• Integrations
  • Security
  • Pricing
Sign in
FacebookInstagramXLinkedInTelegram

PRODUCT

  • Recap
  • Pricing
  • Reviews
  • Release notes

FEATURES

  • Integrations
  • Pricing
  • Security and Privacy

INTEGRATIONS

  • Coinbase Taxes
  • Kraken Taxes
  • Binance Taxes
  • Ethereum Taxes
  • More Integrations

RESOURCES

  • Help Center
  • Resources library
  • Blog
  • Find an accountant

COMPANY

  • About us
  • Careers
  • Contact us
Bitcoin Policy UK
Privacy policyTerms of serviceCookie PolicyDPA
©2026 Recap Technologies Limited. All rights reserved.
71-75 Shelton Street, Covent Garden, London, England, WC2H 9JQ
Telephone: 01174 630352

Privacy Policy

Last Updated: September 16, 2026

1. Who we are

Recap Technologies Limited provides the website at recap.io and the app at app.recap.io, together Recap. Our company number is 11218777 and our registered address is 71-75 Shelton Street, Covent Garden, London, England, WC2H 9JQ. Our ICO registration reference is ZB735084.

Contact dataprotection@recap.io about privacy, your data rights or a complaint. Our Data Protection Officer is Daniel Howitt.

This notice covers website visitors, account holders, people using Recap through a business or advisor, and people whose information those customers provide. “Personal data” means information relating to an identified or identifiable individual. Recap is not authorised by the FCA and does not file tax returns or act as a tax agent; our Terms of Service explain what the product is.

Contents

  • 1. Who we are: who is responsible for your information and how to contact us.
  • 2. Information we process and where it comes from: what we collect and who provides it.
  • 3. Encryption and access: what is encrypted on your device and what we handle in readable form.
  • 4. Why we use information and our lawful bases: each purpose and the legal ground for it.
  • 5. Support, analytics and AI: support tools, website statistics, product analytics, advertising and where AI is used.
  • 6. Who receives information: every provider and recipient, and what each gets.
  • 7. Who is responsible for your information: when Recap is responsible and when a business or your accountant is.
  • 8. Wallet screening: how screening results are handled and how to challenge one.
  • 9. International processing: where data is processed and the safeguards for transfers.
  • 10. Retention and deletion: how long we keep each type of record and what deletion removes.
  • 11. Your rights and complaints: your data rights, how to use them, and how to complain.
  • 12. Children and changes: accounts are for adults; how we tell you about changes.

2. Information we process and where it comes from

InformationSource and use
Account and contact detailsYou, your team administrator or an advisor provide your email, name or alias, invitations and account settings. Authentication services provide login and security information. If someone invites you to a team or portfolio, we receive your email address from them and keep the invitation record.
Portfolio informationYou or an authorised user provide transactions, notes, settings and uploaded records, which may cover cryptoassets, stocks and shares or other chargeable assets. Connected exchanges, brokers and public blockchain data services supply transaction history, identifiers, wallet addresses, balances and related information. Recap uses that information to identify assets and to obtain market prices and FX rates. In our systems, wallet addresses and transaction information are linked to your account, so we treat them as your personal data even though the ledger itself is public. Section 6 explains what the blockchain data providers we query receive, which is different.
Team and portfolio metadataWe hold membership, roles, sharing relationships and details such as portfolio names, type, tax authority and usage counts to administer Recap.
Billing and referralsYou and our payment, subscription and referral providers supply billing details, payment status, subscription history and referral information. If you create an account after following a referral link, we store that referral against your account so a later subscription can be attributed. Payment providers handle payment credentials. If you pay in Bitcoin, the transaction and the address you pay from are recorded on the public blockchain and in our records.
Screening informationCustomers submit wallet addresses. HopTrail supplies risk labels and associated address, counterparty and transfer information.
Support informationYou provide messages, attachments and information shared for troubleshooting. With your authorisation, support staff can access a shared portfolio. We keep a copy of the emails we send you, including invitations and notifications, so support can see what you received.
Product feedbackYou submit feedback in the app. We store it with your account and use an AI service to produce a short title, summary and category for our team.
Directory enquiriesIf you contact an accountancy firm through our Find an accountant directory, you provide your name, email address, optional phone number and message, which we pass to the firm you chose.
Directory listingsAccountancy firms and their team members provide names, photos, contact details and publications for our Find an accountant directory, which we publish on our website and let the firm edit through a link we send it.
Technical and usage informationYour use of Recap generates IP addresses, device and browser details, requests, errors and security events, including when you are active and which browser you use, and your approximate country from your IP address so we can suggest the right tax authority. Optional analytics records visits, feature use and interactions when you turn it on. Advertising tags can disclose website visits and browser identifiers to advertising providers with your consent.

