1Who we are
Varde is provided by Stripy Fish Networks Limited — see our company details below.
Stripy Fish Networks Limited is a company registered in England and Wales (company number 4958546), registered office 26 Wellhead Lane, Westbury, Wiltshire, BA13 3PT ("we", "us", "Stripy Fish Networks").
We are registered with the UK Information Commissioner's Office as a data controller for the personal data described in this notice — registration number ZC148489.
We're a small organisation and aren't required to appoint a Data Protection Officer under UK GDPR. We haven't appointed one — for anything privacy-related, contact privacy@stripyfish.net.
2What we collect, and why
What we collect depends on how far you use the platform. The table below reflects our internal Record of Processing Activities and is kept in step with it.
Layer 1 — free self-assessment
You can complete our free self-assessment without an account. We do not ask for your name or firm details. If you submit a request through our "request access" form, the email address (and optionally your firm name and region) you provide is used only to follow up on that request and is retained for up to 2 years, then deleted. The assessment itself is designed to cover your firm's processes and systems, not client names, regulatory reference numbers, or other personal data — though as with any free-text answer, it's possible to incidentally include something personal the questions don't ask for.
Legal basis: if you found and used the tool yourself and submitted a request-access form, we follow up on your unprompted request relying on our legitimate interest in responding to it (Article 6(1)(f) UK GDPR). If we (or a reseller partner acting on our behalf) proactively invited your firm, we identified your firm using a public regulatory record such as the FCA Register or Companies House, and obtained your specific contact address from your firm's own published website — that invitation relies on our legitimate interest in reaching firms who may benefit from the service (Article 6(1)(f) UK GDPR) — every such invitation includes a one-click opt-out link, in addition to your rights below.
Layer 2 — portal accounts and gap reports
A paid gap report requires a portal account. We collect your name, work email address, organisation name, and authentication credentials (a passkey public key, or a password hash — we never store your actual password or passkey private key). If you provide one, we also hold a mobile number against your account, encrypted at rest. We also store the content of your gap report conversation and audit log entries recording actions taken on your account (not their content).
Legal basis: contract performance — delivering the paid service you've signed up for (Article 6(1)(b) UK GDPR).
Layer 3 — policy documents
Generating a policy document involves organisational context you provide: your FCA firm reference number, the name and title of your CF10 (or equivalent) holder, your firm's address, and the resulting policy content itself, along with a record of who reviewed and approved it and when.
Legal basis: contract performance (Article 6(1)(b) UK GDPR).
Layer 4 — compliance packs
A compliance pack is a point-in-time snapshot of your firm's gap report and policy document content, frozen at the moment you generate it, so it can serve as a defensible record of the compliance steps taken at that time. It's downloadable as a PDF or HTML document, and can optionally be shared via a time-limited public link you create yourself. We record who generated it and when.
Legal basis: contract performance (Article 6(1)(b) UK GDPR).
Access invitations
If you're invited onto the platform, we hold your email address and a hashed invitation token for up to 10 days, deleted on acceptance or expiry.
Legal basis: contract performance — giving your organisation's staff access is part of delivering the service already agreed with your firm (Article 6(1)(b) UK GDPR). Where an invitation instead came from us proactively contacting your firm using a public record, see the Layer 1 basis above.
Payment
Paid layers are billed through Stripe. We pass Stripe your billing name and email address and receive back payment status and metadata — we never see or store your full card number. Stripe processes and retains payment data under its own privacy policy and terms, which apply alongside this notice.
Legal basis: contract performance (Article 6(1)(b) UK GDPR).
Audit logs
We keep a security and compliance audit trail across the platform — a hashed (not plain-text) identifier for who took the action, event type, timestamp, and (where applicable) your IP address and browser/device identifier. Audit entries record that an action happened, not its content. We keep this trail for up to 6 years, in line with the Corporation Tax record-keeping period under the Finance Act 1998, after which entries are automatically deleted.
Legal basis: legitimate interests in maintaining the security and integrity of the platform (Article 6(1)(f) UK GDPR). The 6-year limit reflects our storage-limitation obligation under Article 5(1)(e) UK GDPR to keep data for no longer than necessary.
Support chat
If you use the support chat widget — available whether or not you have an account — we collect the full content of your messages, and, only if you choose to provide one, a contact email address so we can follow up. Messages are handled by a tiered AI assistant: most questions are answered automatically, and only escalate to a member of our team if the assistant can't help or you explicitly report a bug, billing, or legal issue.
Legal basis: legitimate interests in operating basic customer support for the platform (Article 6(1)(f) UK GDPR).
