Legal
Privacy Policy
Last updated 4 September 2026
This policy explains what personal data Covered collects, why, and what you can do about it. We've tried to keep it plain and honest.
Who we are
Nexium Web Development ("Nexium", "we", "us") operates Covered (coveredhq.co.uk), an operations and scheduling app for hospitality. We are the data controller for your account and website data. When your venue adds its own staff's details, your venue is the controller of that staff data and Covered acts as your processor — handling it on your instructions. Questions? Email [email protected].
What we collect
- Account details — your name, email, venue name, and a securely hashed password.
- Data you enter — staff names, roles, contact details, contracted hours, availability, rotas, temperature logs, allergen records, checklists and incident notes.
- Payment data — handled entirely by Stripe. We never see or store your card number, only your subscription status and a Stripe customer reference.
- Technical data — your IP address, browser type, and a single essential cookie that keeps you signed in.
- Waitlist — if you join our early-access list, your email address.
How we use it
To provide and run the service, sign you in, take payment, respond to you, keep the service secure, and improve Covered. Our legal bases are: performing our contract with you, our legitimate interests in running and securing the service, your consent (for example, the waitlist), and our legal obligations.
The AI rota feature
When you use "Ask Covered" to build a rota from a plain-English instruction, that instruction and your team's first names are sent to our AI provider (Cloudflare Workers AI, or Anthropic where enabled) to interpret it. This data is not used to train their models.
Who we share it with
We use a small number of trusted processors to run Covered:
- Cloudflare — hosting, database and AI.
- Stripe — payment processing.
- Anthropic — optional AI rota interpretation.
We do not sell your data — ever.
Cookies
Covered uses a single essential cookie to keep you logged in. There are no advertising or tracking cookies.
Security & retention
Passwords are hashed and never stored in plain text, data is sent over HTTPS, and access is restricted. We keep your data while your account is active. If you close your account, we delete or anonymise your data within a reasonable period, except where we must keep records (for example, for tax).
Your rights
Under UK data protection law you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. To exercise any of these, email [email protected]. You can also complain to the Information Commissioner's Office (ico.org.uk).
International transfers
Our infrastructure is UK/EU-based where possible. Some processors (such as Stripe) may process data outside the UK under appropriate safeguards.
Changes
If we change this policy, we'll post the update here and revise the date above.