Privacy Policy

This privacy policy explains how Orderly Solutions Ltd ("Orderly", "we", "us" and "our") collects, uses, stores and shares personal data in connection with our platform, website, app and services (the "Platform"). It also explains your rights and how to contact us. We are committed to handling personal data lawfully, fairly and transparently in accordance with UK data protection law, including the UK GDPR and the Data Protection Act 2018 (the “Data Protection Laws”).

Your use of the Platform is governed by our separate terms of service (the “Terms and Conditions”) which can be found here [www.keeporderly.com/terms], as amended from time to time. Please ensure that you read our Terms and Conditions carefully to understand how our Platform and services work and before you create an account with us to use the Platform.

This privacy policy applies to you as a user of the Platform, website, app or services. It also applies to anyone who creates an account with Orderly, including an individual originally named in a specific role (such as an Executor, Beneficiary, Guardian or Emergency Contact, as each term is defined in the Terms and Conditions) who later creates their own account.

Where a user names someone in a role and that person has not yet created an account, we will provide the named individual with a separate privacy notice explaining that they have been added to the Platform, who we are, what we hold about them and how to exercise their rights.

Where the person named is a minor, we will provide that separate notice to a person with parental responsibility for them.
Who we are
Orderly allows you to bring your financial information into one place and helps you organise your affairs and plan your estate. To support this, the Platform lets you build an asset register, store documents in a secure vault, connect external sources of information (including open banking and email), name people in roles such as Beneficiaries and Executors, and create a will using our Will Builder (as defined in the Terms and Conditions). The Platform also allows individuals in different roles, such as Beneficiaries and Executors, to access limited information or complete certain steps via the Platform at the appropriate time in accordance with the design of the Platform.

Orderly is the controller of the personal data in accordance with the Data Protection Laws and as described in this privacy policy.

Terms not otherwise defined in this privacy policy shall have the same meaning as is found in the applicable Data Protection Laws or the Terms and Conditions.

Legal entity name: Orderly Solutions Ltd

Registered in England and Wales, company number 16777106

Registered office: 167-169 Great Portland Street, 5th Floor, London, W1W 5PF

Email: privacy@keeporderly.com.

Because we process large volumes of sensitive financial information and some special category data on a significant scale, we have appointed a Data Protection Officer, who can be contacted at privacy@keeporderly.com.
What types of information do we collect
We may collect, use, store and transfer different kinds of personal information about you. Because of what the Platform does, this includes detailed financial information and, in some cases, special category data. We group it as follows:

Identity, contact and Orderly account information: your name, date of birth, mobile number, postal address, email address, marital or relationship status, dependants, sign-in details and credentials, multi-factor authentication, session and device information, and login events (including device and location), and the roles you hold on the Platform.

Open banking account information:information about your bank and payment accounts, including institution, the account type (such as current account, credit card, mortgage or loan), the account owner, the balance, the account open date, the sort code and the account number.

Financial and asset information: account balances, insurance policies, investments, property and other assets and liabilities, whether you enter it yourself, connect it through open banking, or we identify it from a connected email account.

Payment and billing information: the information we need totake and manage payment for a paid subscription, including your billing address, your VAT status where applicable, your subscription status, and records of billing events such as payments, renewals and failed payments. Card payments are handled by our payment provider in its own secure flow, so we receive payment references and confirmation of status but do not store full card numbers.

Documents you upload: the contents of documents and files you store in the Vault (as defined in the Terms and Conditions), and any documents you generate using the Platform, including your will. This also includes attachments, such as policy schedules, statements and certificates, that we save to your Vault when extracting asset details from a connected email account. Further information is set out under “Email connectivity” below.

Identity verification information: information used to verify your identity, and (where relevant) the identity of a person you name in a role, which may include a government document check and a biometric"liveness" check carried out through our identity verification provider at different stages in time. A biometric liveness check involves special category data, please see the section titled “Special category data” below for more information.

Will and estate information: the information you enter into the Will Builder and your estate plan, including gifts, Beneficiaries, Executors, Guardians and any wishes you, record. Some ofthis information may reveal special category data such as health, religious or philosophical beliefs.

