BackLine.
Draft — pending legal review. This is a template for discussion only. Have it reviewed by a qualified solicitor or data-protection adviser, register with the ICO if required, and complete every highlighted placeholder, before publishing or relying on it.

Legal

Privacy Policy

Last updated: 31 August 2026

This policy explains how [McFadden Works legal entity name] (“we”, “us”) handles personal data in connection with BackLine. It covers two different roles: data we handle as a controller (our own customers and website visitors), and data we handle as a processor on behalf of our customers (their staff and operational data inside the portal).

1Who we are

BackLine is operated by [McFadden Works legal entity name], registered in England and Wales under company number [company number], registered office [registered address]. For privacy questions, contact privacy@backline.app. [If you have appointed a Data Protection Officer, name them and give contact details here.]

2Controller vs processor

We are the controller for the personal data of the people who sign up for and administer a BackLine account, and for visitors to our website — we decide how and why that data is used.

We are a processor for the personal data our customers put into the portal about their own staff and operations (form submissions, uploads, HR records, and similar). For that data, the customer is the controller and decides why it is processed; we act on their documented instructions. Section 12 covers that processing, and it is governed by our agreement with the customer.

3Data we collect (as controller)

  • Account & business data — name, work email, phone, password (stored only as a salted hash), and the business and venue details you provide at sign-up.
  • Billing data — billing contact and subscription records. Card payments are handled by our payment provider (Stripe); we do not receive or store full card numbers.
  • Usage & technical data — log data such as IP address, device and browser information, and actions taken in the Service, used for security, troubleshooting, and improving the product.
  • Communications — messages you send us (for example support requests) and your contact preferences.

4How & why we use it

  • to provide, secure, and support the Service and your account;
  • to take payment and manage your subscription;
  • to communicate with you about your account, service changes, and security;
  • to detect, prevent, and investigate fraud, abuse, and technical issues;
  • to improve the Service and develop new features;
  • to comply with our legal obligations;
  • with your consent, to send occasional product updates — which you can opt out of at any time.

5Legal bases (UK GDPR)

We rely on: performance of a contract (to provide the Service and take payment); legitimate interests (to secure, support, and improve the Service, and to run our business, balanced against your rights); consent (for optional marketing and any non-essential cookies); and legal obligation (for example tax and accounting records).

6Cookies

We use strictly necessary cookies to keep you signed in and to keep the Service secure. [If you add analytics or any non-essential cookies, list them here and obtain consent via a cookie banner before setting them.] You can control cookies through your browser settings; blocking essential cookies may stop parts of the Service working.

7Sharing & sub-processors

We do not sell personal data. We share it only with service providers who help us run BackLine, under contracts that require them to protect it and use it only on our instructions, and with authorities where required by law or to protect our rights. Our main sub-processors are:

ProviderPurposeLocation
SupabaseDatabase & file storage[region]
CloudflareHosting, CDN & security[region]
StripePayment processing[region]
ResendTransactional email[region]

[Keep this list current. A full, up-to-date sub-processor list should be maintained and made available to customers.]

8International transfers

Some providers may process data outside the UK. Where they do, we rely on an appropriate safeguard — such as UK adequacy regulations or the International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses — so that your data receives an equivalent level of protection.

9Retention

We keep personal data only as long as needed for the purposes above. Account data is kept while your account is active and for a reasonable period afterwards; billing records are kept for as long as required by tax and accounting law. After account closure, Customer Data is handled as set out in our Terms and in the customer agreement.

10Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, hashed passwords, access controls, and least-privilege practices. No system is completely secure; if a breach affects your rights, we will notify you and the ICO as required by law.

11Your rights

Subject to conditions in law, you have the right to access, correct, delete, or restrict use of your personal data; to object to certain processing; to data portability; and to withdraw consent at any time. To exercise these rights, contact privacy@backline.app. If your personal data is held in a customer's portal (rather than by us as controller), we will refer your request to that customer, who is the controller.

12Data we process for customers

When a customer uses BackLine to collect and store information about their staff and operations, the customer is the controller and we are the processor. We process that data only to provide the Service and on the customer's documented instructions, apply appropriate security, assist the customer with data-subject requests and breach obligations, and delete or return the data at the end of the service, as set out in our data-processing terms. If you are a member of staff whose data is held in a BackLine portal, please contact your employer, who controls that data.

13Changes

We may update this policy from time to time. We will change the “last updated” date above and, for material changes, give you reasonable notice.

14Contact & complaints

For any privacy question or to exercise your rights, contact privacy@backline.app or write to [McFadden Works legal entity name], [registered address].

If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to address your concerns first.