Stripy Fish Networks Limited

Privacy Notice

How Varde — our SYSC 10A compliance assessment, gap report, and policy platform — collects, uses, and protects your data.

Last updated 7 August 2026 · Applies to the Varde platform only · Questions: privacy@stripyfish.net

1Who we are

Varde is provided by Stripy Fish Networks Limited, a company registered in England and Wales, registered office 26 Wellhead Lane, Westbury, Wiltshire, BA13 3PT ("we", "us", "Stripy Fish Networks").

We are registered with the UK Information Commissioner's Office as a data controller for the personal data described in this notice — registration number ZC148489.

We're a small organisation and aren't required to appoint a Data Protection Officer under UK GDPR. We haven't appointed one — for anything privacy-related, contact us directly.

For anything privacy-related, contact privacy@stripyfish.net.

2What we collect, and why

What we collect depends on how far you use the platform. The table below reflects our internal Record of Processing Activities and is kept in step with it.

Layer 1 — free self-assessment

You can complete the SYSC 10A self-assessment without an account. We do not ask for your name or firm details. If you request an access code by email, that email address is used only to deliver the code and is deleted 30 days after your assessment completes. The assessment itself is designed to cover your firm's processes and systems, not client names, FCA registration numbers, or other personal data — though as with any free-text answer, it's possible to incidentally include something personal the questions don't ask for.

Legal basis: if you found and used the tool yourself, providing the access code you requested relies on contract/service necessity (Article 6(1)(b) UK GDPR). If we (or a reseller partner acting on our behalf) proactively invited your firm using contact details sourced from a public regulatory record such as the FCA Register or Companies House, that specific invitation relies on our legitimate interest in reaching firms who may benefit from the service (Article 6(1)(f) UK GDPR) — every such invitation includes a one-click opt-out link, in addition to your rights below.

Layer 2 — portal accounts and gap reports

A paid gap report requires a portal account. We collect your name, work email address, organisation name, and authentication credentials (a passkey public key, or a password hash — we never store your actual password or passkey private key). If you provide one, we also hold a mobile number against your account, encrypted at rest. We also store the content of your gap report conversation and audit log entries recording actions taken on your account (not their content).

Legal basis: contract performance — delivering the paid service you've signed up for (Article 6(1)(b) UK GDPR).

Layer 3 — policy documents

Generating a SYSC 10A policy document involves organisational context you provide: your FCA firm reference number, the name and title of your CF10 (or equivalent) holder, your firm's address, and the resulting policy content itself, along with a record of who reviewed and approved it and when.

Legal basis: contract performance (Article 6(1)(b) UK GDPR).

Access invitations

If you're invited onto the platform, we hold your email address and a hashed invitation token for up to 10 days, deleted on acceptance or expiry.

Legal basis: contract performance — giving your organisation's staff access is part of delivering the service already agreed with your firm (Article 6(1)(b) UK GDPR). Where an invitation instead came from us proactively contacting your firm using a public record, see the Layer 1 basis above.

Payment

Paid layers are billed through Stripe. We pass Stripe your billing name and email address and receive back payment status and metadata — we never see or store your full card number. Stripe processes and retains payment data under its own privacy policy and terms, which apply alongside this notice.

Legal basis: contract performance (Article 6(1)(b) UK GDPR).

Audit logs

We keep a security and compliance audit trail across the platform — a hashed (not plain-text) identifier for who took the action, event type, timestamp, and (where applicable) your IP address and browser/device identifier. Audit entries record that an action happened, not its content. We keep this trail for up to 6 years, in line with standard UK company record-keeping practice, after which entries are automatically deleted.

Legal basis: legitimate interests in maintaining the security and integrity of the platform (Article 6(1)(f) UK GDPR). The 6-year limit reflects our storage-limitation obligation under Article 5(1)(e) UK GDPR to keep data for no longer than necessary.

We never ask for special category data (health, biometric, political, religious, or similar) as part of any layer of the platform, and none is knowingly collected.

3How we use AI

Varde is AI-powered — this makes assessments faster and more consistent than a manual questionnaire. Assessment answers, gap report conversations, and policy generation context are processed by Claude, made by Anthropic, to produce your results.

Your answers are not shared with any other third party and are never used to train AI models. For Layer 3 policy documents, a second AI pass automatically checks the document for regulatory accuracy immediately after it is generated — findings are stored for our own internal review and are never applied to your document or shown externally. Anthropic retains API data for up to 30 days for security and operational purposes only, after which it is deleted.

Legal basis: generating your results uses the same legal basis as the layer you're using (see section 2, above). The automated quality-check pass is a narrower, separate use of that same data, carried out under our legitimate interest in maintaining service quality (Article 6(1)(f) UK GDPR) — findings are visible only to our own staff under confidentiality obligations, and this review is never shared externally.

AI output across every layer is advisory only — it surfaces potential gaps and drafts documents for your review. No decision with a legal or similarly significant effect on you is made solely by automated means (Article 22 UK GDPR); policy documents always require human review and approval before use.

4Who we share data with

We do not sell personal data, and we do not share it with third parties beyond the processors who help us run the service:

ProcessorWhat they process
AnthropicAssessment, gap report, and policy generation content, to produce AI-assisted results
StripeBilling name, email, and payment processing for paid layers
Fasthosts (email delivery)Sends invitation, account setup, and password reset emails — recipient address and message content only, never compliance conversation content
Hosting infrastructureRuns the application and database that store your data — hosted with Amazon Web Services (AWS) in the United Kingdom (London)

When your firm registers or updates its profile, we check the FCA firm reference number, company number, or VAT number you provide against the FCA Register, Companies House, and HMRC's VAT registration checker, to confirm they're valid. These checks only ever send the identifier itself — never your name, email, or any other personal data — and we treat this as firm-level verification, not sharing personal data with a sub-processor.

