Privacy Policy
Last updated: 25 September 2026
1. About this Privacy Policy
Keep Improving is a reporting, action-management and continuous-improvement service.
It allows customers, employees, contractors, visitors, tenants, service users and other permitted reporters to submit issues, feedback, compliments, complaints, suggestions, concerns and improvement opportunities through public forms without creating an account.
Authorised organisation users can then use the Keep Improving dashboard to review submissions, manage cases, assign responsibility, record actions, verify completion, close cases and review reporting trends.
This Privacy Policy explains how personal information is handled when you:
- visit the Keep Improving website
- create or use a Keep Improving account
- submit a report through a Keep Improving public form
- are identified or mentioned in a report
- contact Keep Improving
- use features within the Keep Improving service
This policy is written primarily for users in the United Kingdom and is intended to reflect the UK GDPR, the Data Protection Act 2018 and other applicable UK data-protection requirements.
2. Who Is Responsible for Your Personal Information?
2.1 Keep Improving's own service data
For information used to operate the Keep Improving service itself, such as account information, billing information, security logs, website enquiries and service administration, the data controller is:
Digital Safety Records Limited
Trading as:
Keep Improving
Website:
Registered office and principal business address:
36 Easterdown Close, Plymouth, PL9 8SS, United Kingdom
Privacy contact email:
admin@keepimproving.app
Company number:
17109237
ICO registration:
Digital Safety Records Limited is not currently registered with the Information Commissioner's Office (ICO).
Data Protection Officer:
No formal Data Protection Officer is currently appointed. Data-protection enquiries are handled by the Data Protection Contact at admin@keepimproving.app.
2.2 Reports submitted to an organisation
When you submit a report through a Keep Improving form belonging to a customer organisation, that organisation will normally decide why the report is being collected and how the information will be used.
In that situation:
- the customer organisation will normally be the data controller for the report and resulting case information
- Keep Improving will normally act as a data processor providing the reporting and case-management service on the organisation's behalf
- the organisation is responsible for identifying its lawful basis for using the information and providing any additional privacy information relevant to its own activities
The reporting form may identify the organisation receiving the report.
If you have a question about how that organisation uses the information in your report, you should normally contact the organisation directly.
Keep Improving may separately process limited technical information for its own legitimate service-security, fraud-prevention, abuse-prevention and operational purposes. Where Keep Improving determines those purposes itself, it acts as controller for that limited processing.
3. Information We May Collect
The information we process depends on how you use Keep Improving.
3.1 Public report information
A public report may contain:
- reporter type, such as customer, employee, contractor, visitor, tenant, service user or other
- report category
- free-text report content
- site, department, area or location associated with the reporting route
- QR code or form used to make the report
- date and time of submission
- optional name
- optional email address
- optional telephone number
- information contained in uploaded images or PDF documents
- information about another person where they are mentioned in the report
- anonymous-reporting selection where enabled
A public reporter is not required to create a Keep Improving account.
3.2 Information that may be sensitive
Because Keep Improving can be used to report operational, staff, compliance and safety concerns, a report may sometimes contain information that is sensitive or subject to additional legal protection.
Depending on what a reporter chooses to include, this could include:
- health information
- information about alleged misconduct
- information about criminal allegations or offences
- information revealing racial or ethnic origin
- religious or philosophical beliefs
- trade union membership
- sexual orientation or sex-life information
- other special-category personal information
Reporters should only include sensitive personal information where it is genuinely relevant to the matter being reported.
Customer organisations using Keep Improving are responsible for ensuring that they have an appropriate lawful basis and, where required, an additional legal condition for processing special-category or criminal-offence data.
3.3 Dashboard account information
For authorised organisation users, we may process:
- name
- email address
- authentication information
- organisation membership
- user role
- site or area permissions
- restricted-case permissions
- account status
- invitation information
- login and session information
- activity required for audit, security or support
Passwords are handled through the configured authentication service and are not intended to be stored by Keep Improving in readable form.
3.4 Organisation information
We may process:
- organisation name
- business details
- sites
- departments and areas
- organisation branding
- reporting-form configuration
- QR code configuration
- subscription plan
- entitlement information
- billing status
Some organisation information may not be personal information, but it may become personal information where it identifies an individual or sole trader.
