounting and professional indemnity purposes, then deleted.
- Hosting logs — retained by Netlify under their own retention schedule; we do not extract or archive them.
If you'd like something deleted sooner, ask and we will unless we are legally required to keep it.
How we protect it
The site is served over HTTPS with HSTS and a content security policy. Access to the enquiry mailbox and the Netlify account is restricted to the principal, protected by multi-factor authentication. We do not hold enquiry data on removable media or personal devices outside of managed, encrypted storage.
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and tell you directly where the risk is high.
What we don't do
- We don't use your enquiry to send you marketing. There is no newsletter and no mailing list.
- We don't profile you or make any decision about you by automated means.
- We don't buy contact data or use enrichment services.
- We don't track you across sites, and we honour Global Privacy Control signals by virtue of tracking nothing.
Client engagement data
If you engage us for a review or build, the files you share are handled under the engagement terms we agree together: exchanged over a channel you approve, used only for the engagement, and deleted on completion. Where we handle personal data on your behalf we act as your processor, under a data processing agreement, and we're happy to work under your NDA.
Your rights
Under UK GDPR you can ask us to:
- tell you what personal data we hold about you (access)
- correct it (rectification) or delete it (erasure)
- stop or limit what we do with it (objection and restriction)
- give it to you in a portable form (portability)
Email hello@repologic.uk. We'll respond within one month, and we won't charge you for it. If we need to verify who you are, or need clarification to answer a broad request, that month starts once you've given us what we asked for.
Complaints
You have the right to complain directly to us if you think we've mishandled your personal data. Email hello@repologic.uk with "Data protection complaint" in the subject line, or write to us at the registered office below. We will acknowledge your complaint within 30 days and tell you what we intend to do about it. You can complain however you like — we won't insist on a particular form or channel.
You can also complain to the Information Commissioner's Office at any time, at ico.org.uk or 0303 123 1113. You don't have to come to us first, though we'd rather have the chance to put it right.
Children
This site offers professional services to businesses. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.
Changes to this policy
If we start doing something new with data — analytics, a newsletter, a new processor — we'll update this policy before we do it, and revise the date at the top. Material changes will be summarised here.