Privacy Policy
This Privacy Policy explains how the Portabl Group collects, uses, and protects your personal data when you use the Portabl website and membership services. We process your personal data on the lawful bases set out in this policy.
Data Controllers
The entity responsible for your personal data depends on the nature of the service you receive:
- Portabl Benefits Ltd is the data controller for UK membership data, including your account, subscription, and service delivery data.
- Portabl.co Ltd is the data controller for website operation and analytics data collected from portabl.co.
- Portabl Technologies Ltd is the data controller for platform technology operation data.
All three entities are registered at The Basement, 34a Hyde Park Square, London, England, W2 2NW. If you are unsure which entity holds your data, please contact us at hello@portabl.co.
Applicable Law
We process your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), being the retained EU law version of the General Data Protection Regulation (EU) 2016/679 as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019, together with the Data Protection Act 2018.
Data We Collect
Account and Membership Data
When you register or purchase a membership, we collect: email address; first and last name; phone number; company name (where applicable); and billing address. We do not store card or bank account details; these are handled directly by our payment service provider.
Usage Data
We collect information about how you use the Service, including: IP address; browser type and version; pages visited; time and date of visit; time spent on pages; and device identifiers.
Country and Location Data
We collect your country of residence and billing address as part of the membership registration process. This information is required to comply with our legal obligations, including determining the applicable VAT treatment for the supply of digital services under UK and international tax rules. We may also use your IP address to verify your country of access for VAT and regulatory compliance purposes. We do not collect precise device GPS location data.
How We Use Your Data
We use your personal data to: provide and maintain your membership and the Service; process and manage your subscription payments; send you service communications, including renewal reminders; provide customer support; analyse and improve the Service; comply with legal and regulatory obligations; and, where you have given consent, send you marketing and promotional communications.
Lawful Basis for Processing (UK GDPR)
The following table sets out the lawful basis we rely on for each category of processing:
| Processing activity | Lawful basis | Notes |
|---|---|---|
| Account registration and membership management | Contract performance | Necessary to deliver your membership |
| Payment processing | Contract performance | Necessary to charge for your subscription |
| Customer support | Contract performance / Legitimate interests | To resolve queries and complaints |
| Platform usage analytics | Legitimate interests | To improve the Service; you may opt out via cookie settings |
| Marketing and promotional emails | Consent | You may withdraw consent at any time by unsubscribing |
| Third-party product referrals | Consent / Contract performance | Where you request referral to a third-party provider |
| Legal and regulatory compliance | Legal obligation | Where required by law or regulation |
| VAT and tax compliance (country determination) | Legal obligation | To determine applicable VAT treatment for digital services; country of residence collected at registration and verified via IP address |
Retention of Data
We retain your personal data only for as long as necessary for the purposes set out in this policy. The following indicative retention periods apply:
- Account and membership data: for the duration of your membership and 6 years thereafter (contractual limitation period)
- Financial transaction data: 6 years from the date of transaction (statutory compliance)
- Marketing data: until you withdraw consent, or 3 years from your last interaction with us, whichever is earlier
- Usage and analytics data: generally up to 26 months, unless required longer for security or legal purposes
- VAT and tax records: 7 years from the date of supply (statutory minimum)
Transfer of Data
Your personal data is stored and processed primarily within the United Kingdom. Some of our third-party service providers operate infrastructure in the United States and other countries. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including the use of UK-approved Standard Contractual Clauses (SCCs) or transfers to countries covered by UK adequacy regulations. We will not transfer your personal data to any country or organisation unless adequate data protection controls are in place.
Disclosure of Data
We may disclose your personal data: where required by law or regulatory obligation; to protect the rights or property of the Portabl Group; to investigate suspected wrongdoing; or to protect the safety of our users or the public. We may share your data within the Portabl Group for the purposes of providing and improving the Service. We do not sell your personal data to third parties.
Security of Data
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, disclosure, or destruction, in accordance with our obligations under UK GDPR. No method of internet transmission or electronic storage is 100% secure.
Your Rights Under UK GDPR
You have the following rights in respect of your personal data:
- Right of access: to request a copy of the personal data we hold about you
- Right to rectification: to have inaccurate or incomplete data corrected
- Right to erasure: to request deletion of your personal data in certain circumstances
- Right to restrict processing: to request that we limit how we use your data
- Right to data portability: to receive your data in a structured, machine-readable format
- Right to object: to object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent: where processing is based on consent, to withdraw it at any time without affecting the lawfulness of prior processing
We will respond within one calendar month of receipt of your request. Where your request is complex or we receive a large number of requests simultaneously, we may extend this period by a further two months. We will notify you within one month of receipt if such an extension is required and explain the reasons for it.
To exercise any of these rights, please contact us at hello@portabl.co. We may ask you to verify your identity before responding.
Right to complain: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not handled your personal data in accordance with UK GDPR. The ICO can be contacted at www.ico.org.uk or by telephone on 0303 123 1113.
