Legal

Privacy Notice

This notice explains how personal data is handled when you visit or use PPE Flo.

Last updated: 19 September 2026

1. Who controls your data

David Yeboah, trading as PPE Flo, is the data controller for account, website, support, security and commercial information used to operate PPE Flo. Where a care organisation enters information about its staff, service users or care activities, that organisation is normally the controller and PPE Flo processes the information on its instructions.

2. Personal data we collect

  • Account and identity data: name, email address, login identifiers, organisation, branch and role.
  • Service content: PPE usage, deliveries, audit answers, corrective actions, notes, report data and records your organisation chooses to enter.
  • Support and communications: messages, requests, notification preferences and delivery status.
  • Technical and usage data: IP address, browser and device details, timestamps, activity logs, security events and feature usage.
  • Commercial data: plan, subscription status, invoices, transaction references and limited payment-method details such as card brand and last four digits. Paddle processes full payment details.
  • Website analytics: pages visited, referral source and aggregated interaction information where analytics is enabled.

3. Why we use personal data and our legal bases

  • To create accounts, provide the service, administer subscriptions and respond to support requests — performance of a contract.
  • To secure PPE Flo, prevent fraud, maintain audit trails, improve reliability and understand service use — our legitimate interests and those of our customers.
  • To send service messages and keep accounting, tax and compliance records — contract performance and legal obligations.
  • To send optional marketing communications or use non-essential cookies — consent, where required. You may withdraw consent at any time.
  • To establish, exercise or defend legal claims and respond to lawful authority requests — legitimate interests or legal obligation.

4. Information entered by care organisations

Customer organisations decide what operational content to enter and who may access it. They are responsible for providing required privacy information to staff and service users, choosing a lawful basis, limiting data to what is necessary, and handling requests relating to that content. PPE Flo should not be used to store clinical records unless the customer has determined that doing so is lawful and appropriate.

5. Who receives personal data

We share personal data only where needed with:

  • hosting, database, authentication, security, analytics, email and customer-support providers acting as subprocessors;
  • Paddle, our Merchant of Record, for product sales, checkout, subscription management, payments, refunds, tax compliance, fraud prevention and invoicing;
  • professional advisers such as legal and accounting advisers under duties of confidentiality;
  • a buyer or successor if the business is reorganised, sold or transferred; and
  • courts, regulators, law enforcement or other authorities where disclosure is legally required.

We do not sell personal data.

6. International transfers

Some providers may process data outside the United Kingdom or European Economic Area. Where required, we use recognised safeguards such as UK adequacy regulations, EU adequacy decisions, the UK International Data Transfer Agreement or addendum, and Standard Contractual Clauses, together with appropriate security assessments.

7. Retention

We keep account and service data while an account is active and for a limited period after it closes so records can be exported, disputes resolved, security maintained and legal duties met. Retention may vary by subscription plan and customer instruction. Payment and accounting records may be retained for up to seven years. Security logs are kept only as long as reasonably necessary. When data is no longer needed, it is deleted or anonymised, subject to backups and legal holds.

8. Security

We use appropriate technical and organisational safeguards, including encryption in transit, access controls, organisation-level separation, least-privilege permissions, audit logging, monitoring and security review. No internet service can guarantee absolute security, so customers must also protect credentials and manage user access carefully.

9. Cookies and analytics

Essential browser storage is used for sign-in, security and core preferences. We also use Google Analytics to understand page visits and referral sources. Browser settings can block or delete cookies, although blocking essential storage may prevent sign-in or other core functions. Where consent is legally required for non-essential analytics or marketing technology, it will not be used until consent is given.

10. Your rights

Depending on the law that applies, you may ask to access, correct, erase or restrict your personal data; receive portable data; object to processing based on legitimate interests; and withdraw consent without affecting earlier lawful processing. UK and EEA requests are normally answered within one month. If your request concerns data controlled by your care organisation, contact that organisation first.

Submit a request through the support channel in PPE Flo. You may also complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority.

11. Changes and contact

We may update this notice when the service or law changes. Material changes will be highlighted in the service or otherwise communicated where appropriate. Privacy questions and rights requests can be submitted through the support channel available inside PPE Flo.