Legal Document

Privacy Policy

Effective date: 9 April 2026  ·  Last updated: 9 April 2026

This Privacy Policy explains how Hidbrain Ltd (“we”, “us”, “our”) collects, uses, discloses and protects personal data when you use the Timemy software-as-a-service platform (“Service”). It is issued in accordance with the UK General Data Protection Regulation (“UK GDPR”) as retained in UK law by the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018 (“DPA 2018”).

1. Data Controller

The data controller for personal data processed in connection with the Service is:

Hidbrain Ltd

Company number: 12170656

United Kingdom

Privacy enquiries: privacy@hidbrain.com

Data Protection Officer: dpo@hidbrain.com

Where your employer or organisation (“Customer”) subscribes to the Service, the Customer is an independent data controller for data about their own contracts and suppliers. Hidbrain Ltd acts as a data processor on the Customer's behalf for that data (see Section 10).

2. What Personal Data We Collect

We collect the following categories of personal data:

2.1 Account & Profile Data

Full name, email address, job title, and company name provided when you register or update your profile.

2.2 Authentication Data

Password hashes (we never store plain-text passwords), session tokens, and multi-factor authentication credentials managed through Supabase Auth.

2.3 Contract & Supplier Data

Business documents, contract metadata, supplier contact names, email addresses and phone numbers uploaded or entered by users. This data is controlled by the Customer organisation; Hidbrain Ltd processes it on their behalf.

2.4 Billing & Payment Data

Billing name, address and payment method details. Payment card data is processed solely by Stripe, Inc. and is never transmitted to or stored on our systems. We retain Stripe customer IDs and subscription metadata only.

2.5 Usage & Technical Data

IP address, browser type and version, operating system, referral URL, pages visited, timestamps, and feature interactions — collected automatically via server logs and analytics.

2.6 Communications Data

Messages sent through our contact form, support emails, and any correspondence with our team.

2.7 Cookies & Tracking Data

See Section 9 (Cookies) for full details.

We do not knowingly collect special category data (Article 9 UK GDPR) such as health, racial origin, political opinions, or biometric data. Please do not include such data in documents uploaded to the Service.

3. Legal Basis for Processing (Article 6 UK GDPR)

We process personal data only where a lawful basis applies:

PurposeLegal Basis
Providing and maintaining the ServiceArticle 6(1)(b) — performance of contract
Processing payments via StripeArticle 6(1)(b) — performance of contract
Sending service-critical notifications (e.g. contract reminders)Article 6(1)(b) — performance of contract
Complying with legal obligations (e.g. tax, anti-money laundering)Article 6(1)(c) — legal obligation
Fraud prevention, security monitoring and abuse detectionArticle 6(1)(f) — legitimate interests
Improving the Service through aggregated usage analyticsArticle 6(1)(f) — legitimate interests
Marketing communications to existing customersArticle 6(1)(f) — legitimate interests (with opt-out)
Marketing communications to new prospectsArticle 6(1)(a) — consent
Responding to support and contact form enquiriesArticle 6(1)(b) / Article 6(1)(f)

Where we rely on legitimate interests (Article 6(1)(f)), we have conducted a legitimate interests assessment confirming that our interests are not overridden by your fundamental rights and freedoms. You may request a copy of this assessment by contacting us at privacy@hidbrain.com.

4. How We Use Your Personal Data

We use personal data to:

  • Create and manage your account and company workspace;
  • Deliver contract management, reminder, and reporting features;
  • Process subscription payments and manage your billing relationship;
  • Send transactional emails including contract renewal alerts, password resets and account notices;
  • Provide customer support and respond to enquiries;
  • Monitor, maintain and improve the security and performance of the Service;
  • Comply with our legal and regulatory obligations under UK and EU law;
  • Enforce our Terms of Service and protect the rights of other users.

5. Sharing & Disclosure of Personal Data

We do not sell or rent personal data. We share data only in the following circumstances:

5.1 Sub-processors

We use the following categories of sub-processor, each bound by appropriate data processing agreements:

  • Supabase Inc. — cloud database, authentication and file storage (EU/US)
  • Stripe, Inc. — payment processing (EU/US, SCCs in place)
  • Resend Inc. — transactional email delivery
  • Microsoft Azure — AI document intelligence for contract extraction (EU data centre option)
  • Vercel Inc. — application hosting and edge delivery

5.2 Legal Disclosure

We may disclose data where required by law, court order, or to cooperate with regulatory authorities including the Information Commissioner's Office (“ICO”).

