Legal

Privacy Policy

Last updated: 1 June 2026

Notice: Subvention is currently free to use. Online payment is not yet enabled. The business operator and correspondence address will be confirmed before paid checkout is turned on.

Subvention ("we", "us") provides a grant-discovery service at subvention.co.uk. This policy explains what personal data we collect, why, how long we keep it, and your rights under the UK GDPR and the Data Protection Act 2018.

1. Data we collect

  • Account data: name, email address, hashed password (or Google OAuth identifier) — when you sign up.
  • Search & profile data: company number, sector, location, funding needs — when you run a search.
  • Saved items: grants and searches you save, plus any notes, pipeline stages and next-actions you add — stored against your account so you can return to them.
  • Application data: drafts you create, messages you send to funders via our service.
  • Usage data: pages viewed, grants clicked, anonymous interaction signals used to improve matching.
  • Payment data: when you buy a pass, payment is handled directly by Stripe. We receive only the plan, amount, status and a transaction/session reference — never your card number. We also keep a record of your purchases (plan and date) for accounting.
  • Communication data: emails you send/receive through the platform, suppression and delivery status from our email provider (Brevo).

2. Why we process it (lawful basis)

  • Contract: to provide the grant-search, drafting and application service you signed up for.
  • Legitimate interest: to improve match quality, prevent abuse, and operate the service securely.
  • Consent: for marketing emails (you can withdraw at any time via the unsubscribe link in every email).
  • Legal obligation: to retain payment records under HMRC rules.

3. How long we keep it

Account and application data is retained for as long as your account is active, then deleted within 365 days. Payment records are retained for 7 years (HMRC requirement). Email suppression lists are retained permanently (legal requirement under PECR — we must not email anyone who has unsubscribed).

4. Who we share with

  • Stripe (payments) — Ireland/USA, processor
  • Brevo (transactional + marketing email) — France, processor
  • Anthropic (AI matching + drafting) — USA, processor; no personal data passed beyond what you've entered for the search
  • Cloudflare (DNS, email routing) — USA/global, processor
  • Google (OAuth sign-in only) — USA, joint controller for the identification step

We do not sell your data. We do not share it with advertisers.

5. Your rights

You have the right to access, correct, delete, restrict or port your personal data, and to object to processing. Email hello@subvention.co.uk with the subject "Data request" and we will respond within 30 days. You may also complain to the UK Information Commissioner's Office at ico.org.uk.

6. Cookies and tracking

We use only essential cookies (authentication session). We do not use third-party analytics, advertising, or cross-site tracking cookies. Anonymous usage signals are stored server-side and not linked to any device identifier.

7. Contact

Data controller: Subvention, United Kingdom. The named legal operator and correspondence address will be confirmed before paid checkout is enabled. Email: hello@subvention.co.uk.