SmartLPA

Legal

Privacy Policy

Last updated

SmartLPA Ltd (“SmartLPA”, “we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights you have over it. It applies to the SmartLPA web application and website (the “Service”), and should be read alongside our Terms of Service.

1. Who we are (Data Controller)

SmartLPA Ltd is the “data controller” responsible for your personal data.

  • Company: SmartLPA Ltd, a company registered in England and Wales, company number 17309200.
  • Contact for privacy matters: support@smartlpa.co.uk.

We are not required to appoint a statutory Data Protection Officer, but the contact above is responsible for overseeing data protection at SmartLPA.

2. What SmartLPA does (and does not) do

SmartLPA is a document-preparation and checking tool. We help you prepare and review Lasting Power of Attorney (“LPA”) forms for England and Wales, and we run an automated check against the Office of the Public Guardian’s (“OPG”) requirements.

We are not a law firm and do not provide legal advice. We do not submit your LPA to the OPG on your behalf. Our role is to help you complete and check your own forms. This distinction matters for how your data is used — see our Terms of Service for more.

3. Personal data we collect

We collect the following categories of personal data.

3.1 Data you provide to create your LPA

To prepare your LPA forms, you provide details about the people involved. This can include:

  • Donor (the person the LPA is for): full name, address, date of birth, and (for Health & Welfare LPAs) preferences about care and life-sustaining treatment.
  • Attorneys and replacement attorneys: full names, addresses, and dates of birth.
  • Certificate provider: full name and address.
  • People to be notified (if any): names and addresses.

3.2 Special-category (sensitive) data

Health & Welfare LPAs (form LP1H) concern your health, care, and welfare. Information you provide in a Health & Welfare LPA — including any preferences about medical treatment and life-sustaining treatment — is “special-category” personal data under UK GDPR (data concerning health). We handle this data with additional care, and we only process it on the basis of your explicit consent, given when you choose to create a Health & Welfare LPA (see “Legal bases”, section 6).

3.3 Uploaded photographs of signed forms

When you use our checking service, you photograph your completed and signed LPA pages and upload them to us. These images contain the personal data above, plus signatures, and are processed by our automated checking service (see section 5).

3.4 Account and contact data

  • Email address — used to create your account and sign you in (we use passwordless “magic link” sign-in).
  • Phone number — only if you choose to receive SMS reminders (optional; see section 6 on consent).
  • Email address, if you ask us for a free guide. You do not need an account. We record your address, when you asked, and which page you asked from. Separately, and only if you tick the optional box, we record that you agreed to receive occasional guidance by email. These are two different decisions and we store them separately — asking for the guide never signs you up for anything else.

3.5 Payment data

When you pay, our payment processor Stripe collects and processes your card details directly. SmartLPA does not receive or store your full card number. We store a record that a payment was made (amount, date, and Stripe’s reference), not your card data.

3.6 Technical and usage data

  • Sign-in sessions and security tokens (to keep you logged in and secure your uploads).
  • Cookies necessary for the Service to function — see section 10.
  • Optional advertising-measurement cookies — only if you accept them. See section 10.
  • 4. How we use your personal data

    We use your personal data to:

    • Prepare your LPA forms from the details you provide.
    • Run our automated check against OPG requirements and give you the results.
    • Take payment for the service.
    • Create and secure your account, and sign you in.
    • Send service messages (for example, your receipt, or that your check is ready).
    • Send SMS reminders, only if you have opted in.
    • Send you a guide you requested, and — only if you separately agreed — occasional guidance about making and using an LPA.
    • Keep records we are required to keep, and detect and prevent fraud or misuse.
    • Comply with our legal obligations.

    We do not sell your personal data, and we do not use it for third-party advertising.

    5. The automated checking service and artificial intelligence

    Important — please read this carefully.

    Our checking service uses artificial intelligence provided by Anthropic to read the photographs of your LPA and check them against OPG requirements. To do this:

    • The content of your LPA — including the personal data and, for Health & Welfare LPAs, the special-category health data described above — is sent to Anthropic’s API for automated analysis.
    • Anthropic acts as our data processor and processes this data on our instructions, under a data processing agreement.
    • This involves a transfer of your personal data outside the UK (Anthropic is based in the United States). We rely on appropriate safeguards for this transfer — see section 8 (International transfers).

    The check is automated, but it does not make a legally-significant decision about you: it produces a report for you to review and act on. You remain responsible for your own LPA. If you would prefer not to have your data processed by AI in this way, you should not use the checking service.

    7. Who we share your data with (sub-processors)

    We use trusted third-party service providers (“processors”) to run the Service. Each processes your data only on our instructions, under a data processing agreement. They are:

    ProviderWhat they doData they processLocation
    StripePayment processingCard & payment data (collected directly by Stripe)UK/EU/US
    NeonDatabase hostingAll LPA and account data (encrypted at rest)EU
    Amazon Web Services (S3)Storage of uploaded form photographsPhotos of your signed LPAsUnited Kingdom (London)
    AnthropicAI checking serviceLPA content incl. health data (see section 5)US
    ResendSending emailsYour email addressUS
    Upstash (QStash)Background job processingJob references (not your form data)EU
    Ideal PostcodesLooking up addresses from a postcodeThe postcode you type into the address finder. The lookup is made by our server, so they do not receive your name, your IP address, or the address you go on to select.UK
    VercelApplication hostingTechnical/usage dataUS/global
    Vercel (Analytics)Website analytics — how many people visit and which pages they viewPage address and referring site. No cookies, no device fingerprinting, and no information that identifies you as an individual.US/global
    TwilioSMS reminders (if enabled)Your phone number (only if you opt in)Ireland (EU)
    Google Ireland LtdAdvertising conversion measurement (only if you accept optional cookies)Cookie identifiers, IP address, and the value of your order. Never your name, your email, or your LPA content.Ireland/US
    Meta Platforms Ireland LtdAdvertising measurement (only if you accept optional cookies)Cookie identifiers, IP address, and — after a purchase — a one-way encrypted (hashed) form of your email address. Never your LPA content.Ireland/US

    We do not share your personal data with anyone else except where required by law, or to establish, exercise, or defend legal claims.

