Privacy
Plain answers about the personal information Coverkey holds. Last updated 21 August 2026.
1. Who we are
Coverkey is a product of Sperrin Consulting & Automation, company number NI741657, registered at 24 Dromdallagan, Draperstown, BT45 7EY. For the account and billing details of the business that signs up, we are the data controller. For the team member details a business enters — names, work emails, and stored logins — that business is the controller and we process them on its behalf, on its instructions. Contact for anything on this page: support@coverkey.co.uk.
2. What we hold, and why
Admin accounts: the email address and hashed password of each admin, so they can sign in. Lawful basis: our contract with your business.
Team records: the names and work email addresses of the colleagues your business adds, and the work logins stored against them — username, password and, where added, the authenticator setup key. Logins are stored encrypted, are only ever decoded inside the database, and are shown only to your own signed-in admins while that colleague is marked on cover or has left. How this is protected is on our Security page. Lawful basis: your business's instructions under our contract.
The activity record: every time a login is viewed, we permanently record who viewed it, whose login it was, which system, and when. This record is the product's core promise — it cannot be edited or deleted, by anyone. Lawful basis: legitimate interest in tamper-evident security records, which is the very thing your business buys.
Phone-code cover: if your business uses a Coverkey phone number to receive security codes, we hold the mobile number each admin gives us for their own cover calls, and a record of each call that number takes — when it arrived, whether it was connected, and a masked form of the caller's number (for example +4420••••00); the full caller number is never stored. We do not record, listen to, transcribe or store the calls themselves, and we never hold the security code that is read out — the call is simply connected to a person, who types the code in by hand. Lawful basis: our contract with your business.
The Diary: if your business switches the Diary on, your team's notes — spoken or typed on WhatsApp — and the questions asked of them are held under the same org-scoped protection as the rest of your account. A voice note's audio is used only to turn it into a written note, and is then discarded — the written note is the record. Those messages reach us over WhatsApp through Twilio, listed above. The record of questions asked is kept like the activity record above. Lawful basis: your business's instructions under our contract.
Billing: handled by Stripe. We never see or store card numbers.
Marketing: account owner emails may be added to our product-updates list. Lawful basis: consent — and unsubscribing is one click in any such email.
3. Where it lives
Your stored logins and activity record live in an EU data centre (Paris). The companies below help us run the service; none of them can read your stored logins, which never leave the database unencrypted.
| Company | What they do for us | Where |
|---|---|---|
| Supabase | Database hosting — where your stored logins and activity record live | EU (AWS Paris, eu-west-3) |
| Vercel | Application hosting — serves the Coverkey app itself | Global edge, app data stays in the EU database |
| Stripe | Payments — your card details go to Stripe, never to us | EU/US under Stripe's data-protection terms |
| Resend | Transactional email — sign-in and account emails | EU/US under Resend's data-protection terms |
| Twilio | Phone-code cover — connects a call from your cover number to a verified admin's phone. Also carries the Diary on WhatsApp, where a business has it switched on: the notes your team sends, spoken or typed, the questions they ask and the replies they get back | Cover calls: EU (Ireland region). Diary messages: EU/US under Twilio's data-protection terms |
| Groq | Voice-note transcription — turns a spoken Diary note into text; the audio is then discarded | United States under Groq's data-protection terms |
| Voyage AI | Diary search — turns note text into a form that can be searched | United States under Voyage's data-protection terms |
| Anthropic | The Diary — writes up notes and answers questions from them | United States/EU under Anthropic's data-protection terms |
| Mailchimp | Marketing email list (account owner emails only) | United States — an international transfer made under Mailchimp's UK/EU data-protection terms |
| GoDaddy | Domain, DNS and routing for our support mailbox | EU/US under GoDaddy's terms |
| Microsoft 365 | Our support mailbox — holds emails you send us | EU region mailbox |
4. Cookies
Essential sign-in cookies only. No analytics, no tracking, no advertising pixels — which is why there's no cookie banner.
5. How long we keep things
For the life of your account, plus a 90-day wind-down after a cancelled account closes — sooner if you ask. There are two exceptions, one longer and one shorter.
The activity record is kept indefinitely, because tamper-evidence is only worth something if it's permanent. What that means when an account is erased is described next.
Records of calls to a cover number are kept for 60 days and then cleared automatically — deliberately shorter than everything else, because when calls arrive says something about when individuals work, and that does not need keeping. They are cleared in bulk by the date alone: nobody, including us, can pick out and remove an individual call record, which is the same guarantee the activity record carries.
6. Erasure — exactly what happens
Email support@coverkey.co.uk from your account owner's address and, once we've verified the request, within 30 days we will: close the account so no one can sign in to it; permanently destroy every stored login — usernames, passwords and authenticator setup keys are deleted beyond recovery, not archived; replace the names and email addresses on your team records and admin accounts with anonymous placeholders; and anonymise the business name itself. The activity record survives as a skeleton — its timestamped entries are kept so the history that views happened cannot be quietly rewritten, but the team records those entries point at no longer carry anyone's name or email. This is irreversible, including for us.
If your business had a cover number, erasure also removes every admin's stored mobile number and stops the cover number connecting any call. The number itself is held on our account rather than released straight back into circulation, so it cannot be reassigned to a stranger while a system somewhere still has it registered — you remain responsible for removing it from your own systems. Existing call records already hold nothing but a masked caller number and clear themselves within 60 days.
7. Your rights
You can ask us for a copy of the personal information we hold (access), ask us to correct it (rectification), ask for it in a portable form, object to our use of it, or ask for erasure as described above. Team members whose details were entered by their employer can come to us directly, though we may need to route the request through the business, as it controls those records. If you're unhappy with how we've handled any of this, you can complain to the UK Information Commissioner's Office at ico.org.uk.