NEW FEATURE: Making It Easier for People to Apply for Their Benefits. Learn more.
Part 1 — Who we are, and which part of this policy applies to you
We are Investment Solver Ltd, trading as Inbest.
This policy explains how we handle personal data under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).
Sometimes we run a service ourselves and decide what happens to your information; sometimes we run it for another organisation — a lender, a council, a charity — and they decide, while we act only on their instructions. Which applies depends on how you reached us, and determines whose privacy notice governs your information and who to contact.
| If you… | Then… |
|---|---|
| used a benefits calculator on another organisation’s website or app | that organisation is responsible for your information. See Part 3, and their privacy notice. |
| …and then chose to start an Inbest service from your results — for example a benefit application, or reminders | we are responsible for that service. See Part 2.4 and 2.5. |
| are being helped with a case by an adviser at a council, housing association, charity or other organisation | that organisation is responsible for your case. See Part 3. |
| were sent a link by an adviser to fill in a form or upload documents | the organisation that sent the link is responsible. See Part 3. |
| used the Inbest-branded benefits calculator on our own website | we are responsible. See Part 2.2. |
| are an adviser or other professional with an Inbest login | we are responsible for your account. See Part 2.6. |
| visited inbest.ai, contacted us, or receive marketing from us | we are responsible. See Part 2.1. |
Part 4 applies whichever of these you are.
Throughout this Part we are the data controller; exercise your rights with us (Part 4.5).
Your enquiries, marketing preferences and website visit data (Part 4.7), used to respond to you, send marketing you have agreed to and keep the site secure. Basis: consent (Art. 6(1)(a)); legitimate interest (Art. 6(1)(f)) for business-customer marketing (PECR Reg. 22(3)), service messages, security and analytics. Kept: enquiries 2 years; preferences until you opt out.
The calculator questionnaire is answered anonymously: we do not ask who you are or try to identify you. Your answers are held against a random identifier stored in your browser so you can reopen your results; we do not link it to a person.
Some services on your results page — applying for benefits on your behalf, or sending reminders — cannot work anonymously. If you choose to start one, we tell you what we need and who it goes to before you give it (Parts 2.4 and 2.5). You can use the calculator without them.
Basis: legitimate interest (Art. 6(1)(f)). Kept: anonymous calculation records 12 months from last access.
If you choose to email your results, we use your email address once to send the link and do not store or log it. Basis: consent (Art. 6(1)(a)). Kept: not stored.
Where you ask us to apply on your behalf— we collect your identity, contact and household details and the health, disability and support needs the application covers (special category data), and send them only to the organisations that are responsible for the particular benefit(s), named to you before you agree. Each is independently responsible for your information once sent.
Basis: consent (Art. 6(1)(a)) and, for health data, your explicit consent (Art. 9(2)(a)), given after seeing exactly what will be sent and to whom. If the application covers someone else, you confirm you have their agreement or the authority to act for them. Withdrawing consent (any time) stops anything unsent and deletes our copy; an application a provider already holds is changed or removed with that provider — we will tell you who they are. On a partner-branded calculator we act on the partner’s instructions until you start our service, and tell you when that changes. Kept: application 12 months; consent evidence 12 months.
Where you ask us to, we use your mobile number or email address only to send a link to your results and a small number of reminders. WhatsApp delivery is by Meta Platforms; messages never contain your personal details. Reply STOP or contact us to stop. Basis: consent (Art. 6(1)(a); PECR Reg. 22). Kept: until the reminders end or you opt out, then deleted.
For advisers and professionals using our systems (the people you help: Part 3), we may hold your name, work email, organisation, role, logins, activity and time-tracking logs and support correspondence — to provide, secure, audit and bill the service. Basis: contract (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)). Kept: account records 12 months after closure; audit logs 2 years.
Technical data — IP fragments, device and browser type, error and request logs — keeps all our services secure and working. Basis: legitimate interest (Art. 6(1)(f)). Kept: 12 months, unless needed for an investigation.
Where our agreements with client organisations allow, we may use information from our services in aggregated or anonymised form — from which no individual can be identified — to understand how they are used and to improve them. We do not use identifiable case data for this purpose.
To manage contracts with customers, suppliers and partners we process their representatives’ contact and role details and our communications with them (Art. 6(1)(b), 6(1)(f)); we keep what legal obligations such as accounting rules require (Art. 6(1)(c)) and what is needed to defend legal claims. Kept: 6 years after the contract ends.
This Part covers services we run for another organisation: partner-branded calculators; our case management system, where an adviser at a council, housing association or charity is helping you; forms and document uploads you were sent a link to; and the messages, calls and emails exchanged through them.
