Privacy
Privacy notice
What we hold about you, why, for how long, and your rights.
Who we are
User Solutions Limited, trading as Harrier Signals, is the controller for the processing described here. We are registered in England and Wales, company number 06359733, at Belmont Suite, Paragon Business Park, Chorley New Road, Horwich, Bolton, BL6 6HG. Our ICO registration reference is ZC239532. Contact hello@harriersignals.co.uk, or write to the registered office, for privacy questions, rights requests or complaints. Our director is responsible for data protection.
Information we use and why
When you start a trial or a subscription we use your organisation's legal name and company number, your work email address, your first name if you give it, the trade or role you choose if you choose one, the briefing you pick, your coverage or your confirmed sites, your alert preference and your marketing preference, together with the records of what you ask us to do. Estate Intelligence uses each confirmed care home as the centre of its own comparison circle. Regional supplier coverage uses the centre of your postcode district. We use this information to check that the customer is an incorporated business, to verify your address, to set up and deliver the briefing and to answer support enquiries.
The customer is your organisation, not you personally. Our lawful basis for personal data about a corporate customer's staff is our legitimate interest in administering the service securely and accurately. Where the law requires a record, for example for tax, the basis is legal obligation. Optional marketing to you rests on your consent, given separately.
We keep evidence that the customer accepted the terms and any order. That evidence is the verified work email address, the organisation's legal name and company number, the date and time of acceptance and confirmation, and the version of the terms, the offer and the privacy information shown at the time. We do not ask for the name or job title of the person accepting. We record any marketing consent, and any withdrawal of it, separately. Our basis for keeping proportionate contract evidence is our legitimate interest in accountability and in establishing, exercising or defending a legal claim.
Stripe processes card payments on its own pages. We receive the billing name and address, the invoice and subscription references, the payment status and the card brand and last four digits. We do not receive or store full card numbers or security codes. Stripe processes information for its own payment, fraud and legal purposes as well, as described in its privacy notice.
To secure accounts and deliver reliably we use verification and account-link records, the times of requests, delivery and bounce status, error records and minimal fraud-prevention information. Our basis is our legitimate interest in protecting accounts, preventing abuse and providing the service. We do not use email open pixels or click tracking in any email. Necessary account and billing messages are separate from optional promotions.
If you tick the optional box, we use your work contact details to email you about continuing after the trial and about new briefings. We rely on your consent for that and you can withdraw it at any time, using the link in any such email or by writing to us, without affecting the service. We keep a minimal record of the choice so that we respect it. Our approach to introducing Harrier Signals to organisations that have not asked us is in section 3.
We read selected public registers to identify changes affecting incorporated businesses, NHS bodies, care homes run by individuals or partnerships, and their premises. Those registers contain some personal information, such as the names of registered managers or transport managers, sole-trader names and, in some registers, home addresses, even though our briefings are about organisations. Reading and filtering those registers is processing of personal data. Our basis for the limited personal-data processing involved is our legitimate interest in reliable company monitoring, assessed source by source. Section 2 explains what we keep and what we do not.
We hold correspondence, feedback, complaints, rights requests and the evidence behind a correction or an incident. We use these to respond, to correct errors, to meet legal obligations and to protect legal rights. We do not publish an attributed testimonial or identifiable feedback without agreement.
Who receives information
Access is limited to the director and to the service providers that host, store, secure, send and take payment for the service. The table below is our supplier and transfer schedule. Each provider acts as our processor for the service data it handles. Stripe and Google also act as controllers for their own purposes, as their notices describe.
