Privacy policy

Questions about this policy? Email info@protechos.co.uk.

PROTECH OS LTD (“Protech OS”, “we”, “us”), company number 17110868, registered at 3 Hury Way, Darlington, United Kingdom, DL2 2XF, provides an AI-assisted health and safety documentation platform. This policy explains what personal data we process — both for visitors to www.protechos.co.uk and for account holders using the Protech OS application — and your rights over it. Contact: info@protechos.co.uk.

Who we are

PROTECH OS LTD is the data controller for personal data about our website visitors and account holders. For the personal data your organisation puts into the application (e.g. named site personnel), we act as your data processor and you are the controller.

The data we process

Website visitors. If you join the waitlist we collect the email address you provide, to tell you about early access and launch updates (lawful basis: consent). With your consent we also use analytics cookies to understand how the site is used (see the Cookies policy).

Account holders. Your name, work email, job title and organisation; authentication data (passwords are hashed); the clients, sites, projects and documents you create; documents you upload and the content extracted from them; comments; activity and audit logs; and usage and diagnostic data.

How we use it and our lawful bases

  • Provide the service (contract): run your account, generate and store documents, send transactional email (invites, approvals, reminders).
  • Secure and improve (legitimate interests): audit logging, error monitoring, product analytics, abuse prevention.
  • Analytics and waitlist (consent): website analytics cookies and waitlist updates load/send only with your consent.
  • Legal obligations: accounting and responding to lawful requests.

AI processing of your content

To generate documents, content you provide — including text extracted from files you upload — is sent to our AI provider (Google, Gemini API) for processing and returned to you. We do not permit your content to be used to train third-party public models. Please do not upload material you are not authorised to process in this way.

Who processes your data (sub-processors)

We do not sell your data. We use vetted providers to run the service:

ProviderPurposeRegion / notes
SupabaseDatabase, authentication, file storageEU region
VercelApplication and website hostingGlobal edge
Google (Gemini API)AI document generationReceives your content
Google AnalyticsWebsite analyticsConsent-gated cookies
Google Tag ManagerTag / script managementConsent-gated
PostHogProduct analyticsEU cloud where available
ResendTransactional email
InngestBackground job orchestration
SentryError monitoring
LoopsWaitlist / marketing email

Where your data is stored

Your primary data (database, authentication, file storage) is hosted in the EU. Some sub-processors (e.g. Google, Vercel, Sentry, Loops) may process data outside the UK/EU; where they do, we rely on appropriate safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement, or EU Standard Contractual Clauses.

Retention and deletion

Uploaded source documents (e.g. PCIs, CPPs) are automatically deleted after a 30-day retention window once used to generate your documents; the extracted information is kept as part of your documents. Your documents and account data are retained while your account is active. You can permanently delete your organisation at any time — this erases your documents, account data and uploaded files from storage. Waitlist emails are kept until you unsubscribe.

Your rights

Under UK GDPR you may access, rectify, erase, restrict, port and object to the processing of your personal data, and withdraw consent at any time. Account holders can export or delete their organisation’s data in-app. To exercise any right, contact info@protechos.co.uk. You may also complain to the Information Commissioner’s Office (ICO), ico.org.uk.

Cookies

See our Cookies policy for the cookies we use and how to manage your choice.

Security

We apply database-level tenant isolation, encryption in transit and at rest, access controls, rate limiting and append-only audit logging.

Children

The service is for business use by adults (18+) and is not intended for children.

Changes

We may update this policy; the date above reflects the current version.