Privacy policy

Last updated: Sep 13, 2026

1. Who this applies to

SaaS Policy Manager is used by early years and childcare organisations to manage their internal policies. Accounts are held by adults acting on behalf of an organisation (owners, managers and staff) — the service is not directed at, and does not knowingly collect personal data from, children.

2. Information we collect

  • Account details: your name, work email address, password (stored hashed, never in plain text), organisation name and, optionally, a logo you upload.
  • Policy content: the policy documents your organisation creates, uploads or edits, and any instructions you give to AI-assisted review or rewrite features.
  • Billing information: your subscription plan, billing period and payment status. Card details are entered directly with Stripe and are never seen or stored by us.
  • Usage and security logs: IP address, browser/device (user agent) and timestamps recorded when policies are accessed, used to secure accounts and investigate misuse.
  • Contact form submissions: the name, email address and message you choose to send us.
  • Cookies: see section 8 below.

3. How we use your information

  • to provide the service, including authenticating you, keeping tenants' data separate, and running scheduled template-comparison and AI review features;
  • to process payments and manage your subscription and AI credit allowance;
  • to send account, security (including two-factor authentication codes) and billing-related emails;
  • to respond to support and contact form enquiries;
  • to maintain the security, integrity and audit trail of the service.

4. Legal basis for processing

We process account, billing and content data because it is necessary to perform our contract with your organisation. We process security/audit logs and rely on essential cookies under our legitimate interest in keeping the service secure and reliable. Where we ever rely on consent (for example, for non-essential cookies, should we introduce any), you may withdraw it at any time.

5. Who we share information with

We share information with the following categories of service provider, solely to operate the service:

  • Stripe, to process subscription payments;
  • Anthropic (Claude), OpenAI (ChatGPT) and Google (Gemini) — whichever AI provider is configured for your account — to generate AI-assisted policy suggestions, reviews and rewordings from the policy text you submit to those features;
  • our transactional email provider, to deliver verification, password reset, two-factor authentication and billing emails;
  • our internal team, via operational alerting, to monitor the health of the service.

We do not sell your information, and we do not share it with advertisers or use it for advertising.

6. International transfers

Some of the providers listed above, including our AI providers, may process data outside the UK/EEA (for example, in the United States). Where this happens, we rely on that provider's standard contractual clauses or equivalent safeguards for the transfer.

7. Data retention

We retain account and policy data for as long as your organisation's account is active, and for a limited period afterwards to allow reactivation, meet legal or accounting obligations, and resolve disputes, after which it is deleted or anonymised. Security and audit logs are retained for a shorter, fixed period sufficient for security investigations.

8. Cookies

We use only strictly necessary cookies: a session cookie to keep you signed in, a CSRF token cookie to protect forms from cross-site attacks, and, where you choose "remember me", a cookie that keeps you signed in between visits. We also use a small local storage flag to remember that you've dismissed our cookie notice. We do not currently use analytics, advertising or other non-essential cookies. If that ever changes, we will update this policy and ask for your consent first.

9. Security

Each organisation's policy content is encrypted at rest using keys specific to that organisation, and access is restricted to your organisation's own account. We support two-factor authentication as an additional layer of account security. No method of transmission or storage is completely secure, but we work to protect your information using appropriate technical and organisational measures.

10. Your rights

Subject to applicable law, you may have the right to request access to, correction of, deletion of, or a copy of your personal data, and to object to or restrict certain processing. You can update most account details yourself, or contact us using the details below to make a request.

11. Changes to this policy

We may update this privacy policy from time to time. Material changes will be communicated to account holders, and the "last updated" date above will reflect the latest revision.

12. Contact

For any privacy question or request, contact us at info@dms.com.

We use essential cookies to keep you signed in and to secure your session. We don't use any advertising or analytics cookies. See our Privacy policy for details.