Important: This Privacy Policy explains how Carderra Limited ("we", "us" or "our") collects, uses and protects your personal information when you use the Civicore service. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Introduction
Civicore (operated by Carderra Limited) respects your privacy and is committed to protecting your personal data. This policy explains how we collect, use, disclose and safeguard your information when you use our AI-powered service for councillors and Members of Parliament. It applies to all users of the Service, including councillors, MPs and authorised staff members.
2. Data controller and data processor
Data controller
Carderra Limited
128 City Road, London, United Kingdom, EC1V 2NX
Company registration number: 14061262
Data Protection Officer
Email: dpo@civicore.co.uk · Phone: 07482 760228
Controller / processor relationship
- Carderra Limited acts as a Data Processor when processing personal data on behalf of our users (councillors, MPs and local authorities) in the course of providing the Service.
- Users of the Service act as Data Controllers for the constituent inquiries and related personal data they submit.
- We process personal data only on your instructions and in accordance with this Privacy Policy.
3. Information we collect
3.1 Personal information you provide
Account information:
- Full name
- Email address
- Phone number
- Professional postal address (office address)
- Username and password (encrypted)
Professional information:
- Job title and role (e.g. Councillor, MP)
- Local authority or constituency details
- Political party affiliation (optional)
- Verification documents (if required)
Communication data:
- Messages, inquiries and feedback submitted through our Service
- Email correspondence with our support team
- Survey responses and feedback forms
Constituent inquiry data (where processed on your behalf):
- Anonymised or pseudonymised summaries of constituent inquiries
- Categories of issues raised (housing, planning, benefits, etc.)
- We strongly advise against submitting identifiable personal data of constituents (see the Acceptable Use Policy in our Terms)
3.2 Technical information automatically collected
- IP address (anonymised where possible)
- Browser type and version
- Operating system and device information
- Date and time of access
- Pages viewed and features used
- Session duration and interactions
- Referring website or source
3.3 AI training and service improvement data
To improve our AI models and service quality, we may analyse:
- Aggregated and anonymised usage patterns
- Performance metrics of AI-generated responses
- User feedback and correction data
We do not use personal data (including constituent information) to train our AI models unless it has been fully anonymised and aggregated.
4. Legal basis for processing (UK GDPR)
- Contractual necessity (Article 6(1)(b)): providing the Service and fulfilling our contract with you.
- Public task (Article 6(1)(e)): processing constituent inquiries on behalf of public officials in the public interest.
- Legitimate interests (Article 6(1)(f)): service improvement, security and business operations.
- Consent (Article 6(1)(a)): marketing communications, which you may withdraw at any time.
- Legal obligation (Article 6(1)(c)): compliance with applicable legal requirements.
4.1 Special category data
We do not intentionally collect special category data (Article 9, UK GDPR). Should such data be inadvertently submitted, we will delete it promptly upon discovery. Users are expressly prohibited from submitting special category data.
5. How we use your information
5.1 Service provision
- To create and manage your user account
- To provide, maintain and deliver the Civicore Service
- To generate AI responses to constituent inquiries (as a draft tool)
- To store and retrieve your inquiry history and preferences
5.2 Communication and support
- To respond to your inquiries and provide customer support
- To send Service-related notifications and updates
- To inform you of changes to our Terms or Privacy Policy
- To send billing and subscription-related communications
5.3 Service enhancement
- To analyse usage patterns and improve the Service
- To train and refine our AI algorithms (using anonymised data only)
- To develop new features and functionality
- To monitor and evaluate the performance of the Service
5.4 Security and compliance
- To protect against fraud, abuse and security threats
- To verify your identity and eligibility
- To comply with applicable laws and regulations
- To enforce our Terms and Conditions
6. How we share your information
We do not sell, trade or rent your personal information. We may share information in the following limited circumstances:
6.1 Service providers
- Stripe: payment processing (we do not store full card details)
- AWS/Azure: cloud hosting and infrastructure (account data, usage data, AI processing)
- SendGrid: email delivery (email address)
- Analytics providers: service analytics (anonymised usage data)
- Support tools: customer support management (contact details and support tickets)
All service providers are contractually bound to process data only on our instructions and to maintain appropriate security measures.
6.2 Legal requirements
- Law, court order or government regulation
- Enforcement of our Terms and Conditions
- Protection of our rights, property or safety (or those of our users)
6.3 Business transfers
In the event of a merger, acquisition, reorganisation or sale of assets, your information may be transferred as part of the transaction. You will be notified of any such transfer.
