Your data
Privacy policy.
This page explains what personal data The Real Debt Guy collects, why we collect it, how we look after it, and the rights you have over it. Plain English, no jargon, everything you'd want to know if it were your data (and it is).
Who we are.
The Real Debt Guy is a trading name of Mm Corp Limited, a company registered in England and Wales.
- Company number: 09564956
- Registered office: 22 Westward Way, Harrow, England, HA3 0SE
- Correspondence address: PO Box 480, Sevenoaks, TN13 9JY
- ICO registration: ZB169848
- Email: info@therealdebtguy.com
Mm Corp Limited is the data controller for the personal data collected through therealdebtguy.com and the services provided through it. That means we're the organisation responsible for deciding how and why your data is used, and we're the ones you contact if you have a question about it.
What personal data we collect.
We only collect data when you give it to us or when it's necessary to run the website. Here's every point where data gets collected.
-
Contact form (/contact-us)
- What
- Your name, email address, and the message you send us. Optional phone number if you provide it.
- When
- When you submit the contact form.
-
Newsletter signup
- What
- Your first name and email address.
- When
- When you sign up via any newsletter form on the site.
-
Letter Audit upload (/help/letter-audit/upload)
- What
- Your name, email address, phone number, a short description of your situation, and the letters or documents you upload (up to four). Uploaded letters may contain personal data belonging to you and to third parties named in the letters (such as creditor employees, reference numbers, and account details).
- When
- After you buy a Letter Audit and complete the upload form.
-
Clarity Call and Private Call bookings
- What
- Your name, email address, and the date/time slot you booked. Anything you type into the booking notes.
- When
- When you complete checkout and book a slot.
- What we don't collect
- We do not record calls. We take handwritten or typed notes during the call if it helps us support you; those notes are kept for as long as we're actively supporting you and then deleted.
-
Community signup
- What
- Your name and email address so we can process your subscription and add you to the private group. Once you're inside the Community, anything you post there is handled by Facebook under Facebook's own privacy policy.
- When
- When you subscribe to the Community.
-
Payment information
- What
- Your name, email address, billing address, and payment metadata (transaction ID, amount, product bought). We never see or store your card details. Stripe handles those end-to-end.
- When
- When you check out on any Stripe payment link.
-
Website analytics
- What
- Pseudonymous data about how the site is used: pages viewed, referrer, device type, approximate location (country/region, not street level), time on page. Collected via Google Analytics 4 with IP anonymisation on.
- When
- Every visit, unless you decline analytics cookies via the cookie banner.
-
Server logs
- What
- Standard web-server logs: IP address, browser user-agent, requested URL, response code, timestamp. Collected by our hosting provider (Vercel) for security and abuse prevention.
- When
- Every request to the site.
We do not collect: your date of birth, national insurance number, bank account details, credit-file data, health information, or any special-category personal data. If a Letter Audit upload happens to contain any of that (e.g. a benefits letter), we'll only use it to prepare your report and it's covered by the same protections as the rest of your data.
Why we collect it and our legal basis.
Under UK GDPR we have to tell you the "legal basis" we're relying on for each type of processing. Here it is:
To provide the services you've paid for
Legal basis: contract. When you buy a Letter Audit, Clarity Call, Private Call, or Community subscription, we need your contact details and (for the Letter Audit) the letters you upload so we can actually do the work. Without this data, we can't deliver the service.
To respond to your contact form messages
Legal basis: legitimate interest. If you ask us a question via the contact form, we use your email to reply. Our legitimate interest is running a business that answers its enquiries.
To send you the monthly newsletter
Legal basis: consent. You've actively signed up. You can unsubscribe at any time using the link at the bottom of every email; we act on that immediately.
To run the website and understand how people use it
Legal basis: legitimate interest for essential functions (making the site work, protecting it from abuse), consent for analytics (understanding traffic patterns and improving the site). Analytics cookies are only set if you allow them via the cookie banner.
To meet our legal and tax obligations
Legal basis: legal obligation. We're required by HMRC to keep records of sales and payments for six years. Financial records that identify you as a customer are kept for this period regardless of any other retention rule.
What we don't do
We don't sell your data to anyone. We don't use it for advertising retargeting. We don't share it with third parties for marketing. We don't build profiles of you to serve you different content or prices. We don't run automated decision-making that has legal or similarly significant effects on you.
How long we keep your data.
We keep data only as long as we need it. Here's what "as long as we need it" means in practice:
- Newsletter subscribers: until you unsubscribe. When you unsubscribe, we delete your record from Mailchimp within seven days.
- Contact form messages: 24 months from your last message, then deleted from our inbox.
- Letter Audit uploads (the letters and any attachments): 12 months from delivery of your report, then permanently deleted.
- Letter Review and Action Plan reports we've prepared: 12 months from delivery, then permanently deleted.
