

Privacy Policy
unlock£d is owned and operated by Sable & Wolf Limited. This notice explains what personal data we collect when you use this website, why we collect it, who we share it with, and the rights you have over it. It is written to describe what the service actually does.
Effective date: 31 July 2026
1. Who we are
The data controller is Sable & Wolf Limited, a company registered in England and Wales under company number 10261642, with its registered office at First Floor, Lumiere, Elstree Way, Borehamwood, Hertfordshire, WD6 1JH.
For any question about this notice, or to exercise any of the rights described in section 11, contact privacy@unlocked.biz.
2. Data you give us when you create an account
Registration collects:
- Your name — recorded as the director or contact name for the account.
- Your email address.
- Your UK mobile number, which we normalise to international E.164 format before storing it.
- Your company name and company number, as selected from a Companies House lookup.
Your phone number is the primary credential for the account. We create the account keyed to the phone number and verify it by sending a one-time passcode by SMS. Your email address is stored against your profile but is deliberately not attached to the login identity until you confirm control of it by clicking a link we send you — this prevents someone registering an account against an email address they do not own.
Our systems contain a date-of-birth field that is not currently in use: the sign-up flow does not ask for a date of birth and does not store one. If that changes, this notice will be updated before the field is enabled.
3. Data you give us when you submit an enquiry
When you complete one of the assessment flows — R&D tax credits, Patent Box, capital allowances, business rates, cybersecurity, business funding, grants, land remediation, energy, a business sale, wealth management, or a dispute — we store the enquiry against your company. Every enquiry record can include:
- The company name and company number you searched for.
- Contact name, phone number and email address as entered on the review screen. We keep the phone number exactly as you typed it as a point-in-time record, alongside a normalised E.164 version used to match the enquiry to your account if you later register.
- The indicative value range the tool estimated for that opportunity.
- The answers you gave in that specific flow. Depending on the flow this includes: your R&D activities and spend band; patent status, jurisdiction, applicant and any patents you selected; staff numbers, security priorities and downtime tolerance; funding amount, term, purpose and whether you are a homeowner; property addresses and postcodes for a capital allowances claim; your reason for selling, timeline and sale type; asset and income ranges for wealth management; your energy supplier, purchase method and spend range; suspected contaminants on a site; dispute type, duration and employee counts; and any free-text additional information you choose to add.
Some flows let you reach a confirmation screen without completing the contact step. Where that happens we still store the enquiry and the company it relates to, without contact details.
4. Identity verification data
If you start identity verification, we record that verification was completed and which document type you selected (passport or driving licence), against your profile. This website does not currently collect or store images of identity documents.
5. Data collected automatically
We operate our own event-tracking endpoint, which writes to our database. It records:
- Your IP address and user agent string, taken from the request headers, and the device type, browser and operating system derived from them.
- Session and anonymous identifiers used to link the steps of a single visit together, and to connect an anonymous visit to your account if you go on to register.
- Attribution data — the utm_source, utm_medium, utm_campaign, utm_term and utm_content parameters on the link you arrived through, the referring site, and the page you landed on.
- Journey progress — which flow you are in, which step you have reached, and whether it was completed or abandoned.
Separately, when analytics is enabled for the deployment, we use PostHog to capture page views and product-usage events, and Vercel Analytics to capture aggregate traffic measurements in production. PostHog is configured to create identified person profiles only for users we have identified, and to record page views on in-app navigation.
6. Cookies and similar technologies
We use cookies and similar browser storage for two purposes:
- Strictly necessary — to hold your signed-in session so you stay logged in as you move between pages, to protect the sign-in process, and to remember small interface preferences such as whether the dashboard sidebar is open. The service cannot work without these.
- Analytics and performance — to understand how visitors move through the site so we can improve it, through the tools named in section 5. These are not necessary for the service to function.
- Advertising and conversion measurement — with your permission, to tell the advertising platform that brought you here that an enquiry was made, so we can measure which advertising works. We share the fact of the enquiry and a hashed form of your contact details; never your name, phone number or email in readable form. This is off unless you allow it, and you can change your choice below.
You can block or delete cookies through your browser settings. Blocking strictly necessary cookies will stop you being able to sign in or stay signed in.
7. Connected accounting software
Not currently available. You may see an option to connect accounting software such as Sage, Xero or QuickBooks. That connection is not live: we do not currently read your accounting data, and we hold no access or refresh tokens for any accounting provider. The option is shown as an indication of what is planned, and these terms will be updated before it is switched on.
This notice previously stated that we store such tokens “in encrypted form”. That is not the case, and saying it was inaccurate — the storage table existed but nothing ever wrote to it, has no rows, and has since been removed. Corrected rather than left standing, because a privacy notice that describes processing we do not carry out is as misleading as one that omits processing we do.
