Legal
Privacy Policy
Build Assure Limited
Last updated: ⟦DATE⟧ · Version 0.4 · Draft for solicitor review
Draft pending legal review
This is version 0.4 of our Privacy Policy. It has not been reviewed by a solicitor. Values shown as ⟦like this⟧ have not been settled yet and must be completed before this policy is relied upon. Where a control described here has not been built, or where the platform does something the policy does not yet cover, we say so in a marked note rather than leaving it out.
1. Who we are
BuildAssure is provided by Build Assure Limited, a company registered in England and Wales under company number 16843792, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ ("BuildAssure", "we", "us", "our").
We are registered with the Information Commissioner's Office under registration reference ⟦ICO registration number⟧.
Contact for privacy and security queries: buildassureapp@gmail.com.
2. What this policy covers — and what it does not
This policy explains how we handle personal data for our own purposes: when you visit our website, enquire about BuildAssure, or hold an account with us.
It does not apply to the project data our customers put into the platform. Where a construction company or its project team ("Customer") uses BuildAssure to record information about its own personnel, contractors, sites and projects, the Customer is the data controller and BuildAssure acts only as a data processor, handling that data on the Customer's documented instructions. Our processing in that role is governed by our Data Processing Agreement, not by this policy. If you are an employee, subcontractor or consultant whose details appear in a Customer's records, please direct any request to that Customer in the first instance; we will support them in responding.
3. Personal data we collect
As controller, we collect:
- Account and identity data
- Name, work email address, job title, employer, and role or permission group. Passwords are stored hashed; we never store them in plain text.
- Contact and enquiry data
- The information you give us when you contact us, request a demo, or subscribe to updates.
- Billing data
- The details needed to invoice and take payment for a subscription.
- Technical and usage data
- IP address, device and browser information, server and security logs, and aggregated in-app usage analytics.
- Cookie data
- See section 8.
We do not intentionally collect special category data. Where a Customer's own content incidentally contains it — for example, health information in an accident report — we process it strictly as that Customer directs, in our processor capacity.
4. Why we use it, and our lawful basis
- To provide, operate and support the Service, authenticate users and enforce access controls — performance of a contract, UK GDPR Article 6(1)(b).
- To secure, maintain, monitor and improve the Service, diagnose faults and prevent misuse, and to market to existing business contacts — legitimate interests, Article 6(1)(f).
- To meet legal, accounting and regulatory obligations — legal obligation, Article 6(1)(c).
- To market to individuals who are not existing business contacts, and for any cookie that requires it — consent, Article 6(1)(a).
5. Who we share it with
We do not sell personal data. We share it with:
- Your employer or Customer organisation, since the platform is by design a shared, multi-user workspace for that organisation's projects.
- Sub-processors who support our infrastructure. Our current sub-processor list is maintained at Annex 3 of our Data Processing Agreement and is available on request from buildassureapp@gmail.com.
- Others where required by law, or to protect the rights, property or safety of BuildAssure, our Customers or third parties.
Assets your browser loads directly
While you use the platform, your browser fetches the PDF viewer library used to display drawings from two public code networks, Cloudflare cdnjs and jsDelivr. Those networks see your IP address, our site's address and your browser details — not the page you were on. They receive no project content and no account identifier, and they are not sub-processors within the meaning of the list above. Our typefaces are served from our own domain, so no request is made to Google Fonts for them. Some print-preview routes are the exception: they load a stylesheet from fonts.googleapis.com, so opening one does reach Google.
Known gap — disclosed, not yet in Annex 3
The platform contains a drawing-analysis capability which sends a whole uploaded CAD drawing file and its filename to a separate extraction service. That service is not yet named in Annex 3 of our Data Processing Agreement. Section 7 of that agreement requires us to give Customers at least 30 days' advance notice before adding a sub-processor, and adding this one is subject to that notice.
6. Where your data is held
Our primary infrastructure is hosted in the United Kingdom (AWS eu-west-2, London), and customer data is stored at rest in the UK. Where a sub-processor processes personal data outside the UK, we put an appropriate safeguard in place — UK adequacy regulations where they apply, or the UK International Data Transfer Agreement or the International Data Transfer Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment.
7. How long we keep it
We keep personal data for as long as an account remains active, and for a reasonable period afterwards to meet legal, accounting and audit-trail obligations. Construction compliance records are typically retained for the life of a project plus the applicable limitation period. Retention for Customer project data is agreed with each Customer and set out in the Data Processing Agreement; Customers may request deletion of their tenant's data on termination, subject to any overriding legal retention requirement.
8. Cookies
We use strictly necessary cookies, which are required for login and core functionality, and first-party analytics cookies which help us understand how the site and platform are used. We do not use advertising, retargeting or third-party social-media cookies.
Under the Privacy and Electronic Communications Regulations 2003 as amended by the Data (Use and Access) Act 2025, first-party analytics and functionality cookies do not require your opt-in consent, but we must tell you clearly that we use them and give you a free and effective way to opt out. You can turn analytics off at any time using the "Manage cookies" control in our website footer. Full detail is in our Cookie Policy.
