Legal
Effective Date: 9 March 2026 · Version 1.0
This Privacy Policy applies to Business Legal Rating Ltd. and governs the collection, use, and disclosure of personal data when you use the Business Legal Rating platform at businesslegalrating.com. It complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the EU GDPR, the California Consumer Privacy Act (CCPA/CPRA), and other applicable data protection laws.
Business Legal Rating Ltd. ("we", "us", "our") is the data controller responsible for your personal data. We operate the Business Legal Rating platform, which provides AI-powered legal preparedness assessments for businesses.
Our Data Protection Officer (DPO) can be contacted at [email protected]. For UK GDPR purposes, we are registered with the Information Commissioner's Office (ICO). For EU users, we have appointed a representative in the European Economic Area.
We collect the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Identity Data | First name, last name, job title | Registration form |
| Contact Data | Email address, phone number | Registration form |
| Company Data | Company name, website, industry, size, country | Registration form |
| Assessment Data | Answers to 40 legal preparedness questions | Assessment form |
| Publicly Scraped Data | Information publicly available on your company website | Automated scraping |
| Account Data | OAuth login identifier, login method, last sign-in | Authentication provider |
| Payment Data | Stripe customer ID, payment intent ID (no card numbers stored) | Stripe (third party) |
| Technical Data | IP address, browser type, device type, operating system | Automatic collection |
| Usage Data | Pages visited, features used, time on site | Analytics cookies (with consent) |
| Cookie & Consent Data | Your cookie preferences and consent timestamp | Cookie banner |
Special Categories: We do not intentionally collect special category data (e.g., health, race, religion, political opinions). If you inadvertently include such data in your assessment answers, please contact us immediately for removal.
We use your personal data for the following purposes:
Under UK GDPR and EU GDPR, we rely on the following lawful bases:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and authentication | Contract performance (Art. 6(1)(b)) |
| Generating your legal rating | Contract performance (Art. 6(1)(b)) |
| Payment processing | Contract performance (Art. 6(1)(b)) |
| Analytics cookies | Consent (Art. 6(1)(a)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
| Platform security and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Aggregated anonymised analytics | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance and regulatory requests | Legal obligation (Art. 6(1)(c)) |
We retain your personal data for as long as necessary to fulfil the purposes for which it was collected:
Upon expiry of the applicable retention period, data is securely deleted or anonymised.
Under UK GDPR and EU GDPR, you have the following rights:
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights:
To submit a verifiable consumer request, contact us at [email protected] with the subject line "CCPA Request". We will respond within 45 days.
Your data may be transferred to and processed in countries outside the UK or European Economic Area (EEA), including the United States. Where we transfer data internationally, we ensure appropriate safeguards are in place, including:
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.
The Business Legal Rating platform is intended for business use only and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (if you have an account) and by displaying a prominent notice on the platform. The "Effective Date" at the top of this page will be updated accordingly. Your continued use of the platform after changes take effect constitutes acceptance of the revised policy.
For any privacy-related questions, requests, or complaints, please contact our Data Protection Officer:
Business Legal Rating Ltd.
Data Protection Officer
Email: [email protected]
For UK GDPR complaints: Information Commissioner's Office (ICO) — ico.org.uk
We use cookies to provide essential platform functionality and, with your consent, to analyse usage and improve our service. We never sell your data. Read our Cookie Policy and Privacy Policy.
Compliant with UK GDPR, UK PECR, EU ePrivacy Directive, and US CCPA. Consent is recorded with timestamp and version number for accountability.