EFEngineers Framework
Home About Pricing Open the Tracker →
Legal

Privacy Policy

Last updated: [DATE] · Template — see notice below
Before you publish this page: this is a standard SaaS legal template, not legal advice, and it has not been reviewed by a solicitor. Replace every bracketed placeholder with your real details, and have a qualified solicitor review this document — particularly the liability and indemnity clauses — before relying on it for a live commercial product, especially one handling construction H&S and CDM data.

This Privacy Policy explains how [Company name / trading name] ("we", "us") collects, uses, and protects personal data when you use the Engineers Framework Design Delivery Tracker (the "Service"). We are the data controller for the personal data described below. Our contact details are at the end of this policy.

1. What data we collect

Account data

  • Name, email address, role, and company, provided when you create an account or are invited to one.
  • A hashed password (we never store your password in readable form).

Project data

Data you or your organisation enter into the Service — deliverable logs, risk registers, hazard logs, fee records, change control records, decision logs, and audit records. This may include personal data about third parties (for example, named individuals in an "Owner" or "Issued to" field) that you or your colleagues enter. You are responsible for having a lawful basis to enter personal data about others into the Service.

Technical data

  • A session cookie used to keep you signed in (see our Cookie Policy).
  • Standard server logs (IP address, browser type, request timestamps) kept for security and troubleshooting.

Payment data

If you subscribe to a paid plan, payment is processed by our payment provider, Stripe. We do not store your full card details ourselves — see Stripe's privacy policy.

2. How we use your data

  • To provide and operate the Service, including authentication and access control.
  • To communicate with you about your account, including invitations and service notices.
  • To process payments for paid plans.
  • To maintain security, prevent misuse, and comply with legal obligations.
  • To improve the Service, using aggregated or anonymised data where possible.

3. Lawful basis (UK GDPR)

We process account and project data under the following lawful bases: performance of a contract (to provide the Service you've signed up for), legitimate interests (security, service improvement, and communicating essential service information), and, for payment data, compliance with legal obligations. Where you enter personal data about third parties into project registers, you (or your organisation) act as the data controller for that data, and we act as a data processor on your behalf.

4. Who we share data with

We do not sell personal data. We share data with:

  • Stripe — payment processing, if you are on a paid plan.
  • Resend (or another email provider) — sending invitation and account emails, if configured.
  • Other members of your own organisation and project, according to the access controls your organisation's administrators configure within the Service.
  • Law enforcement or regulators, where we are legally required to.

5. International transfers

[If self-hosted in the UK/EU: Data is hosted in the United Kingdom / European Economic Area and is not transferred outside it. / If using third-party US-based processors: Some processors (e.g. Stripe) may transfer data outside the UK; where they do, we rely on their standard contractual clauses or equivalent safeguards.] — confirm and edit this section to match your actual hosting and processor setup.

6. Data retention

We retain account and project data for as long as your account is active, plus a reasonable period afterwards to allow for data export and to meet legal retention obligations, after which it is deleted or anonymised. Audit trail records are retained for the life of the project, reflecting the record-keeping purpose of a controlled document system.

7. Your rights

Under UK GDPR, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion, in certain circumstances; object to or restrict certain processing; request a copy of your data in a portable format; and complain to the Information Commissioner's Office (ICO) at ico.org.uk. To exercise these rights, contact us at [contact email]. Where personal data was entered by your organisation into project registers, some requests may need to be directed to your organisation as the data controller for that data.

8. Security

We use industry-standard measures to protect data, including encrypted connections (TLS), hashed passwords, and access controls scoped to organisations and projects. No system is completely secure; we cannot guarantee absolute security.

9. Children

The Service is intended for business use by adults. We do not knowingly collect data from children.

10. Changes to this policy

We may update this policy from time to time. We will post the updated version here with a new "last updated" date.

11. Contact and complaints

Data controller: [Company name / trading name], [registered address]. Contact: [contact email]. You can also complain to the ICO, the UK's data protection regulator.

Engineers Framework

Design delivery tracking, built for consultancy design delivery teams.

Product

Overview Pricing Open the tracker

Company

About Contact

Legal

Terms of Service Privacy Policy Cookie Policy
© Engineers Framework. All rights reserved. Registered in England & Wales · [Company number] · [Registered address]