Legal
Privacy Policy
This explains what Lost Properly does with personal data. It covers two quite different situations, and the difference matters, so they are kept apart below.
Last updated 1 September 2026
The short version
- There is no advertising, no analytics, no tracking and no profiling anywhere in this service.
- We never sell personal data, and we never share it for anyone else's marketing.
- The only cookie either site sets is the one that keeps you signed in. See the cookie notice.
- For lost property records inside a school, the school is in charge of the data and we act on their instructions.
1. Who we are
Lost Properly provides lost property software to schools, workplaces and venues. If you want to reach us about anything on this page, or to exercise any right described below, use the contact details we have given you or the address on your invoice or agreement. We will reply to any request about personal data within one month.
Registered company details and our ICO registration number are added here once registration completes. If you need them before then, ask and we will send them.
2. Two roles, kept separate
Data protection law distinguishes between the organisation that decides what happens to personal data (the controller) and one that only acts on instructions (the processor). We are each of these in different circumstances.
This website: we are the controller
If you fill in the demo form on this site, we decide what happens to what you sent, and this policy governs it.
The Lost & Found system: we are the processor
Records inside a school's system belong to that school. They decide what is collected and how long it is kept; we hold and process it under a written agreement, on their instructions, and for nothing else.
3. This website
What we collect
Only what you type into the demo request form:
- Your name
- Your organisation
- Your email address
- Your role, and roughly how many people are on your roll, if you tell us
- Anything you write in the message box
There is no analytics on this site. We do not run advertising pixels, session recording, heatmaps, or any third party tracking. We do not build a profile of you and there is no automated decision making.
Why, and on what legal basis
To reply to you and to arrange a demonstration if you want one. The lawful basis is our legitimate interest in responding to an enquiry that you chose to send us. You can ask us to stop and to delete it at any time, and we will.
How long we keep it
Enquiries are deleted within 24 months, and sooner on request. If you become a customer, the contract record is kept for seven years after it ends, because tax law requires it.
4. The Lost & Found system
When a school or organisation runs Lost Properly, the personal data inside it is theirs. Their own privacy notice governs it and questions from pupils, parents or staff should go to them first. What follows describes the system honestly so that they, and you, can see what it does.
What the system holds
- An account for each person: their name, username, email address and role.
- Reports of lost and found items: a title, description, category, colour, where and when, and any name written on the item.
- Photographs, where somebody chooses to upload one.
- A record of which member of staff reviewed each report and when.
The public display board shows items only. It carries no names, no email addresses and no account details, so it is safe to put on a screen in a corridor.
Children
Most people using the system in a school are children. We have designed it accordingly: there is no profiling, no advertising, no nudge to share more than is needed, and no data used for anything except reuniting somebody with their property. A child's report is visible to them and to the staff who review it, and nobody else.
Where it is held
Each client has their own separate database. By default these run on our hardware in the United Kingdom, reached through Cloudflare, which carries the traffic. Clients who would rather keep their records on their own premises can buy the on-site option, in which case everything except sign-in stays in their building.
Who else is involved
These are the only third parties that touch anything, and only for the purpose given:
| Who | What they do | What they see |
|---|---|---|
| Cloudflare | Carries traffic to the service, and hosts this website | Traffic in transit, and IP addresses |
| Microsoft Entra or Auth0 | Signs people in, where the client uses single sign-on | Sign-in details, held under the client's own arrangement with them |
| Google Fonts | Serves the typefaces the pages use | The IP address of anyone loading a page |
We are removing the Google Fonts dependency by serving the typefaces ourselves, which will take that row off this table entirely. Until it is done, it is listed here rather than left unmentioned.
How long it is kept
The client decides. The system holds property records so that a question months later can still be answered, and each client sets their own retention period in their settings. When a client leaves, we return or delete their data on their instruction. Backups are kept on a rolling cycle of roughly two months, so deletion takes full effect once those have rotated out.
5. Keeping it safe
- Every connection is encrypted in transit.
- Each client's data sits in its own separate database, not in a shared table.
- Passwords are stored hashed with a per-account salt, never in a form we can read.
- Invoices and similar documents are stored outside the web root and served only to the one named person entitled to them.
- Administrative tools are reachable only from our own local network, never from the internet.
- Backups are taken daily and verified by restoring them, not merely written and assumed.
What is not encrypted, so that you are not misled. Traffic is encrypted in transit and passwords are never stored in a readable form. The disk the service runs on is not encrypted at rest, and neither are the backup archives. Access is controlled by the operating system and by physical control of the hardware. Anyone with physical possession of the machine or a backup could read what is on it. We are addressing this, and until we have, it is written here rather than left for somebody to discover.
No system is perfect. If something goes wrong that puts personal data at risk, we will tell the affected client without undue delay and within 24 hours of becoming aware, so they can meet their own 72 hour duty to the Information Commissioner.
6. Your rights
Under UK data protection law you can ask for a copy of your data, ask for it to be corrected or deleted, object to how it is used, or ask for it to be restricted or transferred.
Where to ask matters. If your data is in a school's Lost & Found system, ask the school: it is their record and they decide. They will come to us and we will act on it. If it is an enquiry you sent through this website, ask us directly.
If you are unhappy with how we have handled something you can complain to the Information Commissioner's Office at ico.org.uk, though we would rather you told us first so we can put it right.
7. Changes
If this policy changes in a way that affects you, we will say so rather than quietly editing the page. The date at the top always reflects the current version.