3.5 Case-management information
Authorised users may add or create:
- case priority
- case status
- assigned user
- due date
- case notes
- corrective actions
- improvement actions
- verification records
- closure information
- audit-history entries
- information showing that an attachment previously existed
3.6 Billing information
Subscription billing is provided through Stripe.
Depending on the transaction, we may receive or process:
- customer name
- billing email
- Stripe customer identifier
- subscription plan
- subscription status
- invoice information
- payment status
- billing-cycle information
- payment-failure status
Keep Improving does not need to store full payment-card details in its own application database where payment details are handled directly by Stripe.
3.7 Website and technical information
When you use the website or service, technical information may include:
- IP address
- browser type
- device information
- operating system
- date and time of requests
- pages or routes accessed
- session and authentication information
- security logs
- rate-limit information
- error information
- technical metadata necessary to operate and protect the service
Where possible, technical information used solely for abuse prevention should be minimised and retained only for as long as necessary for that purpose.
3.8 Contact and support information
If you contact Keep Improving, we may process:
- name
- email address
- telephone number if supplied
- organisation
- enquiry type
- message content
- support correspondence
- information you choose to provide while resolving the enquiry
4. Anonymous Reporting
Some Keep Improving forms may allow a reporter to select:
Submit anonymously
Where anonymous reporting is selected, identifying reporter information should not be exposed to ordinary organisation dashboard users as part of the case.
Anonymous reporting does not necessarily mean that absolutely no technical information is processed anywhere in the service.
Keep Improving may retain the minimum technical information reasonably required for:
- security
- fraud prevention
- abuse prevention
- rate limiting
- service integrity
- investigation of malicious use
This technical information must:
- be access-restricted
- not be displayed to ordinary organisation users as reporter identity
- be used only for the relevant security or operational purpose
- be retained for a defined and proportionate period
A reporter should not include identifying information within the free-text report or an uploaded file if they want the report content itself to remain anonymous.
5. How We Use Personal Information
Depending on our role and the circumstances, personal information may be used to:
- provide and operate the Keep Improving service
- create and manage user accounts
- authenticate dashboard users
- create organisations, sites, areas and reporting forms
- generate and operate QR reporting routes
- receive public submissions
- create and manage cases
- assign cases and actions
- send authorised service notifications
- support verification and closure workflows
- maintain audit history
- display reporting and management information
- provide exports requested by authorised users
- manage subscriptions and entitlements
- process billing events
- provide customer support
- respond to enquiries
- protect the service against spam, abuse, fraud and security threats
- diagnose faults and maintain service reliability
- enforce account and subscription rules
- comply with legal obligations
- establish, exercise or defend legal claims where necessary
We do not use public reports to provide public case tracking in the current MVP.
6. Lawful Bases
UK data-protection law requires a valid lawful basis for processing personal information.
The lawful basis depends on the purpose and the relationship with the person concerned.
For personal information processed by Keep Improving as controller, relevant lawful bases may include:
Contract
Where processing is necessary to:
- create and operate a customer account
- provide the subscribed service
- administer a subscription
- respond to requests connected with the service
Legitimate interests
Where necessary for legitimate business interests, provided those interests are not overridden by the rights and interests of the individual.
This may include:
- service security
- fraud and abuse prevention
- maintaining service reliability
- investigating technical faults
- protecting accounts and organisations
- maintaining proportionate operational records
- responding to business enquiries
- establishing or defending legal claims
Where legitimate interests are relied on, Keep Improving must consider the necessity and impact of the processing.
Legal obligation
Where processing is necessary to comply with a legal requirement that applies to Keep Improving.
Consent
Consent may be used where required for particular optional activities, such as certain non-essential cookies or electronic marketing, where applicable.
Consent will not automatically be the lawful basis for every public report.
Customer organisations
Where Keep Improving acts as a processor for report and case information, the customer organisation is responsible for determining the lawful basis for its own use of that information.
If a report contains special-category or criminal-offence information, the customer organisation must also identify any additional legal condition required for that processing.
7. Public Reporting Forms
The intended public reporting journey is:
Scan QR code or open public link → complete form → submit
Public reporters are not required to:
- create a Keep Improving account
- create a password
- install an app
- authenticate using a social account
A reporting form may ask for:
- reporter type
- report category
- description
- optional evidence
- optional contact information
The organisation operating the form may configure which options are available.
