Privacy Policy
How we collect, use, and protect your personal data when you use Pension Tech services.
Last reviewed: 9 June 2026 · Effective from: 9 June 2026
Contents
1. Who We Are
Pension Tech (“we”, “us”, “our”) operates the website pensiontech.uk and provides pension audit and analysis services to members of UK public sector pension schemes and professional intermediaries. We are the data controller for personal data collected through our website and services.
Important notice: Pension Tech is not regulated by the Financial Conduct Authority (FCA). We provide informational audit services only. Nothing in this policy or our services constitutes financial advice, investment advice, or any regulated financial activity under the Financial Services and Markets Act 2000.
Data Protection lead:privacy@pensiontech.uk
Postal address:Pension Tech, [PLACEHOLDER: PO Box or registered address], [PLACEHOLDER: town/city], [PLACEHOLDER: postcode]
ICO registration number:[PLACEHOLDER: ZxxxxxxxxX — obtain from ico.org.uk/registration]
2. Data We Collect
We collect only the data we need to deliver the pension audit service. The categories we may collect are set out below.
| Category | Examples |
|---|---|
| Identity | Full name, date of birth, National Insurance number, employee or payroll reference numbers |
| Contact | Email address, telephone number, postal address |
| Scheme & service records | Annual benefit statements, service extracts, retirement estimates, employment history, part-time records, career break documentation, transfer records, McCloud transition information, payslips and P60s provided as supporting evidence |
| Audit findings | Our analysis, conclusions, challenge pack contents, and all correspondence relating to your audit case |
| Billing & transaction | Fee records and invoices. Payment card data is processed directly by our payment provider; we do not store full card numbers |
| Technical & usage | IP address, browser type, pages visited, upload metadata — collected for website security and service improvement only |
| Special category — Health(Article 9 data) | Health or disability information that appears within pension documents where an ill-health retirement, injury award, or health-related benefit is under review. We collect this only with your explicit consent and only to the extent necessary for the audit. See Section 3 for the lawful basis. |
Data we do not collect: We do not collect racial or ethnic origin, political opinions, religious beliefs, genetic data, biometric data, or criminal conviction data as part of the pension audit process. We collect trade union membership information only if it appears incidentally in pension records provided by you.
3. Lawful Bases for Processing
The UK General Data Protection Regulation (UK GDPR) requires us to identify a lawful basis for every type of processing. We rely on the following bases:
Article 6(1)(b) — Performance of a contract
Processing identity, contact, scheme records, audit findings, and billing data is necessary to provide the pension audit service you have requested. Without this data we cannot deliver the service.
Article 6(1)(f) — Legitimate interests
We process technical and usage data to maintain website security, prevent fraud, and improve our services. Our legitimate interest does not override your rights; you may object to this processing at any time (see Section 8).
Article 6(1)(c) — Legal obligation
In certain circumstances we may be required to retain or disclose data to comply with a legal obligation, such as a court order, regulatory requirement, or HMRC obligation.
Article 9(2)(a) — Explicit consent (special category health data)
Where pension documents contain health or disability information relating to an ill-health pension, injury award, or similar benefit, we will ask for your explicit written consent before processing that information. You may withdraw consent at any time, though withdrawal may prevent us from completing the health-related element of the audit.
Note on consent: We do not rely on consent as the lawful basis for processing ordinary personal data. Consent is used only where required by law — specifically for special category (health) data — so that it is freely given and not a condition of receiving our service.
4. How We Use Your Data
- ✓To carry out the pension audit you have requested: reviewing documents, identifying potential errors or discrepancies, producing a written report, and providing a challenge pack where the evidence supports one.
- ✓To communicate with you about your case: progress updates, requests for additional documentation, and delivery of your findings.
- ✓To process payment for the fixed-fee or success-based audit service.
- ✓To manage your account and respond to queries, complaints, or subject access requests.
- ✓To fulfil legal and regulatory obligations, including co-operating with supervisory authorities.
- ✓To maintain website security and detect fraudulent activity.
- ✓To improve our services, using anonymised or aggregated data where possible.
We will not use your data for direct marketing without your separate, explicit consent. We will never sell your personal data to any third party.
5. Third Parties & Sub-processors
We share your data with trusted third parties only where necessary to deliver our service, comply with the law, or protect our legitimate interests. All sub-processors are bound by data processing agreements that require them to protect your data to the same standard we do.
Current sub-processors:
[PLACEHOLDER: list each sub-processor, their country of processing, and the purpose — e.g. cloud hosting provider, payment processor, email delivery provider, document storage service, analytics provider]
Audit My Pension (NHS cases): For NHS pension cases, your documents and relevant personal data may be shared with Audit My Pension (auditmypension.co.uk), our specialist NHS scheme partner. Audit My Pension acts as a separate, independent data controller for the NHS audit element. Please review their privacy policy before proceeding if your audit involves NHS pension records.