We need a valid email address to provide an account, and billing details for a paid subscription. An import or screening request needs the information required to perform it. If you do not provide required information, we may be unable to provide that feature. Analytics and marketing choices are never a condition of using Recap.

3. Encryption and access

What is encrypted. The app encrypts your portfolio contents on your device before uploading them: the transactions, accounts, wallet addresses and exchange connections you have added, your notes and settings, and your reports. We do not hold your secret phrase, so we cannot read those contents unless you share a portfolio with our support team. Losing the necessary keys can make your portfolio inaccessible; recovering a login password does not recover encryption keys.

What passes through in readable form, and what we keep. To fetch your data and run the service, some information has to be readable while a request is being handled. We designed Recap so that this information is used and discarded rather than stored, and so that what we do keep cannot be tied back to you:

  • Wallet addresses and extended public keys pass through our servers on their way to the blockchain data services in section 6. We keep a record that an address was looked up, with no link to your account, and our request logs never record your identity, IP address or browser on the same request as an address. Short-lived caches of chain data are keyed by address only and expire within an hour.
  • Exchange credentials and connection tokens pass through our proxy to the exchange you connected and are not stored on our servers. The proxy strips your IP address and browser details before a request leaves Recap and does not log credentials. Where an exchange uses a sign-in authorisation rather than an API key, we keep only the record needed to complete that authorisation and protect it from misuse.
  • Transaction data and balances returned by an exchange or blockchain service stream back to your browser, where they are encrypted into your portfolio. We do not store them.
  • Screening results are stored, because you need to see them again, but with no link to the account, team or portfolio that requested them.
  • Diagnostic information can contain addresses or transaction details when something goes wrong, and anything you choose to include in a problem report. It goes to our error-monitoring provider with your account identifier so that we can help you, and is the one readable path that can pair an address with your identity.
  • Account details, team membership, permissions, portfolio metadata such as names and counts, billing information, feedback you submit and copies of the emails we send you are stored in readable form, because we need them to run your account.

Sharing with the support team is optional. Turning on the Share data with the Recap support team setting for a portfolio gives authorised staff read access to that portfolio. The setting shows whether your team has a support-sharing arrangement, not which portfolios are shared. Turning it off ends support access to all portfolios shared by that team. Sharing uses encrypted keys and does not require disclosing your secret phrase.

Authorised staff use an internal administration tool for account and service information and the app for portfolios shared with support. We log administrative changes, staff activity signals and the enabling and disabling of support sharing. These logs do not record each time a staff member reads a shared portfolio. While you use Recap, your browser holds keys and decrypted information, and key material can remain in its storage afterwards. Protect your device and browser profile. Copies that you, or someone you shared with, have downloaded are outside our control.