8. Contact Details Provided With a Report
Where a public form asks for contact details, providing them should normally be optional unless the organisation operating the form has a specific justified requirement.
Suggested form wording may explain:
Leave your details if you'd like us to contact you about this report.
Where contact information is supplied, the customer organisation may use it to follow up on the report in accordance with its own privacy information and lawful basis.
Keep Improving processes that information as part of providing the service.
9. Uploaded Files and Images
Public submissions may include permitted attachments.
Supported public upload types are:
Images
- JPG
- JPEG
- PNG
- WebP
Documents
Limits:
- maximum 10 MB per file
- maximum 5 attachments per submission
Office documents, archives, executables and other unsupported file types should not be accepted through public submission forms in the MVP.
10. Seven-Day Evidence Retention
This is a fixed Keep Improving product rule.
Files and images uploaded through a public submission are retained temporarily and are permanently deleted 7 days after the original submission date.
This applies to:
- original uploaded images
- generated thumbnails
- generated compressed previews
- uploaded PDFs
- other permitted public-submission evidence
The seven-day period does not restart or extend because:
- the case remains open
- the case status changes
- a user views the file
- a user downloads the file
- a thumbnail is generated
- a preview is generated
- a manager adds notes
- an action remains outstanding
After deletion:
- the underlying case record remains where applicable
- the report text remains subject to the relevant case-retention rules
- actions, notes and audit history may remain
- metadata may remain to show that evidence previously existed
- the deleted file should no longer be available through the application
- previous access links should no longer provide access to the deleted file
Authorised organisation users are responsible for downloading any evidence they are lawfully entitled and required to retain before it expires.
If they download a copy, that copy becomes subject to the organisation's own retention and data-protection responsibilities.
11. Case and Account Retention
Retention depends on the type of data and the organisation's subscription status.
11.1 Active paid organisations
Non-file case records may remain available for the life of an active paid subscription unless:
- an authorised Administrator deletes information where permitted
- a future approved retention policy applies
- deletion is required by law
This may include:
- report text
- case status
- assignments
- actions
- notes
- audit history
- non-file evidence metadata
Publicly uploaded evidence remains subject to the separate seven-day deletion rule.
11.2 Trial organisations
The optional Keep Improving trial lasts 14 days and can be started deliberately by an eligible Administrator from Billing & Plan. No payment card is required to start the trial.
When an unconverted trial ends, the organisation returns to the Free Plan and its data is preserved. Trial expiry does not itself cause organisation or case data to be deleted.
Publicly uploaded evidence remains subject to the separate fixed seven-day deletion rule regardless of trial status.
11.3 Cancelled organisations
After cancellation, normal paid access continues until the end of the current paid billing period.
After paid access ends, the organisation may enter a limited recovery or read-only period. Under the current product rules, retained organisation data may be permanently deleted after the applicable 30-day post-cancellation retention period unless the subscription is restored or a legal reason requires different retention.
11.4 Unresolved failed payments
A failed paid subscription receives a 14-day full-service grace period from the first failed payment. If payment remains unresolved after that grace period, the organisation may become read-only and new public submissions may stop.
Under the current product rules, unresolved unpaid organisations may be permanently deleted after the applicable 30-day retention period. Publicly uploaded evidence remains subject to the separate seven-day deletion rule throughout.
11.5 Backups
Where information has been permanently deleted from the live application, it should no longer be available to users or normal application services.
Deleted information may remain temporarily in encrypted disaster-recovery backups until those backups expire under the applicable backup-retention schedule.
Backups must not be used as an alternative archive.
If a backup restoration reintroduces data that had already been deleted, the deletion state should be reapplied as part of the recovery process.
12. Restricted Reporting
Keep Improving supports:
- restricted forms
- restricted categories
- individually restricted cases
Restricted cases are intended to be visible only to:
- Administrators
- specifically authorised Managers
- specifically assigned users who also hold explicit restricted-case permission
Assignment to a restricted case does not, by itself, grant access.
Ordinary Supervisors and Viewers should not automatically be able to access restricted cases.
