Home

Privacy Policy

This policy explains how Robert Caswell, trading as Debt Challenger ("we", "us") collects, uses, and protects your personal data when you use the Debt Challenger service at debtchallenger.co.uk (the "Service").

We are the data controller for the personal data described here. We are committed to handling your data lawfully, fairly, and transparently in accordance with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.

1. Who we are

Controller: Robert Caswell, trading as Debt Challenger (sole trader)
Trading address: 323 Prince Rupert Drive, Aylesbury, HP19 9DF
Contact for data protection enquiries: privacy@debtchallenger.co.uk

We have not appointed a Data Protection Officer (we are not legally required to). The same contact email reaches the person responsible for data protection compliance.

2. What data we collect

2.1 Data you provide directly

  • Account: full name, email address, hashed password, postal address (used as the "from" address on letters)
  • Vulnerable customer self-flag (optional, set during onboarding) and the date you set it
  • Subscription tier, billing cycle, sender profiles (additional names and addresses for letters)
  • Files you upload: letters from debt collection agencies, your responses, and any other correspondence you choose to attach to a case
  • Free-text feedback you give us when redrafting a letter

2.2 Data we generate about your activity

  • Letters generated by the Service on your behalf (and stored in your account)
  • Structured analysis we produce from documents you upload (e.g. flags such as "valid agreement provided", "assignment chain incomplete")
  • Posting dates, Royal Mail tracking numbers, and computed response deadlines
  • Audit log of administrative actions taken by our staff on your account (e.g. viewing letters, changing tier)
  • Server logs: timestamps, IP address, user agent, error traces. Retained for up to 30 days for security and debugging

2.3 Data we receive from third parties

  • Stripe: payment status, last four digits of the card, expiry, country of issue, card fingerprint (a non-reversible hash used to prevent abuse). We never see or store full card numbers.
  • Cloudflare Turnstile: a CAPTCHA outcome flag during registration (no personal identifiers captured by us)

3. How we use your data & lawful bases

Each processing activity has at least one of the lawful bases set out in Article 6(1) of the UK GDPR.

PurposeLawful basis
Providing the Service (account, letter generation, deadline tracking)Contract performance (Art 6(1)(b))
Processing your payment, sending invoices, preventing payment fraudContract performance + legitimate interests (Art 6(1)(b) + (f))
Sending transactional emails (verification, password reset, deadline reminders)Contract performance (Art 6(1)(b))
Preventing abuse, fraud, multi-account evasion of plan limitsLegitimate interests (Art 6(1)(f))
Reviewing your data to debug issues and improve the ServiceLegitimate interests (Art 6(1)(f))
Recording administrative actions taken on your account (audit log)Legitimate interests + legal obligation (Art 6(1)(f) + (c))
Retaining records for tax and accounting (where applicable)Legal obligation (Art 6(1)(c))
Marketing emails (only if you opt in)Consent (Art 6(1)(a))

We do not process special category personal data (such as health, religion, or biometric data). If you choose to mark yourself as a vulnerable customer during onboarding, that flag is treated as ordinary personal data and used only to adjust how we communicate with you.

4. Automated processing

We use AI services (see Section 6 — Sub-processors) to:

  • Extract structured information from documents you upload (e.g. agency name, debt amount, addresses)
  • Analyse correspondence you upload (e.g. whether a SAR response includes the original agreement, whether claims are made about assignment)
  • Generate draft letters grounded in a curated library of UK statutes and regulator rules — each composed fresh for the individual case, not a fixed template

These processes are not automated decisions with legal or similarly significant effects on you under Article 22 of the UK GDPR. Every generated letter is reviewed by you before it is posted; no debt is reduced, written off, or settled by the Service itself.

5. Retention

CategoryRetention
Account, cases, letters, attachmentsUntil you delete your account
Audit log entries (admin access records)7 years for accountability and to defend against complaints
Server logs (IP, error traces)Up to 30 days
Stripe transaction records6 years (HMRC requirement)
Database backups30 days rolling

When you delete your account (Settings → Danger Zone or by emailing privacy@debtchallenger.co.uk), we permanently delete your account, cases, letters, attachments, sender profiles, and uploaded files. Some residual records may persist for the periods stated above for legal reasons (e.g. Stripe transactions for tax compliance).

6. Sub-processors

We use the following third parties to deliver the Service. Each is contractually bound to handle your data in compliance with UK GDPR.

ProviderPurposeLocation
SupabaseDatabase and file storageUK (eu-west-2)
VercelWeb hosting and serverless computeEU / US (DPF certified)
AnthropicAI processing of documents and letter generationUS (DPF certified)
Stripe Payments UK LtdPayment processingUK / US (DPF certified)
ResendTransactional email deliveryEU / US (DPF certified)
UpstashRate limiting and cachingEU
CloudflareCAPTCHA (Turnstile) and edge securityGlobal edge / EU origin
SentryError and performance monitoring (helps us find and fix faults)EU / US (DPF certified)

We update this list when we add or change providers. Where personal data is transferred outside the UK, we rely on appropriate safeguards such as the UK Extension to the EU-US Data Privacy Framework or Standard Contractual Clauses approved by the ICO.

7. Your rights

Under UK GDPR you have the following rights, which you can exercise at any time by emailing privacy@debtchallenger.co.uk:

  • Access — request a copy of your personal data (Art 15)
  • Rectification — ask us to correct inaccurate data (Art 16). You can edit most fields yourself in Settings.
  • Erasure — ask us to delete your data (Art 17). You can do this yourself from Settings → Danger Zone for immediate effect.
  • Restriction — ask us to pause certain processing (Art 18)
  • Portability — receive your data in a machine-readable format (Art 20)
  • Objection — object to processing based on legitimate interests (Art 21)
  • Withdraw consent — where consent is the lawful basis (e.g. marketing emails)

We respond to data subject requests within one calendar month. We may extend this by a further two months for complex requests, in which case we will tell you within the first month.

If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint.

8. Security

  • All data is transmitted over HTTPS / TLS 1.2 or higher.
  • Passwords are hashed using bcrypt with a work factor of 12.
  • File storage is private; access requires short-lived signed URLs scoped to your account.
  • We restrict administrative access to a small, named list of staff. Every privileged action on a user account is recorded in an internal audit log.
  • We use a Cloudflare Turnstile CAPTCHA on registration to slow down automated abuse.
  • We apply per-IP and per-account rate limits on sensitive endpoints (registration, password reset, file upload).

No system is perfectly secure. If you believe your account has been compromised, change your password immediately and contact us.

9. Cookies and similar technologies

We use a small number of strictly necessary cookies that are required for the Service to function:

  • Authentication session cookie (set on login, cleared on sign-out)
  • CSRF protection cookie
  • Cloudflare Turnstile cookie during registration only

We do not currently use analytics, advertising, or third-party tracking cookies. If we add any in future, we will update this policy and present a consent banner before any non-essential cookie is set.

10. Marketing communications

We send service-related emails (account verification, password reset, deadline reminders, security alerts) based on contract performance. These cannot be opted out of without closing your account.

We do not currently send marketing emails. If we introduce them, we will rely on consent (or the soft opt-in under PECR for existing customers) and you will be able to opt out at any time.

11. Children

The Service is intended for adults aged 18 or over. We do not knowingly collect data from children. If you believe a child has provided personal data to us, please contact privacy@debtchallenger.co.uk and we will delete it.

12. Changes to this policy

We may update this policy from time to time. We will notify you of material changes by email at the address on your account and update the "Last updated" date below. Continued use of the Service after such notice constitutes acceptance of the updated policy.

Last updated: 20 May 2026. Version 1.0.