UK GDPR Compliance Statement
Last updated: 7 July 2026
1. Overview
This statement sets out how 30 Something Creative meets its obligations as a data controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The UK GDPR applies because we offer services to individuals in the United Kingdom and/or the European Economic Area and we process the personal data of those individuals.
2. Data controller
Data controller: 30 Something Creative
Trading names: The Rebuild Planner, Life After 30
Address: Brighton, England, United Kingdom
Contact: hello@lifeafter30.co.uk
3. Lawful basis for processing
- Contract: processing your purchase through Paddle checkout, and sending purchase confirmation and product access emails.
- Consent: sending waitlist, newsletter and marketing emails to opted-in subscribers; storing the planner content you enter (including any health data).
- Legitimate interests: improving the app, understanding usage patterns, fraud prevention.
- Legal obligation: retaining financial records for 7 years as required by HMRC.
4. Special category data
The Rebuild Planner includes a menstrual cycle tracker, mood log and other wellbeing features. Where you voluntarily enter cycle data, symptoms or reproductive health information, this constitutes special category data under Article 9 UK GDPR (data concerning health). We process this data only on the basis of your explicit consent, given when you enter it. You may delete this data, or your entire account, at any time from within the app.
5. Data minimisation and purpose limitation
We collect only the personal data necessary for the purposes described in our Privacy Policy. We do not use personal data for purposes incompatible with those for which it was collected, and we do not use your planner content to train AI models.
6. Data processor and controller relationships
We use the following third parties and rely on their published GDPR/UK GDPR compliance documentation and agreements:
- Paddle.com — acts as Merchant of Record for all orders, and is an independent data controller (not simply our processor) for payment and billing data relating to your transaction. Paddle's own Privacy Policy governs this processing.
- Lovable Cloud — hosts the app and stores account and planner data, as our processor, in an encrypted database within the EU/UK.
- MailerLite — processes waitlist and email marketing data on our behalf, as our processor.
7. International data transfers
Where any third party processes data outside the United Kingdom or European Economic Area, we rely on Standard Contractual Clauses (SCCs) or UK International Data Transfer Agreements (IDTAs) incorporated into our agreements, and on adequacy decisions made by the UK government in respect of certain countries.
8. Data subject rights procedures
- All requests should be directed to hello@lifeafter30.co.uk.
- We will acknowledge requests within 5 working days.
- We will respond fully within one calendar month (or notify of an extension where the request is complex).
- We will verify the identity of the requester before releasing or deleting data.
- We will not charge a fee for most requests unless they are manifestly unfounded or excessive.
9. Data breach procedures
- We will assess the risk to individuals as quickly as possible.
- Where a breach is likely to result in a risk to individuals' rights and freedoms, we will notify the ICO within 72 hours of becoming aware of it.
- Where a breach is likely to result in a high risk to individuals, we will notify affected individuals directly without undue delay.
- We maintain an internal record of all breaches, including those not reportable to the ICO.
10. Data protection by design and default
- We collect only the data strictly necessary for each function of the app.
- No analytics or advertising tracking is deployed on the app.
- Passwords are hashed; data is encrypted in transit and at rest.
- You can delete your account and all associated data at any time from within the app.
11. Retention schedule
- Customer purchase records: 7 years (HMRC / legal obligation), separate from Paddle's own records as Merchant of Record.
- Waitlist and email marketing list: until unsubscribe or erasure request.
- Account and planner data: until you delete your account; wiped from live systems within 30 days and from backups within 90 days.
- Server access logs: approximately 30 days.
12. Review
This compliance statement and associated policies will be reviewed annually, or whenever significant changes are made to our data processing activities.
This document is intended as a practical working compliance statement, not formal legal advice. Independent legal review is recommended before relying on it commercially.