If your organisation is managed by one of our reseller partners, we remain the data controller for your own account and compliance data — in the same way as for organisations we onboard directly. Your reseller partner can see your organisation's name and purchase/product status (not your compliance report content) as their own commercial record of the relationship they refer and administer; this disclosure is made on the basis of contract performance and our legitimate interest in operating our reseller distribution model, not because the reseller shares control over your account data.

We keep a fuller sub-processor list internally and will share specifics — including current hosting and email delivery providers — on request to privacy@stripyfish.net.

We may also disclose data where required by law, or to a regulator or law enforcement body making a lawful request.

5International transfers

Anthropic and Stripe both have infrastructure that extends outside the UK and EEA, including to the United States. Each transfer is covered by the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum (Addendum B.1.0, issued by the ICO) — the specific safeguard that satisfies the UK's transfer regime, confirmed directly against each provider's published data processing agreement. We keep transfers outside the UK to what's necessary to run the service.

Fasthosts, our email delivery provider, is UK-based — sending an invitation or notification email does not involve an international transfer.

Our hosting infrastructure is located within the United Kingdom. Storing and processing your data there does not itself involve any international transfer.

6How long we keep data

WhatRetention
Completed Layer 1 assessments12 months if no one at your firm has registered a portal account. Once anyone at your firm registers, your firm's whole assessment history — including anything completed before then — moves to the statutory retention period: up to 5 years (the SYSC 10A retention floor), or up to 7 years if the FCA directs your specific firm to retain records longer. This is decided per firm, not per individual.
In-progress Layer 1 sessions30 days
Access code emails30 days after assessment completion
Gap reports (Layer 2)Retained for as long as your organisation continues to use the platform. Separately, if a report sees no activity from your team for 90 days, it moves to a "lapsed" state — this isn't automatically deleted yet, but you can request deletion at any time (see your rights, below).
Policy documents (Layer 3)Retained for as long as your organisation continues to use the platform. Automatic deletion isn't in place yet — you can request deletion at any time.
Access invitations10 days from issue, or immediately on acceptance/expiry
Audit logsUp to 6 years, then automatically deleted

We're in the process of building automatic deletion for lapsed gap reports and lapsed policy documents — until that's live, manual deletion on request is the way to have data removed once you no longer need it.

7Your rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your personal data, subject to the limit below
  • Restrict processing in certain circumstances
  • Object to processing based on legitimate interests — where you do, we must stop unless we can show compelling legitimate grounds that override your interests (see below)
  • Port your data to another provider in a structured, machine-readable format — this applies where processing is based on contract or consent and carried out by automated means; it doesn't extend to data we hold under legitimate interests, such as audit logs
  • Complain to the ICO if you think we've got something wrong (see Contact, below)

Objecting to legitimate interests processing

We rely on legitimate interests (Article 6(1)(f) UK GDPR) for: proactively inviting your firm to try Layer 1 using contact details sourced from a public regulatory record; audit logging; and internal AI quality-assurance review (see section 2 and section 3, above). You can object to any of these at any time — for outreach invitations specifically, every invitation includes a one-click opt-out link that stops further contact immediately, in addition to emailing us. Once you object, we stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed to establish, exercise, or defend a legal claim.

Erasure has a legal limit

You can ask us to erase your personal details (name, email, mobile number) at any time and we will act on that promptly. Under UK GDPR Article 17(3)(b), this doesn't extend to the underlying compliance record itself where a legal retention obligation applies — SYSC 10A requires firms to keep compliance records for the retention periods set out above. In that case we remove your personal details immediately and retain the record, with no way to identify you from it, until its retention period ends.

Backups

When we delete your personal data — whether in response to an erasure request or through automatic retention expiry — it's removed from our live systems immediately. Encrypted backups are retained separately for up to 12 months as part of our disaster recovery process, on a fixed rotation schedule, and are automatically purged once that window passes. During this period your data is encrypted and inaccessible in normal operation; it's only ever touched in the event of a genuine disaster-recovery restore, and any pending erasure requests are re-applied immediately after a restore, before the system returns to service.

To exercise any of these rights, email privacy@stripyfish.net. We'll respond within one month of receipt, or let you know within that time if we need up to a further two months for a complex request (UK GDPR Article 12).

8Cookies

We use two strictly necessary cookies, both set with the Secure, HttpOnly, and SameSite flags and unreadable by other sites or by JavaScript: a session cookie (__Host-session) that keeps you signed in, and — only if you verify your email to view a specific assessment report or transcript link — a per-assessment cookie that remembers that verification for up to 90 days so you don't have to re-verify on every visit. We don't use any advertising, analytics, or tracking cookies, and we don't run any third-party tracking scripts.

9Security

Your data is encrypted in transit and access-controlled. Every change made to your organisation's data is captured in an audit log. Passwords are never stored in plain text; passkey-based sign-in never transmits a private key to our servers at all.

If something goes wrong

If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we'll notify the ICO within 72 hours as required by UK GDPR Article 33, and tell you directly under Article 34 if the risk to you is high.

10Not legal or regulatory advice

Varde surfaces potential compliance gaps and drafts supporting documents — it is not legal or regulatory advice. Consult a qualified compliance professional for guidance specific to your firm.

11Changes to this notice

We'll update the date at the top of this page whenever we make a material change, and where a change affects how we handle your data going forward, we'll take reasonable steps to let account holders know.

12Contact and complaints

Stripy Fish Networks Limited
26 Wellhead Lane, Westbury, Wiltshire, BA13 3PT
privacy@stripyfish.net
ICO registration: ZC148489

If you're unhappy with how we've handled your data and we haven't been able to resolve it, you can complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.

← Back