Automated Decision-Making
We do not make decisions about you solely by automated means that produce legal or similarly significant effects. If we introduce automated decision-making or profiling in the future, we will update this policy and ensure appropriate safeguards are in place before doing so.
Personal Data Breaches
In the event of a personal data breach, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, where feasible and where the breach is likely to result in a risk to your rights and freedoms. Where a breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay.
Special Categories of Personal Data
Portabl Benefits Ltd does not intentionally collect or process special category personal data as defined under UK GDPR, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation. If you believe we have inadvertently collected such data, please contact us at privacy@portabl.co and we will take steps to delete it.
When Portabl Acts as a Data Processor
Where Portabl Benefits Ltd processes personal data on behalf of a business customer, Portabl Benefits Ltd acts as a Data Processor and the business customer acts as the Data Controller. Individuals in this situation should refer to their employer's or organisation's own privacy notice. Business customers wishing to enter into a Data Processing Agreement should contact legal@portabl.co.
Service Providers
We use third-party service providers to facilitate and improve the Service. These providers have access to your personal data only to perform specific tasks on our behalf and are contractually obligated not to use it for any other purpose. The categories of providers we use include:
- Payment processing: our appointed payment service provider processes membership payments on our behalf. Privacy policy and terms are provided to you at the point of payment.
- Website and product analytics: we use analytics tools to understand how visitors use the Website and how members use the Member Platform. Analytics data is collected in aggregated form.
- Marketing and customer relationship management: we use a CRM and marketing platform to manage member communications, send service and promotional emails, and maintain customer records.
- Advertising and remarketing: where you have given consent, we use advertising platforms to serve relevant content on third-party channels.
We review our service providers regularly. If you have questions about the providers we use, please contact us at hello@portabl.co.
Analytics
We use analytics tools to monitor and analyse use of the Website. Analytics cookies are only set with your prior consent. Where Google Analytics is used, you can opt out at tools.google.com/dlpage/gaoptout.
Marketing and Advertising
Where you have given consent, we may use advertising and remarketing platforms to serve relevant content on third-party websites. These use cookies set only with your prior consent. You can opt out of interest-based advertising through your browser settings or via the opt-out mechanisms provided by individual advertising platforms.
Payments
We use an appointed payment service provider to process membership payments. We do not store or collect your card or bank account details. Our payment service provider adheres to PCI-DSS standards.
Children's Privacy
The Service is not directed to anyone under the age of 18. We do not knowingly collect personal data from anyone under 18. If you become aware that a minor has provided us with personal data, please contact us.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting a prominent notice on the Service prior to the change taking effect, and will update the effective date at the top of this policy.
Cookie Policy
This Cookie Policy explains how Portabl.co Ltd uses cookies and similar tracking technologies on portabl.co. This policy should be read alongside our Privacy Policy.
What Are Cookies
Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work, to improve efficiency, and to provide information to site operators. Some cookies are essential for a website to function; others require your consent under the UK Privacy and Electronic Communications Regulations 2003 (PECA), as amended.
How We Use Cookies
We use cookies to: enable the Website to function correctly; remember your preferences; analyse how visitors use the Website; and serve relevant advertising. The categories below set out each type we use.
Cookie Categories
Strictly Necessary Cookies
These cookies are essential for the Website to function and cannot be switched off. They enable core features such as security, session management, and account access. They do not require your consent and are set in response to actions you take, such as logging in or completing a form.
Functional Cookies
These cookies allow the Website to remember choices you make, such as your language preference or region, to provide a more personalised experience. They require your consent.
Analytics Cookies
These cookies help us understand how visitors use the Website. They collect information in an aggregated, anonymised form and do not identify you personally. They require your prior consent. We use Google Analytics for this purpose; you can opt out at tools.google.com/dlpage/gaoptout.
Marketing and Advertising Cookies
These cookies are used to serve relevant advertising on third-party platforms based on your visit to the Website. They require your prior consent. You can opt out of interest-based advertising through your browser settings or via the opt-out mechanisms provided by individual advertising platforms.
Your Consent
When you first visit the Website, a cookie consent banner will be presented. You may accept or decline non-essential cookies by category. We will not set any non-essential cookies before you have given your consent.
You can update your cookie preferences at any time via the cookie settings link in the website footer. You can also manage cookies through your browser settings; disabling certain cookies may affect the functionality of the Website.
Third-Party Cookies
Some cookies are placed by third-party services that appear on our pages. We do not control these cookies. Please refer to the privacy and cookie policies of individual third-party providers for further information.
Changes to This Cookie Policy
We may update this Cookie Policy from time to time. Material changes will be notified via the Website and the effective date will be updated.
Contact Us
Portabl.co Ltd|The Basement, 34a Hyde Park Square, London, England, W2 2NW
Email: hello@portabl.co