Privacy Policy

Last updated: March 2026

1. Introduction

CivicShield ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the CivicShield platform at civicshield.co.uk.

We are a UK-based legal process assistant and comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. What Data We Collect

We collect the following categories of personal data:

  • Account information: Name, email address, username, and password (hashed)
  • Profile information: Phone number and address (optional, provided by you)
  • Issue data: Descriptions of issues you submit, including names of organisations, dates, and circumstances
  • Complaint data: Generated complaint letters, recipient details, and correspondence records
  • Usage data: Pages visited, features used, and interaction patterns to improve the service
  • Technical data: IP address, browser type, device information, and cookies

3. How We Use Your Data

We use your personal data for the following purposes:

  • To provide and operate the CivicShield platform
  • To generate AI-powered legal analysis of your issues
  • To create and send complaint letters on your behalf
  • To manage your account and communicate with you about the service
  • To improve our service through anonymised usage analytics
  • To comply with legal obligations

4. Legal Basis (UK GDPR)

We process your personal data on the following legal bases:

  • Contract: Processing necessary to provide the CivicShield service you have signed up for (Article 6(1)(b))
  • Legitimate interests: Improving our service, preventing fraud, and ensuring security (Article 6(1)(f))
  • Consent: Where you opt in to optional features such as marketing communications (Article 6(1)(a))
  • Legal obligation: Where we are required to retain data by law (Article 6(1)(c))

5. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required by law to retain certain records.

Issue and complaint data is retained for the duration of your account to allow tracking and follow-up. Usage analytics are anonymised and retained for up to 24 months.

6. Your Rights

Under the UK GDPR, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you (Subject Access Request)
  • Right to rectification: Request correction of inaccurate or incomplete data
  • Right to erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to restrict processing: Request that we limit how we use your data
  • Right to data portability: Request your data in a machine-readable format
  • Right to object: Object to processing based on legitimate interests

To exercise any of these rights, contact us at support@civicshield.co.uk. We will respond within 30 days.

7. Cookies

We use essential cookies to operate the platform (authentication, session management, and theme preferences). These are strictly necessary and do not require consent.

We may use analytics cookies to understand how users interact with CivicShield. These are only set with your consent. You can manage cookie preferences through your browser settings.

8. Third Parties

We share data with the following third parties, only as necessary to provide the service:

  • Anthropic (Claude AI): Issue descriptions are sent for AI analysis. Anthropic processes data under their API terms and does not retain prompts for training.
  • Vercel: Hosting provider for the application
  • Railway: Database hosting provider
  • Stripe: Payment processing for subscriptions (Pro and Agency plans)

We do not sell your personal data to any third party. All third-party processors are bound by data processing agreements.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS), hashed passwords, secure database access controls, and regular security reviews.

10. Contact

If you have any questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Email: support@civicshield.co.uk

If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

← Back to CivicShield