Privacy Policy

Last updated: 30 October 2025

1. Who we are

This Privacy Policy explains how Okkayd Ltd (“Okkayd”, “we”, “us”, or “our”) collects, uses and protects personal information.

Okkayd Ltd
31 Grove Road
Ware, Hertfordshire SG12 7HS
United Kingdom
support@okkayd.com

We are the data controller for the purposes of the UK Data Protection Act 2018 and the UK GDPR.

2. Information we collect

We collect information you provide directly, automatically, and through our partners.

Information you provide

  • Account details (name, email address, password)
  • Billing information (processed securely by Stripe)
  • Contracts or documents you upload for AI analysis
  • Feedback or support messages

Automatically collected data

  • IP address, browser type and device information
  • Usage logs and diagnostics for performance and security

From third parties

  • Payment status and fraud signals from Stripe

3. How we use your information

We process your data to:

  • Provide and improve our AI contract-review services
  • Create and manage user accounts
  • Process payments and subscriptions (via Stripe)
  • Respond to support requests
  • Comply with legal and security obligations

4. Legal basis for processing

Under the UK GDPR we rely on the following legal bases:

  • Performance of a contract – to deliver our service
  • Legitimate interest – to improve and secure our platform
  • Consent – for marketing and cookies
  • Legal obligation – for record keeping and compliance

5. How we share data

We share personal data only with:

  • Stripe Payments UK Ltd (for secure billing)
  • Amazon Web Services (AWS) hosting in London (EU West 2)
  • Analytics and email providers (used under data-processing agreements)

We never sell personal data.

6. Data storage and security

Data is stored securely on AWS servers in London (EU West 2). We apply:

  • Encryption at rest and in transit
  • Role-based access controls
  • Regular back-ups and monitoring

Uploaded contracts are encrypted and accessible only to the account holder and authorised team members.

7. Retention

We retain data only as long as necessary to provide the service or meet legal obligations. User-generated files and analyses can be deleted by the user at any time.

8. Your rights

You may:

Requests can be sent to support@okkayd.com.

9. Cookies and tracking

We use essential and optional cookies.

Essential cookies

Required for login, security, and payments. These cannot be disabled.

Analytics cookies

Used to understand site performance (Google Analytics or similar). Set only with your consent.

Marketing cookies

Used for advertising or retargeting (if enabled in future). You can opt out at any time.

To manage cookies, adjust your browser settings or preferences on our cookie banner.

10. International transfers

Data is hosted in the UK/EU. Where a processor operates elsewhere, we use Standard Contractual Clauses approved by the UK ICO to ensure adequate protection.

11. Children’s privacy

Okkayd is intended for users aged 18 and over. We do not knowingly collect data from children.

12. Updates

We may update this policy to reflect legal or technical changes. The date at the top shows the latest version.