1. Who we are

The CIC Association (a Community Interest Company, incorporated 26 August 2009) is the data controller for the purposes of UK data protection law — including the UK GDPR and the Data Protection Act 2018. This notice covers our free grant-draft preparation service.

2. What we collect

When you use the grant-draft form, we collect only what we need to prepare and deliver your draft:

  • Your name and email address — so we can send you your draft.
  • Your organisation and (optionally) its Companies House number.
  • Your intended funder, the amount (if given), your organisation type (if given), and your description of the funding need.

Your Companies House number is also used to enforce our free-tier limit of three drafts per CIC per month.

3. How your data is protected

Your answers are encrypted in your browser before they leave your device, using public-key encryption (RSA-OAEP). The encrypted file is stored with Cloudflare (R2 object storage) and can only be decrypted by our own processing equipment using a private key that never leaves it. We do not store your personal data in readable form.

We record a hashed, versioned audit entry confirming your consent at the time you submitted (a one-way hash — it does not reveal your answers).

4. Why we process it (lawful basis)

We process your data on the basis of your consent (Article 6(1)(a) UK GDPR). Consent is collected at the point of submission, against the versioned label shown on the form. If you opt in separately to occasional updates, that marketing consent is collected and processed on the same basis, and can be withdrawn with one click from any email we send you.

5. How it's stored, and retention

Personal data lives only inside the encrypted envelope in Cloudflare R2. The database row we write contains operational metadata (status, a companies house number for the cap, blob keys) — not your readable answers.

  • Draft link: the single-use link we email you expires 72 hours after issue and works once — a second visit is rejected.
  • Retention: we delete the encrypted input and your draft from our storage once delivery is complete, in line with our data-retention schedule. Consent audit records are kept to evidence your consent.

6. Transfers outside the UK

The providers we use to store the encrypted file and to email you your draft — Cloudflare and Resend — are US-based providers, so your data is transferred outside the UK. We rely on appropriate safeguards for these transfers as required by UK data protection law.

7. Sharing and third parties

We do not sell your data. We share it only with the processors named above (Cloudflare for storage, Resend for email delivery), each bound by contract to act on our instructions. A draft is prepared by our own automated drafting tooling; no third-party funding decision is involved and no funder receives your data through this service.

8. Your rights

Under UK data protection law you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate data;
  • Erase your data ("the right to be forgotten");
  • Restrict or object to processing;
  • Withdraw consent at any time — including using the one-click unsubscribe in any email we send you;
  • Lodge a complaint with the Information Commissioner's Office.

To exercise any of these rights, or to withdraw consent, contact us at [email protected].

9. Changes to this notice

We may update this notice as the service develops. The current version number is shown at the top of this page (2026-08-14), and consent labels on the forms reference it so you always know which version you agreed to.