Privacy Notice
1. Information we collect
Depending on the Service, we may process business contact details, organisation and role information, facility and site information, service requests, client declarations, subscription and report records, correspondence, payment/transaction records supplied by payment providers, and technical/security metadata generated when the Service is used.
2. Facility information
Most facility information is business or site data rather than personal data. Where facility information can be linked to an identifiable person, we handle it as personal information where applicable law requires.
3. Why we use information
We use information to evaluate and fulfil requests, establish and administer commercial relationships, generate and deliver reports, maintain monitoring subscriptions, preserve evidence and contractual audit trails, provide support, secure the Service, prevent misuse, comply with law and improve service quality and methodology.
4. Legal bases
Where a legal basis is required, processing may be necessary to take steps requested before entering a contract, perform a contract, comply with legal obligations, pursue legitimate interests in operating and securing a professional risk-intelligence service, or rely on consent where applicable law specifically requires it.
5. Service providers
We use service providers for cloud infrastructure, databases, code deployment, communications and email delivery. Current infrastructure may include Cloudflare, Supabase, GitHub and Resend. Providers act under their own terms and applicable data-protection obligations, and the provider set may change as the Service evolves.
6. International processing
Service providers and data sources may operate in multiple countries. Where applicable law requires safeguards for international transfers, we will use an appropriate lawful transfer mechanism or other permitted safeguard.
7. Data minimisation
Please provide only information reasonably necessary for the requested Service. Do not submit sensitive personal information, health information, government identifiers, passwords, financial credentials or unrelated personal records through facility intake forms.
8. Retention
We retain information only for as long as reasonably necessary for the purposes described above, taking account of active service relationships, contractual and audit requirements, report reproducibility, security needs, legal obligations, limitation periods and dispute requirements. Evidence and contractual records may need to be retained after a subscription ends so that historical reports can be explained and defended.
9. Security
We use reasonable administrative and technical safeguards appropriate to the nature of the information and the Service. No internet or cloud service can guarantee absolute security.
10. Disclosure
We may disclose information to service providers, professional advisers, authorities where legally required, or a successor in a legitimate corporate transaction. We do not disclose Client facility information for unrelated advertising purposes.
11. Your rights
Depending on applicable law and your location, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent or complaint to a supervisory authority. Some rights are subject to legal exceptions, including contractual, security, evidentiary and record-retention requirements.
12. Business contacts acting for organisations
If you interact with us on behalf of an organisation, we may retain your business contact details and authority/acceptance records as part of the organisation’s contractual history.
13. Children
The commercial facility intelligence Service is not directed to children and should not be used to submit children’s personal information.
14. Automated processing
The Service may use automated and AI-assisted processing to support risk-data retrieval, classification, drafting and quality workflows. We do not intend facility-intake automation to make solely automated decisions that produce legal or similarly significant effects on an individual.
15. Changes
We may update this Notice as the Service, providers or legal requirements change. Material changes will be reflected by a new version/effective date. Contractual acceptance records retain the version accepted at the relevant time.
16. Contact
Privacy requests may be sent to thebrink2028@gmail.com. Where required for an enterprise engagement, additional controller/processor details and a data-processing agreement can be provided in the applicable contract.