- Call booking records and any handwritten/typed notes we took: until we're no longer actively supporting you, then deleted. Typically 6 months.
- Community membership records: for as long as you're a member. If you cancel your subscription, we remove you from the private Facebook group. Anything you posted inside the group while you were a member stays under Facebook's control and is subject to Facebook's own retention and deletion rules. You can delete your own posts and comments at any time from within Facebook.
- Payment and accounting records (Stripe transactions, invoices, receipts): six years from the end of the tax year in which the transaction happened. This is required by HMRC and overrides all the retention periods above.
- Analytics data: retained by Google for up to 14 months, then automatically deleted. We can only see aggregate reports, not identifiable individual data.
- Server logs: up to 30 days, then automatically deleted by Vercel.
If you ask us to delete your data earlier, we will, with the exception of records we're legally required to keep (like the Stripe transaction and any HMRC-required accounting records). We'll always explain what we can and can't delete when you ask.
Your rights over your data.
Under UK GDPR you have the following rights. All of them are free to exercise and we'll respond within one calendar month.
- Access. You can ask for a copy of all the personal data we hold about you.
- Correction. If any of your data is wrong or out of date, you can ask us to correct it.
- Deletion. You can ask us to delete your data. We'll do so unless we're legally required to keep it (see section 5).
- Restriction. You can ask us to stop using your data for a specific purpose while we sort out a query.
- Portability. You can ask us to send your data to you (or another provider) in a common machine-readable format.
- Objection. You can object to us using your data on the basis of legitimate interest. If you object, we'll stop unless we have a compelling reason to continue.
- Withdraw consent. Where we rely on your consent (like the newsletter or analytics cookies), you can withdraw it at any time. Withdrawing consent doesn't affect anything we already did lawfully before you withdrew it.
- Complain to the ICO. You always have the right to complain to the Information Commissioner's Office (see section 12), though we'd appreciate the chance to sort things out first.
To exercise any of these rights, email us at info@therealdebtguy.com. We might ask for proof of identity before acting, to make sure we're not giving your data to someone impersonating you.
Cookies.
We use a small number of cookies. Some are essential to make the site work; others help us understand how the site is used. You choose which non-essential cookies to allow via the banner on your first visit.
- Essential cookies. Needed for the site to work (e.g. remembering your cookie choice, keeping form sessions alive). Always on.
- Analytics cookies. Google Analytics 4 with IP anonymisation. Only set if you accept them.
- Third-party cookies. Set by Stripe when you check out and by Tally when you use a form. These are needed for the payment or form to function.
You can change your cookie preferences any time by clearing your browser cookies for this site, which will re-trigger the banner on your next visit.
How we keep your data safe.
We take security seriously. Practical steps we take:
- All traffic to and from therealdebtguy.com is encrypted with HTTPS (TLS).
- All third-party providers listed in section 4 are established services with their own security certifications (SOC 2, ISO 27001, or equivalent).
- Access to your data inside our business is limited to the people who need it to deliver a service you've paid for.
- Passwords for our provider accounts are unique, strong, and stored in a password manager. Two-factor authentication is on wherever it's offered.
- Letter Audit uploads are stored in Tally's secure infrastructure and downloaded only when needed to prepare a report.
No system is 100% secure. If we ever have a data breach that's likely to result in a risk to your rights and freedoms, we'll notify the ICO within 72 hours and let you know directly without undue delay, as required by law.
International data transfers.
Some of our providers (Vercel, Stripe, Mailchimp, Calendly, Zoom, Facebook/Meta, and Google) are based outside the UK or transfer data internationally. Where we transfer your data outside the UK, we rely on one of the following safeguards, as required by UK GDPR:
- The UK's data bridge with the country (e.g. the UK Extension to the EU-US Data Privacy Framework, for certified US providers).
- UK International Data Transfer Agreements or the EU Standard Contractual Clauses with the UK Addendum, where the provider is not covered by a data bridge.
If you'd like specifics on the safeguard we rely on for any particular provider, email us at info@therealdebtguy.com and we'll share the details.
Children.
Our services are for adults. We don't knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please email us and we'll delete it.
Changes to this policy.
We may update this policy from time to time, for example, when we change or add a service, or when data protection law changes. When we do, we'll update the "last updated" date at the top of this page.
For material changes that affect your rights or how we use your data, we'll let you know directly (by email if you're a subscriber or customer) before the changes take effect.
Complaints.
If you're unhappy with how we've handled your data, please contact us first at info@therealdebtguy.com and give us a chance to put it right.
You also have the right to complain directly to the Information Commissioner's Office (the UK's data protection regulator) at any time:
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Contact us.
Questions about this policy, or about your data? Get in touch and we'll come back to you.
The Real Debt Guy
Mm Corp Limited (company number 09564956)
PO Box 480, Sevenoaks, TN13 9JY
Email: info@therealdebtguy.com
ICO registration: ZB169848