Restricted reporting may be used for matters such as:
- serious staff concerns
- sensitive compliance matters
- allegations
- confidential contractor issues
- serious health and safety concerns
Keep Improving is not a specialist whistleblowing, safeguarding or investigation platform.
Customer organisations remain responsible for deciding whether Keep Improving is appropriate for the particular type of report they choose to collect.
13. Who We Share Information With
Personal information may be shared with service providers where necessary to operate Keep Improving.
These may include providers of:
- cloud hosting
- database services
- authentication
- file storage
- payment processing
- transactional email
- error monitoring
- analytics, where enabled
- security and abuse prevention
- support tools
- backup and recovery services
Known core technology providers include:
Supabase
Used for application services including PostgreSQL database services, authentication, storage, Row Level Security and server-side application functions.
Vercel
Used to host and deliver the production web application and related application infrastructure.
Stripe
Used for subscription billing and related payment services. Stripe processes payment and billing information under its own privacy terms where it acts as an independent controller for parts of its service.
MailerSend
Used for transactional service email, including account, invitation and notification messages where applicable.
Used as an optional authentication provider for dashboard users who choose Continue with Google. Keep Improving requests only the identity information required for authentication and does not request Gmail, Drive, Calendar or Contacts access as part of this sign-in flow.
Cloudflare Turnstile
Used on dashboard sign-in to help distinguish legitimate users from automated or abusive traffic. Cloudflare may process limited technical information required to provide the Turnstile security check.
Analytics and advertising tracking
No non-essential analytics or advertising tracking service is currently confirmed as active in the production Keep Improving service. If this changes, this Privacy Policy and the Cookie Policy will be updated before or when the new processing begins, as required.
We may also share information where necessary:
- with professional advisers
- with insurers
- to comply with law or a lawful request
- to protect legal rights
- in connection with a business sale, merger or restructuring, subject to appropriate safeguards
Keep Improving does not sell personal information to advertisers.
14. International Transfers
Keep Improving may be used by customers internationally, and some of our technology providers operate across more than one country. As a result, personal information may in some circumstances be processed or stored outside the United Kingdom.
Where UK data-protection law requires safeguards for an international transfer, Digital Safety Records Limited will rely on an appropriate lawful transfer mechanism, such as applicable UK adequacy regulations, contractual safeguards or another mechanism permitted by law.
The precise transfer arrangements may depend on the service provider, service configuration and location involved.
For information about applicable safeguards relating to Keep Improving's own processing, contact admin@keepimproving.app.
15. Cookies and Similar Technologies
Keep Improving may use cookies or similar technologies that are necessary to:
- maintain secure sessions
- authenticate dashboard users
- protect the service
- remember essential preferences
Non-essential analytics or marketing cookies must not be used without the appropriate transparency and consent where required by law.
A separate Cookie Policy should identify:
- the cookies actually used
- their purpose
- provider
- duration
- whether they are essential
- how consent can be changed
Do not publish a generic cookie list that does not reflect the live production site.
16. Security
Keep Improving is designed with security controls including:
- multi-tenant architecture
- tenant isolation
- Supabase Row Level Security
- server-side permission checks
- role-based access
- restricted-case permissions
- secure file access
- file-type validation
- upload limits
- rate limiting
- abuse controls
- audit logging
- secrets management
- environment separation
- Stripe webhook verification
- secure headers
- dependency and security review
- backup and recovery arrangements
No online service can guarantee absolute security.
Customers and authorised users are responsible for:
- keeping login credentials secure
- using appropriate account access
- removing access when a user no longer requires it
- not sharing sensitive information unnecessarily
17. Children's Information
Keep Improving is a business reporting service and is not designed specifically for use by children as independent account holders.
However, some customer organisations, such as education or care organisations, may operate in environments involving children or young people.
If a customer organisation uses Keep Improving to collect information involving children, that organisation is responsible for ensuring that its use of the service is lawful and appropriate, including providing suitable privacy information and safeguards.
Dashboard accounts are intended for users aged 18 or over. Public reporting forms do not require a dashboard account, and customer organisations remain responsible for ensuring that any use involving children or young people is lawful and appropriate for their context.
18. Automated Decision-Making
The current core Keep Improving service is not intended to make solely automated decisions that produce legal or similarly significant effects on individuals.