We do not share your personal data with pension scheme administrators except as a direct part of the correction or challenge process, and only with your knowledge and instruction.
6. International Transfers
We aim to keep your data within the United Kingdom at all times.
[PLACEHOLDER: confirm whether any sub-processors store or access data outside the UK or EEA. If yes, identify the transfer mechanism for each — e.g. UK adequacy regulations, International Data Transfer Agreement (IDTA), or the ICO-approved Addendum to the EU Standard Contractual Clauses (SCCs). If no transfers occur, replace this paragraph with a clear statement to that effect.]
Where any transfer does occur outside the UK, we ensure appropriate safeguards are in place as required by Chapter V of the UK GDPR and current ICO guidance on restricted transfers.
7. Retention Periods
We keep your data only for as long as necessary for the purpose for which it was collected, and no longer than required by law. Our current retention schedule is:
| Data category | Retention period | Reason |
|---|---|---|
| Pension documents & service records | [PLACEHOLDER: e.g. 12 months from audit completion] | To allow for follow-up queries and scheme correction timelines |
| Audit report & findings | [PLACEHOLDER: e.g. 6 years from report date] | Limitation Act 1980 — contractual claims period |
| Billing records | [PLACEHOLDER: e.g. 7 years from transaction date] | HMRC / Companies Act accounting obligations |
| Correspondence & complaints records | [PLACEHOLDER: e.g. 3 years from closure] | To respond to any re-opened complaint or dispute |
| Website & technical logs | [PLACEHOLDER: e.g. 90 days] | Security monitoring and fraud detection |
You may request early deletion at any time (see Section 8). Where early deletion conflicts with a legal obligation — such as a tax or accounting requirement — we will explain the limitation and delete as much as we lawfully can.
8. Your Rights Under UK GDPR
You have the following rights in relation to your personal data. To exercise any right, contact our Data Protection lead (see contact details below). We will respond within one calendar month and may ask you to verify your identity before acting on a request.
Right of access (Subject Access Request)
You can request a copy of all personal data we hold about you, together with information about how and why we use it.
Right to rectification
You can ask us to correct inaccurate or incomplete personal data.
Right to erasure
You can ask us to delete your data where it is no longer needed, where you have withdrawn consent, or where processing is unlawful. Legal retention obligations may limit this right — we will always explain if that applies.
Right to restrict processing
You can ask us to pause processing of your data — for example, while a dispute about accuracy is resolved.
Right to object
You can object at any time to processing based on our legitimate interests. We must stop unless we can demonstrate compelling grounds that override your interests.
Right to data portability
Where processing is based on contract or consent and carried out by automated means, you can request your data in a structured, machine-readable format.
Right to withdraw consent
Where we rely on consent (e.g. for special category health data), you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing that took place before withdrawal.
Right to lodge a complaint with the ICO
If you are unhappy with how we have handled your data, you have the right to complain to the Information Commissioner's Office. See Section 13 for contact details.
To exercise any of these rights, email our Data Protection lead at privacy@pensiontech.uk or write to us at our postal address. We will respond within one calendar month. There is no fee for making a request, unless requests are manifestly unfounded or excessive.
9. Children's Data
Our services are directed exclusively at adults (aged 18 and over) who hold or have held membership of a UK public sector pension scheme. We do not knowingly collect personal data from anyone under the age of 18. If you believe we have inadvertently collected data about a child, please contact privacy@pensiontech.uk and we will delete it without delay.
10. Automated Decision-Making
We do not currently make decisions about you using solely automated processing that produce legal or similarly significant effects on you. All audit findings are produced and reviewed by human analysts before being communicated to you. Should we introduce any automated decision-making in the future, we will update this policy and — where required by UK GDPR — seek your explicit consent before doing so.
12. Changes to This Policy
We review this Privacy Policy at least annually and whenever our data practices change materially. When we make significant changes, we will:
- Update the “Last reviewed” date at the top of this page.
- Display a prominent notice on our website for at least 30 days.
- Email registered users if the change affects how we process data we already hold about them.
Where a change introduces a new purpose or lawful basis for processing, we will seek fresh consent or provide you with a reasonable opportunity to opt out before the change takes effect.
13. Complaints & Contact
If you have a concern about how we have handled your personal data, please contact us first — we aim to resolve all concerns promptly and fairly.
Data Protection lead
privacy@pensiontech.uk
Pension Tech UK Limited, Aquarius House, 43 Web Tree Avenue, Hereford, United Kingdom, HR2 6HQ
If we are unable to resolve your concern to your satisfaction, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent data protection regulator:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
Make a complaint online