1. Who is responsible for your information?
During the controlled private beta, IDpurge is operated personally by the individual who invited you to test the service. The invitation or accompanying beta communication must identify that operator and provide a direct contact method. Do not submit personal information if you have not been given those details.
Before public or paid launch, IDpurge will be operated through an incorporated limited company. This notice must then be updated with the company's full legal name, company number, registered office address and dedicated privacy contact details.
2. What information do we collect?
Depending on how you use the service, IDpurge may process:
- account and authentication information, such as your email address and login/session records;
- identity information, including your full legal name and previous names or aliases;
- contact information, including primary and additional email addresses and mobile number;
- address information, including postal address, postcode and country;
- service records, including scans, broker checks, exposure findings, evidence, request status, notes and action timestamps;
- correspondence and support information when you contact IDpurge or when IDpurge communicates with a broker on your behalf; and
- limited technical and security information needed to authenticate users, operate the service, prevent abuse and investigate faults.
IDpurge is designed to minimise the information it collects. You should not submit special category information, criminal-offence information or information about another person unless IDpurge has specifically asked for it and you are lawfully entitled to provide it.
3. Where does the information come from?
Most information is provided directly by you during account creation and onboarding. IDpurge may also obtain information from data brokers, people-search services, public-facing sources and organisations contacted as part of the privacy-removal process. Broker replies and removal confirmations may also become part of your service record.
4. Why do we use it and what is the lawful basis?
IDpurge uses personal information only where there is a lawful reason to do so.
- Providing the requested privacy service. During the invited beta, this is based primarily on legitimate interests in operating and testing the service and carrying out the privacy actions you ask IDpurge to perform. Where a paid customer contract exists in future, processing necessary to provide that service will also rely on performance of the contract or steps requested before entering it.
- Account security, fraud prevention and service reliability. This is based on legitimate interests in protecting users, systems and the service from misuse.
- Compliance with law and regulatory obligations. Where processing is required by law, IDpurge relies on the applicable legal obligation.
- Optional marketing or non-essential tracking. IDpurge does not currently use advertising or analytics tracking. If optional marketing or non-essential cookies are introduced, they must use an appropriate lawful basis and, where required, prior consent.
IDpurge does not use consent as a blanket justification for the core service. Where consent is specifically relied on, you may withdraw it at any time without affecting processing that was lawful before withdrawal.
5. Sharing information with brokers and service providers
To carry out a removal, opt-out, correction or related privacy request, IDpurge may need to send enough identifying information to the relevant broker or organisation to allow them to locate the correct record and verify the request. Only information reasonably necessary for that purpose should be shared.
IDpurge also uses specialist providers to host, authenticate, secure and operate the service. Current infrastructure includes Supabase, Vercel and Linode. Providers are expected to act only for the purposes for which they are engaged and to apply appropriate security measures.
IDpurge does not sell customer personal information and does not provide customer data to third parties for their own advertising purposes.
6. International transfers
Some technology providers may process or support personal information outside the United Kingdom. Where UK data-protection law restricts an international transfer, IDpurge must use an applicable lawful transfer mechanism and appropriate safeguards. Before public launch, the exact hosting regions, subprocessors and transfer safeguards must be documented and this notice updated where necessary.
7. How long do we keep information?
Personal information is kept only for as long as it is reasonably needed for the purpose for which it was collected. The factors used to decide retention include whether your account is active, whether broker requests remain open, whether records are needed to evidence actions taken on your behalf, security and fraud-prevention needs, dispute periods and legal or regulatory obligations.
Private-beta test information should be reviewed at the end of the beta and deleted or anonymised when it is no longer needed. Before public launch, IDpurge must adopt and publish a documented retention schedule and make sure operational deletion processes match it.
8. Security and data minimisation
IDpurge is designed around authenticated access, server-side privileged operations and per-user data separation. Access to customer records should be restricted to what is needed to provide and operate the service. No system can guarantee absolute security, but IDpurge aims to use proportionate technical and organisational measures and to minimise the personal information stored and disclosed.
9. Cookies and similar technologies
IDpurge currently aims to use only technologies that are strictly necessary for login, authentication, security and delivery of the service. It does not currently use advertising, behavioural tracking or analytics cookies. See the Cookie Notice for more detail.
10. Automated decision-making
IDpurge does not currently make solely automated decisions that produce legal effects or similarly significant effects for customers. Automated tools may assist operational work, but important customer and broker actions remain subject to human oversight.
11. Your data-protection rights
Depending on the circumstances, UK data-protection law may give you rights to:
- be informed about how your personal information is used;
- ask for access to your personal information;
- ask for inaccurate or incomplete information to be corrected;
- ask for information to be erased in certain circumstances;
- ask for processing to be restricted in certain circumstances;
- receive certain information in a portable format where the right applies;
- object to certain processing, including processing based on legitimate interests; and
- withdraw consent where processing is specifically based on consent.
During the private beta, use the direct contact method supplied with your invitation to make a rights request. Identity verification may be required before information is disclosed or changed.
12. Complaints
Please raise any privacy concern with IDpurge first using the contact method supplied with your invitation so it can be investigated. You also have the right to complain to the UK Information Commissioner's Office (ICO) if you believe your information has been handled unlawfully. Information about making a complaint is available from the ICO at ico.org.uk.
13. Children
IDpurge is not currently designed for children to open or manage their own accounts. Do not submit a child's personal information unless this has been specifically agreed with IDpurge and you have lawful authority to act for that child.
14. Changes to this notice
This notice will be reviewed as the service changes. Material changes affecting how personal information is used should be brought to users' attention before the new processing begins. A full legal-entity and supplier/transfer review is mandatory before public paid launch.