Provenly

Provenly — Privacy Notice

Version: v1

Effective date: 16 July 2026


Who we are

Provenly is a health and safety compliance platform operated by Matthew McAllen, a sole trader trading as Provenly.

Contacthello@provenly.co.uk
ICO registration referenceZC195864

This notice explains what we do with personal data. It has two parts, because your position depends on who you are:

  • Part A — if your employer uses Provenly and you have been asked to read and acknowledge documents.
  • Part B — if you hold a Provenly account as a business owner, manager or auditor.

If you are unsure, Part A almost certainly applies to you.


Part A — If you are an employee

In one paragraph

Your employer uses Provenly to share health and safety documents with you and to keep a record that you have read them. Your employer decides what data is held about you and why. We hold and protect that data on their behalf — we do not decide what to do with it. In legal terms, your employer is the controller and we are their processor.

This means: if you want to see, correct or remove your data, ask your employer first. They instruct us, and we act on their instruction. We cannot act on our own.

What is held about you

  • Your name
  • Your email address — your work address, or a personal address if you confirmed you were happy to use one
  • The date you started work, and the date your employer started tracking you in Provenly
  • Which groups and teams you belong to
  • A record of each document you were asked to read — when you were asked, whether you opened it, which version you saw, when you confirmed you had read and understood it, along with your IP address and the browser you used
  • When you log in
  • Any personal information that happens to appear inside the documents your employer uploads

Why it is held

So that your employer can show — to a court, an insurer, or a regulator — that they gave you the health and safety information you were entitled to, and that you confirmed you had read it.

This matters more than it might sound. If someone is injured at work, the question of whether they were properly informed is often the question the whole case turns on. These records are the answer to it.

Your employer relies on their legitimate interests — running a safe workplace and being able to demonstrate that they did.

You are not being asked to consent, and your consent is not the legal basis. We want to be clear about that, because the button you press says "I have read and understood" and we do not want it mistaken for something it is not. Pressing it records that you were shown the document and confirmed you had read it. It does not mean you have agreed to the processing of your data, and it does not waive any of your rights below.

Your employer must be able to explain their legitimate interests to you if you ask. We provide them with a template to help them do that.

Who your data is shared with

We use three companies to run the platform. They hold or handle your data on our behalf, under contract, and cannot use it for anything of their own:

SupabaseStores the database and the documentsUnited Kingdom (London)
VercelRuns the softwareUnited Kingdom (London)
ResendSends the emails you receiveIreland

The current list is always in Schedule 2 of our Terms of Service.

Your data stays in the UK or the European Economic Area. We do not transfer it elsewhere.

We do not sell your data. We do not advertise. We do not use your data to train artificial intelligence — no document, no record of yours, is sent to any AI service.

How long it is kept

Your employer decides. They will normally keep it for a long time, and there is a good reason for that: some health and safety claims — particularly those involving illness caused by exposure at work — can be brought decades later. The record that you were given the right information is what protects both of you.

When your employer closes their account, they tell us to return the data to them or delete it, and we do as they instruct.

Your rights

You have the right to:

  • be told what data is held about you and why — this notice;
  • see a copy of it;
  • have mistakes corrected;
  • have it erased, in some circumstances;
  • object to it being used, in some circumstances;
  • restrict its use while a dispute is resolved;
  • receive a copy in a portable, machine-readable form.

How to use them: ask your employer. They hold the relationship with you, and they instruct us. We will help them respond quickly — the platform can produce everything held about you as a file, in minutes.

One thing to know about erasure

If you ask for your data to be erased, your employer can remove your name and email from your account. But the record that a named person acknowledged a named document at a stated time is normally kept, even after that.

That is allowed by law — the UK GDPR permits personal data to be retained where it is needed to establish, exercise or defend legal claims. And it protects you as much as your employer: if you are ever injured and it matters what you were told and when, that record is the evidence.

If you want that record removed as well, you can ask, and your employer decides. We will tell them plainly, in writing, that removing it destroys the evidence permanently.

