What ZC243713 actually is
Under the Data Protection (Charges and Information) Regulations 2018, almost every UK organisation that uses personal information has to pay a data protection fee to the Information Commissioner's Office and appear on its public register of fee payers. ZC243713 is the reference the ICO issued to Youzse Ltd when we did that.
Every ICO registration number begins with a Z. It identifies one organisation's entry on one public register, and that entry names the organisation, its address, the tier of fee it pays and the dates its registration runs between. Anyone can look it up without an account, without asking us and without telling us they did.
That is the whole point of a public register. A supplier can claim anything on its own website. A register entry is held by the regulator, not by us, and it either says what we say it says or it does not.
How to check it for yourself
Do not take this page's word for it. The check takes about thirty seconds and you should run it on every supplier who holds data for you, not only on us.
- 1
Open the register entry
Go straight to the entry for ZC243713, or search the ICO register of fee payers for "Youzse". Both routes land on the same record.
- 2
Check the name and the address
The entry should read Youzse Ltd at 66 Paul Street, London EC2A 4NA. A number that resolves to a different organisation is a number that belongs to somebody else.
- 3
Check the registration is in date
ICO registration runs for twelve months and has to be renewed. The entry shows the start and end dates. An expired registration is not a registration.
- 4
Check the tier makes sense
The tier is set by staff numbers and turnover, not by how much data an organisation holds. A very small company on a very large tier, or the reverse, is worth a question.
If anything on the register entry disagrees with anything on this page, the register is right and we have made a mistake. Tell us and we will fix the page.
What registration means, and what it does not
ICO registration is routinely oversold. It is a legal obligation that comes with a fee and a form, and meeting it is the floor rather than the ceiling. Here is the honest split.
What it does mean
- Youzse Ltd has declared to the UK's data protection regulator who we are, where we are and that we process personal data.
- We have paid the statutory data protection fee for our tier and we are listed on a register anybody can search.
- The ICO knows where to find us, which matters if somebody ever complains about how we have handled their data.
- Failing to register when you should is itself an offence the ICO can fine an organisation for. Being registered removes that exposure.
- It is a public, dated, third-party record that Youzse Ltd is a real organisation taking a real legal duty seriously.
What it does not mean
- It is not approval. The ICO does not approve, endorse or recommend any organisation, and any supplier telling you they are "ICO approved" is telling you something that does not exist.
- It is not certification. Nothing about our systems has been certified by the ICO, and registration is not ISO 27001, Cyber Essentials or SOC 2.
- It is not an audit. Nobody from the ICO has inspected our code, our database or our security controls in order to issue this number.
- It does not cover your business. Our registration covers Youzse Ltd only. If your business holds customer records, you almost certainly need your own.
- It does not, on its own, make anybody UK GDPR compliant. Registration is one duty among many, and the rest of them are ongoing.
Who controls what
Most of the confusion about data protection in software like this comes from one question: when a client books an appointment with your business through Youzse, whose data is it? The answer decides who is responsible for what, and it is not the same answer for every record on the platform.
Your business is the controller of your clients' data. You decide who your clients are, what you record about them and how long you keep it. Youzse processes that data on your instructions, under a data processing agreement you accept when you sign up. We are the controller only of the data we hold about you, as our own customer.
That split is not a technicality we can waive. It is why your clients' records live in a database isolated to your business, why we will not use them to market to anyone, and why a data subject request about your client is yours to answer with our tooling rather than ours to answer instead of you.
Youzse Ltd
ControllerData about our own customers: the business owners and staff who hold a Youzse account, their billing records and their support history.
Youzse Ltd
ProcessorData about your clients, held and processed on your instructions under the data processing agreement you accept at signup.
Your business
ControllerYour own clients: who they are, what you record about them, how long you keep it and what you use it for. This is why you need your own ICO registration.
Does your business need its own ICO registration?
Very probably yes. If you are a salon, barber, garage, groomer, trainer or trade holding client names, phone numbers, appointment histories or vehicle records, you are processing personal data and the fee applies to you. It applies to sole traders too, which is the part most people are surprised by.
Your fee tier is decided by staff numbers and annual turnover, not by how much data you hold, so most independent businesses land in Tier 1. Registering is done directly with the ICO, takes a few minutes and cannot be done for you by a supplier: the register entry has to be in your own organisation's name.
The figures below are the ICO's own, read from their published guide on the date shown. Use their self assessment rather than this page to decide your tier, because they set it and we do not.
Tier 1
£52a yearMicro organisations: no more than 10 members of staff, or a maximum turnover of £632,000. Most independent salons, barbers, garages and sole traders sit here.
Tier 2
£78a yearSmall and medium organisations: no more than 250 members of staff, or a maximum turnover of £36 million.
Tier 3
£3,763a yearLarge organisations that meet neither the Tier 1 nor the Tier 2 criteria.
Paying by direct debit takes £5 off whichever tier applies. Figures published by the ICO and read from their guide on 16 September 2026. Check the current figures before you pay.