| Provider | What it does for us | Where it processes | Transfer safeguard |
|---|---|---|---|
| Cloudflare, Inc. | Hosts the website and the application, holds the account database and stored briefings, routes inbound email to our mailbox | Its global network, including the United States | Certified under the UK Extension to the EU-US Data Privacy Framework. Its customer data processing addendum incorporates the EU standard contractual clauses |
| Resend, Inc. | Sends the emails you asked for, verification, briefings, account and billing messages, and the optional emails you consented to | United States | Its data processing addendum incorporates the UK Addendum to the EU standard contractual clauses and commits to the UK Extension to the EU-US Data Privacy Framework |
| Stripe Payments UK Limited and Stripe, Inc. | Takes card payments, issues invoices and runs the billing page | United Kingdom, Ireland and the United States | Its data processing agreement uses the UK-US Data Privacy Framework and the UK International Data Transfer Addendum |
| Google LLC (Google Workspace) | Our mailbox. Email to hello@harriersignals.co.uk is routed to it and replies come from it | European Union and United States data centres | Certified under the UK Extension to the EU-US Data Privacy Framework |
We checked each provider's stated transfer mechanism on its own published pages on 15 September 2026. You can ask us for the relevant terms. We do not use AI drafting tools on your contact details, on support correspondence or on personal fields from source files.
We may share necessary information with professional advisers, insurers, a regulator, a court or another person where the law requires it or where it is necessary to establish or defend a legal right. Briefings are designed to name organisations and business premises and to exclude the names and direct contact details of individuals. Where a source fact legitimately includes personal information, the recipients of the affected briefing receive that limited information. We do not sell contact details and we do not publish customers' coverage choices.
How long we keep information
A signup that is not verified is deleted after seven days. Verification and address-change links expire after 24 hours and work once. The link to your account in our emails identifies you and does not open the account on its own. A sign-in link expires after 24 hours and works once. A signed-in session ends 30 days after it was last used, or sooner when you or your account's owner ends it. Expired link and session records are removed within seven days of expiring. A verified setup that never receives a first briefing is deleted 30 days after signup unless you have asked us to keep it open, in which case we record the extension.
Account, contact and coverage information is deleted 90 days after the last trial or subscription ends. What remains is the organisation's name and company number, the briefing and the dates of the trial, so that the one-trial-per-organisation rule can be applied, and the evidence of acceptance described above, which we keep for six years after the relevant service ends. Neither of those records contains your name or address once that period has passed.
Accounting and tax records are kept for six years from the end of the financial year concerned, or longer where a specific legal requirement applies. Ordinary support correspondence is deleted twelve months after the matter closes. The outcome record of a complaint, a rights request, an incident or a correction is kept for six years after closure. Our providers' delivery and error logs are kept for the short periods set in their services and are not used to track anyone.
For prospective customers, section 3 applies. A record about a person we have not yet written to is removed one calendar month after we collected it unless we have written to them. Where we have written and had no reply, the record is deleted 90 days after the last message. A minimal suppression record, holding only the address and the reason, is kept for as long as renewed contact remains realistically possible, and reviewed annually.
We keep dated copies of the public register files we read, so that any briefing can be checked against what the register said on the day. Some of those files contain names or contact details as the publisher included them. We do not extract or use those fields, we limit access to the director, and we are reducing the copies to their corporate fields under a review recorded in our records of processing. For care homes we keep one coded value derived from the registered manager's name in the current CQC file for each location, so that the next month's file can show that the registered manager recorded by CQC has changed. We never keep the name. The code is replaced each month and cannot be turned back into the name without it. Our briefings and the evidence behind them are kept for six years after the relevant service ends.
Deleted records may remain in a provider's backups until they expire. Cloudflare's database keeps a 30-day point-in-time restore. Our own copy of collection data sits on an external disk refreshed by hand, and a deleted record leaves it at the next refresh. A restored backup is put back under the same deletion and suppression rules. A legal hold can suspend a particular deletion, and when it does we record its scope, reason and review date.
Your rights and choices
You may ask for access to, correction of, erasure of or restriction of your personal data, and you may object to processing that rests on our legitimate interests. An objection to marketing stops it. Portability applies to automated processing based on consent or on a contract with you personally, which is not the usual position for a corporate account.
Ask by any clear route. No form, wording or subject line is required. We may ask for proportionate information to confirm your identity or find your records. We respond within one month. Where a request is complex we may extend by up to two further months and we will tell you within the first month if so. We search our source stores, account records, correspondence and historical copies. We do not assume that no personal data is held because a briefing concerns a company.
