Privacy policy
Last updated: June 2026
Who we are
EMSist (“we”, “our”, “us”) operates the website emsist.uk. We are a UK-based company registered with the Information Commissioner's Office (ICO). Our contact email is [email protected]. For your account, payment and website usage data we act as the data controller. For personal data contained inside documents you upload (for example, names of staff in an EMS manual), we act as a data processor on your behalf — consultant customers can request our data processing agreement at the email above.
What data we collect
- Account data: Email address when you sign up or use our free scan. We use this to authenticate you and deliver your results.
- Payment data: Processed securely by Stripe. We never see or store your full card details. Stripe's privacy policy applies to payment processing.
- Uploaded documents: EMS documents you upload for scanning. Each file is held only for the seconds needed to extract its text, then deleted — before analysis begins. We do not retain, log, or back up your uploaded files.
- Scan results: The gap analysis output — compliance scores, findings, recommendations, and short quoted excerpts from your documents used as evidence for each finding — is stored in your account so you can access past reports.
- Usage data: If you accept analytics cookies, we use Google Analytics to understand how the site is used. We also use Cloudflare's cookieless analytics.
How we use your data
- To provide and improve the EMSist scanning service
- To send you your scan results and reports (delivered by email via Resend)
- To process payments via Stripe
- To send occasional product updates if you opt in (via Mailchimp — you can unsubscribe at any time)
- To respond to support requests
We do not sell, rent, or share your personal data with third parties for marketing purposes.
Document security
We take the security of your EMS documents seriously. Uploaded files are transmitted via TLS encryption through Cloudflare and held on our server only for the seconds it takes to extract their text, after which the files are deleted — including when a scan fails. Documents are never retained, logged, or included in backups. Only the scan results (compliance scores, findings, recommendations, and short quoted evidence excerpts) are stored. During analysis of paid scans, the extracted document text is processed by Anthropic's Claude API; Anthropic does not train on this data and does not retain it beyond the API request.
Sub-processors and international transfers
We use the following providers to operate EMSist. Where a provider processes data outside the UK, transfers are protected by a recognised safeguard — the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (“UK Addendum”), or the UK extension to the EU–US Data Privacy Framework (“DPF”).
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Application hosting | EU (Finland/Germany) | None needed (UK adequacy for EEA) |
| Supabase, Inc. | Database and authentication | EU (AWS Ireland) | EU-hosted; SCCs + UK Addendum for support access |
| Anthropic, PBC | AI analysis of document text (paid scans) | USA | SCCs + UK Addendum (Anthropic DPA) |
| Cloudflare, Inc. | CDN, TLS, DNS, security, analytics | Global edge (UK/EU primary) | SCCs + UK Addendum; DPF certified |
| Stripe Payments UK Ltd | Payment processing | UK/USA | Stripe DPA; DPF certified |
| Resend (Plus Five Five, Inc.) | Transactional email (report delivery) | USA | SCCs + UK Addendum (Resend DPA) |
| Intuit Inc. (Mailchimp) | Opt-in marketing email | USA | SCCs + UK Addendum; DPF certified |
| Google LLC (Analytics) | Website usage analytics (only with your consent) | USA | SCCs + UK Addendum; DPF certified |
Privacy policies: Supabase, Stripe, Cloudflare, Anthropic, Resend, Mailchimp, Google.
Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and all associated data
- Object to processing of your data
- Request data portability
- Withdraw consent at any time
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
Data retention
Account data and scan results are retained for as long as your account is active. If you delete your account, all associated data is permanently removed within 30 days, and ages out of our rotating backups within a further 14 days. Results of anonymous free scans (run without an account) are automatically deleted after 90 days. Uploaded documents are never retained — they are deleted within seconds of upload, once their text has been extracted.
Cookies
EMSist uses essential cookies required for authentication (Supabase session cookies), which need no consent. Google Analytics cookies are used only if you accept them via the consent banner — if you decline, no analytics cookies are set. You can change your mind by clearing this site's data in your browser, which will show the banner again.
Changes to this policy
We may update this privacy policy from time to time. Material changes will be communicated via email to registered users. The “last updated” date at the top of this page indicates when the policy was last revised.
Contact
If you have questions about this privacy policy or how we handle your data, contact us at [email protected]. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).