Information about other people you add: where you name another person in a role (such as a Beneficiary, Executor, Guardian or Emergency Contact), they may become a user of our Platform and we will collect information about that person that you pass on to us prior to that person creating an account via the Platform, such as their name, contact details and relationship to you. See "Information about people you name" below for how we handle this.

Technical and usage information: informationabout the device and browser you use, your IP address, and how you interactwith the Platform, collected through cookies and similar technologies asdescribed in our Cookie Policy, which can be accessed here: www.keeporderly.com/cookies

Marketing and communications information:your preferences for receiving marketing from us, and your communication preferences, together with your support conversations with us.

Estate activation information: any death or incapacity report, each estate attestation and the time it was made, the identity-check result for each attestor, the freezing of your record, the cool-off window and your response (if any), and the release of each asset.

Audit and activity records: a version and audit trail of the changes made to your assets and your will, together with system, security and access logs.

Business administration information: where you administer an organisation’s use of Orderly, your identity and role, the organisation’s structure, and its licence and seat allocations. This does notinclude any individual user’s assets, will or Beneficiaries.

We may also from time to time collect, use and share aggregated data such as statistical or demographic data. For example, we may aggregate individuals' technical and usage data to calculate the percentage of users accessing a specific website or Platform feature in order to analyse general trends in how users are interacting with our website and Platform to help improve the website and our service offering.
How we collect your information
We collect information in the following main ways:
  • Directly from you, when you create an account with Orderly, you provide details about your assignment of individuals to different roles within the Platform, enter information, upload documents, build your estate plan, or contact us.
  • From your bank or payment provider through open banking, where you choose to connect a payment account (available on our paid essential tier). This gives us account information (such as account and balance details) only. It does not allow us to move money or make payments on your behalf. The regulated open banking service is provided by Yapily Connect Limited (“Yapily”), a regulated third-party provider (FCA Firm Reference Number 827001) that provides account information services only. Please see the section below titled “Open banking connectivity” for further information on understanding your connectivity via Yapily to provide us with open banking account information. You give, and can withdraw, this permission through Yapily at any time. Withdrawing it stops us receiving further updates, but it does not delete information we have already received; you can ask us to delete it, and we also offer you this choice when you downgrade.
  • From a connected email account. Connecting your email is entirely optional and is switched off by default. If you do choose to connect, the Platform accesses your mailbox on a read-only basis and reads the content of your messages, their attachments and related metadata to identify financial and asset information that may be relevant to your record. This reading is carried out using automated tools, including a third-party tools. The Platform only surfaces suggested items for you to review and either confirm or dismiss; it does not send, delete or change anything in your mailbox. You can disconnect the email connection at any time through your account settings, which will stop the Platform from accessing your mailbox going forward. We support Gmail, Outlook and IMAP accounts. We connect to these accounts through Unified.to, an integration provider acting on our behalf. See “Email connectivity” below for further information, including our limited use commitments in relation to information received from Google accounts.
  • From identity verification and other providers, when you or a person you name completes an identity check, or when you sign in through a third-party sign-in provider.
How and why we use your personal data
The Data Protection Laws require us to have a lawful basis for using your personal data. Depending on what we are doing, we rely on one or more of the following legal bases for collecting your personal data:
  • Performance of a contract with you: Where we need to perform the contract we are about to enter into or have entered into with you, for example, through your acceptance of the Terms and Conditions.
  • Legitimate interests (balanced against your rights): We may use your personal data where it is necessary to conduct our business and pursue our legitimate interests, for example to prevent fraud and enable us to give you the best and most secure customer experience. We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
  • Compliance with a legal obligation: We may use your personal data where it is necessary for compliance with a legal obligation that we are subject to. We will identify the relevant legal obligation when we rely on this legal basis.
  • Your consent: We rely on consent only where we have obtained your active agreement to use your personal data for a specified purpose, for example if you opt in to receive marketing updates from us.
Where we use special category data, we also rely on an additional condition, as explained under "Special category data" below. We have set out below, in a table format, a description of all the ways we plan to use the various categories of your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
Identity,contact and account information
What we doWhy we do itLawful basis
Create and manage your account, authenticate you and keep the Platform secure.So we can provide the Platform to you and protect your account.Performance of our contract with you.   Necessary for our legitimate interests (for security and prevention of misuse).
Communicate with you, including sending service messages and updates to this privacy policy or our terms and respond to your support requests when you contact us via email or our Platform. So we can operate the Platform, keep you informed and to help you with your use of our services and Platform. Performance of our contract with you.   Necessary for our legitimate interests (operating the Platform, providing support and keeping you informed).