You do not have to give marketing consent or feedback to use the service. Without a working delivery address, a verified corporate identity and the setup and payment information the service needs, we cannot provide it. We make no solely automated decisions about individuals with legal or similarly significant effects. If an automated check on your signup goes wrong, write to us and a person will look at it.
To complain about how we have handled personal data, write to hello@harriersignals.co.uk or to the registered office. Any clear message counts. We acknowledge within 30 days, investigate and tell you the outcome without undue delay. You may also complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/ at any time.
Public registers and the people named in them
Harrier Signals monitors selected official records about incorporated businesses, NHS bodies, care homes run by individuals or partnerships, and their premises. The sources we read are the Food Standards Agency's food hygiene ratings, the Care Quality Commission's register and monthly files, Companies House, the Traffic Commissioners' published bulletins, the DVSA operator licence registers, The Gazette, the Home Office register of licensed sponsors, the Charity Commission register, the payment practices reporting service, Ordnance Survey open data and aggregate statistics from NOMIS. The sources used in a briefing are named in it. A source that is not named is not used.
Those registers contain personal information as the publisher included it, such as the names of registered managers and transport managers, sole-trader names and, in some registers, addresses that may be homes. We read the fields we need to identify the organisation, the premises and the change, and we discard the rest. We do not keep names, we do not keep home addresses, and we do not build profiles of individuals. Outside care homes, a sole trader or an ordinary partnership is left out, because we cannot tell a business address from a home for them.
The Care Quality Commission publishes every registered care home, including homes run by an individual or an ordinary partnership, so that the public can compare them. Estate Intelligence reports on those homes when they sit inside a subscriber's comparison circle. We show the home's registered name, its registered beds, its ratings with their dates and a link to its page on the CQC website, as CQC publishes them. We do not keep or show the owner's name. We leave out any home whose registered name is its owner's name or a street address, and we keep no name, full postcode or map position for it. If you run a care home and do not want it in our briefings, write to hello@harriersignals.co.uk. We will take it out of every briefing from the next issue and keep a record of your request.
For care homes we keep one coded value derived from the registered manager's name in the current CQC file, so that the next file can show that the registered manager recorded by CQC changed. The name itself is never stored and the code is replaced each month. We treat that code as personal data, not as anonymous, and it is covered by the rights in section 1.
We keep dated copies of the register files we read as our record of what each register said on the day. Where those files contain personal fields we do not use them, we limit access to the director, and we are reducing them to their corporate fields under a recorded review.
Because we do not keep names, we cannot write to the individuals who appear in these registers. This notice is how we inform them. The publisher's own notice explains the register's purpose, not ours. We record the reasoning for each source in our records of processing. We do not use the two CQC prosecutions and coroners' report files, which name individuals, and we do not use restricted address data.
We do not infer that a missing register entry proves a revocation, a closure, misconduct or insolvency. If you believe a register record or a briefing refers to you, write to hello@harriersignals.co.uk with the reference. We will search what we hold, tell you what we found and correct our own processing. We cannot amend the publisher's register, and we will point you to its correction route.
Introducing Harrier Signals to organisations
We introduce Harrier Signals to incorporated organisations that we believe need it. To do that we may hold a business contact's name, professional role, work email, employer and company number, the public business source we found the contact in and the date we found it, the reason we think the briefing is relevant, and the history of our contact, including any request to stop.
Our basis is our legitimate interest in proportionate marketing to relevant corporate organisations, assessed and recorded before we write. We write only to addresses at incorporated organisations. Where the law requires consent, we do not write. Each message names us, names the public source we found your details in, links this notice and offers a free and simple way to say no. We send at most one introduction and one follow-up, by hand from our own mailbox. A request to stop, a complaint or an unsubscribe stops all marketing to you at once, and a change of sender address does not reset it.
We provide this information no later than one calendar month after we collect your details, or in the first message if that is sooner. The retention periods and rights in section 1 apply. Write to hello@harriersignals.co.uk to object.
Version HS 2026-09-24.2. Describes the service as it runs on the date of the version.