Briefings

Ideas on reputation, intelligence and the businesses built on a good name.

Ideas, stories, and things worth thinking about.

Latest
← All briefingsWe Are Now ICO Registered, and Here Is How to Check Any Supplier Yourself
1 October 2026

We Are Now ICO Registered, and Here Is How to Check Any Supplier Yourself

The moment a customer scans a QR code in your salon or your garage, their details land somewhere. A name, an email address, sometimes a phone number. They came to you, they trusted you, and now that information is sitting in a piece of software that you chose.

That is a real responsibility and it is worth taking seriously. So here is some news, followed by something more useful than the news.

Reputcon Ltd is registered with the Information Commissioner's Office as a data controller. Registration number ZC262238, registered on the 29th of September 2026. Anyone can look it up on the ICO's public register at ico.org.uk/ESDWebPages/Entry/ZC262238.

What ICO registration actually means

It means we have registered with the ICO and paid the data protection fee. That is all it means, and we want to be precise about it, because this is an area where people overclaim.

The ICO has not approved Reputcon. It has not certified, audited, endorsed or vetted us. There is no inspection involved. Registration is a legal requirement for organisations handling personal data in the UK, and meeting it puts you on a public list that anybody can search.

That sounds modest, and it is. But a supplier who has not done it has skipped a basic legal step, and that tells you something worth knowing before you hand them your customers' details.

We handle personal data in line with UK GDPR and the Data Protection Act 2018.

How to check any supplier in about a minute

This is the genuinely useful part, and it applies whether or not you ever use Reputcon. Any software you already use that holds customer data can be checked the same way.

Go to ico.org.uk and find the register of data protection fee payers. Search the company's name. You will get the registered organisation, its registration number, its registered address and the date the registration took effect.

Three things are worth looking at while you are there. First, whether they appear at all. Second, whether the registered address matches the company you think you are dealing with. Third, whether the registration is current rather than lapsed.

It takes a minute and most business owners have never done it for a single one of their suppliers. If you only ever do it once, do it for whatever holds your customer list.

While you are checking, it is also worth looking up the company itself at Companies House. Ours is registered in England and Wales, company number 17486849, registered office at DeskLodge Beacon Tower, Colston Street, Bristol BS1 4XE.

Who is responsible for what

This part confuses people and it matters, so plainly.

Under our Terms, the business stays in control of its customers' data. In the language of the regulations, you are the controller. We act on your instructions, which makes us the processor. The sub-processors we rely on are listed in our Privacy Policy.

In practice that means the relationship with your customers remains yours. We do not get to decide what happens with their information. You do, and we do what you have asked us to do with it.

Your own obligations as a controller are worth checking rather than assuming, and the ICO's own guidance at ico.org.uk is written for small businesses and is clearer than most things in this area. We are not in a position to give you legal advice about your situation.

How the data is actually held

Everything a business stores with us is encrypted using AES-256, specifically AES-256-GCM. That is the same grade of encryption banks use to secure accounts and intelligence agencies use to protect classified material.

It covers the connections and API keys a business sets up, and it covers their customers' names, email addresses and phone numbers. Each one is encrypted and sealed to that business's account alone.

The master key is held separately from the database. The practical consequence is the point: if somebody obtained a complete copy of the database, it would be unreadable to them. The data and the means of reading it do not sit in the same place.

And when our team needs to open a client's data in order to help them with something, it requires two-step verification and it is recorded. Access is not a thing that quietly happens.

Why we are writing about this before launch

Reputcon has not launched yet. It opens soon, and we have not held a single customer's data in anger.

That is exactly why this is the right moment to say it. Security and data handling decisions made after launch are patches. Made before, they are architecture. We would rather be clear about what we have built while nobody is depending on it than reassure people afterwards.

There is also a consistency point. We are building a system that watches a business's reputation. It would be a poor look to be careless with the thing that most quickly destroys one.

The full detail, including the encryption and access arrangements, is on our security page at reputcon.com/security. The waitlist is on the same site.

Reputcon is opening soon.
Reputation and business intelligence on one timeline, built for businesses that live on their name. Join the waitlist and you will be in ahead of general release.
Join the waitlist