4. Why we use information and our lawful bases

For processing we control, we use the following bases under UK data protection law:

PurposeInformation involvedLawful basis
Provide an individual's account and requested features, manage subscriptions and answer service requestsAccount, billing, connection, portfolio and support information as neededPerformance of our contract with that individual
Administer business accounts and communicate with employees, team members and business contactsContact details, roles, invitations, subscription and support administrationLegitimate interests in delivering and managing the business relationship
Secure Recap, investigate faults, prevent misuse and maintain reliabilityAccount identifiers, requests, technical logs, activity signals and relevant diagnostic informationLegitimate interests in a secure, reliable service and preventing fraud; legal obligation where a specific duty applies
Keep a copy of emails we send you and read and sort product feedbackRecipient, subject and content of our emails; feedback text, account identifier and the generated title, summary and categoryLegitimate interests in supporting you, acting on feedback and handling disputes
Keep the website working and measure anonymous visit and performance statisticsRequest information such as IP address and browser details, used by Vercel to produce anonymous aggregate statisticsLegitimate interests in operating, securing and understanding the website. This use is limited to anonymous, cookieless or equivalently short-lived identifiers, is not linked to a Recap account and is not used for advertising. It runs by default; you can switch statistics off in Cookie Settings.
Record subscription sales and cancellations in our analyticsSubscription amount, invoice reference and a cancellation reason category, without free textLegitimate interests in understanding revenue and cancellations
Invite you to review RecapEmail address, account identifier, language and subscription statusLegitimate interests in obtaining genuine reviews. You can opt out using the link in the invitation or by contacting us
Understand how you use the website and productConsented analytics events, device or account identifiers, and email address for identified product analyticsConsent
Measure and personalise advertisingWebsite visits, campaign information, events and browser or device identifiers shared with advertising providersConsent
Send product updates, newsletters and tax-deadline emailsEmail address, plan and communication preferencesConsent; or legitimate interests in promoting our own similar services where the PECR soft opt-in applies: we collected your details during a sale or negotiations for one, offered a simple refusal at collection and in every subsequent message, and you have not opted out
Administer referrals and commissionsReferral identifiers, contact details and subscription or payment statusLegitimate interests in administering the referral programme
Publish and maintain the Find an accountant directory and pass enquiries to firmsFirms' listing details and team members' names, photos and contact details; enquirers' detailsLegitimate interests in running the directory; the firm is responsible for its own listing content
Keep statutory financial records and comply with binding legal requirementsRelevant billing, account or other information required for the obligationLegal obligation
Handle complaints, prove completion of erasure requests and establish or defend legal claimsRelevant correspondence, limited erasure evidence and records needed for a claimLegitimate interests in accountability and protecting legal rights; legal obligation where applicable

You can object to any processing we base on legitimate interests, and you can withdraw consent at any time; withdrawing it does not affect what was done before. Where we act as a processor (section 7), the business customer decides why the data is used, and the table above does not cover that processing.

5. Support, analytics and AI

Recap's tax calculations are rule-based and do not use AI. We do not use your portfolio contents or client information to train AI models, and we do not sell that information.

Our support and error-monitoring providers may use AI to help answer support questions or investigate technical faults. Intercom processes conversation content, contact details, your app version and usage metrics such as the number of accounts and transactions in your portfolio. Sentry processes technical information and error context together with your account identifier and email address; error context can include wallet addresses or transaction details involved in the error, and anything you include in a bug report. Information you paste or attach can be read by the service receiving it even if it also exists in an encrypted portfolio.

Feedback you send through the app's feedback form is summarised and categorised by an AI model (Anthropic Claude) running on Amazon Web Services in the UK and EU. The text is not used to train the model. Do not include client names, addresses or wallet details in feedback.

If you share a portfolio with our support team, only Recap staff see it, inside the app. We do not pass its contents to support, error-monitoring or AI providers.

Anonymous website statistics. By default we collect anonymous aggregate statistics about website visits and page performance so we can operate and improve recap.io. We use Vercel Web Analytics and Speed Insights. They use request information, including IP address and browser details, with short-lived identifiers and without analytics cookies or persistent browser identifiers. We do not link these statistics to your Recap account, use them to profile you or share them for advertising. Individual-level input is kept only as needed to produce the aggregate results and is then removed. You can switch statistics off in Cookie Settings. Identified measurement and advertising remain off until you accept them.

