top of page

Privacy Policy

 

This Privacy Policy explains how we collect, use, share and protect personal information when you use recordsarchive.co.uk, order a certificate, scanned copy, legalisation or apostille service from us, or otherwise contact us. It is written to comply with the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.

 

1. Who We Are


​1.1. We are Anextica Ltd, trading as "recordsarchive.co.uk" ("we", "us", "our"), a company registered in England and Wales under company number 17369502, with registered office at Suite A, 82 James Carter Road, Mildenhall, IP28 7DE.
1.2. For the purposes of UK data protection law, we are the "data controller" of the personal data described in this policy. Our contact details are set out in section 13 below.
1.3. If you have appointed a data protection officer or contact, their details (if applicable) will be provided on request.

​

2. The Personal Data We Collect

We may collect and process the following categories of personal data:

2.1. Data about you (the customer)

Identity data: full name, title, date of birth, gender.

Contact data: postal address, delivery address, email address, telephone number.

Account and order data: order history, order reference numbers, service selections, correspondence with us.

Payment data: card type and last four digits, billing address and transaction reference (full card numbers are processed by our payment provider and are not stored on our systems).

Technical data: IP address, browser type and version, device information, and data collected via cookies (see our Cookie Policy).

Identity-verification data: where required for anti-fraud or eligibility purposes, copies of identity documents such as a passport or driving licence.

2.2 Data about a third party named on a document

Because our service involves obtaining official records, the certificate or document you order will usually contain personal data about someone else — for example, the person(s) named on a birth, marriage, death or divorce record. This may include:

Names, dates of birth, dates and places of registration.

Family relationship details (for example, parents' names on a birth certificate, or spouses' names on a marriage or divorce record).

In some cases, information that could reveal special category data, such as details that indirectly suggest health information (for example, cause of death on a death certificate).

Where you order a document relating to someone other than yourself, you confirm to us that you have an appropriate lawful basis (such as their consent, a legitimate family or legal interest, or another lawful entitlement) for requesting that record, and that you will handle any personal data you receive from us in accordance with applicable data protection law.

​

3. How We Collect Your Data

3.1 Directly from you, when you place an order, create an account, contact customer support, or complete a form on the Website.

3.2 Automatically, through cookies and similar technologies when you use the Website (see our separate Cookie Policy).

3.3 From third parties, including government registration authorities, embassies, consulates, the Foreign, Commonwealth & Development Office ("FCDO"), notaries, couriers and payment processors, in the course of fulfilling your order.

​

4. How We Use Your Data and Our Lawful Basis

We only use personal data where we have a lawful basis to do so under UK GDPR. The table below sets out our main purposes and the corresponding lawful basis.

4.1 Performing your order

To search for, obtain, scan, legalise and deliver the certificates or documents you have ordered, and to process payment. Lawful basis: performance of a contract with you (and, where applicable, legitimate interests in fulfilling a request made on behalf of a third party).

4.2 Customer service and communication

To respond to enquiries, process refund requests, and handle complaints. Lawful basis: performance of a contract, and our legitimate interest in resolving issues and maintaining customer relationships.

4.3 Identity verification and fraud prevention

To verify your identity or entitlement to a document, and to detect and prevent fraud or unlawful use of our services. Lawful basis: legal obligation (where applicable, such as under money-laundering or identity-verification requirements for notarial services) and our legitimate interests in preventing fraud.

4.4 Legal and regulatory compliance

To keep records required by law, including financial and anti-fraud records, and to respond to lawful requests from regulators or authorities. Lawful basis: legal obligation.

4.5 Marketing

To send you information about our services that may be of interest, where you have opted in to receive such communications. Lawful basis: consent. You can withdraw consent at any time by using the unsubscribe link in any marketing email or by contacting us.

4.6 Improving our services

To analyse how the Website is used and improve its functionality, content and performance. Lawful basis: legitimate interests.

​

5. Special Category and Sensitive Data

​

5.1 Some documents we source (for example, death certificates, or documents relating to adoption) may contain, or indirectly reveal, special category data such as health-related information. We process such data only to the extent necessary to fulfil your order, on the basis of your explicit consent given when you place the order, or because the processing is necessary for the establishment, exercise or defence of legal claims, or for reasons of substantial public interest in accordance with Article 9 UK GDPR and Schedule 1 of the Data Protection Act 2018.