Send you marketing about our products and services, where permitted.So we can tell you about features you may be interested in.Consent  Necessary for our legitimate interests where the soft opt-in applies.
Identity,contact and account information
What we doWhy we do itLawful basis
Aggregate and organise your financial information, build your asset register, and power features such as the Vault, the Readiness Score (as defined in the Terms and Conditions) and the Will Builder.So we can provide the core Platform to you.Performance of our contract with you.  
Receive account information through open banking and identify information from a connected email account.So we can bring your information into one place and keep it current.Performance of our contract with you.
Make relevant information available to the people you have chosen after your death, through estate activation.So we can carry out the estate-planning service you signed up for.Performance of our contract with you.   Necessary for our legitimate interests, and the legitimate interests of the people you have chosen (in giving effect to your plan and releasing the information to them, supported by a legitimate interests assessment. We do not rely on our contract with you as the basis for processing the personal data of the people you name, because they are not party to it).
Improve and develop the Platform.So the Platform remains useful and safe.Necessary for our legitimate interests (to keep our Platform and services relevant, to develop our products and business and to inform marketing strategy), using minimised or aggregated data where possible.
Identity verification information
What we doWhy we do itLawful basis
Verify your identity, and the identity of people you name in a role, including a document and biometric liveness check.So we can prevent fraud and misuse, and confirm identity before releasing information (for example where you are a Beneficiary or Executor).Performance of our contract with you (the identity check is necessary to enter into and deliver the estate-release service).   Special category biometric data: substantial public interest in the prevention and detection of fraud, under Article 9(2)(g)  and Schedule 1, paragraph 14 of the Data Protection Act 2018, supported by our Appropriate Policy Document. Where the check is a solely automated decision with a significant effect, we rely on the exception in Article 22B(3)(a) of the GDPR that the decision is necessary for entering into or performing a contract with you.
Payment and billing information
What we doWhy we do itLawful basis
Take payment for a subscription and manage refunds, and keep records of transactions.So we can provide paid access and meet our accounting obligations.Performance of our contract with you.   Compliance with a legal obligation (keeping accounting and tax records under the Companies Act 2006 and applicable tax legislation).
Documents you upload to the Platform  
What we doWhy we do itLawful basis
Store the documents and files you keep in the Vault and the documents you generate on the Platform, including your will, link them to the relevant assets, and make them available to your Executor and to a Beneficiary at the moment it needs to be released. So we can hold the documents that evidence your asset register and give effect to your estate plan.Performance of our contract with you.   Necessary for our legitimate interests (and those of your chosen recipients).
Information about people that you add to the Platform
What we doWhy we do itLawful basis
Hold and use the details of the people you name in a role (such as Executor, Beneficiary, Emergency Contact, Guardian or Dependant), such as their name, contact details and relationship to you, and contact them where appropriate.So we can operate the roles you have set, make your estate plan work and give effect to your wishes and instructions with respect to estate planning. Necessary for our legitimate interests and the individual that you add (in making your estate plan work, balanced against their rights and supported by a legitimate interests assessment).
Estate activation and attestation
What we doWhy we do itLawful basis
Operate dual attestation and estate activation, including receiving a death or incapacity report, verifying and recording each attestation, freezing your record and running the cool-off window before anything is released.So we can confirm that any release is properly authorised and prevent fraudulent activation of an estate.Performance of our contract with you.  Necessary for our legitimate interests, and those of the estate, in preventing fraudulent activation, with regards to the Executor and Emergency Contact who attest.
Technical, usage and marketing information
What we doWhy we do itLawful basis
Understand how the Platform is used, keep it secure, and maintain and improve it.So we can run, protect and improve the Platform.Necessary for our legitimate interests (running, protecting and improving the Platform).  Compliance with a legal obligation (our security duties under Articles 5(1)(f) and 32 of the UK GDPR).
Record and honour your marketing and communication preferences.So you receive only what you have chosen.Consent
Marketing and communications information
What we doWhy we do itLawful basis
Send you marketing about our products and services, where permitted.So you receive only what you have chosen.Consent
Audit and activity records
What we doWhy we do itLawful basis
Keep a version and audit trail of the changes made to your assets and your will, together with system, security and access logs, and retain the audit trail and make it available to the Executor after your death.So we can secure and investigate the Platform, and so an Executor can respond to any challenge to your will or to the asset record.Necessary for our legitimate interests (security, fraud prevention, and maintaining an evidenced record you as the Executor can rely on to answer a challenge).   Compliance with a legal obligation where applicable.
Special category data
Some of the information we process is special category data, which the Data Protection Laws gives extra protection. This includes the biometric data used in an identity liveness check, and any information revealing health, religious or philosophical beliefs that appears in what you enter or upload to the Platform (for example  the contents of documents in your email or Vault).

