1Who we are
Varde is provided by Stripy Fish Networks Limited, a company registered in England and Wales, registered office 26 Wellhead Lane, Westbury, Wiltshire, BA13 3PT ("we", "us", "Stripy Fish Networks").
We are registered with the UK Information Commissioner's Office as a data controller for the personal data described in this notice — registration number ZC148489.
We're a small organisation and aren't required to appoint a Data Protection Officer under UK GDPR. We haven't appointed one — for anything privacy-related, contact us directly.
For anything privacy-related, contact privacy@stripyfish.net.
2What we collect, and why
What we collect depends on how far you use the platform. The table below reflects our internal Record of Processing Activities and is kept in step with it.
Layer 1 — free self-assessment
You can complete the SYSC 10A self-assessment without an account. We do not ask for your name or firm details. If you request an access code by email, that email address is used only to deliver the code and is deleted 30 days after your assessment completes. The assessment itself is designed to cover your firm's processes and systems, not client names, FCA registration numbers, or other personal data — though as with any free-text answer, it's possible to incidentally include something personal the questions don't ask for.
Legal basis: if you found and used the tool yourself, providing the access code you requested relies on contract/service necessity (Article 6(1)(b) UK GDPR). If we (or a reseller partner acting on our behalf) proactively invited your firm using contact details sourced from a public regulatory record such as the FCA Register or Companies House, that specific invitation relies on our legitimate interest in reaching firms who may benefit from the service (Article 6(1)(f) UK GDPR) — every such invitation includes a one-click opt-out link, in addition to your rights below.
Layer 2 — portal accounts and gap reports
A paid gap report requires a portal account. We collect your name, work email address, organisation name, and authentication credentials (a passkey public key, or a password hash — we never store your actual password or passkey private key). If you provide one, we also hold a mobile number against your account, encrypted at rest. We also store the content of your gap report conversation and audit log entries recording actions taken on your account (not their content).
Legal basis: contract performance — delivering the paid service you've signed up for (Article 6(1)(b) UK GDPR).
Layer 3 — policy documents
Generating a SYSC 10A policy document involves organisational context you provide: your FCA firm reference number, the name and title of your CF10 (or equivalent) holder, your firm's address, and the resulting policy content itself, along with a record of who reviewed and approved it and when.
Legal basis: contract performance (Article 6(1)(b) UK GDPR).
Access invitations
If you're invited onto the platform, we hold your email address and a hashed invitation token for up to 10 days, deleted on acceptance or expiry.
Legal basis: contract performance — giving your organisation's staff access is part of delivering the service already agreed with your firm (Article 6(1)(b) UK GDPR). Where an invitation instead came from us proactively contacting your firm using a public record, see the Layer 1 basis above.
Payment
Paid layers are billed through Stripe. We pass Stripe your billing name and email address and receive back payment status and metadata — we never see or store your full card number. Stripe processes and retains payment data under its own privacy policy and terms, which apply alongside this notice.
Legal basis: contract performance (Article 6(1)(b) UK GDPR).
Audit logs
We keep a security and compliance audit trail across the platform — a hashed (not plain-text) identifier for who took the action, event type, timestamp, and (where applicable) your IP address and browser/device identifier. Audit entries record that an action happened, not its content. We keep this trail for up to 6 years, in line with standard UK company record-keeping practice, after which entries are automatically deleted.
Legal basis: legitimate interests in maintaining the security and integrity of the platform (Article 6(1)(f) UK GDPR). The 6-year limit reflects our storage-limitation obligation under Article 5(1)(e) UK GDPR to keep data for no longer than necessary.
3How we use AI
Varde is AI-powered — this makes assessments faster and more consistent than a manual questionnaire. Assessment answers, gap report conversations, and policy generation context are processed by Claude, made by Anthropic, to produce your results.
Your answers are not shared with any other third party and are never used to train AI models. For Layer 3 policy documents, a second AI pass automatically checks the document for regulatory accuracy immediately after it is generated — findings are stored for our own internal review and are never applied to your document or shown externally. Anthropic retains API data for up to 30 days for security and operational purposes only, after which it is deleted.
Legal basis: generating your results uses the same legal basis as the layer you're using (see section 2, above). The automated quality-check pass is a narrower, separate use of that same data, carried out under our legitimate interest in maintaining service quality (Article 6(1)(f) UK GDPR) — findings are visible only to our own staff under confidentiality obligations, and this review is never shared externally.
AI output across every layer is advisory only — it surfaces potential gaps and drafts documents for your review. No decision with a legal or similarly significant effect on you is made solely by automated means (Article 22 UK GDPR); policy documents always require human review and approval before use.
5International transfers
Anthropic and Stripe both have infrastructure that extends outside the UK and EEA, including to the United States. Each transfer is covered by the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum (Addendum B.1.0, issued by the ICO) — the specific safeguard that satisfies the UK's transfer regime, confirmed directly against each provider's published data processing agreement. We keep transfers outside the UK to what's necessary to run the service.