5.2 We do not use special category data for marketing or profiling purposes.

​

6. Who We Share Your Data With

We share personal data only where necessary to provide our services, and always subject to appropriate safeguards. Recipients may include:

  • UK and overseas government registration authorities (for example, the General Register Office, local register offices, courts, and equivalent overseas bodies) in order to search for and obtain certificates.

  • The FCDO, where you have ordered legalisation or apostille services.

  • Notaries and translation providers, where notarisation or translation forms part of your order.

  • Payment service providers, to process your payment securely.

  • Postal and courier companies, to deliver physical documents to you.

  • IT, hosting and customer-support service providers who process data on our behalf under contract.

  • Professional advisers (such as lawyers, auditors or insurers) and law enforcement or regulatory bodies, where required by law or to protect our legal rights.

  • We do not sell your personal data to third parties.

​

7. International Transfers

7.1 Where your order requires us to contact an overseas registration authority, embassy or consulate (for example, for an overseas birth certificate or a legalisation service in a non-UK jurisdiction), your personal data will necessarily be transferred outside the UK to that body. Such transfers are made on the basis that they are necessary for the performance of the contract between us, at your request.

7.2 Where we use service providers located outside the UK (for example, cloud hosting providers), we ensure appropriate safeguards are in place, such as the UK's International Data Transfer Agreement, an adequacy decision, or equivalent standard contractual clauses recognised under UK data protection law.

 

8. Data Retention

8.1 We retain personal data relating to your order for as long as necessary to fulfil the order, deal with any related complaint, refund or legal claim, and to comply with our legal, tax and accounting obligations (generally up to 6 years from the end of the relevant tax year, unless a longer period is required by law).

8.2 Copies of documents obtained on your behalf, and any related order data, will generally be securely deleted or destroyed no later than 90 days after despatch of your order, unless you have asked us to retain a digital copy for longer, or we are required to keep records for legal or regulatory reasons.

8.3 Identity-verification documents are retained only for as long as necessary for the purpose for which they were collected, and in line with any applicable anti-money-laundering record-keeping requirements.

 

9. How We Protect Your Data

9.1 We use appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction, including encryption of data in transit, access controls, and staff training.

9.2 No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee its absolute security, and use of email to communicate with us is at your own risk.

9.3 In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office and, where required, affected individuals, in accordance with UK GDPR.

​

10. Cookies

10.1 Our Website uses cookies and similar technologies to operate correctly, remember your preferences, and understand how visitors use the site. For full details of the cookies we use and how to manage your preferences, please see our Cookie Policy.

11. Your Rights

Under UK data protection law, you have the following rights in relation to your personal data:

  • Right of access — to obtain a copy of the personal data we hold about you.

  • Right to rectification — to have inaccurate or incomplete data corrected.

  • Right to erasure — to ask us to delete your personal data in certain circumstances.

  • Right to restrict processing — to ask us to limit how we use your data in certain circumstances.

  • Right to data portability — to receive certain data in a structured, commonly used, machine-readable format.

  • Right to object — to object to processing based on legitimate interests or to direct marketing.

  • Rights related to automated decision-making — we do not currently carry out any processing that involves solely automated decision-making, including profiling, which produces legal or similarly significant effects.

11.1 To exercise any of these rights, please contact us using the details in section 13. We may need to verify your identity before responding, and will normally respond within one month.

11.2 Because much of the data we handle relates to official government records, some rights (for example, erasure or rectification of data contained within a certificate itself) may not apply, as we are not able to alter or delete official records held by a third-party government authority; such requests should be directed to the issuing authority.

11.3 You also have the right to lodge a complaint with the UK's data protection regulator, the Information Commissioner's Office (ICO), if you believe we have not handled your personal data properly:

Website: ico.org.uk

Telephone: 0303 123 1113

Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF#

​

12. Children's Data

12.1 Our services are not directed at children, and we do not knowingly collect personal data directly from children. Where a certificate you order (for example, a child's birth certificate) contains personal data about a child, we process that data only as part of fulfilling a lawful order placed by a parent, guardian or other authorised adult, in accordance with this policy.

 

13. How to Contact Us

13.1 If you have any questions about this Privacy Policy or wish to exercise any of your rights, please contact us at privacy@recordsarchive.co.uk or by post at Anextica Ltd, Suite A, 82 James Carter Road, Mildenhall, IP28 7DE.

 

14. Changes to This Policy

14.1 We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The "last updated" date below shows when it was last revised. We encourage you to review this policy periodically.

 

 

Last updated: 04 August 2026

bottom of page