That organisation — whose branding was on the page, who sent the link, or who your adviser works for; ask us if unsure — is the data controller. We are its processor: we act only on its documented instructions under a written contract meeting Article 28 UK GDPR, and its privacy notice, not this one, governs your information. Exercise your rights with it; requests sent to us are passed on. The services we use on its behalf are listed in Part 4.1.
We share personal data only where necessary, with: the organisations that decide your application (Part 2.4 — each an independent controller); service providers acting on our instructions under contract (hosting, storage, messaging, AI-assisted processing, monitoring, analytics — listed below); partners you choose to continue to; and professional advisers and authorities where the law requires or allows. We do not sell personal data.
| Provider | What it does for us | Location |
|---|---|---|
| Google Cloud Platform | Hosting and file storage for our services | United Kingdom (London) |
| MongoDB Atlas | Database hosting | United Kingdom (London) |
| Cloudflare | CDN, DNS and traffic security in front of our services | Global network (US) |
| ElevenLabs | Speech-to-text transcription; Text-to-speech | United States |
| OpenAI | AI-assisted processing of service content | United States |
| Anthropic (Claude) | AI-assisted processing of service content | United States |
| Twilio | Telephony, SMS and WhatsApp message delivery | United States |
| Twilio SendGrid | Transactional email delivery | United States |
| Sentry | Error monitoring | United States |
| Meta (WhatsApp Business Platform) | WhatsApp messaging | Ireland / United States |
| Microsoft (Microsoft 365) | Outlook mail and calendar integration for advisers | EU / United Kingdom |
We update this table when providers change, and give client organisations advance notice as set out in our Data Processing Agreement.
Where a provider processes data outside the UK we rely on the UK Extension to the EU–US Data Privacy Framework, the IDTA / UK Addendum to the EU SCCs with a transfer risk assessment, or a UK adequacy regulation — as listed against each provider in the table in 4.1 — and otherwise only on an Article 49 UK GDPR exception such as your explicit consent.
The periods above are our standard retention periods where we are the controller. Where another organisation is the controller (Part 3), its retention periods apply and we delete or return data on its instruction, at the latest when our contract with it ends.
We protect personal data with measures appropriate to its sensitivity: encryption in transit and at rest, role-based access, multi-factor authentication for professional users, audit logging, and the tightest controls on health and other special category data. If a breach affects you, we will tell you and the ICO as the law requires.
We also use automated processing and, in places, AI tools to run and improve our services — for example, estimating your entitlements from the answers you give, or routing an application or message to the right place. Where an AI tool helps produce a record about you, a person reviews it before we rely on it. No decision with legal or similarly significant effects on you is made solely by automated means — benefits and registrations are decided by the organisations that receive your application — and you can ask at any time for a person to review anything we have produced about you.
You may access, correct or erase your data, restrict or object to its use (to direct marketing, at any time), receive it in portable form, withdraw consent (without affecting prior processing), and complain to the ICO (ico.org.uk, 0303 123 1113) — though we would welcome the chance to help first.
Where: Part 2 matters — us, at [email protected]. Part 3 matters — the organisation responsible (we forward requests sent to us). An application a provider already holds — that provider. We respond within one month, extendable by two for complex requests.
Our services are for adults. Anyone providing information about a child or another adult in their household must have the authority to do so. If you believe we hold information about someone without proper authority, contact us.
We use the following cookies and browser storage. Analytics cookies are set only with your consent where the law requires it.
| Purpose | Name | Type | Third-party access | Duration |
|---|---|---|---|---|
| inbest.ai only — distinguishes unique visitors (Google Analytics 4) | _ga | Analytics | 2 years | |
| inbest.ai only — persists session state (Google Analytics 4) | _ga_EXYTCHCYP1 | Analytics | 2 years | |
| Benefits Calculator only — unique visitor ID for aggregate statistics (Matomo) | _pk_id.* | Analytics | No | 1 year |
| Benefits Calculator only — links actions in the same visit (Matomo) | _pk_ses.* | Analytics | as above | 30 minutes |
| Benefits Calculator only — records the referrer (Matomo) | _pk_ref.* | Analytics | as above | 6 months |
| Benefits Calculator only — the random identifier of your calculation, so you can reopen it, and so an Inbest service you start from your results (Parts 2.4, 2.5) can be linked to it | userId (localStorage) | Functional | Shared with our own application service where you start one | Until you clear browser storage or delete the calculation |
| Case management system — keeps you signed in | session / login cookies | Strictly necessary | No | Session |
You can manage cookies through your browser settings.
We update this policy when our services or the law change.