Funeral OS · Last updated 19 July 2026
Privacy notice
This notice explains how personal information is used when people visit, trial, administer or receive support for Funeral OS. Customer organisations remain responsible for the funeral and workforce records they enter.
1. Who is responsible
Funeral OS is the service name. For website, account, trial, billing and support information, the controller is the legal supplier identified in the applicable order form or subscription confirmation. Contact the privacy lead at privacy@funeralassistance.uk.
For case, family, deceased-person, employee and supplier information entered by a Customer, that Customer is normally the controller and the Supplier acts as its processor. Questions about those records should first be directed to the relevant funeral organisation.
2. Information we handle
- identity and contact details for account users, trial contacts and support correspondents;
- organisation, role, subscription, billing and account-administration details;
- authentication, session, device, IP, browser, security and audit information;
- support requests, feedback and service communications;
- locally stored trial and draft information on the user’s device;
- Customer Data submitted to provide the service, which may include funeral-case, family, workforce, location, financial and special-category information.
3. Purposes and lawful bases
| Purpose | Usual basis |
|---|---|
| Provide accounts, trials, subscriptions and support | Contract or steps requested before contract |
| Secure, troubleshoot and prevent misuse | Legitimate interests and legal obligations |
| Billing, tax and business records | Contract and legal obligations |
| Service notices and requested communications | Contract or legitimate interests |
| Process Customer Data | Customer’s documented instructions as processor |
We do not currently use account or case data for behavioural advertising. We do not make solely automated decisions about people that produce legal or similarly significant effects.
4. Special-category and deceased-person information
Funeral work can involve health, religious, biometric or other sensitive information. Customers must collect only what is necessary and configure access carefully. The Supplier processes it only on documented instructions and does not determine the Customer’s Article 9 condition. UK GDPR does not apply to information about a deceased person as such, but records may identify or reveal sensitive information about living relatives and staff and must still be protected.
5. Sharing and processors
Information may be shared with vetted hosting, database, email-delivery, mapping, support and professional-service providers; with a Customer’s authorised users and integrations; during a genuine business transaction; or where law, regulators, courts, safety or legal claims require it. Providers receive only what they need and are bound by appropriate terms. A current subprocessor list and change-notification process must be supplied to contracted Customers.
6. International transfers
Where a provider processes personal information outside the UK, the Supplier will use a lawful transfer mechanism such as UK adequacy regulations or the UK International Data Transfer Agreement/Addendum, with supplementary safeguards where required. Contracted Customers may request relevant transfer information.
7. Retention
Account and Customer Data is kept only for the subscription, support and agreed exit period, then deleted or anonymised unless law or a dispute requires longer. Security logs are retained for a limited period proportionate to investigation needs. Billing and tax records may be retained for the statutory period. Trial data stored only in the browser is designed to expire after seven days and can be cleared by the user; server-side verification and claim records follow the documented trial-retention schedule.
8. Security
Measures include access controls, tenant scoping, secure session cookies, CSRF protection, audit records, encryption in transit, provider controls, backups and tested development practices. No system is risk-free. Customers must manage users, devices and exports appropriately and promptly report suspected incidents.
9. Your rights
Depending on the circumstances, people may have rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent where consent is used. To exercise rights for Supplier-controlled data, email privacy@funeralassistance.uk. Identity may need to be verified. Requests about Customer Data will normally be referred to or handled with the relevant Customer.
10. Complaints and updates
Please contact the privacy lead first so the issue can be investigated. You may also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint. This notice is reviewed when processing, providers or law changes. Material changes will be brought to affected users’ attention.