Legal

Privacy policy

Last updated: 6 August 2026

Who operates CertWatch

CertWatch is operated by RogerSon Ltd. For privacy questions or requests, email certwatch@rogergroup.xyz.

Data we use

  • Account data: email address, account identifier and subscription status.
  • Property data: addresses, postcodes, property type, region, certificate types, issue dates, expiry dates and notes you enter.
  • Payment references: Stripe customer, Checkout and subscription identifiers. Stripe handles full card details.
  • Service data: contact details, brief notes and accepted compliance documents submitted for done-for-you setup.
  • Analytics: consented usage information used to understand site performance.

Done-for-you source files

Portfolio-setup files are uploaded through an authenticated intake. We encrypt each file with an application key before storing it in Netlify Blobs. Only authorised CertWatch operators can download it through the operator workflow.

Source files are scheduled for deletion 30 days after fulfilment. Files in abandoned draft or cancelled intakes are deleted after 30 days. Property and certificate records entered into your dashboard remain until you delete them or close the account.

Data minimisation

Do not upload passports, identity documents, bank details, tenancy agreements, tenant correspondence, right-to-rent evidence or special category personal data. Redact tenant details from accepted compliance documents before sending them.

Service providers

We use Netlify for hosting, server functions and encrypted blob storage; Neon or Netlify Database for account and dashboard records; Auth.js and Resend for password-free sign-in and service email; Stripe for payments; and consented analytics providers for site measurement.

Your choices and rights

You may ask for access, correction, deletion, restriction or portability of personal data, or object where applicable. Email certwatch@rogergroup.xyz. We may need to verify the request and retain billing records where law requires it.