About Datavacy

Built by someone who's
been on your side of the desk

Datavacy was built from first-hand conversations with small businesses struggling to navigate GDPR without expensive consultants, complicated systems or legal jargon. Here's why I decided to build something different.

✓ Founded in Oxford, UK
✓ Solo-built, solo-run
✓ ICO Registered ZC137164
The Story
Why I built Datavacy

I'm Leon, sole founder and director of Datavacy. Before this, I spent over a decade in technical support, application support, and functional consultancy, including several years working with Microsoft Dynamics 365.

In August 2025, an old colleague who'd run three care homes for over nine years told me one of them had recently been fined by the ICO after a family member's Subject Access Request turned up missing and inaccurate records. On top of the fine, she'd spent over £1,500 on a solicitor just to review their GDPR paperwork, for a care home already stretched thin looking after residents.

(This is how the situation was described to me personally, and I haven't been able to independently verify the details of the case, but the story stuck with me, and it's what set everything else in motion.)

That conversation sent me down a rabbit hole. Over the following months, I spoke to small business owners across gyms, recruitment agencies, accountants, dental practices, and more care homes. Almost every conversation landed in the same place:

"We know we should sort our GDPR. We just don't know where to start."

Most believed they were too small to be at real risk, or that proper compliance software would be too expensive and complicated for a business their size. But the ICO doesn't scale its expectations down just because your business is small — documenting your data, answering SARs within the statutory timeframe, and reporting a breach within 72 hours apply just the same to a 3-person agency as a global bank.

So I built Datavacy: UK GDPR compliance software designed specifically for small businesses, with no jargon, no enterprise price tag, and no need for a £1,500 solicitor just to find out where you stand.

Datavacy launched commercially in June 2026. It's registered with the ICO, holds a UK trade mark, and every piece of legal content on this site has been reviewed by a solicitor. But underneath all of that, it's still just one person trying to build the thing they wish had existed for that care home. If that's you, I'd love to help.

What I Believe
The principles behind Datavacy
💷

Priced for small business reality

No enterprise sales calls, no "request a quote." Plans start at £29/month because that's what a small business can actually justify spending on compliance.

⚖️

Accuracy over marketing

Every legal claim on this site, from deadlines to thresholds, is checked against the actual UK GDPR text and reviewed by a solicitor before publication.

🗣️

Plain English, always

GDPR is written in legal language. Datavacy translates it into things you actually need to do, without losing the substance underneath.

Want to know more?

Whether you've got a question about Datavacy, a suggestion, or just want to say hello, I'd genuinely like to hear from you.

Security & Trust Centre