1. Purpose and scope
This policy sets out how SCOTT&YOUNG LTD, trading as OX9.APP, handles the data it holds — how we collect it, secure it, decide who can access it, how long we keep it, who processes it on our behalf, and what we do if something goes wrong. It covers personal data and operational data held in and about the OX9.APP service.
- Controller: SCOTT&YOUNG LTD (trading as OX9.APP), company no. 16697821, registered office 29 Grenville Way, Thame, OX9 3YN, England.
- Point of contact: beetge31@gmail.com
- ICO registration: pending — number to be added
2. Our data-protection principles
We handle data in line with the UK GDPR principles:
- Lawfulness, fairness and transparency — we process data on a valid legal basis and tell people what we do (see the Privacy Policy).
- Purpose limitation — data is collected for specified purposes and not used in incompatible ways.
- Data minimisation — we collect only what we need. For example, analytics use a hashed reference, not names.
- Accuracy — we keep data accurate and let users correct it.
- Storage limitation — we keep data only as long as needed (see the retention schedule).
- Integrity and confidentiality — we secure data with appropriate technical and organisational measures.
- Accountability — we can demonstrate how we meet these principles.
3. Categories of data we hold
- Account/identity data — email, name, profile details.
- Business/organiser data — listing content, contact and location details, offers, event details, uploaded images.
- Transaction data — payment metadata (from Stripe), invoices/receipts, membership and listing status.
- Usage/analytics data — pseudonymised event data (e.g. listing views) keyed to a hashed reference.
- Operational/system data — logs, backups, and configuration needed to run and secure the Service.
4. Roles: controller and processors
OX9 (SCOTT&YOUNG LTD) is the data controller. We use the following processors / sub-processors, each engaged under terms requiring them to protect data and act on our instructions:
| Sub-processor | Function | Primary location | Notes |
|---|---|---|---|
| Supabase | Database, authentication, file/object storage | EU (London / eu-west-2) | Row-level security enabled; images in event-images bucket |
| Stripe | Payment processing | UK/EU/US | Card data handled by Stripe; OX9 does not store full card numbers |
| Hetzner | Server/VPS hosting (jis-v4) | EU (Helsinki) | Application, reverse proxy, cron jobs |
| Brevo | Transactional/marketing email and push (once connected) | EU | Not yet connected at v1.0 |
| OpenStreetMap | Map tile delivery | EU | Serves map imagery to the user's device |
| GitHub | Source-code repository | US | Operational code hosting; not designed to hold user personal data |
We review this list as the stack evolves and update the Privacy Policy and this Data Policy accordingly.
5. Security controls
We apply technical and organisational measures proportionate to the risk, including:
- Encryption in transit — HTTPS/TLS across the Service and admin surfaces.
- Database access control — row-level security (RLS) on tables; administrative access gated to authorised operator identity; sensitive write operations restricted to defined server-side functions.
- Pseudonymisation — analytics identifiers are hashed rather than storing direct identifiers.
- Secret management — application secrets and credentials are held server-side (environment configuration), not embedded in client code or shared documents.
- Least privilege — access to systems, credentials and data is limited to those who need it to operate the Service.
- Backups — regular automated backups of the database and generated documents (e.g. invoices), with restore capability.
- Separation of environments — a permanent staging environment is used for building and testing; only proven changes reach production.
- Monitoring — automated health checks and logging to detect faults and misuse.
6. Retention schedule
| Data | Retention | Basis |
|---|---|---|
| Active account data | Duration of the account | Contract / legitimate interests |
| Closed-account data | Deleted or anonymised within a reasonable period after closure, unless legally required otherwise | Storage limitation |
| Invoices, receipts and financial records | ≥ 6 years | UK tax/accounting law |
| Payment metadata | As needed to manage the membership/listing and meet financial-record duties | Contract / legal obligation |
| Analytics (pseudonymised) | Retained pseudonymised; aggregated data may be kept indefinitely | Legitimate interests |
| System logs and backups | Rolling retention window appropriate to security and recovery needs define exact window at review | Legitimate interests / security |
| Support communications | As long as needed to handle the matter and any follow-up | Legitimate interests |
7. Handling data-subject requests (DSARs)
Requests to access, correct, delete, restrict, object to, or port personal data are received at beetge31@gmail.com and handled as follows:
- Log the request and the date received.
- Verify the requester's identity (proportionately).
- Locate relevant data across the database, storage and processors.
- Assess any exemptions or third-party data.
- Respond within one month (extendable by two months for complex/numerous requests, with notice).
- Record the outcome.
Requests are handled free of charge unless manifestly unfounded or excessive.
8. Personal data breach response
If we suspect or detect a personal data breach:
- Contain and assess — take immediate steps to limit the breach and assess the risk to individuals.
- Record — log the breach, its effects and remedial action (breach register).
- Notify the ICO — where the breach is likely to result in a risk to individuals' rights and freedoms, within 72 hours of becoming aware, where feasible.
- Notify affected individuals — without undue delay where the breach is likely to result in a high risk to them.
- Review — identify root cause and improve controls to prevent recurrence.
The breach point of contact is beetge31@gmail.com.
9. Data-protection by design and by default
New features are designed to collect the minimum data needed, to default to the most privacy-protective settings that still deliver the feature, and to keep sensitive operations server-side. Material new processing is assessed for privacy impact before launch, and a formal Data Protection Impact Assessment (DPIA) is carried out where processing is likely to be high-risk.
10. Roles and responsibility
Overall accountability for data protection sits with the controller (SCOTT&YOUNG LTD). Day-to-day data-handling, security operations and request handling are managed through the OX9 operations function. There is no statutory requirement identified at this stage to appoint a Data Protection Officer; this is kept under review as the Service grows. Confirm at compliance review.
11. Review
This policy is reviewed at least annually and whenever the data stack, processors, or legal requirements change materially — including at the point of ICO registration and professional legal review.
12. Contact
Data-handling questions, DSARs and breach reports: beetge31@gmail.com.
SCOTT&YOUNG LTD trading as OX9.APP · Company Registration No. 16697821 · Registered in England and Wales · Registered office: 29 Grenville Way, Thame, OX9 3YN.