Privacy Policy
Last updated: 19 June 2026
This Privacy Policy explains how Condit ("we", "us", "our") collects, uses and protects personal data when you visit condit.co.uk, use the Condit application at condit.app, or otherwise interact with us. It is written to comply with the UK GDPR and the Data Protection Act 2018.
1. Who we are
Condit is a web-based art condition reporting and workflow tool operated by [Condit Ltd], a company registered in England and Wales (company number [00000000]), registered office [registered address]. We are the data controller for the personal data described in this policy, except where we act as a processor on behalf of a business customer (see section 4).
For any privacy question, or to exercise your rights, contact us at hello@condit.co.uk. We are registered with the UK Information Commissioner's Office (registration number [ICO reg number]).
2. Scope
This policy covers personal data we process as a controller: visitors to our marketing site, people who contact us, and the account holders who sign in to Condit. Where a business customer uploads content into Condit that contains other people's personal data, the customer is the controller of that content and we process it under their instructions - see section 4 and our Data Processing Agreement.
3. What data we collect
Account data
When you are invited to and set up a Condit account, we process your name, email address, an encrypted (hashed) password, your role within your organisation, and the date you accepted our terms and last signed in.
Organisation data
Your organisation's name, branding (logo, colours) and the report templates it configures.
Content you create in the app
Tasks, report drafts, comments, drawn signatures (stored as an image), photographs, and the report content you enter. This content may itself contain personal data about third parties (for example the name of an examiner, or details of a client or collector). Report drafts are held only while a report is in progress; the finished report is generated as a PDF you download and store on your own systems.
Communications
If you use our contact form or email us, we process the information you provide (name, email, message).
Technical data
IP address, browser and device information, and security/usage logs generated when you use the service. See our Cookie Policy for details of local storage and cookies.
4. When we are a processor, not a controller
For the content your organisation enters into Condit (tasks, reports, photographs, signatures and any third-party personal data within them), your organisation is the data controller and Condit acts as a data processor. We process that content only on your organisation's documented instructions, as set out in our Data Processing Agreement, which forms part of our agreement with each business customer.
5. How we use your data and our legal bases
| Purpose | Lawful basis |
|---|---|
| Providing and operating the Condit service to your organisation | Performance of a contract |
| Creating and securing your account, authentication | Performance of a contract |
| Sending service emails (invites, password resets, important notices) | Performance of a contract |
| Billing and taking payment | Performance of a contract; legal obligation |
| Responding to enquiries and providing support | Legitimate interests (helping people who contact us) |
| Securing the service, preventing fraud and abuse, keeping logs | Legitimate interests (security) |
| Improving the service | Legitimate interests (developing our product) |
| Meeting legal, accounting and tax obligations | Legal obligation |
6. Who we share data with
We do not sell your personal data. We share it only with the service providers we rely on to run Condit, each bound by contract to protect it and to process it only on our instructions. These fall into the following categories:
- Hosting and database - your application data is stored by our hosting provider, Supabase, on infrastructure located in the European Union (Ireland).
- Email - to send service messages such as invitations and password resets.
- Content delivery - to serve our website, fonts and software libraries (these providers receive your IP address in order to deliver the content, but set no cookies).
A current list of the specific providers we use is set out in our Data Processing Agreement and is available on request; we will give business customers reasonable notice before adding a new one. We may also disclose data where required by law, to enforce our terms, or in connection with a merger or sale of our business.
7. International transfers
Some providers above process data outside the UK. Where they do, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, or transfers to countries the UK government recognises as providing adequate protection.
8. How long we keep data
- Account data: for as long as your account is active, and up to 12 months after it is closed, then deleted or anonymised.
- Report drafts and tasks: these are working data, intended to be kept only while a report or job is in progress. They remain until your organisation deletes them or your organisation's account ends; we do not keep them as a long-term archive, and we do not retain a database of your finished reports. When you delete a draft or task it is moved to a recycle bin and then permanently and automatically erased shortly afterwards (currently within around 48 hours).
- Billing records: retained for 6 years to meet accounting and tax obligations.
- Backups: deleted data may persist in encrypted backups for a short period before being overwritten.
9. How we protect your data
We use encryption in transit (HTTPS), encrypted password storage, access controls and database-level row security so that organisations can only access their own data. No system is perfectly secure, but we take reasonable measures appropriate to the risk.
10. Your rights
Under UK data protection law you have the right to access, correct, delete, restrict or object to our use of your personal data, to data portability, and to withdraw consent where we rely on it. To exercise any right, email hello@condit.co.uk. If your personal data sits within content controlled by your organisation, we will direct your request to them. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
11. Children
Condit is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18.
12. Changes to this policy
We may update this policy from time to time. We will post the revised version here and update the date above; significant changes will be notified to account holders.
13. Contact
[Condit Ltd], [registered address]. Email: hello@condit.co.uk.