This Privacy Policy explains how Conformiq ("Conformiq", "we", "us") collects, uses and protects personal data when you use our website and services at conformiq.co.uk (the "Service"). We are the data controller for personal data about our account holders. For customer data uploaded into the Service, we act as a data processor on behalf of the customer organisation.
1. Who we are
Conformiq provides equipment and inspection-certificate tracking software for organisations in the UK and Europe. Contact for privacy enquiries: info@conformiq.co.uk.
2. Data we collect
- Account data: name, work email, organisation name, encrypted password (or Google sign-in identifier), role.
- Customer content: equipment records, inspection certificates and related documents you upload.
- Billing data: subscription tier, subscription status and billing period. Card details are handled directly by Stripe — we never see or store them.
- Support data: help-desk tickets and messages you send us.
- Technical data: IP address, browser and device information, log entries, and cookies strictly necessary to keep you signed in.
3. Lawful bases
- Contract — to provide the Service you signed up for.
- Legal obligation — to keep records for tax, accounting and regulatory purposes.
- Legitimate interests — to secure our Service, prevent abuse, and communicate essential service updates.
- Consent — where required (for example, non-essential marketing communications, if any).
4. How we use your data
We use personal data to operate the Service, authenticate users, deliver reminder emails about expiring certificates, provide customer support, process payments, and meet legal obligations. We do not sell personal data and we do not use it for advertising.
5. Subprocessors
We use the following subprocessors to deliver the Service. Each is bound by contractual data-protection obligations:
- Lovable Cloud (Supabase) — application hosting, database and file storage (EU region).
- Stripe Payments Europe, Ltd. — subscription billing and payment processing.
- Google LLC — optional Sign in with Google (identity only).
- Lovable Email — transactional and reminder email delivery.
6. International transfers
Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards such as the UK IDTA and EU Standard Contractual Clauses.
7. Retention
Account and customer content are retained for the life of your subscription and for up to 90 days after cancellation, then deleted or anonymised. Billing records are retained for 6 years to meet UK tax law. Support tickets are retained for 24 months. Reminder logs are retained for 24 months.
8. Your rights
Under UK/EU GDPR you have the right to access, rectify, erase, port, restrict or object to processing of your personal data, and to withdraw consent where processing is based on consent. To exercise any of these rights, email info@conformiq.co.uk. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk).
9. Security
We use encryption in transit (TLS), encryption at rest for uploaded documents, role-based access controls, and audited backend infrastructure. No system is perfectly secure — please use a strong, unique password and enable your organisation's own account-security controls.
10. Cookies
Conformiq uses only strictly-necessary cookies to keep you signed in. See our Cookie Policy for details.
11. Changes
We may update this policy from time to time. Material changes will be communicated by email to account owners. The "Last updated" date at the top of this page shows the current version.
Note. This policy is provided as a starting template. Your organisation should seek independent legal advice before relying on it in a regulated context.