Last updated 29 August 2026

Privacy Policy

1. Who we are

Saundy ("we", "us") provides Saundy Inspect, a property inspection platform available at saundy.com, its web application, and its mobile apps.

  • Legal entity: SAUNDY LTD, a private limited company registered in England and Wales
  • Company number: 17363175
  • Registered office: 128 City Road, London, England, EC1V 2NX
  • Contact: hello@saundy.com

For personal data collected through our websites and the accounts our customers create with us, we are the data controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

If your data reached us because it appears in an organisation's inspection content (for example you signed an inspection report, or you appear in a photo or note), we act as a data processor on that organisation's behalf. See section 10.

2. Data we collect

Account data. When you register we collect your name, email address, and a password (stored only as a salted hash). We record the date you accepted our terms.

Organisation and team data. Organisation names, team membership, roles and permission groups, and the names and email addresses of people invited to join an organisation (including invitees who have not yet created an account).

Base location (optional). Team members can set a base postcode so their organisation can see how far each person is from an inspection site when assigning work. It is entirely optional, set separately for each organisation you belong to, and visible to that organisation's admins. You can change or clear it at any time from your profile page, and it is deleted when you delete your account. To turn postcodes into map coordinates, our servers look them up against the open postcodes.io geocoding service; each lookup contains a bare postcode and nothing else — no names, account identifiers, or network addresses — so nothing that could identify you is shared (see the note at Sub-processors).

Billing data. Payments are handled by Stripe. We do not see or store card numbers; we store only your Stripe customer and subscription identifiers, your plan tier, and your report-credit balance.

Enquiries and register interest. If you ask us to contact you about Saundy Inspect (for example through the register-interest form on this site), we collect your name, email address, and optionally your company name.

Activity within inspection records. Inspection records kept by your organisation include the names of the team members who were assigned to them, submitted them, and signed off defects, and the drawn signatures added to submitted reports. These form part of your organisation's inspection content.

AI-assisted features (optional). The Service offers optional AI features, including the Saundy template assistant, which drafts inspection templates from what you tell it or from documents you upload. When your organisation uses an AI feature, the content that feature needs (for the template assistant: the messages typed, the template being worked on, and any uploaded document) is sent to our AI sub-processor (Anthropic) to produce the result — see Sub-processors for what each feature sends. We record who used a feature and when, so we can apply the fair-use allowances. Nothing is sent in the background of normal use, what AI features produce is advisory until your organisation accepts it, and Anthropic does not use the data to train its models.

Emails. We send transactional email only (welcome emails, password resets, and team invitations). We do not send marketing email and we do not operate mailing lists. The one exception: if you register interest in Saundy Inspect, we will email you about availability and early access, and we delete your details or stop contacting you whenever you ask.

What we do not collect. Our websites use no analytics, no advertising trackers, and no third-party tracking scripts. All fonts, styles, and scripts are served from our own domains. We do not store IP addresses or browser fingerprints against your account.

3. Purposes and lawful bases

Purpose Data Lawful basis (UK GDPR Art. 6)
Providing your account and the service Account, organisation, team data Contract (Art. 6(1)(b))
Distance-aware assignment of inspection work Optional base postcode Contract (Art. 6(1)(b))
Billing, subscriptions, and report credits Billing data Contract (Art. 6(1)(b))
Security and abuse prevention Account and activity data Legitimate interests (Art. 6(1)(f))
Transactional email Email address Contract (Art. 6(1)(b))
Optional AI-assisted features, with fair-use limits The content your organisation submits to the feature being used; usage records Contract (Art. 6(1)(b))
Responding to enquiries and register-interest requests Name, email, company Steps at your request prior to entering a contract (Art. 6(1)(b))
Accounting and tax records Billing data Legal obligation (Art. 6(1)(c))

We do not currently rely on consent for any processing, and we make no automated decisions producing legal effects.

4. Cookies

We use no advertising, analytics, or tracking cookies, which is why you do not see a cookie consent banner on our sites.

The only cookie we set is:

Cookie Purpose Lifetime
.AspNetCore.Antiforgery.* Protects forms on this site and in the portal against cross-site request forgery. Strictly necessary for security. Session

The portal also stores your sign-in tokens in your browser's local or session storage so you stay signed in, and the mobile app stores your sign-in tokens and offline inspection data on the device so you can work without a connection. These are strictly necessary to provide the service you have requested and are exempt from consent requirements under the Privacy and Electronic Communications Regulations (PECR).

5. Who we share data with

We share personal data only with the sub-processors needed to run the service: hosting, payments, transactional email, and — only when your organisation uses an optional AI feature — AI processing. The current list, with what each one receives, is maintained at Sub-processors.

We may also disclose data where required by law, court order, or to protect our rights, and in the event of a merger or acquisition (in which case this policy continues to apply to data collected under it).

We never sell personal data.

6. International transfers

Some sub-processors may process data outside the UK. Where that happens we rely on UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, as incorporated in each sub-processor's data processing terms.

7. How long we keep data

Data Retention
Account and organisation data Until you delete your account (see section 8)
Base postcode Until you clear it on your profile page, or deleted with your account
Inspection content (sites, templates, inspections, reports, photos, defects, signatures) Until your organisation deletes it or the organisation is deleted; inspection records are your organisation's documents and have no automatic expiry
Register-interest and enquiry details Deleted within 6 months of our launch contact, or immediately on request
AI feature usage records (who used one and when) Until your organisation is deleted
Expired sign-in tokens, password reset tokens, and invitations Deleted within 30 days of expiry
Billing records As required by UK tax law (typically 6 years)
Backups Retained for 7 days, then deleted automatically. Data erased from live systems may persist in backups until they expire; backups are used only for disaster recovery, and erasures are re-applied if a backup is restored.

8. Your rights

Under the UK GDPR you have the right to access, rectify, erase, restrict, and object to the processing of your personal data, and the right to data portability.

You can exercise the most common rights directly in the portal:

  • Erasure: delete your account from your profile page. This removes or anonymises your personal data, including your name in inspection history, your drawn signature on reports you signed as a team member, and any base postcode you set.
  • Portability / access: download a copy of your personal data as JSON from your profile page. The export includes any base postcode you have set.
  • Rectification: edit your name and email, and set or clear your base postcode, on your profile page.

For anything else, email hello@saundy.com. We respond within one month.

You also have the right to complain to the Information Commissioner's Office (ICO): ico.org.uk.

9. Security

Passwords and sign-in tokens are stored only as cryptographic hashes. All traffic is encrypted in transit (TLS), each customer organisation's data is isolated by tenant-level access controls, and access within an organisation is governed by roles and permission groups.

10. When we act as a processor

Organisations use Saundy Inspect to record inspections of their properties. That content can include personal data: the names, roles, and drawn signatures of people who sign reports, and people who appear incidentally in photos or notes. For that data the organisation is the controller and we are a processor: we process it only on their instructions, under our Data Processing Agreement.

If you believe an organisation holds your data in its inspection records and you want it accessed, corrected, or deleted, please contact that organisation directly; they control it. We provide them the tools to honour your request.

11. Changes to this policy

We will post any changes on this page and update the "Last updated" date above. Material changes will be announced to account holders by email.