How UserChecks collects, uses and protects personal data — for visitors to this website and for the people whose data is held in the product.
Effective 1 June 2026UserChecks is a product by Riccom. It is operated by Riccom Ltd ("Riccom", "we", "us"). We are registered in England & Wales, company number 05613089, with our registered office at The Old Stables, Calcroft Lane, Clanfield, Oxfordshire OX18 2PB, United Kingdom.
We are registered with the Information Commissioner's Office (ICO), registration number ZA047398.
For any question about this policy or your personal data, contact us at privacy@riccom.co.uk.
Riccom handles personal data in two distinct ways through UserChecks, and the rules differ for each.
As a data controller. When you visit this website, fill in our contact form, or otherwise enquire about UserChecks, Riccom decides why and how your data is used. This policy covers that data.
As a data processor. UserChecks is used by client organisations — safety teams, compliance teams, operators of equipment that needs regular inspection — to run their own QR-driven equipment inspections. The records inside the product (their sites, their assets, the people who carry out and sign off inspections, and the inspection data itself) belong to the client. They are the controller; Riccom processes that data on their instructions under a written contract. If your data sits inside UserChecks because you work for, or are inspected by, one of our clients, that organisation is your first point of contact, and their privacy notice governs it. The "Data inside UserChecks" section below explains our role.
As a controller, we collect:
We do not knowingly collect special-category data through this website, and we ask you not to include sensitive personal information in the free-text form fields.
| What we do | Why | Lawful basis (UK GDPR) |
|---|---|---|
| Reply to your enquiry and arrange a demo | To respond to a request you made | Legitimate interests / steps towards a contract |
| Keep a record of correspondence | To manage the relationship and our own records | Legitimate interests |
| Maintain and secure the website | To run a safe, working site | Legitimate interests |
| Send you information you've asked for | Because you asked | Consent, where consent applies |
We do not run automated marketing drip campaigns off the back of a demo enquiry, and we will not sell or rent your details to anyone.
This website uses no analytics and sets no tracking or advertising cookies. Because we set no non-essential cookies, no cookie consent banner is required.
We share website personal data only with service providers who help us run the site and respond to you, and only as far as needed. Our sub-processors are:
We use no other sub-processors for website enquiry data.
We may also disclose data where the law requires it, or to protect our rights.
The product and our primary hosting are in the United Kingdom: Microsoft Azure, UK South and UK West regions. Website enquiry data is hosted in the UK.
Our email delivery sub-processor, Twilio SendGrid, processes contact-form and transactional email in the United States. This involves a transfer of personal data outside the UK. That transfer is safeguarded under Twilio's Data Processing Addendum, using the UK International Data Transfer Agreement (IDTA) — and the EU Standard Contractual Clauses where applicable — with appropriate safeguards in place. Where any other transfer of personal data outside the UK takes place, we likewise rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement.
We keep enquiry and correspondence data for up to 6 years from our last contact with you, then delete or anonymise it. We hold it for that period to deal with your enquiry, manage the relationship, and meet our own legal and accounting record-keeping needs.
Where Riccom acts as a processor for a client organisation, we handle their data strictly on their documented instructions, under a data processing agreement that sets out the subject matter, duration, purpose, security measures and sub-processors involved.
UserChecks runs on Microsoft Azure in the UK (UK South and UK West regions), with per-tenant data isolation. We protect personal data with encryption in transit and at rest, access controls, and UK-region hosting. Our sub-processors for product data are Microsoft Azure (hosting) and Twilio SendGrid (transactional email delivery). We retain product data for 6 years unless a client's contract specifies a different period, in which case the contract governs.
If your data is in UserChecks because of your relationship with one of our clients, please contact that organisation to exercise your rights. We will support them in responding.
Under UK data protection law you have the right to access your data, to have it corrected, to have it erased, to restrict or object to how we use it, and to data portability. Where we rely on consent, you can withdraw it at any time.
To exercise any of these rights over data we hold as a controller, email privacy@riccom.co.uk. We'll respond within one month. (For data held inside UserChecks on a client's behalf, contact that client organisation first.)
If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office at ico.org.uk, though we'd appreciate the chance to put things right first.
We may update this policy from time to time. The effective date at the top shows when it last changed.
Riccom Ltd