Privacy statement
Last updated 16 August 2026
This statement explains how Kestrel Alert ("we", "us") handles personal data as a controller under UK data protection law (UK GDPR and the Data Protection Act 2018). Kestrel Alert is a trading name of M Fordy, sole trader, of Suite RA01, 195-197 Wood Street, London, E17 3NU. Contact for anything in this statement: info@kestrelalert.com.
What personal data we process, and why
Account data (you, our user)
- What: your email address, password (stored as a hash by our authentication provider, never readable by us), your watch list, and delivery records of the alerts we've sent you.
- Why: to provide the service you signed up for. Lawful basis: performance of a contract.
Public-register data (company officers)
- What: information from public registers (Companies House filings and Gazette notices) can include the names (and occasionally other registered details) of company directors and officers.
- Why: to detect and describe significant company events for our users. Lawful basis: legitimate interests (helping businesses assess counterparty risk using information the law already makes public). We only process what the public registers publish, and any person can object (see "Your rights"). Separately, and only in the narrow case described under "Prospective customers" below, we use a director's name and business contact details to introduce our service to the company they run after one of its customers has become insolvent.
Prospective customers (business outreach)
- What: business names and business addresses taken from public insolvency records, such as Gazette notices and statements of affairs filed at Companies House (a statement of affairs lists an insolvent company's creditors). Where a listed creditor trades as a sole trader or partnership, that information can identify an individual. Where the creditor is an incorporated company, we also process the name and role of a current director, taken from the Companies House register, and a business email address for that person obtained from Hunter, a business email directory. We do not process home addresses, personal (non-work) email addresses, dates of birth, or any special category data for outreach.
- Why: to introduce our service to businesses recently affected by a customer insolvency, who are most likely to benefit from early-warning alerts. Lawful basis: legitimate interests (proportionate business-to-business outreach using information the law already makes public). Because we obtain these details from public registers and a directory rather than from you, we tell you so in the message itself, naming both sources, which is the notice required by Article 14 UK GDPR. Every such message includes a one-step way to opt out; if you opt out we add you to a suppression list and will not contact you again. We contact one named person per creditor company, once, about the specific insolvency that prompted it. We do not send unsolicited electronic marketing to sole traders or other individuals without consent, and we do not sell prospect data.
- How long: if you do not respond we keep the record only as long as needed to honour a later opt-out and to avoid contacting you again about the same filing. You can ask us to erase it at any time (see "Your rights"); an opt-out suppression entry is kept because deleting it would let us contact you again by mistake.
What we don't do
- We don't sell or share personal data for advertising.
- We don't use advertising or cross-site tracking cookies (see "Cookies").
- We don't make automated decisions with legal or similar effects about anyone.
Where your data lives
The service runs on Amazon Web Services in the London (UK) region. Data is encrypted in transit and at rest. AWS acts as our processor for hosting, email delivery, authentication, and the AI service that drafts alert summaries; those summaries and the text sent to the AI service are logged for audit and quality, inside the same UK-hosted storage. One exception: when we analyse public-register documents (for example the insolvency filings used for the business outreach described above), that AI processing may run in other AWS regions within the EU. Beyond AWS, our only other sub-processor is Google (analytics on the production website; see "Analytics and performance monitoring").
Analytics and performance monitoring
- Google Analytics 4: on our production website we use Google Analytics to understand how the site is used (pages visited, approximate location derived from your IP address, device and browser type). Google acts as our processor; Google Analytics 4 does not log or store full IP addresses, and we don't use it for advertising. Google may process this data outside the UK under UK-approved safeguards. Lawful basis: legitimate interests (understanding and improving the service).
- Amazon CloudWatch RUM: we collect page-load timings, web vitals and JavaScript errors from real visits so we can find and fix problems. This runs inside the same AWS London hosting described above and uses a session identifier cookie; it is not shared with anyone else.
- Google Search Console: we receive aggregated statistics from Google about the search queries that led people to this site. This involves no data collection on the site itself and nothing that identifies you to us.
How long we keep it
- Account data: for as long as you hold an account, then deleted on request or account closure.
- Alert and register history: we keep an archive of public-register events and the alerts we generated from them, as the record that lets users audit what they were told and when. Personal data within it is removed on a valid erasure request (below).
Your rights
Under UK GDPR you can ask us for access to your data, correction, erasure, restriction, portability, and you can object to processing based on legitimate interests, including if you are a company officer whose name appears in the register data we process. Email info@kestrelalert.com; we respond within one month. We maintain a documented erasure procedure covering every store the data reaches, including archived copies, and a suppression step so erased data is not re-created by future register updates.
If you're unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ico.org.uk).
Cookies and local storage
We ask for your consent before setting any analytics cookies. If you accept, Google Analytics sets cookies (names beginning _ga) to distinguish visits, and CloudWatch RUM sets cookies (names beginning cwr) to group page views into a session; if you decline, neither is set and we only receive performance measurements that store nothing on your device. Neither is used for advertising. Your choice is remembered in your browser's local storage; clear the site's data to be asked again. When you sign in, authentication tokens are kept in local storage so you stay signed in; that is strictly necessary for the service. No ad trackers, ever.
Alert emails
We send alert emails to the address on your account from info@kestrelalert.com. Deep links in those emails contain a signed token so you can open the relevant company page without logging in; treat alert emails like any other credential-bearing email and don't forward them.
Changes
If we change this statement materially (for example, adding a sub-processor), we'll notify account holders by email before the change takes effect. See also our terms of service.