We use cookies
We use cookies to enhance your experience, maintain your session, and remember your preferences. Some cookies are essential for the platform to function properly. Learn more in our Privacy Policy
Last updated: 8 April 2026
EstateCopilot ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use our estate administration platform. It applies to all users of the platform and to individuals whose data is entered into the platform by others (for example, beneficiaries and co-executors).
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Data (Use and Access) Act 2025 (DUAA). The DUAA received Royal Assent on 19 June 2025 and its principal data protection provisions came into force on 5 February 2026. Where this policy refers to "UK data protection law", it means the UK GDPR as amended by the DUAA, together with the DPA 2018 and any associated regulations including the Privacy and Electronic Communications Regulations 2003 (PECR) as amended.
We are the data controller for the personal data described in this policy. For questions about how we handle your data, contact us at privacy@estatecopilot.co.uk.
This policy applies to three categories of individuals:
If you are a beneficiary or co-executor whose data was entered by an executor, the sections below marked (indirect data subjects) are particularly relevant to you. We are required by Article 14 of the UK GDPR to provide you with this information, which is also delivered when you access an invitation link.
Executors enter the following personal data about beneficiaries and co-executors:
Source of this data: This data is provided to us by the executor administering the estate. If you are a beneficiary or co-executor, your data was not collected from you directly - it was entered by the executor.
We rely on different lawful bases depending on the category of data subject and the purpose of processing:
| Purpose | Lawful Basis |
|---|---|
| Providing the estate administration service | Art 6(1)(b) - performance of a contract |
| Processing payments | Art 6(1)(b) - performance of a contract |
| Security, fraud prevention, and audit logs | Art 6(1)(f) - legitimate interests |
| Financial record-keeping | Art 6(1)(c) - legal obligation |
| Direct marketing and product updates | Art 6(1)(a) - consent (you may withdraw at any time) |
| Platform improvement and analytics | Art 6(1)(f) - legitimate interests |
We process beneficiary and co-executor data under Art 6(1)(f) - legitimate interests. Our legitimate interest is facilitating lawful estate administration, which benefits beneficiaries directly (they have an interest in receiving their entitlement) and co-executors (they have agreed to assist with administration). We have conducted a Legitimate Interests Assessment (LIA) and concluded that this interest is not overridden by your rights and freedoms.
Once a beneficiary or co-executor creates an account and accepts an invitation, subsequent processing of their account data is on the basis of Art 6(1)(b) - performance of a contract.
You have the right to object to processing based on legitimate interests at any time. See Section 7 for how to exercise this right.
The DUAA 2025 introduced a new category called "recognised legitimate interests" — a defined list of processing activities (such as national security, crime detection, and safeguarding of vulnerable individuals) for which the standard balancing test is automatically satisfied. EstateCopilot does not rely on this new basis. All of our processing under Art 6(1)(f) continues to be assessed through the standard three-part legitimate interests test (purpose, necessity, and balancing), as described above.
We implement industry-standard security measures to protect your data:
We have obtained Cyber Essentials certification, meeting all requirements to keep your data safe.
Under UK data protection law, you have the following rights. These apply to all data subjects, including beneficiaries and co-executors whose data was entered by an executor:
To exercise any of these rights, contact us at privacy@estatecopilot.co.uk. We will respond within one month. We may need to verify your identity before acting on a request.
We retain personal data for as long as necessary for the purpose it was collected and to comply with legal obligations:
On expiry of the relevant retention period, data is securely deleted or anonymised.
We use cookies and similar technologies to provide, protect, and improve our services.
Cookies are small text files stored on your device when you visit a website. We also use localStorage, which stores data locally in your browser.
The DUAA 2025 (in force from 5 February 2026) amended PECR to exempt two categories of cookies from the consent requirement: cookies that collect statistical information about how a website is used (analytics), and cookies that adapt a website's appearance or functions based on user preferences (functional/preference cookies). These categories may now be set without prior consent under UK law.