Run the ICO fee self assessmentBeing listed on Youzse does not register you with the ICO, and our registration number is not one you can quote as your own. If in doubt, run the ICO's self assessment: it is free and it takes about two minutes.
What we do because we are registered
Paying a fee is the easy part. The duties the registration signs us up to are the ones that show up in the product, and all of the following is built into the platform rather than written into a policy and left there.
A record of processing activities
Article 30 of UK GDPR requires a written record of what personal data is processed and why. Youzse maintains one for its own controller activities and gives every business on the platform the tooling to maintain theirs.
A data processing agreement with every business
Every business accepts a DPA before processing begins, and re-accepts it when the terms change. It sets out what we may do with your clients' data, which is considerably less than what you may do with it.
A published subprocessor register
All 5 third parties that touch personal data are listed publicly with what each one processes, where it is located and the safeguards in place. Nothing is added quietly.
Data subject requests with a tracked deadline
Access, erasure, portability and restriction requests are recorded with a 30 day deadline, reminders as it approaches, and a completion certificate when the work is done.
Consent recorded, never inferred
Where consent is the lawful basis, the exact wording shown, the time and the IP address are stored. No record means no consent, and consent checkboxes are never pre-ticked.
Special category data encrypted and access-logged
Health notes, images and anything else falling under Article 9 are encrypted at rest, excluded from bulk exports by default, and every read is written to an access log.
Retention enforced by a nightly job
Every category of data has a retention window, defaulting to the UK norms and adjustable per business. A scheduled job enforces them rather than leaving the policy to be honoured by hand.
Erasure that actually erases
The right to erasure runs a proper workflow: personal fields anonymised, encryption keys destroyed, audit entries pseudonymised, financial records kept but stripped of identifiers, and a deletion certificate issued.
One isolated database per business
Your clients live in a database of your own rather than in a shared table behind a tenant column, which removes the single largest cause of cross-customer data leaks in multi-tenant software.
A breach process with the clock built in
Security incidents are raised, scoped and assessed inside the platform, with a pre-formatted ICO report and a 72 hour notification deadline attached to each one.
Your rights, and the clock on them
UK GDPR gives every individual a set of rights over their own data. They apply whether you are a business using Youzse or a client who booked through it, and they are free to exercise. Responses are due within one calendar month of the request, and the platform puts a 30 day deadline on every request it records so nothing quietly runs past it.
Right of access
One calendar monthAsk for a copy of all the personal data held about you, and be told what it is used for and who it has been shared with.
Right to rectification
One calendar monthHave inaccurate personal data corrected, and incomplete data completed.
Right to erasure
One calendar monthHave your personal data deleted, except where a legal obligation such as HMRC record keeping requires a financial record to be retained without its identifiers.
Right to data portability
One calendar monthReceive the data you provided in a structured, machine-readable format you can take to another provider.
Right to restrict processing
One calendar monthHave processing paused while a dispute about accuracy or lawful basis is resolved. The data is stored but not used.
Right to object
One calendar monthObject to processing carried out under legitimate interests, and object to direct marketing at any time with no exceptions.
Rights around automated decisions
One calendar monthNot be subject to a decision based solely on automated processing where it has a legal or similarly significant effect on you.
Right to withdraw consent
ImmediateWithdraw consent as easily as it was given, wherever consent was the lawful basis for the processing.
If something goes wrong
A personal data breach that is likely to result in a risk to people's rights has to be reported to the ICO within 72 hours of us becoming aware of it. Where the risk is high, the affected individuals have to be told directly as well.
We log security incidents against the affected businesses in the platform, assess what data and how many people were involved, and notify affected businesses within 24 hours of confirming an incident. A pre-formatted ICO report is populated from the incident record so the 72 hour clock is not spent writing prose.
We would rather say this plainly than imply it will never happen. Every platform that says a breach is impossible is a platform that has not thought about it.
Raising a concern
If you are unhappy with how Youzse has handled your personal data, tell us first. We would rather fix it than have you find out from a regulator that we should have. Email the data protection contact on this page and we will respond.
You do not have to come to us first, and you never lose the right to go elsewhere. You can complain to the Information Commissioner's Office directly at any time, free of charge, and doing so costs you nothing and does not affect your account.
If your concern is about a business you booked with rather than about Youzse, that business is the controller of your data and your complaint goes to them, then to the ICO. We will help you reach them either way.
Youzse data protection contact
[email protected]Information Commissioner's Office
Helpline 0303 123 1113. Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
Make a complaint to the ICOWhere the detail lives
- UK GDPRLawful bases, retention, security measures and how data subject requests are handled end to end.
- Privacy PolicyWhat we collect, why we collect it, how long we keep it and who it is shared with.
- SubprocessorsEvery third party that touches personal data, what it processes and where it is located.
- Cookie PolicyThe cookies we set, what each one does, how long it lasts and how to change your consent.
- Data portability requestGenerate a request asking any platform for your own booking data under UK GDPR.
- About YouzseWho runs Youzse, where it is based and the company details behind the registration.
Compliance built in, not bolted on
Consent records, retention rules, data subject requests and an isolated database per business come with every plan. There is no compliance tier and nothing here costs extra.