Martyn's Law procedures

Privacy notice

Last updated 18 September 2026.

Who the controller is

Your organisation is the controller of what you put in. We process it on your instructions so that we can produce your documents and remind you when a review is due. If you need the controller's registered details for your own records, ask and we will give them.

What we hold

  • Your e-mail address, name and telephone number, and those of the responsible person and deputy you name.
  • The organisation's name, address and any company or charity number you give.
  • For each premises: its name, address, Schedule 1 use, the capacity figure and how you worked it out, and your answers about the building.
  • The names and roles of staff you record as having been briefed or trained.
  • The documents we generate, and every earlier version of them.
  • Counts and categories for our own funnel. From the public tier checker, which needs no account: the answer it gave, the Schedule 1 use chosen, and a capacity band such as “200-399”. From inside an account: which step of the questionnaire people stop at, and how many packs were generated. Never an address, never a premises name, never the capacity figure itself, and never the contents of an answer.

The part that is not personal data, and matters more

Your answers describe which doors of a real building lock, where people would shelter, when the building is nearly empty and who holds the keys. That is not personal data and no data protection law is much interested in it — but it is the thing worth stealing here, so:

  • documents live in a private store and are only ever handed out through a link that stops working after fifteen minutes;
  • no third-party script runs on any page that shows your premises — analytics is on the home page and the tier checker and nowhere else;
  • pages behind sign-in are not indexed and send no referrer;
  • our own logs never contain the contents of your answers.

Lawful basis

Legitimate interests: you asked for these documents and for the reminders that go with them, and the processing is what producing them requires. For the review reminders, the interest is yours and the alternative is a document nobody looks at again.

Who else sees it

  • Cloudflare, Inc. (United States and EU) — serves the site and runs the code.
  • Supabase (EU, Frankfurt) — the database and the private document store.
  • Sendinblue SAS, 9-17 rue Salneuve, 75017 Paris (trading as Brevo) — sends the sign-in links and the review reminders.
  • PostHog (EU, Germany) — counts visits to the home page and the tier checker only.

We do not sell anything to anyone, and we do not share your premises data with the SIA, the Home Office, the police or any security firm. Transfers outside the EEA rely on the standard contractual clauses.

How long

While your organisation has an account. Old versions of packs are kept deliberately: if somebody asks what your procedures said two years ago, you should be able to answer. Used and expired sign-in links are purged daily.

You can delete everything at any time from Delete this organisation and all its data. That removes the rows and the stored documents, and cannot be undone.

Your rights

Access, rectification, erasure, restriction, objection and portability, as UK GDPR gives them. The register export and the pack downloads cover most of it without asking anyone. If you are not satisfied, you can complain to the Information Commissioner's Office at ico.org.uk.

Cookies

One: the sign-in cookie, which is strictly necessary and holds two identifiers and nothing else. Analytics uses no cookies, no local storage and no profiles, which is why there is no banner asking you to accept anything.