Measurement and product analytics. If you accept measurement on the website, PostHog stores an identifier in your browser so it can link your visits over time. If you turn on product analytics in the app, we can link events to your Recap user ID and email address. If you also accepted measurement on our website, we link visits collected with that consent to your account so we can see which campaigns bring people to Recap. We do not link visits collected without measurement consent to your account.

Whatever you choose, we record subscription sales and cancellations in our analytics as business records, with a reason category but no free text.

With consent, website advertising tags from Google Ads, Meta and Reddit disclose visits, events and browser or device identifiers for campaign measurement and advertising. These providers may combine that information with information they already hold to measure or personalise advertising. We use Tolt to attribute referrals and administer commissions.

Our Cookie Policy explains these technologies and how to change your choices: Cookie Settings in the website footer for statistics, measurement and marketing, and Improve features by sharing product usage in the app's account settings for product analytics.

Marketing email. If you have an account, we may email you Recap product updates, newsletters and tax-deadline reminders about our own services, on the bases in section 4. Every marketing email has an unsubscribe link, and you can also opt out at any time by emailing dataprotection@recap.io. Unsubscribing does not stop essential account, payment or security messages, which do not contain promotional content.

6. Who receives information

We use providers for particular functions. They receive the information needed for those functions, which may include encrypted contents, readable information, or both.

Provider or recipientPurpose and information
Amazon Web ServicesHosting, storage, delivery and infrastructure, including AI summarisation of product feedback. Encrypted portfolios and relevant readable account, request, screening and technical information.
Auth0 / OktaAuthentication and account security, including contact details, login information and identifiers. If you choose to sign in with Google or Apple, that provider also processes your login under its own notice.
StripePayments and subscription administration. Billing details, identifiers and payment status. Any payment method you choose inside Stripe's checkout, such as PayPal, is handled by Stripe and that method's provider under their own notices; we do not hold a separate relationship with them.
IntercomSupport chat and communications in the app and on the website, including contact details, conversation content, your app version and usage metrics such as the number of accounts and transactions in your portfolio.
Postmark (an ActiveCampaign company)Transactional email, login and verification emails, directory enquiry emails and marketing emails, including recipient details and message content.
SentryError investigation and monitoring, including your account identifier and email address, the browser or request that failed and technical context, which can include wallet addresses or transaction details involved in the error.
PostHogWith consent, website and product analytics, including events, identifiers and email address as described in section 5.
VercelWebsite delivery, traffic statistics, performance monitoring and bot protection for website forms, including request, device and page information.
TrustpilotReview invitations and the reviews widget on our website. When you create an account we register your email address and account identifier with Trustpilot so that a review link can be prepared; after your first paid invoice we may email you, at most once a year, asking for a review. Reviews you leave are public on Trustpilot and the rating is recorded on your support record.
Embedded website content (Mux, YouTube, Cal.com, Google Maps, Blockmark, Sanity)Display of video, booking pages, maps, certification badges, images and content on our website, including your IP address and request details when that content loads. Sanity is our content system and also keeps a live connection open while you read a page.
AlgoliaBlog search on our website, which receives your search terms and IP address as you type.
Accountancy firms you contact through our directoryYour enquiry, sent to the firm you choose. The firm handles it as an independent controller under its own privacy notice.
Google Ads, Meta and RedditWebsite advertising and campaign measurement, including visits, events and browser or device identifiers when enabled with consent.
HopTrailRequested wallet screening, including wallet addresses and screening information. HopTrail hosts the processing it performs for Recap in AWS Europe (London).
Blockchain data providers (QuickNode, Etherscan, Moralis, Helius and the community-run PulseChain endpoints)Public blockchain records, retrieved as explained under Blockchain data providers below.
Exchanges and brokers you connectThe exchange or broker remains the controller of your account with it. We retrieve your transaction history and balances using the access you authorise, whether an API key, a sign-in you approve with the service, or another credential it supports, and we ask for read-only access wherever the service allows it. Most connections go through our proxy, so the exchange sees our infrastructure IP address rather than yours; a few are called from your browser, so that exchange sees your IP address. Some services need your account email or identifier with them so they can match your account.
Image hosts for tokens and NFTsLogos and NFT media are loaded by your browser from the location named in the asset's metadata, including public IPFS gateways and metadata providers' image services. Those hosts receive your IP address and the identity of the asset displayed.
ToltReferral administration, including referral identifiers, referred users' contact details and relevant subscription information.
Teams, advisors and other recipients you authoriseInformation shared through the permissions you grant or under the business customer's instructions.