Where we process special category data, we rely on an additional condition under Article 9 of the UK GDPR. For the biometric identity check, we rely on the substantial public interest condition for the prevention and detection of fraud (Schedule 1, paragraph 14 of the Data Protection Act 2018). For special category data that may appear in what you enter or upload (for example in the Will Builder or in Vault documents), we do not ask for this information, we discourage you from including it, we keep it to the minimum necessary, and we do not use it to make inferences or decisions about you.

Where we need a condition to hold it, we rely on your explicit consent, given at the point you choose to provide the information. We maintain an Appropriate Policy Document for our processing of special category data.
Automated processing and artificial intelligence
We use automated tools, including artificial intelligence, to read documents you upload and correspondence in a connected email account, and to suggest asset details for your record. A person, being you, always reviews and confirms, edits or dismisses each suggestion before it is added to your record, so these tools do not make decisions about you. The one exception is the automated identity check described below under “Automated decision-making”. This includes correspondence in a connected email account. We do not use the content of your mailbox or any documents you upload to train general-purpose artificial intelligence or machine learning models. See “Email connectivity” below for further information about our limited use commitments.

We also use automated tools, including artificial intelligence, to help handle customer support enquiries, which may process the information you include in a support request. You can always ask to deal with a member of our team directly. Separately, we calculate a readiness score in the Platform, which is an automated indicator that shows how complete your plan is and may suggest features or an upgrade. This is a prompt to help you and not an assessment of whether your affairs are in legal order, and it does not make any decision about you.
Automated decision-making
An identity check carried out on the Platform can produce an automated pass or fail result. Where you are a Beneficiary or Executor, that result can affect you, because it can determine whether certain estate-related information is released to you. The information required for this check constitutes special category (biometric) data.

We make this decision because it is necessary for entering into or performing our contract with you (in accordance with Article 22B of the UK GDPR). For the biometric element we rely on the substantial public interest condition for preventing and detecting fraud (Schedule 1, paragraph 14 of the Data Protection Act 2018) and we maintain an Appropriate Policy Document for it as set out above.  