Status today
On our production site we use Vercel Speed Insights, which tracks page-load performance. It sends the address of the page you are on and its performance measurements to Vercel, who also host the application. It sets no cookie. The "Manage cookies" control and the Cookie Policy the paragraphs above refer to have not been built, and the app does not show a cookie or storage consent prompt at all. The sign-in cookies below are strictly necessary and would not need one; the preference, draft and cache items are written without asking you first, which is the gap the legal review of this draft has to resolve. In the meantime you can clear any of it from your browser's site-data settings, and refuse device push notifications at the operating-system prompt.
Strictly necessary — sign-in cookies
Signing in sets first-party cookies whose names begin sb- (these are set by our authentication provider, Supabase, and hold your session and refresh tokens). Our middleware also still reads two older cookies named sb-access-token and sb-refresh-token. Without these you cannot stay signed in, so they are set as soon as you log in and are not optional. Deleting them signs you out.
Preferences and offline data held on your device
The app also writes to your browser's local storage, IndexedDB and cache storage. This data stays on your device — it is not a cookie sent back to us on every request. The main items are:
- Appearance and accessibility —
theme,build-assure-contrast,build-assure-text-size,build-assure-reduced-motion. - Where you left off —
buildassure-selected-project,ba:lastProjectId,freshLogin, and export preferences such ascompliance-pdf-orientationandcompliance-pdf-density. - Unsent site work —
checkItemDraft(an in-progress checklist item),qr_scan_historyandqr_offline_scans(QR scans recorded while offline), andba-offline-projects(which projects you chose to keep available offline). - Offline caches — two IndexedDB databases,
BuildAssureLocal(offline records) andBuildAssureQueryCache(cached API responses), plus service-worker caches namedbuild-assure-…andbuild-assure-assets-…holding pages and static assets so the app still opens with no signal. - Housekeeping and mobile —
ba-sw-recovery-v1-20260221, a write-once flag which, on its first run, clears out an earlier faulty service worker and its caches;ba-native-sw-trial, which does the opposite — inside our native mobile app no service worker is registered at all unless you set that key, which we use to test offline start-up on a specific device; andba-push-token, your device push token, if you enabled notifications.
This list covers the identifiers we found in the platform's own code; treat it as indicative rather than exhaustive while this policy is in draft.
9. How we protect it
We apply technical and organisational measures appropriate to the sensitivity of construction compliance and audit data, including tenant isolation enforced by database-level Row Level Security, encryption in transit and at rest, role-based least-privilege access control, separation of production from development and demo environments, and a documented incident-response process.
We publish an honest account of our current security maturity, including what we have not yet implemented, on our Trust & Security page.
Status today
The Trust & Security page is written but is not yet published on this site. Ask us at buildassureapp@gmail.com and we will send you the current copy, including the roadmap items we have not yet implemented.
BuildAssure does not itself hold ISO 27001 or SOC 2 certification and does not claim to. The infrastructure we build on is independently certified: Supabase, which provides our database, authentication and file storage, holds ISO 27001 and SOC 2 Type II, and Vercel, which hosts the application layer, holds ISO 27001 and SOC 2 Type II. Those certifications cover our providers' platforms and not BuildAssure's own controls — our application logic, access rules and internal processes are outside their scope — and we do not present them as ours.
No system can be guaranteed secure; please use strong, unique passwords and report any suspected security issue to buildassureapp@gmail.com.
10. Your rights
If you are in the UK you have rights under UK GDPR, including to access, rectify, erase or restrict processing of your personal data, to data portability, and to object to certain processing including direct marketing. Where we act as processor on behalf of your employer, we will pass your request to that Customer, who is best placed to respond.
An important limit on erasure. Assurance records are evidence. Once you have signed an inspection, permit or handover, that signature and the associated audit entry form part of a construction quality record which the Customer organisation — and in some cases the law — needs to retain. We will therefore normally satisfy an erasure request by anonymising your personal identifiers rather than deleting the underlying record, so the evidence trail remains intact but is no longer linked to you. Where we cannot erase, we will tell you why.
Closing your account
You can request closure of your account from the Profile page in the app. To be clear about what happens: submitting that form raises a deletion request with our team — it does not delete your account instantly. We do this deliberately, because your account may be attached to signed assurance records that belong to your organisation and cannot be removed unilaterally.
Mechanically, the form emails your request to our team, and then attempts to email you an acknowledgement. That acknowledgement is best effort: if it cannot be sent, the app tells you so on screen, and your request has still been raised. There is no queue, ticket number or status you can follow in the app, and the request is actioned by a person reading an inbox. If you have not heard from us, please chase us at buildassureapp@gmail.com.
Completion normally means your login is removed, your profile is anonymised, and your name is replaced with a non-identifying marker on historical records that must be preserved. We will confirm to you what was deleted and what was retained, and why.
11. Complaints
If you are unhappy with how we have handled your personal data, please contact us first at buildassureapp@gmail.com. We will acknowledge your complaint and respond within the timeframes required by the Data (Use and Access) Act 2025.
You may also complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
12. Children's data
The platform is intended for business use by construction professionals and is not directed at children. We do not knowingly collect personal data from children.
13. Changes
We may update this policy from time to time. Material changes will be notified to Customers, and the "Last updated" date above will reflect the most recent revision.
14. Contact
Build Assure Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
buildassureapp@gmail.com