Who we are
A1Express is a trading name of CLOUDN8TIVE LLP, a limited liability partnership registered in England and Wales (OC447928). Our registered address is 82a James Carter Road, Mildenhall, Suffolk, IP28 7DE. We are the data controller for information you provide when using this service.
Questions or requests about this policy: email privacy@cloudn8tive.com.
What we collect and why
Data you give us
- Company number and name, to look up your filing history from the public Companies House register. This data is already public.
- Email address, to send you your filing receipt and any follow-up we've agreed (e.g. deadline reminders). We store a one-way hash (SHA-256) for internal audit logs. The plain email is only held in our email service queue long enough to deliver.
- Payment details, handled entirely by Stripe. Your card number never touches our servers. We receive only a tokenised reference and the last 4 digits of your card.
- Companies House authentication code, used once, in memory, to authorise the filing with Companies House. It is never written to disk, never logged, never stored. Four independent technical controls enforce this.
- Your name, and a phone number (optional, for support), collected when you create an account so we can address you properly and reach you if a filing needs attention. Both are erased on request.
- Marketing consent, only if you tick the opt-in when creating an account. We record the exact wording you agreed to and when, and you can unsubscribe at any time. Service emails (receipts, deadline reminders you asked for) are separate and always sent.
Data we collect automatically
- Server logs, standard access logs (IP address, request path, HTTP status, timestamp). Retained for 30 days, then deleted automatically.
- Error traces, anonymised crash reports sent to GlitchTip, our self-hosted error tracker. Auth codes and email addresses are stripped before any trace is recorded.
- First-party usage measurement, we measure how our own pages perform, using only our own systems, never a third-party analytics company. It uses no cookies and no browser storage of any kind. Visitors are identified only by a rotating pseudonymous key derived from network and browser signals (never your name, and nothing is stored on your device); your IP address is resolved to a country and region and then discarded, never stored. We record page views, how long a page holds your attention, scroll depth, and where you arrived from. If you give us your email to file, we link that visit's pseudonymous key to a one-way hash of your email, so we can understand the journey from first visit to filing, we never store the email itself in this measurement.
Data we do not collect
- No cookies, and no browser storage of any kind, for marketing, advertising, or measurement.
- No third-party analytics scripts on any page (including this one), our measurement is entirely first-party.
- No behavioural profiling, retargeting, or data brokering.
Lawful basis
We rely on the following lawful bases under UK GDPR:
- Contract, processing your filing and sending your receipt (Art. 6(1)(b)).
- Legitimate interests, server logs for security, fraud prevention, and service reliability. Our interests are proportionate; logs are short-lived and not used for profiling (Art. 6(1)(f)).
- Legitimate interests, first-party usage measurement to understand and improve the service. The data is pseudonymous, never sold or shared, and never used to make any decision about you as an individual (Art. 6(1)(f)).
- Consent, for deadline reminder emails: we hold your email for reminders until you switch them off (from your account or the link in any reminder email).
How long we keep data
| Data | Retention | Reason |
|---|---|---|
| Filing submission record | 7 years | UK statutory accounting retention requirement |
| Email address (receipt/refile) | 7 years or until erasure request | Link receipt to the filing record |
| Audit log (hashed email, no PII) | 7 years | Tamper-evident compliance record |
| Server access logs | 30 days | Security & fraud detection |
| First-party usage measurement (pseudonymous) | 13 months | Understand and improve the service over a full year |
| Payment token (Stripe reference) | Until refund window closes (90 days) | Chargebacks and refunds |
| CH authentication code | Not stored (in-memory only) | Security, never persisted by design |
Pseudonymisation (A-8): email addresses in audit logs are stored as SHA-256 hashes. The hash lets us identify if a given email appears in the audit trail without storing the email itself. This means audit logs are retained for 7 years without holding personally identifiable email addresses.
Who we share data with
- Companies House, your company number, name, and accounts data are transmitted to file your accounts. This is the purpose of the service.
- Stripe, payment processing. Stripe is PCI DSS Level 1 certified. See Stripe's Privacy Policy.
- Resend, transactional email delivery (your receipt). Resend receives your email address to deliver the message. See Resend's Privacy Policy.
- Cloudflare, CDN, DNS, and DDoS protection. Cloudflare processes request metadata (IP addresses) in accordance with its Privacy Policy.
We do not sell, rent, or share your personal data with any third party for marketing purposes.
Your rights
Under UK GDPR you have the right to:
- Access, request a copy of the personal data we hold about you (Subject Access Request).
- Rectification, ask us to correct inaccurate data.
- Erasure, ask us to delete your personal data where we have no legal obligation to retain it (see retention table above, some data must be kept for 7 years). Erasure also removes the link between your email and any pseudonymous usage history we measured, so that history can no longer be attributed to you.
- Restriction, ask us to restrict processing while a dispute is resolved.
- Portability, receive your data in a machine-readable format.
- Object, object to processing based on legitimate interests.
How to exercise your rights
Email privacy@cloudn8tive.com with the subject line "Privacy Request" and your registered email address. We'll respond within 30 days. For a Subject Access Request (SAR) or erasure request, you can also use our automated endpoint:
POST /api/privacy/request
Content-Type: application/json
{
"type": "SAR | erasure",
"email": "your@email.com"
}The endpoint sends a magic-link confirmation to the email address provided before processing any request.
Complaints
If you're not happy with how we've handled your data, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint.
Changes to this policy
We'll post any material changes here with an updated effective date. For significant changes we'll also email registered users.