Skip to content
Legal

Privacy policy

REPs takes the privacy of our professionals and clients seriously. This policy explains what data we collect, how we use it, and the rights you have under UK GDPR.

Last updated · 31 May 2026

01

Data we collect

Account details (name, email, password hash), professional credentials (qualifications, DBS, insurance), profile content, booking and payment metadata, and usage analytics.

02

How we use your data

To operate the platform, verify professionals, process payments, surface relevant search results, send transactional and (with consent) marketing communications, and detect fraud.

03

Lawful basis for processing

We process data under contract (to deliver the service), legitimate interests (platform safety, fraud prevention), legal obligation (record-keeping), and consent (optional marketing and cookies).

04

Who we share with

Stripe (payments), Resend (email), Cloudflare (hosting/storage), Mapbox (location), and verification partners where required. We never sell personal data.

05

International transfers

Some processors operate outside the UK. We rely on UK Adequacy decisions and Standard Contractual Clauses where appropriate.

06

Data retention

Account data is kept for as long as your account is active, plus 6 years for accounting records. Closed-account data is anonymised on a rolling 90-day schedule.

07

Your rights

Under UK GDPR you can access, rectify, erase, restrict and port your data, and object to processing. Email privacy@repsglobal.com to exercise these.

08

Security

We use TLS 1.3, at-rest encryption, scoped access controls, and quarterly third-party penetration testing.

09

Complaints

You can lodge a complaint with the UK Information Commissioner's Office at ico.org.uk.