Privacy policy
1. Who we are
Endorser Limited ("Endorser", "we", "our") is a company registered in England and Wales. Our registered office address is available on request. We are registered with the Information Commissioner's Office (ICO).
2. What this policy covers
This policy describes how we handle personal data through the Endorser website (endorser.co.uk) and the Endorser application (app.endorser.co.uk). It is written for individuals whose data we process — both visitors to the website and individuals whose verifications are processed through the platform on behalf of our customer firms.
3. Data we collect
Website visitors
- Pages visited, referring URL, and aggregated analytics (no individual tracking).
- Form submissions you choose to send (e.g. demo requests).
Application users (customer firm employees)
- Account data: name, work email, role, firm name.
- Authentication metadata: 2FA enrolment, IP address class, sign-in audit.
- Action audit: every action taken in the application is recorded.
Verification subjects (data held on behalf of customer firms)
- Name, date of birth, address, nationality.
- Identity document data (passport, driving licence) provided to the integrated IDV provider.
- Companies House identity reference returned after successful verification.
4. Lawful bases
We process website data on the basis of legitimate interest. We process application user data under contract. We process verification-subject data as a processor on behalf of the customer firm (which is the controller) under our Data Processing Agreement.
5. Where data is held
All Endorser data is hosted in AWS eu-west-2 (London). Personal data does not leave the United Kingdom. Where IDV verification involves a sub-processor, that sub-processor is also UK-based and listed in the DPA.
6. Retention
Verification records and audit logs are retained for the regulatory minimum of five years from the date of verification, in line with the Money Laundering Regulations. After this, data is purged unless the customer firm requests earlier deletion.
7. Your rights
Under UK GDPR, you have the right to access, correct, delete, restrict processing of, and port your personal data. To exercise these rights, contact dpo@endorser.co.uk. We will respond within one calendar month.
8. Complaints
If you believe we have mishandled your personal data, you may complain to the Information Commissioner's Office at ico.org.uk. We would prefer to hear from you first so we can put it right.
9. Changes
We will update this policy when our practices change. Material changes are notified to application users by email; non-material updates are noted by a revision to the date at the top of this page.