    8. International transfers

    Some of our processors are located outside the UK (notably Anthropic, Resend, and Vercel in the United States, and Meta, which is established in Ireland but transfers to the United States). Where your personal data is transferred outside the UK, we ensure it is protected by appropriate safeguards, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with additional protective measures.

    Because our checking service transfers special-category health data to the United States (section 5), we consider this transfer carefully. If you do not wish your data to be transferred in this way, please do not use the checking service.

    9. How long we keep your data (retention) and how it’s deleted

    We keep your personal data only as long as we need it:

    • While you have an account, we keep your LPA drafts and records so you can access them.
    • Uploaded photographs of your signed forms are retained for 30 days and then automatically deleted. This covers the check, any manual review, and the period in which you can correct and re-check a form.
    • Unpaid drafts are deleted 120 days after you last worked on them. Completed (paid) LPAs are kept for 180 days from purchase, so you have time to print, sign, and check them. We email you before either deadline.
    • When you delete your account, your personal data is deleted or irreversibly anonymised.
    • If you asked for a free guide but did not opt in to emails, we delete your email address30 days after we send it — long enough to resend it if it bounced or you ask again.
    • If you opted in to emails, we keep your address until you unsubscribe. There is no fixed period: you decide how long by staying subscribed.
    • When you unsubscribe, we keep a minimal record that you did — your email address and the fact you opted out — for as long as we operate. We do this so you cannot be accidentally added back by a later sign-up. It is used for nothing else, and never to contact you.
    • We keep minimal records of transactions for as long as we are required to for legal, tax, and accounting purposes — typically six years.

    Deleting your data. You can delete your account and associated personal data at any time from your account settings. When you do, we irreversibly remove or anonymise your personal data from our active systems, including the encrypted LPA content and uploaded photographs, subject only to the minimal legal/financial records above.

    10. Cookies

    We use cookies that are strictly necessary for the Service to work — for example, to keep you signed in and to secure your session. These do not require your consent.

    We also use optional advertising-measurement cookies, set by Meta, which help us understand whether our advertising works. We only set these if you choose “Accept” on our cookie banner. If you choose “Reject”, or make no choice at all, they are never set — and if you have accepted and later change your mind, we delete them.

    CookiePurposeLifetime
    slpa_consentRemembers your cookie choice. Strictly necessary — it exists only to record a decision you made, so it is set whichever option you choose.6 months
    _fbpMeta advertising measurement — distinguishes browsers. Optional.3 months
    _fbcMeta advertising measurement — records that you arrived from one of our ads. Optional.3 months
    _gcl_awGoogle advertising measurement — records that you arrived from one of our Google ads, so we can tell which adverts lead to orders. Optional.90 days

    Changing your mind. Select “Cookie settings” at the foot of any page to re-open the banner and change your choice at any time. Choosing “Reject” there deletes the _fbp, _fbc and _gcl_aw cookies from your browser, and we stop sending advertising-measurement information about you to Meta or Google — including from our own servers.

    We do not use cookies for advertising measurement anywhere you enter details about your LPA — the drafting questionnaire, your dashboard and your documents are excluded entirely.

    Our website analytics do not use cookies at all. We use Vercel Analytics to count visits and see which pages are viewed. It stores nothing on your device and does not fingerprint your browser or identify you, so it is not in the table above and is not part of the cookie choice — there is nothing stored for you to consent to. It tells us how many people visited a page, never who they were.

    11. Your rights

    Under UK GDPR, you have the right to:

    • Access the personal data we hold about you.
    • Rectify inaccurate or incomplete data.
    • Erase your data (“right to be forgotten”).
    • Restrict or object to certain processing.
    • Data portability — receive your data in a portable format.
    • Withdraw consent at any time, where we rely on it.
    • Not be subject to solely-automated decisions with legal effect (our check does not make such decisions — see section 5).

    How to exercise your rights. You can delete your account and data yourself at any time from your account settings. For any other request, please contact us at support@smartlpa.co.uk. We will respond within one month.

    Complaints. If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk — though we would appreciate the chance to resolve your concern first.

    12. How we protect your data

    We take security seriously. Measures include:

    • Encryption at rest of the personal data in your LPA drafts and check results.
    • Secure, passwordless sign-in and protected upload links.
    • Access controls limiting who can access personal data.
    • Processing only through vetted providers under data processing agreements.

    No system is perfectly secure, but we work to protect your data using appropriate technical and organisational measures.

    13. Children

    The Service is intended for adults (18+) preparing LPAs. It is not directed at children, and we do not knowingly collect data from children.

    14. Changes to this policy

    We may update this policy from time to time. We will post the updated version here and change the “Last updated” date. If we make significant changes, we will take reasonable steps to notify you.

    15. Contact

    For any privacy questions or to exercise your rights, contact us at:

    SmartLPA Ltd, a company registered in England and Wales (company number 17309200).
    support@smartlpa.co.uk