Privacy notice
What we hold, why, and how to get rid of it.
Last updated 14 September 2026
You are handing us your policies, your passport dates and your household's paperwork. That deserves plain language rather than legal fog, so here is exactly what happens to it.
1. Who we are
PollyHQ is a service operated by POLLYHQ LIMITED ("we", "us"). We read the insurance policies and personal documents you choose to upload, keep track of renewal dates, and answer questions about your own cover.
- Data controller: POLLYHQ LIMITED
- Registered in: England and Wales
- Companies House number: 17456463
- Registered office: Redwings, Herons Farm Lane, Kirdford, RH14 0PR, United Kingdom
- Data protection contact: office@pollyhq.com
- ICO registration: our registration with the UK Information Commissioner's Office is being processed; the reference will be published here once issued.
We are not an insurer, broker or financial adviser, and we are not authorised or regulated by the Financial Conduct Authority. We do not sell cover and we do not sell, rent or trade your information with anyone, ever.
2. What we hold
- Account details — your name, email address, and the postcode and country you give at sign-up, plus any discount code you used.
- Insurance information — insurer, policy number, premium, start and renewal dates, what is covered, excesses, exclusions and claim contact details, together with the documents you upload and the text extracted from them.
- Personal documents you choose to add — for example passports, driving licences, visas and DBS certificates, including holder name, document number, issuing country and expiry date.
- Vehicle information — registration, make and model, MOT, tax and service dates, recorded mileage and indicative value.
- Payment card records you create during a theft report — issuer, card type, a nickname and the last four digits. We never hold full card numbers, expiry dates or security codes.
- Household relationships — who shares your account, and invitations you send.
- Your questions and our answers — so you can go back to them later.
- Fuel and home records — tank size, target price and the prices you record.
Some of this is sensitive by nature — health or life cover, for instance. We only hold it because you uploaded it, and only to do the job you asked of us.
3. Why we hold it, and our lawful basis
- To provide the service you signed up for — reading your documents, tracking renewals, answering your cover questions. Lawful basis: performance of our contract with you.
- To send you reminders about renewals, MOTs, document expiries and fuel prices you asked to be alerted about. Lawful basis: performance of our contract, and your settings, which you can switch off per item at any time.
- To keep the service secure — sign-in, optional two-factor authentication, and keeping households separated. Lawful basis: our legitimate interest in protecting your information.
- To take payment for membership. Lawful basis: performance of our contract and our legal obligations for financial records.
- For sensitive categories (such as health-related cover), we rely on your explicit consent, given when you upload the document. Withdraw it by deleting the record or your account.
4. What we never do
- We never sell or share your information for marketing or advertising.
- We never use your documents to train any AI model.
- We never show one household's records to another. Separation is enforced in the database itself.
- We never store full payment card numbers or security codes.
- We never let our AI reason over expired policies or anyone else's cover.
5. Who else processes it (sub-processors)
We use a small number of specialist providers to run the service. They act only on our instructions and cannot use your information for their own purposes:
- Amazon Web Services, Ireland (eu-west-1) — hosting, database and encrypted file storage for your account, records and uploads, and the sign-in service.
- Google (Gemini models) — receives the text or image of a document when you upload it, and the relevant extracts from your own policies when you ask a question, so it can reply. Used through a paid enterprise route: your content is processed, never used to train models.
- DVSA (Driver and Vehicle Standards Agency, UK government) — receives a vehicle registration you enter and returns official MOT dates and mileage.
- Amazon Web Services (SES) — sends your reminders and account emails. Receives your email address and the message itself.
- Stripe — will take membership payments when paid plans open. Card details go directly to Stripe, never to us.
Some providers process information outside the UK and EEA. Where they do, transfers are covered by approved safeguards such as standard contractual clauses. Links to each supplier's own security arrangements are in our security statement.
6. How long we keep it
- While your account is open — your records stay available to you, including expired policies, because claim history matters.
- When you delete a record — it and any file attached to it are removed straight away.
- When you delete your account — every record, uploaded file and your sign-in are removed immediately and permanently. Routine backups age out within 30 days.
- Payment records are kept for as long as tax and accounting law requires, separately from your policy data.
7. How we protect it
- Your information travels over an encrypted connection and is stored encrypted.
- Uploaded files sit in private storage, never at a public web address, and open only through a short-lived link issued to you.
- Every record is locked to your household at database level, not merely hidden in the screens.
- Two-factor sign-in using a free authenticator app, optional for insurance records and required to add or open a passport, driving licence, ID card, visa, residence permit, health card or DBS certificate.
- Household sharing is invite-only and capped at four people.
- Administrative access is limited by role and used only to run the service.
- Full detail — encryption standards, hosting region, logging, secret management, backups, incident response and how to report a vulnerability — is in our security statement.
8. Your rights
You can, at any time and without asking us:
- Get a copy of everything we hold — one click on the Your data page inside the app.
- Delete your account and all your records — one click on the same page.
- Correct anything — every field extracted from a document is editable.
- Turn off reminders per policy, document or vehicle.
You also have the right to object to or restrict certain processing, and to complain to your data protection regulator. In the UK that is the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF, 0303 123 1113. We would rather you told us first at office@pollyhq.com, but you do not have to.
9. Automated decisions
Our assistant gives guidance, not decisions. It tells you which of your policies appear to respond and why, always with the wording it relied on. Nothing it says binds you or your insurer, and the insurer's decision on any claim is final. Nothing on PollyHQ is regulated financial advice.
10. Children
PollyHQ is for adults. You may record a child's document (a passport, say) as part of your household, but children cannot hold their own account.
11. If something goes wrong
If a breach affects your information, we will notify the Information Commissioner's Office within 72 hours of becoming aware and tell you without undue delay — what happened, what it means for you, and what we are doing about it. To report a security problem to us, email office@pollyhq.com; our full process is in the security statement.
12. Changes and contact
If we change this notice materially, we will tell members before it takes effect. For any privacy question, or to exercise a right the app doesn't already give you, contact us through the app and we will respond within one month. Our registered details: POLLYHQ LIMITED, registered in England and Wales, company number 17456463, registered office Redwings, Herons Farm Lane, Kirdford, RH14 0PR.
