Privacy Policy
This policy explains how Gordon Corporation Ltd collects and uses personal data through gordoncorp.uk and GORDX.
1. Who we are
Gordon Corporation Ltd is the controller of the personal data described in this policy.
- Registered in England and Wales, company number 17470403
- Registered office: 27 Cromer Avenue, Grimsby, DN34 5ED
- Contact for anything about your data: [email protected]
2. What this policy covers
This policy covers personal data about:
- GORDX users: people who sign up for and use GORDX on behalf of their business;
- website visitors: people who visit gordoncorp.uk or contact us;
- job and contractor applicants: people who apply for roles with us.
It does not cover data that GORDX users put into GORDX about their own customers (for example, the names and emails on their invoices). For that data, the GORDX user's business is the controller and we act as its processor under the data processing terms in our Terms of Service. If you received an invoice through GORDX and have a question about your data, contact the business that sent it.
3. Information we collect
| Who | What we collect | Where it comes from |
|---|---|---|
| GORDX users | Name, email, password (stored encrypted), business name, address, company and VAT numbers, bank details you choose to show on invoices | You, when you sign up and fill in your business details |
| GORDX users | Subscription and billing records (plan, payment status, last four card digits) | Stripe, when you subscribe |
| GORDX users | Stripe account status (whether card payments are switched on) | Stripe, when you connect your account |
| GORDX users | Usage and technical data: log-in times, IP address, browser type, error logs | Automatically, when you use GORDX |
| Website visitors | Emails you send us and your IP address | You, and our hosting provider |
| Applicants | Name, contact details, CV, work history and anything else you send us | You, or the job site you applied through (such as LinkedIn) |
We do not collect special category data (such as health or ethnicity) and do not knowingly collect data about children.
4. How we use it and our lawful basis
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Creating and running your GORDX account, sending invoices and reminders you ask us to send | Contract |
| Taking payment for your GORDX plan and keeping billing records | Contract; legal obligation (tax and accounting records) |
| Sending service emails: sign-up confirmation, password resets, billing and changes to our terms | Contract |
| Keeping GORDX secure, preventing fraud and fixing problems | Legitimate interests (running a safe, working service) |
| Understanding how GORDX is used so we can improve it | Legitimate interests |
| Replying to messages and enquiries | Legitimate interests |
| Assessing job and contractor applications | Legitimate interests (hiring); steps before a contract |
| Occasional product news by email | Consent, or legitimate interests for existing customers, with an unsubscribe link in every email |
We do not sell personal data, and we do not use it for automated decision-making that has legal or similarly significant effects on you.
5. Who we share it with
We share personal data only with service providers who help us run GORDX, under contracts that require them to protect it.
| Provider | What they do for us | Where data is processed |
|---|---|---|
| Supabase | Database, logins and server functions | UK, EU or US |
| Cloudflare | Website and app hosting, security, email forwarding | Global network |
| Resend | Sending invoice, reminder and account emails | Ireland (EU) |
| Stripe | GORDX subscription payments, and connecting your own Stripe account | UK, EU and US |
| Monzo | Our business bank account (for payments to us) | UK |
We may also share data with professional advisers (such as accountants or lawyers), with authorities when the law requires it, or with a buyer if Gordon Corporation or GORDX is ever sold, who would have to respect this policy.
When you connect your own Stripe account, Stripe also processes your data as a controller under its own privacy policy.
6. International transfers
Some of our providers process data outside the UK. When they do, we rely on UK adequacy regulations (for example, for the EU) or appropriate safeguards such as the UK International Data Transfer Addendum to the EU standard contractual clauses, or the UK Extension to the EU–US Data Privacy Framework where the provider is certified. You can ask us for details at [email protected].
7. How long we keep it
| Data | How long |
|---|---|
| GORDX account and business details | While your account is open, then deleted within 90 days of closure |
| Billing and payment records | 6 years after the end of the financial year they relate to (UK tax law) |
| Technical and security logs | Up to 12 months |
| Emails and enquiries | Up to 2 years after our last contact |
| Unsuccessful applications | 6 months after the role is filled, unless you agree to us keeping them longer |
8. Cookies and similar technologies
We only use what is strictly necessary to make our sites work, so we do not show a cookie banner.
- GORDX app: stores a login token in your browser so you stay signed in. Signing out removes it.
- gordoncorp.uk: loads fonts from Google Fonts, which means Google receives your IP address when the page loads.
- Cloudflare may set a security cookie to protect our sites from abuse.
We do not use advertising or tracking cookies. If we ever add analytics that need your consent, we will ask first and update this policy.
9. Your rights and how to complain
Under UK data protection law, you can ask us to:
- give you a copy of the personal data we hold about you;
- correct data that is wrong or incomplete;
- delete your data, where we no longer have a good reason to keep it;
- restrict or object to how we use it, including stopping marketing emails at any time;
- send your data to you or another provider in a portable format.
Email [email protected]. We will reply within one month, and it is free in most cases. We may ask you to confirm your identity first.
If you are unhappy with how we handle your data, please tell us first so we can put it right. You can also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.
10. Security
We protect personal data with encryption in transit (HTTPS), hashed passwords, database rules that keep each business's data separate, and access limited to the people and systems that need it. No system is perfectly secure; if a breach affects you, we will tell you and the ICO where the law requires it.
11. Changes to this policy
We will update this policy when the way we use data changes. The date at the top shows the latest version. If a change significantly affects GORDX users, we will email you before it takes effect.