Privacy Policy
Effective date: 9 April 2026 · Last updated: 9 April 2026
This Privacy Policy explains how Hidbrain Ltd (“we”, “us”, “our”) collects, uses, discloses and protects personal data when you use the Timemy software-as-a-service platform (“Service”). It is issued in accordance with the UK General Data Protection Regulation (“UK GDPR”) as retained in UK law by the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018 (“DPA 2018”).
1. Data Controller
The data controller for personal data processed in connection with the Service is:
Hidbrain Ltd
Company number: 12170656
United Kingdom
Privacy enquiries: privacy@hidbrain.com
Data Protection Officer: dpo@hidbrain.com
Where your employer or organisation (“Customer”) subscribes to the Service, the Customer is an independent data controller for data about their own contracts and suppliers. Hidbrain Ltd acts as a data processor on the Customer's behalf for that data (see Section 10).
2. What Personal Data We Collect
We collect the following categories of personal data:
2.1 Account & Profile Data
Full name, email address, job title, and company name provided when you register or update your profile.
2.2 Authentication Data
Password hashes (we never store plain-text passwords), session tokens, and multi-factor authentication credentials managed through Supabase Auth.
2.3 Contract & Supplier Data
Business documents, contract metadata, supplier contact names, email addresses and phone numbers uploaded or entered by users. This data is controlled by the Customer organisation; Hidbrain Ltd processes it on their behalf.
2.4 Billing & Payment Data
Billing name, address and payment method details. Payment card data is processed solely by Stripe, Inc. and is never transmitted to or stored on our systems. We retain Stripe customer IDs and subscription metadata only.
2.5 Usage & Technical Data
IP address, browser type and version, operating system, referral URL, pages visited, timestamps, and feature interactions — collected automatically via server logs and analytics.
2.6 Communications Data
Messages sent through our contact form, support emails, and any correspondence with our team.
2.7 Cookies & Tracking Data
See Section 9 (Cookies) for full details.
We do not knowingly collect special category data (Article 9 UK GDPR) such as health, racial origin, political opinions, or biometric data. Please do not include such data in documents uploaded to the Service.
3. Legal Basis for Processing (Article 6 UK GDPR)
We process personal data only where a lawful basis applies:
| Purpose | Legal Basis |
|---|---|
| Providing and maintaining the Service | Article 6(1)(b) — performance of contract |
| Processing payments via Stripe | Article 6(1)(b) — performance of contract |
| Sending service-critical notifications (e.g. contract reminders) | Article 6(1)(b) — performance of contract |
| Complying with legal obligations (e.g. tax, anti-money laundering) | Article 6(1)(c) — legal obligation |
| Fraud prevention, security monitoring and abuse detection | Article 6(1)(f) — legitimate interests |
| Improving the Service through aggregated usage analytics | Article 6(1)(f) — legitimate interests |
| Marketing communications to existing customers | Article 6(1)(f) — legitimate interests (with opt-out) |
| Marketing communications to new prospects | Article 6(1)(a) — consent |
| Responding to support and contact form enquiries | Article 6(1)(b) / Article 6(1)(f) |
Where we rely on legitimate interests (Article 6(1)(f)), we have conducted a legitimate interests assessment confirming that our interests are not overridden by your fundamental rights and freedoms. You may request a copy of this assessment by contacting us at privacy@hidbrain.com.
4. How We Use Your Personal Data
We use personal data to:
- Create and manage your account and company workspace;
- Deliver contract management, reminder, and reporting features;
- Process subscription payments and manage your billing relationship;
- Send transactional emails including contract renewal alerts, password resets and account notices;
- Provide customer support and respond to enquiries;
- Monitor, maintain and improve the security and performance of the Service;
- Comply with our legal and regulatory obligations under UK and EU law;
- Enforce our Terms of Service and protect the rights of other users.
5. Sharing & Disclosure of Personal Data
We do not sell or rent personal data. We share data only in the following circumstances:
5.1 Sub-processors
We use the following categories of sub-processor, each bound by appropriate data processing agreements:
- Supabase Inc. — cloud database, authentication and file storage (EU/US)
- Stripe, Inc. — payment processing (EU/US, SCCs in place)
- Resend Inc. — transactional email delivery
- Microsoft Azure — AI document intelligence for contract extraction (EU data centre option)
- Vercel Inc. — application hosting and edge delivery
5.2 Legal Disclosure
We may disclose data where required by law, court order, or to cooperate with regulatory authorities including the Information Commissioner's Office (“ICO”).
