Who we are
Northora Digital runs the service and is the data controller for the personal data described here. Contact: gregcosby@northoradigital.uk.
What we hold and why
- Account details — your email, name and a hashed password. To run your account. Legal basis: contract.
- Your websites' data — audit results, rankings, crawl data, reports about sites you add. To provide the service. Legal basis: contract.
- Connected-service credentials — for example a WordPress application password or CRM key you choose to connect. Encrypted before they touch our database; shown back to nobody, including us, once saved.
- Photos you or your clients upload — re-encoded on arrival, with location and camera metadata permanently removed before storage.
- CRM activity counts — if you connect a CRM, we read counts of calls and enquiries to include in your reports. We don't store the conversations themselves.
- Security records — failed sign-in attempts against a hashed IP address, kept for 24 hours, purely to slow attackers.
- Our customer records — when you sign up, your name and email go into our own customer system (run on GoHighLevel) so we can support you and manage beta places. Legal basis: legitimate interest in looking after our customers.
What we don't do
- No advertising trackers, no analytics cookies. The only cookie is the one that keeps you signed in.
- We don't sell or share your data with anyone for marketing.
- No marketing email unless you ticked the separate opt-in box at signup — and you can withdraw that any time by unsubscribing or asking us.
- We don't email the businesses you audit.
Where it lives
On our own infrastructure in the United Kingdom, with nightly backups kept for 14 days. If you connect a third-party service (for example WordPress or a CRM), data flows to that service under its own privacy terms — you chose that connection and can revoke it in Settings at any time.
How long, and your rights
We keep your data while your account exists. Deleting your workspace from Settings removes your sites, audits, reports, photos and credentials from our systems, and your backups age out within 14 days. Under UK GDPR you can ask us for a copy of your data (there's an export button in Settings that does it instantly), ask us to correct it, or complain to the ICO (ico.org.uk) if you think we've handled it badly.