How UserChecks meets its obligations under UK GDPR and the Data Protection Act 2018 — as a business, and as the software our clients trust with their inspection data.
Effective 1 June 2026UserChecks is built for safety and compliance teams who can't afford to be casual about data, so taking data protection seriously isn't optional — it's the job. We handle personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
UserChecks is a product by Riccom. Riccom Ltd is registered in England & Wales (company number 05613089) and is registered with the Information Commissioner's Office, registration number ZA047398.
Data protection law treats these two roles differently, and so do we.
Controller — our own data. For visitors and enquirers on this website, and for the people we deal with as a business, Riccom decides why and how data is used. That makes us the controller. Our Privacy Policy sets out what we collect and why.
Processor — our clients' data. Inside UserChecks, the records belong to the client organisation using it. They decide what goes in and why; they are the controller. Riccom processes that data on their documented instructions under a data processing agreement. We don't use client data for our own purposes.
For the inspection records, sites, assets and people held in UserChecks, the client is the controller and Riccom is the processor.
Where we act as a controller, we rely on:
Where we act as a processor, the lawful basis sits with our client, the controller; we act on their instructions.
Under UK GDPR you have the right to:
Where we hold your data as a controller, exercise any of these rights by emailing privacy@riccom.co.uk. We'll respond within one month and won't charge a fee for a reasonable request.
Where your data sits inside UserChecks because of your relationship with one of our clients, that client is the controller — contact them first, and we'll support their response as their processor.
We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it. As a controller, we keep website enquiry and correspondence data for up to 6 years from last contact. As a processor, we retain product data for 6 years unless a client's contract specifies a different period, in which case the contract governs.
When we use third parties to help deliver this website or UserChecks, we put a contract in place and use only providers that meet our data-protection standards. Our sub-processors are:
We use no other sub-processors.
Our hosting is UK-region throughout (Azure UK), so hosted personal data stays in the UK. Twilio SendGrid processes contact-form and transactional email in the United States, which involves a transfer of personal data outside the UK. That transfer is safeguarded under Twilio's Data Processing Addendum, using the UK International Data Transfer Agreement (IDTA) — and the EU Standard Contractual Clauses where applicable — with appropriate safeguards in place. Where any other transfer of personal data outside the UK takes place, we likewise rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement.
We have processes to detect, report and investigate personal-data breaches. Where we act as a controller and a breach is likely to risk people's rights and freedoms, we'll notify the ICO within 72 hours and affected individuals where required. Where we act as a processor, we'll notify the affected client without undue delay so they can meet their obligations as controller.
We have not appointed a statutory Data Protection Officer, as we are not required to under UK GDPR. Data-protection matters are handled by Riccom Ltd. For any data-protection question, or to exercise your rights over data we hold as a controller, contact us at privacy@riccom.co.uk.
If you have a concern about how we've handled your personal data, please raise it with us first at privacy@riccom.co.uk — we'd like the chance to put it right. You also have the right to complain to the Information Commissioner's Office, the UK's data-protection regulator, at ico.org.uk or by calling their helpline.
Riccom Ltd