← Home
Legal

Privacy Notice.

This notice explains what personal data SafeReplies collects, why we process it, how long we keep it, and the rights you have under UK GDPR. We've kept the language plain. If anything is unclear, talk to us.

Last updated: 6 July 2026

01 Who we are

Safe Replies Ltd ("SafeReplies", "we", "us") is a company registered in England and Wales (company number 17247989). We provide a software service that reviews draft business emails for compliance risk before they are sent. For the personal data described in this notice, SafeReplies is the data controller in respect of our own account, billing and marketing data, and a data processor acting on your organisation's instructions in respect of email content we scan.

We are registered with the UK Information Commissioner's Office (ICO) under registration reference ZC184280.

Questions about this notice or your data can be sent to our data protection contact at privacy@safereplies.com.

02 What this notice covers

This notice applies to visitors to our website, people who start a free trial or hold an account, and the individuals at customer organisations whose emails are scanned by the service. It does not cover third-party websites we link to, which have their own privacy notices.

03 How we handle email content

We don't archive your inbox or train on your emails. When SafeReplies scans a draft, the content is analysed in memory to produce the result. If a user sends a flagged email for manager approval, its content is retained only until the manager has reviewed and actioned it, then deleted. We do not otherwise store email bodies, read them back, or use them to train models.

What we do retain is metadata about the scan — for example which user scanned, how many emails were scanned, and which risk categories were triggered. This metadata is what powers your dashboards, fair-use counting and billing. It does not contain the text of your emails.

AI processing chain. The compliance scan is performed using automated risk-detection models, including large language models provided by OpenAI and Anthropic. These AI providers act as our sub-processors: they are bound by our Data Processing Agreement, appear on our sub-processor list, receive email content only to return the scan result, and are contractually prohibited from retaining your email content or using it to train their models (processed via their zero-retention API terms). We do not send your email content to any AI provider that has not agreed to these terms.

04 Personal data we collect

CategoryExamples
Account data Name, work email, organisation, role, password (stored hashed), team members you invite.
Usage & scan metadata Number of emails scanned, risk flags triggered, timestamps, plugin/platform used. No email bodies.
Billing data Plan, seats, billing contact, invoices. Card payments are handled by our payment processor, Stripe — we don't store card numbers.
Support & contact data Messages you send us, booked-call details, and correspondence with our team.
Website data Limited analytics about how the site is used and, with consent, advertising-related data used by our ad partners (see Cookies below).

05 Why we process it & legal basis

We process personal data under the following legal bases in UK GDPR:

  • Contract — to create and run your account, provide the scanning service, count fair-use, and bill you.
  • Legitimate interests — to secure the service, prevent abuse, improve our risk libraries (using metadata, not email bodies), and send service-related messages.
  • Consent — for optional marketing emails and non-essential cookies (analytics and advertising, including cross-site tracking), which you can withdraw at any time.
  • Legal obligation — to keep records we are required by law to keep, such as for tax.

06 Who we share data with

We don't sell personal data. We share it only with service providers ("sub-processors") who help us run SafeReplies — for example cloud hosting, the AI providers that perform the compliance scan (OpenAI and Anthropic), our payment processor (Stripe), and email/support tools — all bound by contract to protect it. Any sub-processor that handles email content is contractually required to process it in memory only, not to retain it, and not to use it to train models. We may also disclose data where required by law.

On signing a paid contract we enter into a standard Data Processing Agreement (DPA), and can provide our current list of sub-processors on request.

Advertising partners. With your consent, our advertising partners (e.g. Google, Meta) set cookies on our website to measure our campaigns and show SafeReplies ads on other sites. For that data they act as their own data controllers under their own privacy policies. They receive website-visit data only — never your email content or scan results.

07 How long we keep data

  • Email content — processed in memory for the scan; if sent for manager approval, kept only until a manager reviews and actions it, then deleted. Not otherwise retained.
  • Account & scan metadata — held by us as data controller; kept while your account is active and for up to 12 months after closure, then deleted or anonymised.
  • Billing records — kept for 6 years to meet UK tax and accounting requirements.
  • Support correspondence — kept for up to 24 months.

08 How we protect data

We use encryption in transit, access controls, and the principle of least privilege. Because we don't retain email bodies beyond the scan (or, for approvals, until a manager has reviewed them), the most sensitive data isn't kept at rest. We review our security practices regularly and notify affected customers and the ICO of any qualifying breach within the timeframes the law requires.

09 Where your data is stored

We operate in the UK only and store all personal data in the UK — we don't host your data in the EU or the US. When the compliance scan runs, email content is processed transiently by our AI providers (OpenAI and Anthropic) solely to return a result: under our zero-retention terms they do not store your email content or use it to train their models. Where any processing involves a provider outside the UK, we put appropriate safeguards in place (such as the UK International Data Transfer Agreement / Addendum) so your data stays protected to UK standards.

10 Your rights

Under UK GDPR you have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate data, or complete incomplete data.
  • Erase data, or restrict / object to processing, in certain circumstances.
  • Data portability for data you provided to us.
  • Withdraw consent at any time, where we rely on consent.

To exercise any of these, email privacy@safereplies.com. If your emails were scanned as part of your employer's account, your employer is the controller and we will direct your request to them. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

11 Cookies & analytics

Our website uses essential cookies needed for it to work, and — with your consent — analytics to understand how the site is used, and advertising cookies set by our advertising partners to measure our campaigns and show relevant SafeReplies ads on other websites (cross-site tracking). When you first visit, a banner lets you accept or reject non-essential cookies; you can change your choice at any time by clearing the site's cookies in your browser, and our Cookie Policy lists exactly what we set.

12 Changes & contact

We may update this notice to reflect changes to the service or the law. Material changes will be communicated to account admins by email. The "last updated" date at the top of this page always reflects the current version.

Contact our data protection team at privacy@safereplies.com or via our contact page. See also our Terms of Service.

Book a call