GORDONCORPORATION
Legal

Privacy Policy

Effective 26 September 2026

This policy explains how Gordon Corporation Ltd collects and uses personal data through gordoncorp.uk and GORDX.

1. Who we are

Gordon Corporation Ltd is the controller of the personal data described in this policy.

2. What this policy covers

This policy covers personal data about:

It does not cover data that GORDX users put into GORDX about their own customers (for example, the names and emails on their invoices). For that data, the GORDX user's business is the controller and we act as its processor under the data processing terms in our Terms of Service. If you received an invoice through GORDX and have a question about your data, contact the business that sent it.

3. Information we collect

WhoWhat we collectWhere it comes from
GORDX usersName, email, password (stored encrypted), business name, address, company and VAT numbers, bank details you choose to show on invoicesYou, when you sign up and fill in your business details
GORDX usersSubscription and billing records (plan, payment status, last four card digits)Stripe, when you subscribe
GORDX usersStripe account status (whether card payments are switched on)Stripe, when you connect your account
GORDX usersUsage and technical data: log-in times, IP address, browser type, error logsAutomatically, when you use GORDX
Website visitorsEmails you send us and your IP addressYou, and our hosting provider
ApplicantsName, contact details, CV, work history and anything else you send usYou, or the job site you applied through (such as LinkedIn)

We do not collect special category data (such as health or ethnicity) and do not knowingly collect data about children.

4. How we use it and our lawful basis

PurposeLawful basis (UK GDPR)
Creating and running your GORDX account, sending invoices and reminders you ask us to sendContract
Taking payment for your GORDX plan and keeping billing recordsContract; legal obligation (tax and accounting records)
Sending service emails: sign-up confirmation, password resets, billing and changes to our termsContract
Keeping GORDX secure, preventing fraud and fixing problemsLegitimate interests (running a safe, working service)
Understanding how GORDX is used so we can improve itLegitimate interests
Replying to messages and enquiriesLegitimate interests
Assessing job and contractor applicationsLegitimate interests (hiring); steps before a contract
Occasional product news by emailConsent, or legitimate interests for existing customers, with an unsubscribe link in every email

We do not sell personal data, and we do not use it for automated decision-making that has legal or similarly significant effects on you.

5. Who we share it with

We share personal data only with service providers who help us run GORDX, under contracts that require them to protect it.

ProviderWhat they do for usWhere data is processed
SupabaseDatabase, logins and server functionsUK, EU or US
CloudflareWebsite and app hosting, security, email forwardingGlobal network
ResendSending invoice, reminder and account emailsIreland (EU)
StripeGORDX subscription payments, and connecting your own Stripe accountUK, EU and US
MonzoOur business bank account (for payments to us)UK

We may also share data with professional advisers (such as accountants or lawyers), with authorities when the law requires it, or with a buyer if Gordon Corporation or GORDX is ever sold, who would have to respect this policy.

When you connect your own Stripe account, Stripe also processes your data as a controller under its own privacy policy.

6. International transfers

Some of our providers process data outside the UK. When they do, we rely on UK adequacy regulations (for example, for the EU) or appropriate safeguards such as the UK International Data Transfer Addendum to the EU standard contractual clauses, or the UK Extension to the EU–US Data Privacy Framework where the provider is certified. You can ask us for details at [email protected].

7. How long we keep it

DataHow long
GORDX account and business detailsWhile your account is open, then deleted within 90 days of closure
Billing and payment records6 years after the end of the financial year they relate to (UK tax law)
Technical and security logsUp to 12 months
Emails and enquiriesUp to 2 years after our last contact
Unsuccessful applications6 months after the role is filled, unless you agree to us keeping them longer

8. Cookies and similar technologies

We only use what is strictly necessary to make our sites work, so we do not show a cookie banner.

We do not use advertising or tracking cookies. If we ever add analytics that need your consent, we will ask first and update this policy.

9. Your rights and how to complain

Under UK data protection law, you can ask us to:

Email [email protected]. We will reply within one month, and it is free in most cases. We may ask you to confirm your identity first.

If you are unhappy with how we handle your data, please tell us first so we can put it right. You can also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.

10. Security

We protect personal data with encryption in transit (HTTPS), hashed passwords, database rules that keep each business's data separate, and access limited to the people and systems that need it. No system is perfectly secure; if a breach affects you, we will tell you and the ICO where the law requires it.

11. Changes to this policy

We will update this policy when the way we use data changes. The date at the top shows the latest version. If a change significantly affects GORDX users, we will email you before it takes effect.