Conformiq is a record-keeping tool for plant, equipment and inspection certificates. This policy explains what we do with personal data when you use it.
We are the controller for account data — the people who sign up and use Conformiq. We are a processor for the records our customers upload about their own machines and staff; that is covered by our Data Processing Agreement.
Who we are
Conformiq is operated by [TO CONFIRM — registered company name], a company registered in England and Wales, company number [TO CONFIRM], registered office [TO CONFIRM — registered address].
For anything in this policy, including data protection requests, contact us at [TO CONFIRM — privacy contact email, e.g. privacy@conformiq.co.uk].
We have not appointed a Data Protection Officer; we are not required to. [TO CONFIRM]
What we collect, and why
Account and profile data
Your name, work email, phone number (if you add one), company name, your role in the organisation, and your password in hashed form. We use this to create and run your account, apply the right permissions, and contact you about the service.
Lawful basis: performance of a contract.
Billing data
Your subscription status, plan, billing period and invoice history. Card details are handled by our payment processor and never reach our servers — we store only the customer and subscription references they give us.
Lawful basis: performance of a contract, and legal obligation for tax records.
Customer content you upload
Equipment records, certificates, inspection checklists, projects, fuel tickets and photographs. These may contain personal data about your colleagues, operatives, examiners and contractors. Your organisation decides what goes in — you are the controller of that content and we process it on your instructions.
Lawful basis: performance of our contract with your organisation. The lawful basis for the underlying people in those records is your organisation's to determine.
Camera and photo access — please read this one
Conformiq lets you photograph a machine's data plate, a certificate, a delivery docket or a defect, and reads the fields out of the image so you don't have to type them.
That means:
- The whole image is uploaded and stored, not just the fields we extract.
- Images of certificates routinely contain names of examiners, their signatures, employer names, report numbers and contact details — personal data about people who never signed up to Conformiq.
- Photographs of machines can incidentally capture people, number plates and site signage in the background.
- Images are sent to our AI processing provider to be read. They are used to extract the fields and are not used to train anyone's models. [TO CONFIRM — confirm this with your AI provider's terms before relying on it]
If that is not appropriate for a particular document, type the details in by hand instead of photographing it.
Lawful basis: performance of a contract. Where the images contain personal data about third parties, your organisation is the controller and should tell those people what you are doing.
Technical and security data
IP address, device and browser information, sign-in times, failed sign-in attempts, and QR scan events (which machine, when, and whether the scanner was signed in). We use this to keep accounts secure, apply rate limits, investigate abuse and fix faults.
Lawful basis: legitimate interests — keeping the service secure and working. We only keep what we need to do that.
Product usage and support
Feature usage at an aggregate level, support tickets, and anything you tell us in them. Used to fix problems and decide what to build next.
Lawful basis: legitimate interests — improving a service you pay for.
Marketing
If you ask to hear from us, or fill in the roadmap form on our site, we will email you about Conformiq. Every email has a one-click unsubscribe.
Lawful basis: consent, or the soft opt-in for existing customers under PECR. We never sell your details.
The public QR portal — exactly what is visible
Every machine can carry a printed QR code. Anyone who is physically standing at the machine can scan it and see a public page, with no sign-in required. This is deliberate: it is how a site manager checks a machine on the gate.
The public page shows only:
- the machine name, manufacturer and model
- one identifier — serial number, or the plant number if there is no serial
- the owning organisation's name and logo
- for each current certificate type: the type, a status of current / expiring / lapsed, and the expiry date
- a link to the certificate document itself, for certificates that are not lapsed
- the date the record was last updated
It does not show notes, projects, purchase or hire information, hours, defects, inspection checklists, contact details, or the people in your organisation. Expiry dates are hidden once a certificate has lapsed.
Two things to be aware of:
- The certificate document is reachable from the public page. Certificates normally name the examiner and the issuing company, and often carry a signature. If a certificate PDF is attached, treat that information as visible to anyone at the machine.
- Machines set to any status other than active return nothing, and an unrecognised code returns nothing.
If you do not want a machine's certificates public, remove the QR label, or set the machine inactive. You can also rotate a machine's QR token, which immediately kills every label already printed for it.
Who we share data with
We use a small number of sub-processors. The current list, with what each one does and where it is located, is in the DPA. In summary: cloud hosting and database, email delivery, SMS delivery, payment processing, AI document reading, and mapping.
We also share data where we have to: with our professional advisers, and with regulators or law enforcement where the law requires it. If Conformiq is ever sold, account data would transfer with the business, and we would tell you first.
Where your data is stored
Our primary database and file storage are hosted in [TO CONFIRM — hosting region, e.g. eu-west-2 London]. Some sub-processors operate outside the UK. Where they do, transfers are covered by UK adequacy regulations, or by the International Data Transfer Addendum to the EU Standard Contractual Clauses, together with appropriate safeguards.
How long we keep things
| Data | Kept for |
|---|---|
| Account and profile | While the account is open, then 6 months after closure |
| Billing and invoices | 7 years, for tax law |
| Customer content (machines, certificates, projects) | While the subscription is live, then 30 days for export, then deleted |
| Certificate and thorough examination records | See below |
| Security and sign-in logs | 12 months |
| QR scan events | 24 months |
| Support tickets | 3 years after closure |
| Marketing consent records | Until withdrawn, plus 2 years |
Compliance records are treated differently. Reports of thorough examination and inspection records exist to satisfy statutory duties under LOLER and PUWER, and the duty holder is generally required to keep them for a set period. Where a record forms part of that compliance history, we retain it for the duration of the customer's retention obligation even if an individual named in it asks for erasure. That is a legal obligation exemption under UK GDPR, not a refusal to engage — we will always explain what we have kept and why.
Your rights
Under UK GDPR you can ask us to:
- give you a copy of the personal data we hold about you
- correct anything inaccurate
- delete it, where we are not required to keep it
- export it in a portable, machine-readable format
- restrict or object to processing based on legitimate interests
- withdraw consent to marketing at any time
Email [TO CONFIRM — privacy contact email]. We respond within one month and we do not charge. We may ask you to confirm who you are first.
If the data is in a customer's records rather than an account of your own — for example your name appears on a certificate uploaded by a plant hire company — that company is the controller and you should approach them. Tell us and we will pass the request on.
Complaints
Please raise it with us first, so we can fix it. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority: ico.org.uk/make-a-complaint, helpline 0303 123 1113.
Automated decision-making
We do not make decisions with legal or similarly significant effects about you by automated means. The AI that reads your photographs suggests field values for a human to review before anything is saved.
Children
Conformiq is a workplace tool and is not intended for anyone under 18.
Changes
When we change this policy we update the version and date at the top. If a change materially affects how we use your data, we will email account admins and ask you to accept the new version the next time you sign in.