1. Who we are
Civil Gateway provides an API for CBUS-related integration workflows. For privacy questions, use your existing Civil Gateway contact route or the details used during registration.
2. Information we collect
We may collect and process:
- registration details, including name, work email address, company name, registration status, and registration date;
- account and API access details, including API keys, account identifiers, plan usage, and technical authentication data;
- API request and response records needed to provide submissions, feedback, queries, reports, security checks, support, and audit trails;
- website visitor information, including a visitor identifier cookie, host, URL, IP address, user agent, and visit timestamp;
- communications and support information you provide to us.
3. How we use information
We use personal data to review registrations, create and manage accounts, provide and secure the API, authenticate requests, monitor usage, investigate errors or misuse, maintain records, respond to enquiries, and comply with legal or regulatory duties.
4. Lawful bases
Depending on the context, we process personal data because it is necessary to take steps before entering a contract, perform a contract, comply with legal obligations, or pursue legitimate interests such as securing, operating, improving, and supporting the service.
5. Cookies and visitor tracking
In production, the website may set a visitor cookie so repeat visits can be associated with the same visitor identifier. Visitor records currently expire after approximately one day. You can control cookies through your browser settings, but some service functions may not work as intended if cookies are blocked.
6. Sharing information
We may share data with service providers who help operate, host, secure, support, or maintain the service, and with courts, public authorities, regulators, or professional advisers where needed for the service or required by law. We do not sell personal data.
7. International transfers
If data is processed outside the UK, we will use appropriate safeguards where required by data protection law.
8. How long we keep information
We keep personal data only for as long as needed for the purposes described in this policy, including account administration, service delivery, security, legal, audit, and support needs. Visitor records are intended to expire after approximately one day. Registration, account, API, and support records may be kept for longer where needed to provide the service or meet legal and operational requirements.
9. Security
We use technical and organisational measures designed to protect personal data, including API authentication and request signing for protected API routes. No system is completely secure, so you must protect your own credentials and notify us promptly if you believe account access has been compromised.
10. Your rights
Depending on the circumstances, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You may also have the right to complain to the UK Information Commissioner's Office if you are unhappy with how your data is handled.
11. Changes to this policy
We may update this policy when the service, law, or our data handling practices change. The latest version will be published on this page.