Retention: conversations are automatically deleted 90 days after your last message (plus a grace period) if your firm hasn't registered a portal account or isn't a paying customer, or after 6 years if it has and is — the same statutory-claim window we use for our audit log. Anonymous conversations (no account at all) always use the 90-day figure. Tickets — the internal record that an escalation happened, separate from the conversation itself — are kept for up to 6 years regardless of account status, then automatically deleted.
3How we use AI
Varde is AI-powered — this makes assessments faster and more consistent than a manual questionnaire. Assessment answers, gap report conversations, policy generation context, and support chat messages are processed by Claude, made by Anthropic, to produce your results or a response.
Your answers are not shared with any other third party and are never used to train AI models. For Layer 3 policy documents, a second AI pass automatically checks the document for regulatory accuracy immediately after it is generated — findings are stored for our own internal review and are never applied to your document or shown externally. Anthropic retains API data for up to 30 days for security and operational purposes only, after which it is deleted.
Legal basis: generating your results uses the same legal basis as the layer you're using (see section 2, above). The automated quality-check pass is a narrower, separate use of that same data, carried out under our legitimate interest in maintaining service quality (Article 6(1)(f) UK GDPR) — findings are visible only to our own staff under confidentiality obligations, and this review is never shared externally.
AI output across every layer is advisory only — it surfaces potential gaps and drafts documents for your review. No decision with a legal or similarly significant effect on you is made solely by automated means (Articles 22A–22D UK GDPR — the automated decision-making framework inserted by the Data (Use and Access) Act 2025, replacing the previous Article 22); policy documents always require human review and approval before use.
5International transfers
Anthropic, Stripe, and Google (where you've accepted analytics cookies) all have infrastructure that extends outside the UK and EEA, including to the United States. Each transfer is covered by the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum (Addendum B.1.0, issued by the ICO) — the specific safeguard that satisfies the UK's transfer regime (since 5 February 2026, the "data protection test" under Article 46(1A) UK GDPR, following the Data (Use and Access) Act 2025's reform of this area), confirmed directly against each provider's published data processing agreement. We keep transfers outside the UK to what's necessary to run the service.
Fasthosts, our email delivery provider, is UK-based — sending an invitation or notification email does not involve an international transfer.
Our hosting infrastructure is located within the United Kingdom. Storing and processing your data there does not itself involve any international transfer.
6How long we keep data
| What | Retention |
|---|---|
| Completed Layer 1 assessments | 90 days after completion (plus a grace period) if no one at your firm has registered a portal account or your firm isn't a paying customer, or up to 6 years if it has and is — a per-record age cap that applies even while your firm remains an active customer, not extended indefinitely just because the relationship continues. We can retain your firm's records for longer if the FCA directs us to. |
| In-progress Layer 1 sessions | 30 days |
| Access requests (request-access form, contact follow-ups) | 2 years from submission (plus a grace period), then automatically deleted |
| Gap reports (Layer 2) | A report in progress with no activity from your team for 90 days moves to a "lapsed" state and is automatically deleted after a further 90-day grace period if still not resumed. A completed report follows the same 90-day/6-year age cap as assessments above, based on your firm's account/payment status. You can request deletion at any time before either applies (see your rights, below). |
| Policy documents (Layer 3) | 90 days after generation (plus a grace period) if your firm hasn't registered a portal account or isn't a paying customer, or up to 6 years if it has and is — then automatically deleted. You can also request deletion at any time. |
| Compliance packs (Layer 4) | 90 days after generation (plus a grace period) if your firm hasn't registered a portal account or isn't a paying customer, or up to 6 years if it has and is — then automatically deleted. You can also request deletion at any time. |
| Access invitations | 10 days from issue, regardless of whether it was used |
| Audit logs | Up to 6 years, then automatically deleted |
| Support chat conversations | 90 days after your last message (plus a grace period) if your firm hasn't registered a paying account, or up to 6 years if it has. Anonymous conversations always use the 90-day figure. You can request deletion at any time. |
| Support tickets | Up to 6 years regardless of account status — treated as an internal record that an escalation happened, the same way as our audit log. You can request deletion at any time. |
Automatic deletion is live for lapsed gap reports, completed assessments and gap reports that reach the age cap above, policy documents, compliance packs, and support chat conversations/tickets — you can also request deletion at any time before that.
7Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your personal data, subject to the limit below
- Restrict processing in certain circumstances
- Object to processing based on legitimate interests — where you do, we must stop unless we can show compelling legitimate grounds that override your interests (see below)
- Port your data to another provider in a structured, machine-readable format — this applies where processing is based on contract or consent and carried out by automated means; it doesn't extend to data we hold under legitimate interests, such as audit logs
- Complain to us directly if you think we've got something wrong, or to the ICO (see Contact, below)
Objecting to legitimate interests processing
We rely on legitimate interests (Article 6(1)(f) UK GDPR) for: proactively inviting your firm to try Layer 1, identified using a public regulatory record; audit logging; internal AI quality-assurance review; and operating the support chat widget (see section 2 and section 3, above). You can object to any of these at any time — for outreach invitations specifically, every invitation includes a one-click opt-out link that stops further contact immediately, in addition to emailing us. Once you object, we stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed to establish, exercise, or defend a legal claim.
Erasure has a legal limit
You can ask us to erase your personal details (name, email, mobile number) at any time and we will act on that promptly. Under UK GDPR Article 17(3)(b), this doesn't extend to the underlying compliance record itself where a legal retention obligation applies — compliance records may be retained for the periods set out above, in line with our data retention policy. In that case we remove your personal details immediately and retain the record, with no way to identify you from it, until its retention period ends.
Backups
When we delete your personal data — whether in response to an erasure request or through automatic retention expiry — it's removed from our live systems immediately. Encrypted backups are retained separately for up to 12 months as part of our disaster recovery process, on a fixed rotation schedule, and are automatically purged once that window passes. During this period your data is encrypted and inaccessible in normal operation; it's only ever touched in the event of a genuine disaster-recovery restore, and any pending erasure requests are re-applied immediately after a restore, before the system returns to service.
To exercise any of these rights, email privacy@stripyfish.net. We'll respond within one month, or let you know within that time if we need up to a further two months for a complex or high-volume request (UK GDPR Article 12, Article 12A). That one-month clock runs from whichever is latest: when we receive your request, or — if we need to check your identity first — when you provide what we ask for.
8Cookies
Strictly necessary
We use two strictly necessary cookies, both set with the Secure, HttpOnly, and SameSite flags and unreadable by other sites or by JavaScript: a session cookie (__Host-session) that keeps you signed in, and — only if you verify your email to view a specific assessment report or transcript link — a per-assessment cookie that remembers that verification for up to 90 days so you don't have to re-verify on every visit. These are set automatically, without a consent prompt, because the site cannot function without them.
Analytics
We use Google Analytics (GA4) to understand how visitors use the site — pages visited, approximate location, device and browser type, and referring site. This is aggregated usage data; it is never linked to your assessment answers, gap report content, or policy documents. No analytics cookie is set, and no data reaches Google, until you actively accept it: a banner asks for your consent on first visit (Google Consent Mode v2, denied by default), and your choice is remembered so you're not asked again on later visits. You can change your mind at any time by clearing your browser's local site data for this site (your cookie choice itself is stored in local storage, not a cookie — a plain "clear cookies" option in some browsers won't reset it on its own), which brings the banner back on your next visit.
Where you accept, we enable IP anonymisation so Google truncates your IP address before storing it, and we do not use Google Analytics' advertising or remarketing features. Google Ireland processes this data as our processor, under the terms of the Google Analytics Data Processing Terms — see Google's Privacy Policy for how Google itself handles the data, including its own retention settings.
We don't run any advertising or third-party tracking scripts beyond Google Analytics, and we don't use tracking cookies for any purpose other than the analytics described above.
9Security
Your data is encrypted in transit and access-controlled. Every change made to your organisation's data is captured in an audit log. Passwords are never stored in plain text; passkey-based sign-in never transmits a private key to our servers at all.
If something goes wrong
If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we'll notify the ICO within 72 hours as required by UK GDPR Article 33, and tell you directly under Article 34 if the risk to you is high.
10Not legal or regulatory advice
Varde surfaces potential compliance gaps and drafts supporting documents — it is not legal or regulatory advice. Consult a qualified compliance professional for guidance specific to your firm.
11Changes to this notice
We'll update the date at the top of this page whenever we make a material change, and where a change affects how we handle your data going forward, we'll take reasonable steps to let account holders know.
12Contact and complaints
Stripy Fish Networks Limited
26 Wellhead Lane, Westbury, Wiltshire, BA13 3PT
privacy@stripyfish.net
ICO registration: ZC148489
If you think we've infringed UK GDPR in how we've handled your data, you can complain to us directly by emailing privacy@stripyfish.net — we'll acknowledge your complaint within 30 days and, without undue delay, look into it and let you know the outcome (Data Protection Act 2018, section 164A). You don't need to complain to us first, and complaining to us doesn't affect your right to complain to the UK Information Commissioner's Office at any time, at ico.org.uk/make-a-complaint.