This Privacy Policy explains how [Company name / trading name] ("we", "us") collects, uses, and protects personal data when you use the Engineers Framework Design Delivery Tracker (the "Service"). We are the data controller for the personal data described below. Our contact details are at the end of this policy.
Data you or your organisation enter into the Service — deliverable logs, risk registers, hazard logs, fee records, change control records, decision logs, and audit records. This may include personal data about third parties (for example, named individuals in an "Owner" or "Issued to" field) that you or your colleagues enter. You are responsible for having a lawful basis to enter personal data about others into the Service.
If you subscribe to a paid plan, payment is processed by our payment provider, Stripe. We do not store your full card details ourselves — see Stripe's privacy policy.
We process account and project data under the following lawful bases: performance of a contract (to provide the Service you've signed up for), legitimate interests (security, service improvement, and communicating essential service information), and, for payment data, compliance with legal obligations. Where you enter personal data about third parties into project registers, you (or your organisation) act as the data controller for that data, and we act as a data processor on your behalf.
We do not sell personal data. We share data with:
[If self-hosted in the UK/EU: Data is hosted in the United Kingdom / European Economic Area and is not transferred outside it. / If using third-party US-based processors: Some processors (e.g. Stripe) may transfer data outside the UK; where they do, we rely on their standard contractual clauses or equivalent safeguards.] — confirm and edit this section to match your actual hosting and processor setup.
We retain account and project data for as long as your account is active, plus a reasonable period afterwards to allow for data export and to meet legal retention obligations, after which it is deleted or anonymised. Audit trail records are retained for the life of the project, reflecting the record-keeping purpose of a controlled document system.
Under UK GDPR, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion, in certain circumstances; object to or restrict certain processing; request a copy of your data in a portable format; and complain to the Information Commissioner's Office (ICO) at ico.org.uk. To exercise these rights, contact us at [contact email]. Where personal data was entered by your organisation into project registers, some requests may need to be directed to your organisation as the data controller for that data.
We use industry-standard measures to protect data, including encrypted connections (TLS), hashed passwords, and access controls scoped to organisations and projects. No system is completely secure; we cannot guarantee absolute security.
The Service is intended for business use by adults. We do not knowingly collect data from children.
We may update this policy from time to time. We will post the updated version here with a new "last updated" date.
Data controller: [Company name / trading name], [registered address]. Contact: [contact email]. You can also complain to the ICO, the UK's data protection regulator.