I'm Leon, sole founder and director of Datavacy. Before this, I spent over a decade in technical support, application support, and functional consultancy, including several years working with Microsoft Dynamics 365.
In August 2025, an old colleague who'd run three care homes for over nine years told me one of them had recently been fined by the ICO after a family member's Subject Access Request turned up missing and inaccurate records. On top of the fine, she'd spent over £1,500 on a solicitor just to review their GDPR paperwork, for a care home already stretched thin looking after residents.
(This is how the situation was described to me personally, and I haven't been able to independently verify the details of the case, but the story stuck with me, and it's what set everything else in motion.)
That conversation sent me down a rabbit hole. Over the following months, I spoke to small business owners across gyms, recruitment agencies, accountants, dental practices, and more care homes. Almost every conversation landed in the same place:
Most believed they were too small to be at real risk, or that proper compliance software would be too expensive and complicated for a business their size. But the ICO doesn't scale its expectations down just because your business is small — documenting your data, answering SARs within the statutory timeframe, and reporting a breach within 72 hours apply just the same to a 3-person agency as a global bank.
So I built Datavacy: UK GDPR compliance software designed specifically for small businesses, with no jargon, no enterprise price tag, and no need for a £1,500 solicitor just to find out where you stand.
Datavacy launched commercially in June 2026. It's registered with the ICO, holds a UK trade mark, and every piece of legal content on this site has been reviewed by a solicitor. But underneath all of that, it's still just one person trying to build the thing they wish had existed for that care home. If that's you, I'd love to help.