5.3 Business Transfers

In the event of a merger, acquisition or sale of assets, personal data may be transferred to a successor entity, subject to equivalent protections.

5.4 With Your Consent

We may share data with third parties in any other circumstance where we have your explicit consent.

6. International Data Transfers

Some of our sub-processors are based in the United States. Where personal data is transferred outside the UK, we rely on:

  • UK adequacy regulations — for transfers to countries with an adequacy decision granted by the UK Secretary of State;
  • UK International Data Transfer Agreements (IDTAs) or the EU Standard Contractual Clauses (“SCCs”) as adapted for UK use under Schedule 21 DPA 2018, for transfers to the US and other countries lacking adequacy;
  • Supplementary technical and organisational measures where required to ensure an essentially equivalent level of protection.

You may request a copy of the relevant transfer mechanism documents by contacting privacy@hidbrain.com.

7. Data Retention

Data CategoryRetention Period
Account & profile dataDuration of subscription + 90 days after cancellation
Contract & supplier documentsDuration of subscription + 90 days; longer if legally required
Billing records7 years (UK tax law — Finance Act 2012, s.137)
Support communications3 years from last contact
Technical / usage logs12 months rolling
Aggregated analytics data (no PII)Indefinite

After the applicable retention period, personal data is securely deleted or irreversibly anonymised.

8. Your Rights Under UK GDPR

Under Articles 15–22 of the UK GDPR and Part 3 of the DPA 2018, you have the following rights. To exercise them, contact privacy@hidbrain.com. We will respond within one calendar month (extendable by two further months for complex requests).

Right of access (Art. 15)

Request a copy of the personal data we hold about you.

Right to rectification (Art. 16)

Ask us to correct inaccurate or incomplete data.

Right to erasure (Art. 17)

Request deletion of your data where no overriding legal basis applies.

Right to restrict processing (Art. 18)

Ask us to pause processing in certain circumstances.

Right to data portability (Art. 20)

Receive your data in a structured, machine-readable format.

Right to object (Art. 21)

Object to processing based on legitimate interests or for direct marketing.

Right to withdraw consent (Art. 7(3))

Withdraw consent at any time without affecting prior processing.

Rights re: automated decisions (Art. 22)

Not to be subject to solely automated decisions with significant effects.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or by phone on 0303 123 1113.

9. Cookies & Similar Technologies

We use cookies in accordance with the Privacy and Electronic Communications Regulations 2003 (“PECR”). We use only the following categories of cookie:

Strictly necessarySession management, CSRF protection, authentication tokens. These cannot be disabled as the Service depends on them.
FunctionalYour UI preferences (e.g. dark mode, language). Stored in local storage; no consent required.
Analytics (opt-in)Aggregate, anonymised usage statistics to improve the Service. Only set after you provide consent via our cookie banner.

We do not use advertising, tracking or third-party social cookies.

10. Data Processing Agreement

Where a Customer uses Timemy to store and process personal data about their employees, contractors or third-party contacts, Hidbrain Ltd acts as a data processor and the Customer is the data controller for that data (Article 28 UK GDPR). Our standard Data Processing Agreement (“DPA”) is available upon request at privacy@hidbrain.com. The DPA incorporates:

  • A description of the processing activities, nature, purpose and duration;
  • The obligations and rights of both parties;
  • Technical and organisational security measures (Article 32 UK GDPR);
  • Sub-processor obligations and notification requirements;
  • Assistance with data subject rights requests and breach notifications.

11. Security

We implement appropriate technical and organisational measures in accordance with Article 32 UK GDPR, including:

  • TLS 1.2+ encryption in transit for all data;
  • AES-256 encryption at rest for stored documents;
  • Row-level security (RLS) in our database layer ensuring data isolation between Customer organisations;
  • Regular dependency and vulnerability scanning;
  • Access controls with principle of least privilege;
  • Secure password hashing (bcrypt via Supabase Auth).

In the event of a personal data breach likely to result in risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay, as required by Article 33–34 UK GDPR.

12. Children

The Service is not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us immediately at privacy@hidbrain.com.

13. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be notified to registered users by email at least 30 days before taking effect. The “Last updated” date at the top of this page reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.

14. Contact & Complaints

For any privacy-related queries, to exercise your rights, or to raise a concern, please contact our Data Protection Officer at dpo@hidbrain.com or write to us at the address in Section 1. Alternatively, use our contact form.

If we are unable to resolve your concern, you may contact the ICO:

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Tel: 0303 123 1113  ·  ico.org.uk

HomeTerms of ServiceContact© 2026 Hidbrain Ltd. All rights reserved.