Privacy Policy
1. Who this policy covers — and an important distinction
DoorID Ltd processes personal data in two different roles. If you are an Applicant — a person asked to complete a verification by a business you are dealing with — that business is responsible for deciding why your information is needed, and DoorID processes it on that business's behalf and instructions. The notice shown before you start your verification (our Applicant Notice) explains that processing, and requests about it should go to the business that asked you to verify; we will help them respond. This policy covers everything DoorID controls in its own right: our website, client accounts, the client portal, billing, and support.
2. What we collect as controller, and why
| Data | Purpose | Lawful basis (UK GDPR) |
|---|---|---|
| Sign-up and account data — name, work email, company, phone number, country, intended use | Assessing your application, creating and administering the client account, contacting you about it | Contract; legitimate interests in vetting new clients |
| Acceptance records — which agreement versions you accepted, when, from which IP address and browser | Evidencing the agreements between us | Legitimate interests; legal obligation |
| Billing data — plan, usage counts, invoices, payment records, billing contact, payment-method reference | Charging for the service, accounting, tax | Contract; legal obligation |
| Portal usage — logins, actions, access logs, security events | Security, audit, fraud prevention, support | Legitimate interests |
| Support, contact-form and demo-request messages | Answering enquiries and requests | Legitimate interests; steps before a contract |
| Website analytics — page views and interactions, collected without cookies and without identifying you | Understanding how the site is used | Legitimate interests |
We do not run advertising pixels on our website, and we do not use non-essential cookies. If that changes we will ask for your consent first and update this policy.
3. Who we share it with
3.1 We share this data with service providers who help us run DoorID, under contracts that protect it: hosting and data storage (Replit, Inc. and its infrastructure providers, United States); email delivery (Twilio SendGrid, United States); text messages (Twilio Inc., United States); and payment processing. Our payment provider is Mollie B.V. (Netherlands): once automated payments are enabled for your account, your card or Direct Debit details are collected and held by Mollie, not by us; until then we invoice by bank transfer and hold no payment-card details. We may also share data with our professional advisers, and with regulators, courts or law-enforcement bodies where the law requires.
3.2 Where a provider processes data outside the United Kingdom, we rely on safeguards recognised under UK law (adequacy regulations, or standard contractual safeguards incorporated in the provider's terms).
3.3 We do not sell personal data. We do not use client data, and we do not allow our providers to use it, to train third-party artificial-intelligence models.
4. How long we keep it
Account and billing records: for as long as the account is active and afterwards for as long as tax and company law require (normally six years for financial records). Acceptance records: for the life of the account plus six years. Support and enquiry messages: 24 months from the last message. Portal access and security logs: 12 months. Sign-up applications we decline: 6 months.
5. Your rights
5.1 United Kingdom. You have the rights the UK GDPR gives you — access, rectification, erasure, restriction, portability and objection, and the right not to be subject to a solely automated decision with legal effects (we make none about clients). Contact paul@doorid.ai. You can complain to the Information Commissioner's Office at ico.org.uk; we would appreciate the chance to resolve your concern first.
5.2 Australia. If you are in Australia, we handle your personal information in accordance with the Australian Privacy Principles so far as they apply to us. You may ask to access or correct your information at paul@doorid.ai; we will respond within 30 days. Your information may be disclosed to recipients in the United Kingdom and the United States as described in section 3. If you are not satisfied with our response to a complaint, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
6. Security
We protect this data with encryption in transit, access controls, multi-factor authentication for portal users, audit logging and the other measures described in our Data Processing Agreement, Annex B. No system is perfectly secure; if a breach affects you we will tell you and the relevant regulator as the law requires.
7. Children, and automated decisions
Our services are for businesses; we do not knowingly collect data from anyone under 18 as a client. We make no automated decisions with legal effects about clients.
8. Changes and contact
We will publish changes to this policy with a new version number and, for material changes affecting clients, give notice through the portal. Questions about this policy: paul@doorid.ai, or write to DoorID Ltd at the address above.
DoorID Ltd · Company number 17176280 · ICO registration ZC153427
This Workspace, 18 Albert Road, Bournemouth, Dorset, BH1 1BZ
