Northrow Reporting hello@northrowreporting.co.uk

Legal

Privacy Policy

Last updated 24 August 2026. This page explains what Northrow Reporting collects, why, and what happens to it. Where we could not verify something, we have said so rather than guessed.

Who we are

Northrow Reporting

Digital Doctor Ltd, trading as Northrow Reporting. Digital Doctor Ltd is a private limited company registered in England and Wales (company number 12127450), with its registered office at Suite A 82 James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE. Northrow Reporting is a trading name of that company, and Digital Doctor Ltd is the data controller and, where it acts on a broker's instructions, the data processor described in this policy.

Northrow Reporting (northrowreporting.co.uk) provides a monthly insurer commission reconciliation report to UK insurance brokers. Contact: hello@northrowreporting.co.uk or tim@northrowreporting.co.uk.

Two roles

Controller for some data, processor for other data

We act in two genuinely different capacities, and it matters which one applies to a given piece of data:

As controller

For the contact details of prospects and clients (a name, a firm, an email address, anything sent to us at tim@ or hello@northrowreporting.co.uk), we decide why and how that data is used, so we are the controller.

As processor

For the insurer commission statements and policy ledger extracts a broker sends us, and for the policyholder data inside them (names, policy references, premiums, commission figures), we act only on the broker's instructions. We are the processor; the broker remains the controller of their policyholders' data. Our processing terms with each broker client are set out in a data processing agreement, issued with the first invoice.

What we collect

Data we hold, and where it comes from

  • Prospect and client contact details: name, firm, email address, and anything else volunteered in correspondence. Collected when someone emails us, replies to outreach, or is identified as a prospective client from public sources (for example, a firm's own website or Companies House).
  • Insurer commission statements: sent to us by a client broker, typically forwarded by email or uploaded. These contain policyholder names, policy references, premiums and commission figures.
  • Policy ledger extracts: sent to us by a client broker from their own system (for example Acturis), covering the same policies and policyholders as the statements above.

We do not operate a website form, so no data is collected directly through this site beyond what a visitor's browser sends automatically to serve the page (see “Who it is shared with” below).

Why

Lawful basis for each purpose

  • Prospect outreach and correspondence: legitimate interests: reaching out to firms in our target market by email, and replying to enquiries. A recipient can object at any time and we stop.
  • Providing the reconciliation service to a client: performance of a contract with that broker, and, for the policyholder data inside the statements and ledger, the broker's own lawful basis as controller, which we process only on their documented instructions.

Sharing

Who it is shared with

  • Google Workspace: our email is hosted on Google Workspace. Correspondence, statements and ledger extracts sent to our email addresses pass through and are stored within Google's infrastructure, governed by Google's own terms and privacy commitments for Workspace customers.
  • Cloudflare: this website is hosted on Cloudflare Pages and the domain's DNS runs on Cloudflare. Cloudflare may process technical request metadata (such as IP address) to serve the page and apply security protections, under Cloudflare's own privacy policy.
  • Google Fonts: this page loads typefaces from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). Loading a font makes your browser send your IP address to Google as part of that request. No cookies are set and no other data is passed. Google's own Fonts privacy notice covers this narrowly.

We do not sell data, and we do not share policyholder data with anyone beyond what is described above, except where required by law.

Storage

Where it is held, and for how long

Statements and ledger extracts are stored outside our source code repository, on Tim's own machine, and are not committed to version control under any circumstance. We do not currently operate encryption at rest, a formal access-control system, or a certified information security process for this data. We are a small operation and describe our practice accurately rather than claim a standard we do not meet. Access is limited to Tim. We recommend, and intend to move towards, disk-level encryption and a documented retention schedule as the client base grows; until then, this is the honest state of things.

Client data is retained for as long as the client relationship continues, and is deleted within 30 days of a client's request or the end of the engagement, whichever is sooner.

Rights

Your rights

Under UK GDPR you can ask us to access, correct, delete, or stop using your personal data, and to receive a copy of it in a portable format. Email hello@northrowreporting.co.uk to exercise any of these.

If you are a policyholder whose data appears in a statement or ledger we process on a broker's behalf, we act only as their processor. Please raise your request with your broker directly; we will assist them in fulfilling it under our processing agreement.

You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk or on 0303 123 1113.

Transfers

International transfers

We have not identified any transfer of personal data outside the UK in the course of providing this service. Google Workspace and Cloudflare are both large international providers; we have not independently verified the exact processing location or transfer mechanism used for a UK Workspace account or for Cloudflare's edge network, and note that as unverified rather than asserting a specific safeguard. If this changes, or if verification surfaces a transfer, this policy will be updated to name it.

Retention of this notice

Changes to this policy

We may update this policy as the service or our data practices change. The date at the top of this page always reflects the most recent update. Material changes affecting an existing client will also be raised directly with them.