Fasthosts, our email delivery provider, is UK-based — sending an invitation or notification email does not involve an international transfer.
Our hosting infrastructure is located within the United Kingdom. Storing and processing your data there does not itself involve any international transfer.
6How long we keep data
| What | Retention |
|---|---|
| Completed Layer 1 assessments | 12 months if no one at your firm has registered a portal account. Once anyone at your firm registers, your firm's whole assessment history — including anything completed before then — moves to the statutory retention period: up to 5 years (the SYSC 10A retention floor), or up to 7 years if the FCA directs your specific firm to retain records longer. This is decided per firm, not per individual. |
| In-progress Layer 1 sessions | 30 days |
| Access code emails | 30 days after assessment completion |
| Gap reports (Layer 2) | Retained for as long as your organisation continues to use the platform. Separately, if a report sees no activity from your team for 90 days, it moves to a "lapsed" state — this isn't automatically deleted yet, but you can request deletion at any time (see your rights, below). |
| Policy documents (Layer 3) | Retained for as long as your organisation continues to use the platform. Automatic deletion isn't in place yet — you can request deletion at any time. |
| Access invitations | 10 days from issue, or immediately on acceptance/expiry |
| Audit logs | Up to 6 years, then automatically deleted |
We're in the process of building automatic deletion for lapsed gap reports and lapsed policy documents — until that's live, manual deletion on request is the way to have data removed once you no longer need it.
7Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your personal data, subject to the limit below
- Restrict processing in certain circumstances
- Object to processing based on legitimate interests — where you do, we must stop unless we can show compelling legitimate grounds that override your interests (see below)
- Port your data to another provider in a structured, machine-readable format — this applies where processing is based on contract or consent and carried out by automated means; it doesn't extend to data we hold under legitimate interests, such as audit logs
- Complain to the ICO if you think we've got something wrong (see Contact, below)
Objecting to legitimate interests processing
We rely on legitimate interests (Article 6(1)(f) UK GDPR) for: proactively inviting your firm to try Layer 1 using contact details sourced from a public regulatory record; audit logging; and internal AI quality-assurance review (see section 2 and section 3, above). You can object to any of these at any time — for outreach invitations specifically, every invitation includes a one-click opt-out link that stops further contact immediately, in addition to emailing us. Once you object, we stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed to establish, exercise, or defend a legal claim.
Erasure has a legal limit
You can ask us to erase your personal details (name, email, mobile number) at any time and we will act on that promptly. Under UK GDPR Article 17(3)(b), this doesn't extend to the underlying compliance record itself where a legal retention obligation applies — SYSC 10A requires firms to keep compliance records for the retention periods set out above. In that case we remove your personal details immediately and retain the record, with no way to identify you from it, until its retention period ends.
Backups
When we delete your personal data — whether in response to an erasure request or through automatic retention expiry — it's removed from our live systems immediately. Encrypted backups are retained separately for up to 12 months as part of our disaster recovery process, on a fixed rotation schedule, and are automatically purged once that window passes. During this period your data is encrypted and inaccessible in normal operation; it's only ever touched in the event of a genuine disaster-recovery restore, and any pending erasure requests are re-applied immediately after a restore, before the system returns to service.
To exercise any of these rights, email privacy@stripyfish.net. We'll respond within one month of receipt, or let you know within that time if we need up to a further two months for a complex request (UK GDPR Article 12).
8Cookies
We use two strictly necessary cookies, both set with the Secure, HttpOnly, and SameSite flags and unreadable by other sites or by JavaScript: a session cookie (__Host-session) that keeps you signed in, and — only if you verify your email to view a specific assessment report or transcript link — a per-assessment cookie that remembers that verification for up to 90 days so you don't have to re-verify on every visit. We don't use any advertising, analytics, or tracking cookies, and we don't run any third-party tracking scripts.
9Security
Your data is encrypted in transit and access-controlled. Every change made to your organisation's data is captured in an audit log. Passwords are never stored in plain text; passkey-based sign-in never transmits a private key to our servers at all.
If something goes wrong
If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we'll notify the ICO within 72 hours as required by UK GDPR Article 33, and tell you directly under Article 34 if the risk to you is high.
10Not legal or regulatory advice
Varde surfaces potential compliance gaps and drafts supporting documents — it is not legal or regulatory advice. Consult a qualified compliance professional for guidance specific to your firm.
11Changes to this notice
We'll update the date at the top of this page whenever we make a material change, and where a change affects how we handle your data going forward, we'll take reasonable steps to let account holders know.
12Contact and complaints
Stripy Fish Networks Limited
26 Wellhead Lane, Westbury, Wiltshire, BA13 3PT
privacy@stripyfish.net
ICO registration: ZC148489
If you're unhappy with how we've handled your data and we haven't been able to resolve it, you can complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.