Complaints

If you are unhappy about how your data is being handled, speak to your employer first — they control it.

If your complaint is about Provenly specifically, you can complain to us using our complaints form. We will acknowledge your complaint within 30 days and tell you what we have decided.

You can also complain to the Information Commissioner's Office at ico.org.uk.


Part B — If you hold a Provenly account

This part applies if you are a business owner, manager or auditor with a login. Here, we are the controller of your personal data — we decide how to run and secure the service — so you deal with us directly rather than through anyone else.

(The data your business puts into Provenly about its employees is a different matter — your business controls that, and we process it for you under our Data Processing Agreement.)

What we hold about you

  • Your name and email address
  • Your role and which business you belong to
  • Your password, stored only as a one-way hash — we never see it
  • Your two-factor authentication setup
  • When you logged in, and from which IP address
  • A record of the actions you take in the platform
  • Which version of our Terms of Service and this notice you accepted, and when
  • Anything you send us — support requests, feedback

Why, and on what basis

WhyLegal basis
To give you the service you signed up forContract
To keep your account and the platform secure — 2FA, breach-checked passwords, session limitsLegitimate interests (operating a secure service)
To keep an audit trail of what was done in your accountLegitimate interests (the platform's core purpose) and, where it concerns your business's records, legal obligation
To contact you about the serviceContract and legitimate interests
To meet our own legal dutiesLegal obligation

We do not use your data for marketing without asking you first, and we do not sell it to anyone.

Passwords

When you set a password, we check it against a public register of passwords known to have been exposed in breaches. Only the first five characters of a one-way hash are sent — the check cannot reveal your password or identify you, and no account details go with it. If the checking service is unavailable, your password is accepted on our strength rules alone.

Cookies

We use only strictly necessary cookies: the ones that keep you logged in and enforce the idle-session timeout.

We do not use analytics, tracking or advertising cookies. That is why you have never seen a cookie banner from us — we do not need your consent, because we are not doing anything that requires it.

How long we keep it

While your account is open, and for a reasonable period afterwards so that we can answer questions and meet our legal duties. Audit records are kept for as long as your business's account exists, because they are the evidence the platform exists to create.

Your rights

You have the right to be informed, of access, to rectification, to erasure, to restrict processing, to object, and to data portability.

Exercise them by contacting hello@provenly.co.uk. We will respond within one month.

Where you have given consent for something, you can withdraw it at any time, and withdrawing it will not affect anything done before you did.

Complaints

If you are unhappy with how we have handled your personal data, use our complaints form.

We will acknowledge your complaint within 30 days, take steps to look into it, and tell you the outcome. This is a legal duty on us, and we take it as such.

You can also complain to the Information Commissioner's Office at ico.org.uk, or call their helpline on 0303 123 1113.


Applies to everyone

How we protect your data

  • Your business's data is walled off from every other business's at the database level.
  • Two-factor authentication is required for owners, managers and auditors.
  • Passwords must be at least twelve characters, with mixed case, a digit and a symbol, and are checked against known breaches.
  • Documents are never public. They are served only through links that expire after 30 minutes.
  • Sessions end after 60 minutes of inactivity.
  • The audit log is append-only and hash-chained: entries cannot be deleted, and any tampering can be detected.
  • Data is encrypted in transit and at rest by our hosting and database providers.

One thing we will tell you that most services do not: the platform has not yet been independently penetration tested. We have done our own security testing and we build carefully, but an external test has not happened yet. It is scheduled before we take our first paying customer. We think you should know that, and we would rather you heard it from us.

Changes to this notice

If we change this notice we will publish a new version, with a new version number and date.

If the change is significant, we will tell you. You can always see which version of this notice you acknowledged, and when, from within the platform — the version you were shown is recorded, not just the fact that you clicked.

Contact

hello@provenly.co.uk

Our postal address for legal notices is available on request.


End of Provenly Privacy Notice v1.