Future AI capabilities may assist with functions such as:
- categorisation
- priority suggestions
- duplicate detection
- trend summaries
- suggested corrective actions
Such features are not part of the core MVP unless explicitly implemented.
AI must not be used to make uncontrolled high-risk safety decisions or automatically close serious cases.
If future processing materially changes this position, this Privacy Policy must be updated before that processing begins.
19. Marketing Communications
Keep Improving may send service communications that are necessary to operate an account or subscription, such as:
- account verification
- password recovery
- invitations
- service notifications
- trial-expiry warnings
- billing warnings
- security notices
These are different from optional marketing communications.
Where electronic marketing is used, Keep Improving will apply the appropriate consent or other lawful basis and provide a way to opt out where required.
At launch, Keep Improving does not rely on a separate marketing-email platform as part of the core Service. MailerSend is used for transactional service email. If direct marketing is introduced, this policy will be updated as required and recipients will be given the appropriate choices and opt-out controls.
20. Your Data-Protection Rights
Depending on the circumstances and lawful basis, individuals may have rights including:
- the right to be informed about how personal information is used
- the right of access
- the right to correct inaccurate information
- the right to request erasure
- the right to restrict processing
- the right to object to processing
- the right to data portability in applicable circumstances
- rights relating to automated decision-making where applicable
- the right to withdraw consent where processing is based on consent
These rights are not absolute and may depend on the lawful basis and circumstances.
If your request concerns a report submitted to a customer organisation
Where the customer organisation is the controller, the request should normally be made to that organisation.
Keep Improving will support its customer organisation with data-subject requests where required under its data-processing obligations.
If your request concerns Keep Improving's own processing
Contact:
admin@keepimproving.app
We may need to verify your identity before acting on a request.
21. Your Right to Object
Where personal information is processed on the basis of legitimate interests, you may have the right to object to that processing.
You have an absolute right to object to personal information being used for direct marketing.
To object to Keep Improving's own processing, contact:
admin@keepimproving.app
Where your objection concerns how a customer organisation uses report or case information, you should normally contact that organisation as the controller.
22. Complaints
If you have concerns about how Keep Improving handles personal information, please contact us first so that we can investigate.
Privacy contact:
Data Protection Contact, Digital Safety Records Limited admin@keepimproving.app
You also have the right to complain to the UK supervisory authority:
Information Commissioner's Office (ICO) https://ico.org.uk/make-a-complaint/
If another supervisory authority is responsible for your circumstances, you may also have the right to complain to that authority.
23. Data Processing on Behalf of Customer Organisations
Where Keep Improving acts as a processor for a customer organisation, processing should be governed by appropriate contractual data-processing terms.
These should address matters including:
- processing only on documented instructions
- confidentiality
- security
- subprocessors
- international transfers
- assistance with individual rights
- personal-data breaches
- deletion or return of data
- audits and compliance information
A separate Data Processing Agreement or equivalent contractual terms should be created and approved before commercial launch if required.
24. Data Breaches
Keep Improving should maintain procedures for identifying, investigating and managing personal-data breaches.
Where Keep Improving acts as processor and becomes aware of a personal-data breach affecting customer-controlled information, the relevant customer organisation should be informed without undue delay in accordance with contractual and legal obligations.
Where Keep Improving acts as controller, it will assess whether notification to the ICO or affected individuals is required by law.
25. Changes to This Privacy Policy
This policy may be updated when:
- the product changes
- new service providers are introduced
- processing purposes change
- legal requirements change
- new features materially affect privacy
- international transfer arrangements change
The latest version should always be published at:
https://keepimproving.app/privacy
The "Last updated" date at the top of the policy should be changed whenever a material update is published.
Where a change materially affects existing customers or users, additional notice should be provided where appropriate.
26. Contact Us
For privacy questions relating to Keep Improving's own processing:
Data Protection Contact Digital Safety Records Limited 36 Easterdown Close, Plymouth, PL9 8SS, United Kingdom Company number: 17109237 Email: admin@keepimproving.app Website: https://keepimproving.app
If your question relates to a report submitted to a customer organisation, you should normally contact the organisation identified on the reporting form because it will usually be the controller for that report.
