Privacy

Privacy policy

Last updated: 28 July 2026

RepoLogic Limited (company no. 05969213, registered in England & Wales; "we", "us") provides financial modelling and group reporting consultancy through this website, repologic.uk. This policy explains what personal data we handle, why, how long we keep it, and the rights you have over it. We've kept it in plain language because that's how we write everything.

Who is responsible for your data

RepoLogic Limited is the data controller for personal data collected through this site. Our registered office is 128 City Road, London EC1V 2NX. You can reach us about anything in this policy at hello@repologic.uk.

We are not required to appoint a Data Protection Officer, and have not appointed one. Data protection matters are handled by the principal directly.

What we collect, and why

The enquiry form. If you complete the enquiry form on our home page, we collect your name, work email address, the enquiry category you select, and anything you type into the free-text fields (systems involved, number of legal entities, and your description of the situation). We use this solely to respond to your enquiry and, if an engagement follows, to deliver it. Submissions are received and stored by Netlify Forms on our behalf, and forwarded to our Microsoft 365 mailbox.

Please do not include confidential or sensitive information in the form. Send us enough to start a conversation, not your actual data. Do not paste client-identifying details, live financial data, personal data about other people, or anything falling into a special category under UK GDPR. If a matter is sensitive, choose "Confidential — prefer to discuss" and we will arrange a secure channel.

Email correspondence. If you write to us directly, we hold your name, email address and whatever you send, including Model Health Check results if you use the "send my results" button. Same purpose, same basis.

The Model Health Check. The health check runs entirely in your browser. Your answers and score are not transmitted to us, stored, or tracked unless you choose to email them to us.

Hosting logs. Our site is hosted by Netlify, whose servers keep standard technical logs (IP address, pages requested, timestamps) for security and reliability. We don't use these to identify visitors.

Fonts. Typefaces are served directly from repologic.uk. No request leaves this site to load them, and no third party sees your visit.

We use no analytics, no advertising trackers, and no cookies set by us. Netlify may set a strictly necessary cookie in connection with form submission and spam prevention; we set none.

Our lawful bases

We do not rely on consent for anything on this site, so there is nothing here for you to consent to or withdraw.

Who we share it with

Nobody, except the service providers that operate the site and our email:

Both are engaged under written data processing terms that meet Article 28 of the UK GDPR. We do not sell, rent or trade personal data, and we never will. We will disclose personal data where the law requires it, and will tell you unless we are prohibited from doing so.

Where your data goes

Microsoft 365 email is contracted through Microsoft's Irish entity, and the EU benefits from a UK adequacy decision, so no additional transfer safeguard is required.

Netlify, Inc. is based in the United States. Netlify is certified under the EU–US Data Privacy Framework and has opted into the UK Extension to it (the "UK–US Data Bridge"), which the UK government recognises as providing an adequate level of protection. That is the mechanism we rely on for enquiry form data. We monitor the status of that framework, and hold the UK International Data Transfer Addendum as a contractual fallback should it be suspended or withdrawn.

How long we keep it

If you'd like something deleted sooner, ask and we will unless we are legally required to keep it.

How we protect it

The site is served over HTTPS with HSTS and a content security policy. Access to the enquiry mailbox and the Netlify account is restricted to the principal, protected by multi-factor authentication. We do not hold enquiry data on removable media or personal devices outside of managed, encrypted storage.

If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the ICO within 72 hours of becoming aware of it, and tell you directly where the risk is high.

What we don't do

Client engagement data

If you engage us for a review or build, the files you share are handled under the engagement terms we agree together: exchanged over a channel you approve, used only for the engagement, and deleted on completion. Where we handle personal data on your behalf we act as your processor, under a data processing agreement, and we're happy to work under your NDA.

Your rights

Under UK GDPR you can ask us to:

Email hello@repologic.uk. We'll respond within one month, and we won't charge you for it. If we need to verify who you are, or need clarification to answer a broad request, that month starts once you've given us what we asked for.

Complaints

You have the right to complain directly to us if you think we've mishandled your personal data. Email hello@repologic.uk with "Data protection complaint" in the subject line, or write to us at the registered office below. We will acknowledge your complaint within 30 days and tell you what we intend to do about it. You can complain however you like — we won't insist on a particular form or channel.

You can also complain to the Information Commissioner's Office at any time, at ico.org.uk or 0303 123 1113. You don't have to come to us first, though we'd rather have the chance to put it right.

Children

This site offers professional services to businesses. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.

Changes to this policy

If we start doing something new with data — analytics, a newsletter, a new processor — we'll update this policy before we do it, and revise the date at the top. Material changes will be summarised here.