Legal

Privacy policy

Last updated: 28 August 2026

Who operates CertWatch

CertWatch is operated by Baxter House Consultants Ltd, company 10247877, registered in England and Wales. Registered office: 132B Petersham Road, Richmond, TW10 6TZ. For privacy questions or requests, email certwatch@rogergroup.xyz.

Data we use

  • Account data: email address, account identifier and subscription status.
  • Property data: addresses, postcodes, UPRNs, property type, region, certificate types, issue dates, expiry dates and notes you enter.
  • Payment references: Stripe customer, Checkout and subscription identifiers. Stripe handles full card details.
  • Service data: contact details, brief notes and accepted compliance documents submitted for done-for-you setup.
  • Analytics: consented product events used to understand site performance and which features are useful.
  • Marketing choices: the wording, source and time of an optional newsletter consent, including later withdrawal.
  • Business direct mail: a company name, professional role, published office address, source record, approval status, supplier status and response activity for a narrowly targeted postal campaign.

Document reading

PDF and image text recognition runs in your browser. CertWatch does not receive the source document while it is being read. When you confirm the result, we receive the structured fields you reviewed, such as certificate type, property, reference and dates.

Keeping the original document is optional and off by default. If you choose to retain it, the file is encrypted before storage. You can download or permanently delete a retained document from the property page.

Official EPC data

At your request, CertWatch searches the Ministry of Housing, Communities and Local Government Energy Performance of Buildings data service using a saved property address, postcode or UPRN. Address-level EPC data can be personal data. We use it to manage the property record and promote energy efficiency, show you the match for confirmation, then store the UPRN and certificate fields needed for renewal tracking.

Once an exact UPRN is confirmed, CertWatch may check it periodically for a replacement certificate. Automatic changes are recorded in an audit history and can be undone. Public council pages use aggregates only and do not publish address-level EPC records.

Done-for-you source files

Portfolio-setup files are uploaded through an authenticated intake. We encrypt each file with an application key before storing it in Netlify Blobs. Only authorised CertWatch operators can download it through the operator workflow.

Source files are scheduled for deletion 30 days after fulfilment. Files in abandoned draft or cancelled intakes are deleted after 30 days. Property and certificate records entered into your dashboard remain until you delete them or close the account.

Analytics and session replay

Google Analytics and PostHog load only if you accept analytics cookies. Product events use a restricted set of non-identifying properties. Session replay is disabled in sign-in, dashboard, property, intake and operator areas. On eligible public pages, text and form inputs are masked. Withdrawing analytics consent stops collection and clears the PostHog identity.

For narrowly targeted business post, we rely on legitimate interests after checking relevance, necessity, likely impact and prior objections. We use current public business sources, not private home-address data. A private link or QR code may contain a random campaign code. We record when the private page is genuinely used and whether a workflow review is requested so we can measure the letter. Automated previews are filtered and the campaign report does not retain an IP address or full browser identifier.

Newsletter

Creating an account does not subscribe you to marketing. We add an address to the Compliance Watch newsletter only after an optional, unticked consent box is selected. Service emails such as sign-in links and renewal reminders are separate. Every newsletter includes an unsubscribe route, and you can also email us to withdraw consent.

Data minimisation

Do not upload passports, identity documents, bank details, tenancy agreements, tenant correspondence, right-to-rent evidence or special category personal data. Redact tenant details from accepted compliance documents before sending them.

Service providers

We use Netlify for hosting, server functions and encrypted blob storage; Neon or Netlify Database for account and dashboard records; Auth.js and Resend for password-free sign-in and service email; Stripe for payments; MailerLite for consented newsletters; Stannp for approved postal fulfilment; Google Analytics and PostHog for consented measurement; and the official government EPC data service for requested EPC matching and monitoring.

Your choices and rights

You may ask for access, correction, deletion, restriction or portability of personal data. You have the right to object to direct marketing at any time; email certwatch@rogergroup.xyz and we will stop future marketing while retaining the minimum suppression record needed to honour the objection. We may need to verify other requests and retain billing records where law requires it.