Blockchain data providers. To read public blockchains we query node and index services: currently QuickNode, Etherscan, Moralis and Helius, and for PulseChain the community-run public node at rpc.pulsechain.com and block explorer at api.scan.pulsechain.com, which have no published operator. Each runs its own index of a public ledger and answers the same query for anyone. They decide for themselves how their services work, so they are independent controllers of those services and not our processors, and we do not appoint them under a data processing agreement.

Our servers send them only a wallet address, a transaction reference, the contract address of a token or NFT so we can identify it or, if you added a Bitcoin account using an extended public key, that key, together with the chain and block range to retrieve. We never send your name, email address, account or portfolio identifiers, credentials or IP address, and we send one wallet address at a time, so a provider cannot tell from our requests which addresses belong to the same person. Contract addresses may be sent together; they identify assets, not people. In our systems an address you add is linked to your account, so we treat it as your personal data. In the provider's hands it is a public identifier with nothing linking it to you, and we have assessed that sending it is not a disclosure of your personal data. The association between you and your addresses exists only inside Recap, protected as section 3 describes. Asking about an address does not mean you own it: people look up counterparties, contracts and clients' wallets. An extended public key is the one exception to one address at a time, because the addresses it derives are what it is for; it is not on the public ledger, it cannot move your coins, and you can add a Bitcoin account by address list instead.

Handled separately, and not covered by that assessment: wallet screening (section 8) and exchange connections that use your credentials. Customer-specific choices of provider are not currently available.

Some providers are our processors for one task and controllers in their own right for another; a payment provider meeting its own regulatory duties, for example. The DPA lists the providers we may use for business customers' data.

We may also disclose necessary information to professional advisors, authorities or courts to comply with law or establish or defend legal claims. If our business is sold or reorganised, we may disclose information to advisors and transfer it to the successor with appropriate confidentiality and data protection safeguards.

We do not sell personal data for money. Under some US state privacy laws, sharing data with advertising providers through tags counts as a “sale”, “sharing” or targeted advertising. You can refuse or withdraw consent for those tags in Cookie Settings, or contact dataprotection@recap.io.

7. Who is responsible for your information

If you use Recap for yourself, we are the controller (the organisation responsible under data protection law) for how we use your information to run the service, and this notice explains it.

If a business or accountancy firm uses Recap, for its own portfolio or for its clients, that organisation (the business customer) decides why the information is used and we act on its instructions as its processor under our Data Processing Addendum. We remain responsible for our own use of the organisation's contact and billing details.

If you invite your accountant into your portfolio, they use what they see for their professional work and are responsible for that under their own privacy notice. We remain responsible for running the service for you. Who created, pays for or can edit a portfolio does not by itself decide these roles.

Wallet screening is available only through Recap for Professionals and runs when a professional firm requests it for its clients. We carry it out on that customer's instructions (section 8). We do not decide who is screened or what is done with a result.

