This policy explains how Robert Caswell, trading as Debt Challenger ("we", "us") collects, uses, and protects your personal data when you use the Debt Challenger service at debtchallenger.co.uk (the "Service").
We are the data controller for the personal data described here. We are committed to handling your data lawfully, fairly, and transparently in accordance with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.
Controller: Robert Caswell, trading as Debt Challenger (sole trader)
Trading address: 323 Prince Rupert Drive, Aylesbury, HP19 9DF
Contact for data protection enquiries: privacy@debtchallenger.co.uk
We have not appointed a Data Protection Officer (we are not legally required to). The same contact email reaches the person responsible for data protection compliance.
Each processing activity has at least one of the lawful bases set out in Article 6(1) of the UK GDPR.
| Purpose | Lawful basis |
|---|---|
| Providing the Service (account, letter generation, deadline tracking) | Contract performance (Art 6(1)(b)) |
| Processing your payment, sending invoices, preventing payment fraud | Contract performance + legitimate interests (Art 6(1)(b) + (f)) |
| Sending transactional emails (verification, password reset, deadline reminders) | Contract performance (Art 6(1)(b)) |
| Preventing abuse, fraud, multi-account evasion of plan limits | Legitimate interests (Art 6(1)(f)) |
| Reviewing your data to debug issues and improve the Service | Legitimate interests (Art 6(1)(f)) |
| Recording administrative actions taken on your account (audit log) | Legitimate interests + legal obligation (Art 6(1)(f) + (c)) |
| Retaining records for tax and accounting (where applicable) | Legal obligation (Art 6(1)(c)) |
| Marketing emails (only if you opt in) | Consent (Art 6(1)(a)) |
We do not process special category personal data (such as health, religion, or biometric data). If you choose to mark yourself as a vulnerable customer during onboarding, that flag is treated as ordinary personal data and used only to adjust how we communicate with you.
We use AI services (see Section 6 — Sub-processors) to:
These processes are not automated decisions with legal or similarly significant effects on you under Article 22 of the UK GDPR. Every generated letter is reviewed by you before it is posted; no debt is reduced, written off, or settled by the Service itself.
| Category | Retention |
|---|---|
| Account, cases, letters, attachments | Until you delete your account |
| Audit log entries (admin access records) | 7 years for accountability and to defend against complaints |
| Server logs (IP, error traces) | Up to 30 days |
| Stripe transaction records | 6 years (HMRC requirement) |
| Database backups | 30 days rolling |
When you delete your account (Settings → Danger Zone or by emailing privacy@debtchallenger.co.uk), we permanently delete your account, cases, letters, attachments, sender profiles, and uploaded files. Some residual records may persist for the periods stated above for legal reasons (e.g. Stripe transactions for tax compliance).
We use the following third parties to deliver the Service. Each is contractually bound to handle your data in compliance with UK GDPR.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and file storage | UK (eu-west-2) |
| Vercel | Web hosting and serverless compute | EU / US (DPF certified) |
| Anthropic | AI processing of documents and letter generation | US (DPF certified) |
| Stripe Payments UK Ltd | Payment processing | UK / US (DPF certified) |
| Resend | Transactional email delivery | EU / US (DPF certified) |
| Upstash | Rate limiting and caching | EU |
| Cloudflare | CAPTCHA (Turnstile) and edge security | Global edge / EU origin |
| Sentry | Error and performance monitoring (helps us find and fix faults) | EU / US (DPF certified) |
We update this list when we add or change providers. Where personal data is transferred outside the UK, we rely on appropriate safeguards such as the UK Extension to the EU-US Data Privacy Framework or Standard Contractual Clauses approved by the ICO.
Under UK GDPR you have the following rights, which you can exercise at any time by emailing privacy@debtchallenger.co.uk:
We respond to data subject requests within one calendar month. We may extend this by a further two months for complex requests, in which case we will tell you within the first month.
If you are unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint.
No system is perfectly secure. If you believe your account has been compromised, change your password immediately and contact us.
We send service-related emails (account verification, password reset, deadline reminders, security alerts) based on contract performance. These cannot be opted out of without closing your account.
We do not currently send marketing emails. If we introduce them, we will rely on consent (or the soft opt-in under PECR for existing customers) and you will be able to opt out at any time.
The Service is intended for adults aged 18 or over. We do not knowingly collect data from children. If you believe a child has provided personal data to us, please contact privacy@debtchallenger.co.uk and we will delete it.
We may update this policy from time to time. We will notify you of material changes by email at the address on your account and update the "Last updated" date below. Continued use of the Service after such notice constitutes acceptance of the updated policy.
Last updated: 20 May 2026. Version 1.0.