Privacy Policy

This privacy notice tells you what to expect us to do with your personal information.

Contact details

Email : info@tu-du.co.uk

What information we collect, use, and why

We collect or use the following information to provide and improve products and services for clients:

  • Names and contact details
  • Addresses
  • Occupation
  • Payment details (including card or bank information for transfers and direct debits)
  • Information relating to compliments or complaints
  • Account access information
  • Website user information

We also collect or use the following special category information to provide and improve products and services for clients. This information is subject to additional protection due to its sensitive nature:

  • Genetic information

We collect or use the following personal information for the operation of client or customer accounts:

  • Names and contact details
  • Addresses
  • Purchase or service history
  • Account information, including registration details
  • Information used for security purposes
  • Marketing preferences
  • Technical data, including information about browser and operating systems

We collect or use the following personal information for information updates or marketing purposes:

  • Names and contact details
  • Addresses
  • Profile information
  • Marketing preferences
  • Purchase or account history
  • Website and app user journey information
  • IP addresses

We collect or use the following personal information for dealing with queries, complaints or claims:

  • Names and contact details
  • Addresses
  • Payment details
  • Account information
  • Purchase or service history
  • Photographs
  • Correspondence

Lawful bases and data protection rights

Under UK data protection law, we must have a “lawful basis” for collecting and using your personal information. There is a list of possible lawful bases in the UK GDPR. You can find out more about lawful bases on the ICO’s website.

Which lawful basis we rely on may affect your data protection rights which are set out in brief below. You can find out more about your data protection rights and the exemptions which may apply on the ICO’s website:

  • Your right of access - You have the right to ask us for copies of your personal information. You can request other information such as details about where we get personal information from and who we share personal information with. There are some exemptions which means you may not receive all the information you ask for. Read more about the right of access.

If you make a request, we must respond to you without undue delay and in any event within one month.

To make a data protection rights request, please contact us using the contact details at the top of this privacy notice.

Our lawful bases for the collection and use of your data

Our lawful bases for collecting or using personal information to provide and improve products and services for clients are:

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
  • Tudu processes certain personal information on the basis of legitimate interests in order to provide, maintain, and improve our products and services for clients. Our legitimate interest lies in ensuring that users can effectively manage their risk assessments, checklists, tasks, and compliance records through a secure, reliable, and easy-to-use digital platform. This processing is necessary for: Providing users with access to their accounts, records, and task management features. Supporting communication between Tudu and its users (for example, sending updates, notifications, and service information). Analysing platform usage and feedback to enhance performance, functionality, and security. Maintaining accurate audit trails and compliance records that form part of the service we provide. We believe that the benefits of this processing, such as improving safety management, accountability, and operational efficiency, clearly outweigh any potential risks or impacts on the individuals whose data is processed. All personal information is handled securely and proportionately, and individuals can object to this processing at any time if their rights override our legitimate interests.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information for the operation of client or customer accounts are:

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
  • We may process certain information to maintain account security, prevent unauthorised access, detect misuse, and ensure the integrity and reliability of our platform. This processing is necessary to protect both Tudu and its users, and we consider these interests to be balanced and proportionate.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information for information updates or marketing purposes are:

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
  • For existing customers or users, we may send information about product updates, service improvements, or related features that are relevant to the services you already use. We consider this communication to be in both your interest and ours, as it helps you make full and safe use of the platform. These communications are limited, proportionate, and never excessive.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Our lawful bases for collecting or using personal information for dealing with queries, complaints or claims are:

  • Consent - we have permission from you after we gave you all the relevant information. All of your data protection rights may apply, except the right to object. To be clear, you do have the right to withdraw your consent at any time.
  • Contract – we have to collect or use the information so we can enter into or carry out a contract with you. All of your data protection rights may apply except the right to object.
  • Legal obligation – we have to collect or use your information so we can comply with the law. All of your data protection rights may apply, except the right to erasure, the right to object and the right to data portability.
  • Legitimate interests – we’re collecting or using your information because it benefits you, our organisation or someone else, without causing an undue risk of harm to anyone. All of your data protection rights may apply, except the right to portability. Our legitimate interests are:
  • We process relevant personal information to review and respond to enquiries, resolve issues, and improve our services. This processing helps us maintain good customer relationships and ensure users receive accurate, timely support. We consider this use of data necessary and proportionate, with minimal impact on individuals’ privacy.

For more information on our use of legitimate interests as a lawful basis you can contact us using the contact details set out above.

Where we get personal information from

  • Directly from you
  • Suppliers and service providers

How long we keep information

Data Retention Schedule

Tudu only keeps personal information for as long as it is needed for the purpose it was collected, to meet legal, accounting, or reporting requirements, or to resolve disputes. When data is no longer required, it is securely deleted or anonymised.

For more information on how long we store your personal information or the criteria we use to determine this please contact us using the details provided above.

Who we share information with

Others we share personal information with

  • Insurance companies, brokers or other intermediaries
  • Emergency services
  • Regulatory authorities
  • Organisations we’re legally obliged to share personal information with
  • Suppliers and service providers


Third-Party Services We Share Data With

We use a small number of trusted third-party services to operate TuDu, manage subscriptions, process payments, and understand how our platforms are used. These include:

Stripe – Used for subscription and payment processing. Customer names, email addresses, subscription details, and payment method tokens are securely shared with Stripe when subscriptions are created or managed.

Klaviyo – Connected to our Webflow marketing site for email communications and marketing automation.

Google Analytics – Used across our platforms to collect anonymised usage and performance data to help us understand and improve user experience.

Apple App Store and Google Play Store – Used for app distribution and may collect device identifiers, usage data, and crash reports as part of their normal operations.

Our own backend services – Used to provide account management, subscription logic, and app functionality.

Each of these providers maintains its own privacy policy governing how they process your data. We only share the minimum necessary information required to provide TuDu’s functionality and services.

How to complain

If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy notice.

If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.

The ICO’s address:           

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Helpline number: 0303 123 1113

Website: https://www.ico.org.uk/make-a-complaint

Last updated: 10/11/2025