If you contact us about information that a business or accountant controls, we will tell you who is responsible where we can and help them deal with your request. For screening, we usually cannot identify the requesting business from a wallet address or result alone.

8. Wallet screening

Wallet screening uses HopTrail to highlight addresses and transfers associated with risk information. Recap runs the screening and surrounding workflow on the instructions of a professional firm using Recap for Professionals, with HopTrail as a subprocessor for the instructed API processing. HopTrail has confirmed that this processing is hosted in AWS Europe (London). Our agreement requires HopTrail to process personal data on documented instructions. It prohibits unrelated use of personal data received through the API and identifiable profiles for independent commercial exploitation unless expressly authorised in writing by Recap and the relevant controller or required by law. HopTrail may retain and use aggregated, irreversibly anonymised data to improve its services and risk models. Removing a name alone does not make a wallet address anonymous. Results may concern a counterparty and do not establish wrongdoing by the customer or their client. Information may be incomplete or incorrect.

Screening results can include information about alleged offences, which UK law treats as criminal offence data with extra conditions attached (Article 10 UK GDPR, and section 10 and Schedule 1 of the Data Protection Act 2018). The business customer that requests screening is the controller: it is responsible for those extra conditions, for its own privacy information, and for answering rights requests about the people it screens. Recap is the processor. We do not hold the identity of the person being screened, and we do not decide who is screened or what is done with a result.

We store screening results without a link to the requesting customer, so we cannot tell a data subject who requested a screen, or answer a rights request about a result, except by assisting the customer who gives us the result reference. If you believe a result about you is wrong, contact the business you dealt with. If a business customer asks us to restrict or delete a result and supplies the reference, we will do that.

Recap does not make decisions with legal or similarly significant effects about you based solely on a screening result. If a business acts on a screening result, that decision is its own responsibility.

9. International processing

We and our providers process information in the UK, the EEA and other countries, including the United States. Processing within the UK does not require an international-transfer safeguard. For the providers listed in Annex 3 of our Data Processing Addendum, that annex identifies the applicable adequacy decisions or contractual safeguards, including the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.

For the reasons given in section 6, we have assessed that lookups to the blockchain data providers named there do not disclose your personal data, and we do not treat them as international transfers of it. Wallet screening is processed by HopTrail in the United Kingdom. When you connect an exchange or broker, your request goes to the service you chose, wherever it operates. It carries only the access you authorised with that service and, where the service needs it, the account details it uses to recognise you. That service's own notice governs what it does with your account. Our other providers, where they process information and the safeguard for any transfer are listed in Annex 3 of the DPA.

Email dataprotection@recap.io for details of the recipients, countries and safeguards relevant to your data, or a copy of applicable contractual safeguards.

10. Retention and deletion

Cancelling a paid subscription does not close your account. We keep account and portfolio information while providing your account, including on a free plan, subject to deletion requests and the business customer's instructions.

You can delete your account in the app or contact us. The app explains its grace period and scheduled deletion date. Deletion removes information within the scope of your account and may close teams you solely own; it does not remove another team's records. We assist with requests involving shared portfolios and processor data under the DPA.