EstateCopilot handles sensitive estate and bereavement data. We therefore continue to offer users a clear choice over analytics cookies as a matter of best practice. Functional cookies — which store only low-risk UI preferences such as sidebar state and theme — are set without a consent requirement in line with the DUAA exemption, since they do not process personal data for tracking or profiling purposes.
These cookies are necessary for the platform to function and cannot be disabled.
| Cookie/Storage | Purpose | Duration | Provider |
|---|---|---|---|
| Supabase Auth Session | Maintains your login session and authenticates requests | Session / 1 hour refresh | Supabase |
| Stripe Cookies | Payment processing, fraud prevention, and security during checkout | Session / Varies | Stripe |
These cookies remember your interface preferences to provide enhanced functionality. Under the DUAA 2025, cookies that adapt a website's appearance or functions based on user preferences do not require consent. These cookies store only UI state (sidebar position, theme, completed tours) and contain no personal data used for tracking or profiling.
| Cookie/Storage | Purpose | Duration | Provider |
|---|---|---|---|
| sidebar:state | Remembers whether your dashboard sidebar is expanded or collapsed | 7 days | EstateCopilot |
| Product Tour Status | Tracks which product tours you have completed to avoid showing them again | Persistent | EstateCopilot |
| cookie-consent-preferences | Stores your cookie preferences so we remember your choices | Persistent | EstateCopilot |
| Theme Preference | Remembers your light/dark mode preference | Persistent | EstateCopilot |
These cookies help us understand how visitors interact with our platform. Under the DUAA 2025, cookies used solely to collect statistical information about website usage do not require consent. However, given the sensitive nature of our platform, we continue to seek your opt-in consent for analytics cookies as a matter of best practice. You can accept or decline analytics cookies via our cookie banner when you first visit the platform.
| Cookie/Storage | Purpose | Duration | Provider |
|---|---|---|---|
| Google Analytics (_ga, _gid) | Anonymised usage statistics to understand how visitors use our platform | Up to 2 years |
Disabling essential cookies may prevent you from using certain features of our platform.
We do not sell your personal data. We share information only with the following parties:
All third-party data processors are bound by Data Processing Agreements and SCCs requiring them to protect your data in accordance with UK GDPR.
Our data processors may transfer and store data outside the UK. Where this occurs, we ensure that the protections afforded to your data are not materially lower than those required under UK data protection law, as required by the DUAA 2025. We apply the ICO's updated three-step transfer assessment (published January 2026) when evaluating restricted transfers, and rely on the following transfer mechanisms:
The EstateCopilot platform is not designed to be accessed directly by individuals under 18. We do not knowingly create accounts for minors.
However, minors are commonly named as beneficiaries in wills. Executors may record a minor beneficiary's name, relationship to the deceased, and financial allocation within the platform. Where a beneficiary is flagged as a minor:
If you are a parent or guardian and believe a minor's data has been incorrectly handled, please contact us at privacy@estatecopilot.co.uk and we will address your concern promptly.
When an executor enters personal data about beneficiaries or co-executors into EstateCopilot, the executor acts as a data controller in their own right for that data. Executors should ensure:
We may update this Privacy Policy periodically. We will notify you of significant changes by:
For privacy-related questions, data subject rights requests, or concerns:
We will acknowledge your request within 5 working days and respond in full within one calendar month (extendable by a further two months for complex requests, with notice).
Formal data protection complaints (from 19 June 2026): Under the DUAA 2025, you will have the right to submit a formal data protection complaint directly to us. We are implementing a dedicated complaints process ahead of this date. From 19 June 2026, complaints submitted to privacy@estatecopilot.co.uk with the subject line "Formal Data Protection Complaint" will be acknowledged within 30 days and responded to without undue delay. This is in addition to — not instead of — your right to complain to the ICO at any time (see Section 16).
If you are not satisfied with how we handle your data or your rights request, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
This Privacy Policy is effective as of 8 April 2026 and applies to all users of the EstateCopilot platform and to individuals whose data is processed by EstateCopilot as described above.