Privacy Policy
Last updated: 16 August 2026.
Who we are
Lili Pod (operated by Lili Pod Ltd, company number 17335620, registered office 153 Christchurch Road, Ringwood, BH24 3AL, England) provides a booking, scheduling and HR platform to UK training providers and similar businesses. This policy explains how we handle personal data as both a data controller (for our own website visitors and business customers' accounts) and a data processor (for the booking, HR and customer data a business processes using our platform, on that business's own instructions).
If you're a customer of one of our business users — for example, you booked a course through a business's Lili Pod booking page — that business is the controller of your data, and this policy sits alongside their own privacy notice. You can still contact us directly using the details below.
Data we collect
On this marketing website:
- Anything you submit through a contact or demo-booking form (name, email, business name, and your message).
- We do not run analytics, advertising or tracking cookies on this site. See Cookies and site storage below for the full list of what is stored.
Through the Lili Pod app, once a business signs up:
- Account and staff details: name, email, phone number, role.
- Booking data: what a business's customers book, when, and any notes taken about the booking.
- Payment references processed via the business's own connected Stripe account — we never see or store full card numbers.
- Where a business switches on HR: employment records, leave and sickness records, and whether a staff member holds a DBS check plus its renewal date. We do not store DBS certificate numbers or the contents of DBS certificates.
- Documents and certificates a business or its staff choose to upload.
- Messages sent to "Lily," our in-app assistant, when a business chooses to use it.
Why we process it, and on what basis
- Performance of a contract — running the booking platform a business has subscribed to, including taking bookings, payments and sending confirmations.
- Legal obligation — keeping the financial records HMRC requires, and (for businesses using HR) records tied to statutory employment duties.
- Legitimate interests — keeping the platform secure, responding to support requests, and improving the product, balanced against your rights.
- Consent — where a business opts in to something optional, like the Lily assistant or marketing communications from us.
Special category data (health information in sickness records) and DBS-related data (limited to whether a check is held, its level, and when it's due for renewal — never certificate numbers) are only processed where a business switches on HR features, on that business's own lawful basis as data controller for its staff.
Who we share it with
We use a small number of specialist providers to run the Services, each acting as our sub-processor under their own data protection agreement with us:
- Supabase — database, authentication and file storage.
- Cloudflare — application hosting and content delivery.
- Stripe — payment processing, via each business's own connected account.
- Resend — delivery of transactional emails (confirmations, reminders).
- Anthropic and OpenAI — generate replies from the optional "Lily" assistant, only for businesses that choose to use it, and never for HR special-category data.
We do not sell personal data, and we do not share it with anyone for their own marketing purposes. Where a sub-processor is based outside the UK/EEA, we put an appropriate legal safeguard in place (such as the UK's International Data Transfer Addendum or Standard Contractual Clauses) before any data is transferred.
How long we keep it
As a rule, we keep account and booking data for as long as a business's Lili Pod subscription is active, plus what the law separately requires afterwards — for example, financial records relevant to HMRC generally need to be kept for a minimum of six years. If a subscription lapses, the account is not deleted straight away: it enters a grace period in which everything is retained and the business keeps access, we may lock it more fully after 30 days, and we may delete it and the data in it after 90 days. We contact the business before deletion, and their data can be exported or returned at any point beforehand. Financial records are retained for their statutory period regardless of whether the account is deleted. Loyalty reward codes are held for as long as the issuing business's account is active and are deleted with it. DBS-related records are limited to check status and renewal dates — we never hold certificate numbers — and are deleted with the rest of a staff member's HR record when it goes. We're finalising a fuller, per-category retention schedule; this policy will be updated once that work is complete, and a business can always ask us to delete data sooner using the rights below.
Data security
Personal data is encrypted in transit and at rest by our infrastructure providers, and kept isolated between businesses so one business can never see another's data. Access inside a business's own account is role-based — for instance, HR records are only visible to the people a business has specifically granted that permission.
Your rights
Under UK data protection law, you can ask to:
- Access a copy of the personal data we (or a business, as controller) hold about you.
- Correct inaccurate data, or have incomplete data completed.
- Have your data deleted ("the right to be forgotten"), subject to what the law requires us to keep.
- Receive your data in a portable format, or ask us to transfer it elsewhere.
- Object to, or ask us to restrict, certain processing.
If you're a customer of a Lili Pod business, the quickest route is the export/delete tools in your account, or asking that business directly — they hold the data as controller. You can also contact us using the details below, or complain to the UK's Information Commissioner's Office (ico.org.uk) if you're unhappy with how a request was handled.
Children
Lili Pod is intended for use by businesses and their adult staff and customers. Where a business's own services are directed at under-18s (for example, youth training courses), responsibility for any additional safeguards for that data sits with the business as controller.
Changes to this policy
We'll update this page if how we handle data changes, and update the "last updated" date above. Material changes will be flagged to business customers directly.
Contact us
For questions about this policy or our privacy practices, email us at info@lilipod.co.uk, or contact us via the form on our website.