Privacy Policy
1. Introduction
Welcome to the UK Naturalisation Tracker ("we", "our", "us"). We are committed to protecting your personal data and respecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our web application to track your naturalisation journey.
2. Data Controller
For the purposes of data protection legislation, we act as the Data Controller for your personal data. If you have any questions about this policy or your data, please contact us at the details provided at the end of this document.
3. Information We Collect
We collect and process the following categories of personal data:
3.1 Account Information
- Email address (for authentication and communication)
- Full name
- Password (securely hashed, never stored in plain text)
3.2 Document Information
- Passport details (number, issue/expiry dates, issuing country)
- Biometric Residence Permit (BRP) details
- Life in the UK Test certificate details
- English language qualification details
- Residence proof information
- Referee information (names, occupations)
3.3 Travel Information
- Travel dates (departure and return)
- Destination countries
- Reason for travel
- Any notes you choose to add
3.4 Technical Data
- Device type and browser information
- IP address (for security purposes only)
- Usage data and interaction logs
4. Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: You provide explicit consent when creating an account and using our services.
- Contract: Processing is necessary to provide you with the services you have requested.
- Legitimate Interests: To improve our services and ensure security of the application.
5. How We Use Your Data
We use your personal data to:
- Provide and maintain the naturalisation tracking service
- Calculate your absence days and eligibility status
- Store your document information securely
- Generate summary reports and exports
- Send important service-related communications
- Improve and develop our services
- Ensure the security of your account
6. Data Storage and Security
Your data is stored securely using Google Firebase, which provides enterprise-grade security including encryption at rest and in transit. We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
Security Measures Include:
- End-to-end encryption for data transmission (HTTPS/TLS)
- Encryption at rest for stored data
- Secure authentication using Firebase Authentication
- Regular security assessments and updates
- Access controls and audit logging
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specifically:
- Account data: Retained while your account is active and for up to 30 days after deletion request.
- Document and travel data: Retained while your account is active.
- Technical logs: Retained for up to 90 days for security purposes.
When you delete your account, all associated personal data will be permanently removed from our systems within 30 days, unless we are required by law to retain certain information.
8. Your Rights Under UK GDPR
Under UK data protection law, you have the following rights:
Right of Access
Request a copy of all personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of your personal data ("right to be forgotten").
Right to Restrict Processing
Request limitation of how we use your data.
Right to Data Portability
Request your data in a machine-readable format.
Right to Object
Object to processing based on legitimate interests.
Right to Withdraw Consent
Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, please contact us using the details below. We will respond to your request within one month.
9. Data Sharing and Third Parties
We do not sell, trade, or rent your personal data to third parties. We may share your data with:
- Firebase/Google: For hosting and authentication services (as data processor)
- Legal authorities: If required by law or to protect our legal rights
All third-party processors are bound by appropriate data processing agreements and comply with UK GDPR requirements.
10. International Transfers
Your data may be processed in countries outside the UK where Firebase maintains servers. Google maintains appropriate safeguards for international data transfers, including Standard Contractual Clauses approved by the UK Information Commissioner's Office (ICO).
11. Cookies and Local Storage
We use essential cookies and local storage only to:
- Maintain your authenticated session
- Store your preferences (e.g., applicant type)
- Ensure the security of your account
We do not use cookies for advertising or tracking purposes.
12. Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have collected data from a minor, please contact us immediately.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date.
14. Complaints
If you have concerns about how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk
Telephone: 0303 123 1113
15. Contact Us
For any questions about this Privacy Policy or to exercise your data protection rights, please contact us:
UK Naturalisation Tracker
Email: privacy@naturalisation-tracker.co.uk
We aim to respond to all enquiries within 5 working days.