When carrying out this check, we verify that your identity document is genuine and use a liveness check to confirm you are the person shown in it. You have the right to request further information, make representations and give us further evidence (such as an alternative identity document), contest the outcome, and ask for a person to review the decision. Where an automated identity check does not pass, you can ask us to carry out a human review by contacting us at privacy@keeporderly.com. A member of our team will review the outcome and any information you provide, and we will respond to you within one month letting you know the outcome. At the point of the decision, we will tell you what was checked, what was decided and the main reasons for it, and where you, as an Executor or Beneficiary, are blocked from administering or receiving an estate we will prioritise the review.
Open banking connectivity
Any account information you share with us through Yapily is subject to Yapily’s End User Terms (https://www.yapily.com/legal/end-user-terms) and Privacy Notice (https://www.yapily.com/legal/privacy-policy), which you should read carefully. When you connect your account, you authorise Yapily to access and share your open banking account information with us. You may withdraw that authorisation at any time. This will prevent us from receiving further information through the connection, but will not automatically delete information already shared with us. You may request deletion of that information in accordance with the “Your rights” section below.This open banking authorisation is separate from consent under Data Protection Laws. It permits access to your account information under applicable UK open banking laws and regulations; it is not the lawful basis on which we process your personal data.Once we receive your open banking account information, we process it as necessary to provide the Platform under our contract with you, rather than on the basis of your data protection consent. Withdrawing your open banking authorisation therefore stops future access to your account but does not withdraw consent to our processing, as we do not rely on consent for that processing. Any information already received will continue to be handled in accordance with this privacy policy, including the “Your rights” section below.
Email connectivity
Where you choose to connect a mailbox, we connect through Unified.to, an integration provider acting on our behalf under contract. Unified.to does not use your data for its own purposes. We support Gmail, Outlook and IMAP accounts. Signing in to the Platform is handled separately by Auth0 and is not part of the mailbox connection.

We extract only the information needed to create an asset in your record, such as the provider or institution, account, policy or holding type, reference numbers, values, dates and renewal terms. We also save relevant attachments, such as policy schedules, statements and certificates, to your Vault. We do not retain a copy of your mailbox, and content unrelated to something you own is not retained beyond what is needed to classify it. See “How long we keep your information” below.

Mailbox access is read-only: we do not send, delete, modify or reply to emails from your account.

Where you connect a Google account, our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its limited use requirements. For information received from connected mailboxes, we do not sell it or share it with data brokers or advertisers, use it for advertising or to train general-purpose AI or machine learning models, or permit team members to access it except with your explicit consent for a specific support request, where required by law, for security investigations, or in aggregated and anonymised form.
Information about people you name
When you name another person in a role (for example a Beneficiary, Executor, Guardian or Emergency Contact), you provide us with information about them. We use that information only to operate the relevant feature, for example to link them to your plan, to contact them where appropriate, and to make information available to them after your death where you have chosen this.

Because that person has not given us their information directly, the Data Protection Laws requires us to tell them that we hold it. We will provide a separate privacy notice to each adult you name, within a reasonable period and at the latest within one month, explaining that they have been added to the Platform, who we are, what information we hold about them and how they can exercise their rights. Where the person you name is a child, we will provide that separate privacy notice to a person with parental responsibility for them.

You confirm, when you name a person, that you are entitled to provide their information to us.
How you can manage your marketing preferences
When you sign up, or in your settings, you can choose whether to receive direct marketing from us. You can change your mind at any time by using the unsubscribe link in any marketing message, by adjusting your settings, or by contacting us at privacy@keeporderly.com. We will always get your consent before sharing your information with any third party for their own marketing. If you opt out of marketing, you will still receive service messages that are necessary to operate the Platform.
Cookies
We use cookies and similar technologies on our website and in our app. Some are strictly necessary to run the Platform, to sign you in securely and to remember your choices. Strictly necessary cookies do not require your consent and are always on because the Platform will not work properly without them.

Others are optional, including the analytics and marketing tracking we run through HubSpot across our own domains, which help us understand how the Platform is used and measure how well our communications are working.

We only set optional cookies where you have given your consent. We ask for that consent through a cookie banner when you first visit, and you can change or withdraw it at any time through our cookie settings or your browser.

Storing cookies on, and reading information from, your device is also governed by the Data Protection Laws, alongside this privacy notice.