5.3 Business Transfers
In the event of a merger, acquisition or sale of assets, personal data may be transferred to a successor entity, subject to equivalent protections.
5.4 With Your Consent
We may share data with third parties in any other circumstance where we have your explicit consent.
6. International Data Transfers
Some of our sub-processors are based in the United States. Where personal data is transferred outside the UK, we rely on:
- UK adequacy regulations — for transfers to countries with an adequacy decision granted by the UK Secretary of State;
- UK International Data Transfer Agreements (IDTAs) or the EU Standard Contractual Clauses (“SCCs”) as adapted for UK use under Schedule 21 DPA 2018, for transfers to the US and other countries lacking adequacy;
- Supplementary technical and organisational measures where required to ensure an essentially equivalent level of protection.
You may request a copy of the relevant transfer mechanism documents by contacting privacy@hidbrain.com.
7. Data Retention
| Data Category | Retention Period |
|---|---|
| Account & profile data | Duration of subscription + 90 days after cancellation |
| Contract & supplier documents | Duration of subscription + 90 days; longer if legally required |
| Billing records | 7 years (UK tax law — Finance Act 2012, s.137) |
| Support communications | 3 years from last contact |
| Technical / usage logs | 12 months rolling |
| Aggregated analytics data (no PII) | Indefinite |
After the applicable retention period, personal data is securely deleted or irreversibly anonymised.
8. Your Rights Under UK GDPR
Under Articles 15–22 of the UK GDPR and Part 3 of the DPA 2018, you have the following rights. To exercise them, contact privacy@hidbrain.com. We will respond within one calendar month (extendable by two further months for complex requests).
Right of access (Art. 15)
Request a copy of the personal data we hold about you.
Right to rectification (Art. 16)
Ask us to correct inaccurate or incomplete data.
Right to erasure (Art. 17)
Request deletion of your data where no overriding legal basis applies.
Right to restrict processing (Art. 18)
Ask us to pause processing in certain circumstances.
Right to data portability (Art. 20)
Receive your data in a structured, machine-readable format.
Right to object (Art. 21)
Object to processing based on legitimate interests or for direct marketing.
Right to withdraw consent (Art. 7(3))
Withdraw consent at any time without affecting prior processing.
Rights re: automated decisions (Art. 22)
Not to be subject to solely automated decisions with significant effects.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or by phone on 0303 123 1113.
9. Cookies & Similar Technologies
We use cookies in accordance with the Privacy and Electronic Communications Regulations 2003 (“PECR”). We use only the following categories of cookie:
We do not use advertising, tracking or third-party social cookies.
10. Data Processing Agreement
Where a Customer uses Timemy to store and process personal data about their employees, contractors or third-party contacts, Hidbrain Ltd acts as a data processor and the Customer is the data controller for that data (Article 28 UK GDPR). Our standard Data Processing Agreement (“DPA”) is available upon request at privacy@hidbrain.com. The DPA incorporates:
- A description of the processing activities, nature, purpose and duration;
- The obligations and rights of both parties;
- Technical and organisational security measures (Article 32 UK GDPR);
- Sub-processor obligations and notification requirements;
- Assistance with data subject rights requests and breach notifications.
11. Security
We implement appropriate technical and organisational measures in accordance with Article 32 UK GDPR, including:
- TLS 1.2+ encryption in transit for all data;
- AES-256 encryption at rest for stored documents;
- Row-level security (RLS) in our database layer ensuring data isolation between Customer organisations;
- Regular dependency and vulnerability scanning;
- Access controls with principle of least privilege;
- Secure password hashing (bcrypt via Supabase Auth).
In the event of a personal data breach likely to result in risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay, as required by Article 33–34 UK GDPR.
12. Children
The Service is not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us immediately at privacy@hidbrain.com.
13. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be notified to registered users by email at least 30 days before taking effect. The “Last updated” date at the top of this page reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.
14. Contact & Complaints
For any privacy-related queries, to exercise your rights, or to raise a concern, please contact our Data Protection Officer at dpo@hidbrain.com or write to us at the address in Section 1. Alternatively, use our contact form.
If we are unable to resolve your concern, you may contact the ICO:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Tel: 0303 123 1113 · ico.org.uk