6.4 With your consent
We may share your information with third parties where you explicitly consent.
7. International data transfers
Your personal information may be transferred to and processed in countries outside the UK, including the United States and the European Economic Area. Safeguards in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission and the UK ICO
- Assurance that all third-party processors comply with UK data protection standards
- Transfer impact assessments (TIAs) where required
8. Data security
8.1 Technical measures
- Encryption: all data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access controls: strict role-based access controls and authentication
- Security testing: regular vulnerability assessments, penetration testing and audits
- Network security: firewalls, intrusion detection and secure networks
- Backup and recovery: regular encrypted backups with disaster recovery procedures
8.2 Organisational measures
- Staff training: regular data protection training for all employees
- Confidentiality agreements binding all staff
- Data minimisation: we collect only the data necessary
- Privacy by design: privacy considerations integrated into service development
8.3 Data breach response
- Notify the ICO within 72 hours of becoming aware
- Notify affected individuals without undue delay
- Take immediate steps to contain and remediate the breach
9. Data retention
- Account information: duration of active subscription + 24 months
- Communication data: up to 6 years (legal and business record-keeping)
- Technical logs: up to 12 months (security monitoring and service improvement)
- Constituent inquiry data: duration of your account + 30 days, anonymised thereafter
- AI training data: anonymised data may be retained indefinitely (no personal data retained)
- Billing records: 7 years (tax and accounting compliance)
9.1 Deletion at your request
You may request deletion of your account and personal data at any time. We will delete your data within 30 days of your request, subject to legal retention obligations.
10. Your rights
- Right of access: request a copy of the personal information we hold about you
- Right to rectification: request correction of inaccurate or incomplete information
- Right to erasure: request deletion of your personal information in certain circumstances
- Right to restriction of processing: request limitation of processing in certain situations
- Right to data portability: request transfer of your data in a machine-readable format
- Right to object: object to processing based on legitimate interests or direct marketing
- Right to withdraw consent: withdraw consent at any time where processing is consent-based
- Right to lodge a complaint with the Information Commissioner's Office
10.1 How to exercise your rights
Email privacy@civicore.co.uk or write to the Data Protection Officer, Carderra Limited, 128 City Road, London, EC1V 2NX. We respond within 30 days and may ask you to verify your identity first.
11. Data Protection Impact Assessment (DPIA)
We have conducted a DPIA for the processing of personal data through our AI Service, identifying and mitigating risks relating to:
- Automated decision-making and profiling
- Processing of constituent data on behalf of public officials
- The potential for bias or inaccuracies in AI-generated outputs
A summary of our DPIA is available on request to our DPO.
12. AI-specific transparency and use
12.1 AI-generated content
- AI-generated content may contain errors or inaccuracies
- The AI model may reflect biases present in its training data
- Human oversight and review are essential before any official use
12.2 Automated decision-making
The Service does not engage in fully automated decision-making with legal or similarly significant effects. Final decisions on constituent responses are made by human users.
12.3 Transparency
Where AI-generated content is used in official communications, you should consider declaring this in accordance with your local authority's policies on AI usage.
13. Cookies and tracking technologies
13.1 Types of cookies we use
- Essential: required for basic functionality (login, session management) — session duration
- Preferences: remember your settings — up to 12 months
- Analytics: track usage patterns and improve the Service — up to 24 months
- Marketing: personalise marketing communications (with consent) — up to 12 months
13.2 Cookie management
You can control cookie settings through your browser preferences, though disabling essential cookies may affect functionality.
14. Children's privacy
Our Service is not intended for individuals under 18 and we do not knowingly collect their personal information. If you believe we have, please contact us and we will delete it promptly.
15. Changes to this Privacy Policy
- Material changes will be communicated by email and/or a prominent notice on our website at least 30 days in advance
- The 'Last updated' date at the top of this page will be revised accordingly
Continued use of the Service after changes take effect constitutes acceptance of the updated policy. See also our Terms and Conditions.
16. Supervisory authority (UK ICO)
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk
Phone: 0303 123 1113
17. Contact us
Data Protection Officer, Carderra Limited
128 City Road, London, United Kingdom, EC1V 2NX
Email: privacy@civicore.co.uk
Phone: 07482 760228
Company registration number: 14061262