For a full list of the cookies we use, what each one does, how long it lasts and who provides it, please see our Cookie Policy, which we keep up to date as our cookies change.
Who we share your information with
We do not sell your personal information. We share it only where reasonably necessary to operate the Platform, and we require our service providers to keep it secure, to use it only for the purposes we specify, and not for their own purposes. The main categories of recipient are:
  • Identity and authentication providers, who verify identity and manage secure sign-in (for example our identity verification and authentication providers).
  • Open banking and email connection providers, who enable the connections you choose to set up via the Platform.
  • Artificial intelligence providers, who help identify financial information within a connected email account and read documents you upload to suggest asset details for you to confirm.
  • Communications providers, who help us deliver account, security and estate-related notifications by email, SMS and push.
  • Payment providers, who process your payments for a subscription.
  • Hosting and infrastructure providers, who host the Platform and your information.
  • Customer support and CRM providers, who help us respond to your queries and manage our marketing and business relationships.
  • Technology development and support providers:who may have administrative access to our systems for technical support,maintenance and development purposes.
  • App stores, where you access the Platform or pay through them.
  • Professional advisers, authorities and others, where necessary to comply with the law, to enforce our terms, or in connection with a corporate transaction.
  • Other third parties, to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy notice.
Where you, as the user have chosen it, and following estate activation, we also make relevant information available to the people you have named (such as your Executor and Beneficiaries), in accordance with the roles you have set.

Before this happens, the people you name see very little. Until estate activation, each of them sees only a minimal confirmation that they have been named, and none of them sees your assets, your documents, your will or other data or information belonging to you uploaded to the Platform.
Transfers of your information outside the UK
Some of our providers are based, or process information, outside the UK. Where we transfer your personal information outside the UK, we make sure it is protected by an appropriate safeguard, which will usually be either a transfer to a country the UK has decided provides adequate protection, or the use of the UK's standard contractual protections (such as the UK Addendum to the EU standard contractual clauses, the UK International Data Transfer Agreement, or the UK Extension to the EU-US Data Privacy Framework where the provider is certified). Before we rely on any of these, we assess the transfer to satisfy ourselves that your information will be adequately protected.

Your information is hosted in the UK. Our primary systems run in Amazon Web Services' London region, and your data is held in the UK. For resilience and disaster recovery we also take encrypted backups, and those backups are also held in Amazon Web Services’ London region in the UK. The backups are encrypted with separate keys and are held only for recovery purposes rather than as a working copy.

In addition, some of the providers who process information for us operate internationally, including in the United States. The main providers we use are set out below, and we keep a fuller, up-to-date list which we can provide on request.
ProviderWhat they do for usLocation
Amazon Web ServicesHosting and core infrastructureUK, with encrypted backups replicated to Europe.
Auth0 (part of Okta)Sign-in, authentication and session securityUnited States
StripePayment processing and identity verification Europe
Unified.to The read-only email connection and asset scanningGermany
GoogleThe AI model used to read documents and correspondence and suggest assetsGermany
Amazon Web ServicesHosting and core infrastructureUK, with encrypted backups replicated to Europe.
HubSpotCustomer relationship management, marketing and (once live) AI-assisted supportUK
We also work with Yapily, our regulated open banking provider, which operates under its own FCA permissions as a separate controller rather than as our processor.
How we protect your information
We use appropriate technical and organisational measures to protect your personal information, including encryption, access controls, and retention controls. No system is ever completely secure, but we work to protect your information against unauthorised access, loss or misuse, and we have a process for dealing with any personal data breach, including notifying the ICO and affected individuals where the law requires.
How long we keep your information
We keep your personal information only for as long as we need it for the purposes described in this privacy policy, including to meet legal, regulatory, tax and accounting requirements, and to establish or defend legal claims. As a general rule, we keep your account and plan information for as long as your account is active. The table below sets out the main retention periods.
CategoryRetention period
Account, profile, asset register and estate planFor as long as your account is active.
Documents in the Vault, and generated documents including your willFor as long as your account is active, and after death as needed to make information available to your chosen recipients through estate activation.
Raw email message content from a connected email account30 days, after which we keep only the information extracted into your asset register and any copies you have saved to the Vault.
Dismissed candidate items (items you chose not to add)For the life of the active account, until account deletion or after 3 years of inactivity.
Open banking connection and account information dataWe retain account information imported through Open Banking while your Orderly account remains active, so that it can form part of your asset register. To continue automatically refreshing account information, you must reconfirm your authority at least every 90 days. If you do not reconfirm, we stop background refreshes and mark the account information as no longer current. We still retain the historic information in your asset register in read-only form, unless you choose to disconnect and delete the connected-account data. This information will be deleted once you close your Orderly account, or after your account is dormant for three years and is deleted under our account-retention process.
Identity verification recordsNo longer than 30 days after the final verification outcome.
Billing and transaction recordsAs required for accounting and tax, generally up to six years.
Information about people you nameDeleted once the role is no longer active on your account, or whenever it is no longer needed for estate activation.
Audit and activity logsSeven years, as they serve both executor evidence and security and certification purposes.
Estate records after the estate is completedSeven years, aligned with the limitation periods for estate and executor claims.
An estate that is activated but never completedThe same period as above, running from the date of the last activity on the estate.
Assets released to a Beneficiary Until the asset and its linked documents have been released to the Beneficiary and acknowledged. At that point the record becomes part of the Beneficiary's own account, as something they now own, and we keep it under the Beneficiary's account lifecycle rather than the deceased's, so it is retained and deleted in line with that account rather than under the estate. A copy remains in the deceased's audit trail, which we keep for the audit retention period described above.
Role data where a person declines or is removedDeleted within 30 days, keeping only the fact and date of the decline or removal in the audit log.
Dormant Free accountsDeletion after 3 years unless you re-engage.
Account closure at your requestPersonal data deleted within 30 days, apart from records we must keep (such as billing and audit records); backups purge on the 35-day cycle.
When your Subscription ends and your account reverts to the free tier, we do not automatically delete your information as a result of the downgrade. At the downgrade step you can choose to delete all of your data, and we will do so within 30 days, apart from any records we are legally required to retain (such as billing, accounting  and audit records as described in the table above). If you do not choose deletion, access to personal data that depends on a paid feature may be restricted until you subscribe again, subject to the retention periods above and any deletion you request.
Your rights
You have a number of rights under the Data Protection Laws in relation to your personal data.

