Privacy Policy
Last updated: 27 Sep 2026
FireDoorLog is operated by [COMPANY LEGAL NAME], a company registered in England and Wales (company number [COMPANY NUMBER]), registered office [REGISTERED ADDRESS]. We are registered with the Information Commissioner's Office (ICO) under registration number [ICO REGISTRATION NUMBER]. Contact: [CONTACT EMAIL].
1. Our role
- Controller for account data: names, email addresses, login and billing records of people who use FireDoorLog.
- Processor for the building data our customers enter — site addresses, door records, check results, photos, documents and remedial tasks. Our customer (the organisation) is the controller of that data and we process it only on their documented instructions under our Terms, which include the data processing terms required by Article 28 UK GDPR.
2. Data we collect
- Account details: name, email address, password (stored hashed), organisation and role.
- Records of acceptance of our Terms and Privacy Policy.
- Building and inspection data entered by customers, including photographs.
- Billing data: subscription status and Stripe customer references (card details are held by Stripe, never by us).
- Security logs: audit records of changes, and technical logs needed to run the service.
3. Why we use it and our lawful basis
- To provide the service under our contract with you or your organisation (Art. 6(1)(b)).
- To keep the service secure, prevent fraud and keep audit trails (legitimate interests, Art. 6(1)(f)).
- To meet legal and accounting obligations (Art. 6(1)(c)).
We do not sell personal data, use it for advertising or run analytics or tracking tools.
4. Sub-processors
- Lovable Cloud (infrastructure provided by Supabase) — hosting, database, authentication and file storage.
- Stripe Payments Europe Ltd — subscription billing.
- Our email delivery provider — account confirmation and password reset emails.
Data is hosted in the UK/EU. Where a sub-processor transfers data outside the UK, the transfer is protected by UK adequacy regulations or the ICO's International Data Transfer Agreement / Addendum.
5. Retention
- Customer building and inspection data is kept for as long as the organisation's account is open. An admin can export it or delete the whole organisation at any time; deletion removes the data and files from live systems immediately and from backups within 30 days.
- Account data is kept while you have an account and deleted within 30 days of closure.
- Billing records are kept for 6 years to meet HMRC requirements.
6. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, and to data portability. For building data held on behalf of an organisation, please contact that organisation first; we will help them respond. To exercise your rights, email [CONTACT EMAIL]. We respond within one month.
7. Security
Data is encrypted in transit and at rest, access is restricted to members of your organisation, files are held in private storage and shared only through expiring links, and changes to key records are audit-logged.
8. Complaints
If you are unhappy with how we handle your data, contact us first at [CONTACT EMAIL]. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.