RecordRetention approach
Account and portfolio informationWhile needed to provide the account or fulfil the business customer's instructions, then deleted or returned as applicable.
Screening resultsStored with no link to the account, team or portfolio that requested them, as section 8 explains, so we cannot find a result from your account or delete one when an account is deleted. The references to your own results are held in your portfolio. Contact us with a result reference to have that result deleted or restricted.
Billing recordsGenerally six years from the end of the relevant financial year, held by our payment provider. Recap keeps a reference to the Stripe customer so those invoices stay findable after an account is deleted.
Evidence of an account-erasure requestWe keep your email address, the date of your request, how it was made and any reason you gave for six years, so we can show the request was actioned and answer any dispute. Nothing else about you is kept in that record. It is then deleted automatically.
Blocked accountsIf we block an account for abuse or a breach of our Terms, we keep its records while the block is in place so we can prevent repeat abuse and defend claims. A blocked user can still exercise rights by email. When the block is lifted, the block fields are cleared; the account then follows the ordinary retention rules.
Copies of emails we send you, and product feedbackKept while your account exists. When the account is deleted, product feedback is deleted and we redact the address, subject and body from the email log, keeping only delivery metadata (that a message of that type was sent, and whether it was delivered). Device records used to count active sessions are deleted with the account.
Support and complaintsFor resolving the matter and any necessary follow-up, then only as needed for applicable complaint obligations or legal claims. The nature of the issue and relevant limitation period determine the period.
Technical and security logsApplication server logs are kept for three months and Client VPN connection logs for one year. Serverless function logs, proxy logs and content-delivery access logs do not currently expire automatically; we are introducing a 90-day limit for them and will update this notice when it is in place. Connection records that protect an exchange authorisation are kept for a limited period after the connection is made. Screening-queue messages that are not processed are discarded after 14 days. Older host and antivirus logs from retired infrastructure are kept for up to two years.
Website statisticsIndividual-level input to Vercel's statistics is kept only as long as needed for aggregation and removed afterwards. We may retain aggregate results that cannot identify anyone to compare website use over time. This is separate from the retention of consented measurement and product analytics.
Measurement, product analytics, advertising and referral recordsConsented PostHog measurement and product analytics events are kept for up to three years, unless deleted earlier. Separate subscription sales and cancellation records follow the business-record purpose in section 4 and are also kept in PostHog for up to three years. PostHog records linked to your account and referral records in Tolt are deleted as part of account deletion. Contact us about records that remain. Advertising providers apply their own periods.
Review invitation recordsKept while your account exists.
Directory enquiriesThe enquiry email is held by our email provider for 45 days. Our website logs keep the enquiry for up to 30 days.
Directory listingsPublished while the firm's listing is live and removed when the firm asks us to take it down or the listing lapses.
BackupsAutomated database backups are kept for one day. Deleted information may remain in a backup until that cycle completes. It is not used for ordinary operations and deletion is reapplied if a backup is restored.

We do not keep identifiable information just in case it is useful. Where a legal duty or a legal claim requires us to keep limited records longer, we restrict their use to that purpose. We may keep statistics that no longer identify anyone.

11. Your rights and complaints

You can ask us to: give you a copy of your personal data; correct or erase it; restrict how we use it; stop using it where we rely on legitimate interests; or send eligible data to you or another service in a portable format. You can object to direct marketing at any time and withdraw consent as easily as you gave it. These rights have some conditions and exceptions, which we will explain if they apply.

Email dataprotection@recap.io. We may need information to confirm your identity or locate the data, but will request only what is necessary. We normally respond to a rights request within one month. Where law permits an extension for complexity or the number of requests, we will tell you within the initial period and explain why. There is normally no charge.

You can also complain to Recap at that address or by post. We will acknowledge your data protection complaint within 30 days, investigate appropriately, keep you informed and tell you the outcome without undue delay.

You have the right to complain to the Information Commissioner's Office or another competent supervisory authority.

Where the EU GDPR applies to our processing, the equivalent rights under it also apply. If a US state privacy law applies to our processing of your information, your rights may also include opting out of sale, sharing or targeted advertising and appealing a refused request. Contact the same address to exercise or appeal a right. We will explain the available process and will not unlawfully discriminate against you for exercising your rights.

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. Our payment provider applies its own fraud checks to payments under its own notice.

12. Children and changes

Recap accounts are for adults. An adult customer may have a lawful reason to hold portfolio information about a child; the responsible controller must assess the additional protections needed. If a child has created an account, contact us so we can investigate and handle the information appropriately.

We update this notice when our processing changes and will give reasonable notice of material changes. If we want to use your information for a new purpose, we will ask for consent where the law requires it, rather than rely on an updated notice.