You have the right to:
  • Request access to your personal data (commonly known as a "subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
  • Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  • Request erasure of your personal data in certain circumstances. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
  • Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) as the legal basis for that particular use of your data (including carrying out profiling based on our legitimate interests). In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your right to object.
  • You also have the absolute right to object anytime to the processing of your personal data for direct marketing purposes (see the “How you can manage your marketing preferences” section above for details of how to object to receiving direct marketing communications).
  • Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
  • Withdraw consent at any time where we are relying on consent to process your personal data (see the tables under "How and why we use your personal data" above for details of when we rely on your consent as the legal basis for using your data). However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
  • Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in one of the following scenarios:
    o If you want us to establish the data's accuracy;
    o Where our use of the data is unlawful but you do not want us to erase it;
    o Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or
    o You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
You can exercise these rights, or ask us anything about this privacy policy, by contacting us at privacy@keeporderly.com. We will respond within one month, though we may extend this for complex requests, and we may need to verify your identity first. You will not usually have to pay a fee.
How to contact us or complain
If you have a question or a complaint about how we use your personal information, please contact us at privacy@keeporderly.com so we can try to resolve it. You also have the right to complain to the Information Commissioner's Office (www.ico.org.uk) at any time, but we would appreciate the chance to deal with your concerns first.
Children
The Platform is intended for those above the Minimum Age. We do not knowingly allow anyone under the Minimum Age to create an account or access the Platform. For the purposes of this privacy policy, “Minimum Age” means, in relation to any person, 18 years, or, where that person is resident in Scotland, 16 years.We may, however, hold and process limited information about children where you name a child (for example as a Dependant or Beneficiary). In those circumstances, the child is not a user of the Platform. We limit the information we collect and use it carefully and only for the purposes described in this privacy policy. Where required, we make appropriate privacy and transparency information available to a person with parental responsibility.
Updates to this policy
We may update this privacy policy from time to time and keep it under regular review. Where a change is significant, we will take reasonable steps to bring it to your attention. This version was last updated on 4 September 2026.
Third-party links
The Platform may link to third-party websites or services that we do not control. We are not responsible for their privacy practices, and we encourage you to read the privacy notice of any third-party service you use.