8. Lawful bases and how we use your data
- Performance of a contract — creating and securing your account, authenticating you by SMS one-time passcode, generating your results, and progressing an enquiry you have asked us to progress.
- Legitimate interests — understanding how the service is used so we can improve it, preventing fraud and abuse, rate-limiting our endpoints, matching an enquiry you submitted before registering to the account you later create, and introducing you to a specialist appropriate to your enquiry. We balance these against your interests and you can object at any time.
- Consent — where we send you marketing communications, and for non-essential analytics where consent is required. You can withdraw consent at any time without affecting processing carried out before you withdrew it.
- Legal obligation — where we must retain or disclose data to comply with the law.
9. Who we share your data with
We never sell your personal data to third parties. We use the following third-party services, each of which processes data only for the purpose described:
- Supabase — hosts our database and our authentication system. Account, profile and enquiry data is stored here.
- Twilio — delivers the SMS one-time passcode used to verify your phone number and log you in. Your phone number is passed to Twilio for this purpose.
- Resend — delivers our transactional email. Your email address and the message content are passed to Resend.
- Vercel — hosts the website and provides aggregate traffic analytics in production.
- PostHog — product analytics, where enabled for the deployment.
- Companies House — we query the public UK companies register to look up your company and its officers. This is a lookup of public data; we do not send your personal details.
- Creditsafe Connect — company information, credit and risk data, shareholder and charge records used to assess what a business may be able to claim. Queried by company identifier.
- Credas — identity verification (KYC). Where identity checks are required, we pass your name and contact details so Credas can verify your identity directly with you.
- People Data Labs — enrichment of business-contact information associated with a company.
- HM Land Registry — price-paid and commercial/overseas ownership data used to identify and value business premises.
- PropertyData — UK property analytics used for valuation and council-tax context.
- Ordnance Survey Places and postcodes.io — UK address lookup, address autocomplete and postcode geocoding.
- Google — the Places API is used as an address-autocomplete and nearby-premises fallback, and Maps/Street View supplies imagery of a business premises.
- Mapillary and KartaView — alternative street-level imagery providers, used where enabled.
- European Patent Office — patent search and abstracts, used by the Patent Box and grants flows. Searched by company or applicant name.
- Octopus Energy — energy tariff and switching estimates.
- Sage, Xero and QuickBooks — only if you explicitly connect one of them, and only for the data you authorise.
Where you ask us to progress an enquiry, we pass the relevant enquiry details and your contact details to the specialist firm best placed to handle it, so they can contact you.
We will also disclose your data to legal or regulatory authorities where we are required to by law or where it is necessary to protect our rights, and to a buyer or successor if our business or its assets are sold or merged.
Some of these providers operate outside the United Kingdom. Where personal data is transferred internationally, we rely on the UK adequacy regulations where the destination country is covered by them, and otherwise on the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, together with the additional safeguards those require.
10. How long we keep your data
We keep your personal data only for as long as it is necessary for the purposes set out in this notice, or for as long as the law requires us to keep it. In practice that means:
- Account and profile data — kept while your account is open, and for a period afterwards where we still need it to answer a query or deal with a claim.
- Enquiry and lead records — kept while the enquiry is being progressed, and afterwards as the record of the introduction we made.
- Event, analytics and attribution data — kept while it is useful for measuring and improving the service, then deleted or reduced to a form that no longer identifies an individual visit.
Once the purpose the data was collected for has been met, and no legal requirement to keep it applies, we delete or anonymise it.
11. Your rights
Under UK GDPR you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — ask us to delete your data where there is no overriding reason for us to keep it.
- Restriction — ask us to limit how we use your data while a query about it is resolved.
- Portability — receive the data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller.
- Objection — object to processing based on our legitimate interests, and to direct marketing at any time.
- Withdraw consent — where we rely on consent, withdraw it at any time.
To exercise any of these, contact privacy@unlocked.biz. We will respond within one month.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk. We would ask that you raise it with us first so we have the chance to put it right.
12. Security
We put appropriate technical and organisational measures in place to protect your data against unauthorised access, alteration, disclosure or destruction. Access to your account is protected by SMS one-time passcode rather than a reusable password. Traffic to this site is encrypted in transit. Sign-in and session cookies are marked secure, so they are never sent over an unencrypted connection.
13. Links to other websites
This website contains links to websites we do not operate, including our data sources and the specialist firms we introduce you to. We are not responsible for their content or for how they handle your personal data. Read their own privacy notices before giving them anything.
14. Changes to this notice
We may update this notice as the service changes. The latest version will always be posted on this page, and the effective date at the top reflects the current version. See also our Terms & Conditions.