Privacy Policy
Last updated: 9 September 2026
This policy explains how PropSec ("we", "us") collects, uses and protects personal data when you visit propsec.co.uk, contact us, or use the PropSec platform. We are the data controller for the personal data described here.
1. Who we are
PropSec is operated by PROPSEC LTD, a company registered in England and Wales (company number 15847196) with its registered office at 3 Derby Road, Ripley, England, DE5 3EA. PROPSEC LTD is the data controller for the personal data described here. You can reach us atinfo@propsec.co.uk. We offer our services in the UK and, where a customer operates there, the EU and EEA.
2. The law we follow
We process personal data in line with UK data protection law (the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025) and, because we offer our services in the EU and EEA, the EU General Data Protection Regulation (EU GDPR) where it applies.
3. The personal data we process
If you visit the website or contact us:
- contact details you choose to send us, such as your name, work email, company and the content of your message or demo request;
- basic technical data your browser sends when you load a page, such as your IP address and device or browser type, used only to serve the site securely.
If your organisation uses the PropSec platform:
- account data for the people your organisation invites, such as name, work email, role and sign-in records;
- operational data your team enters into the platform, which may include personal data about staff, contractors and visitors (for example training records, permit sign-ons, visitor sign-in and incident records).
For the operational data in the platform, your organisation decides what is collected and why. In that context your organisation is the controller and PropSec acts as a processor on its behalf, under a written data processing agreement.
4. Why we process it, and our lawful basis
- To respond to your enquiries and provide the service: our legitimate interests, or to take steps to enter into and perform a contract.
- To run, secure and improve the website and platform: our legitimate interests in operating a reliable, secure service.
- To meet our legal and regulatory obligations: where the law requires it.
- Where we ask for it: your consent, which you can withdraw at any time.
5. How we use AI
Some PropSec features use AI to draft documents, read certificates and nameplates, summarise records and suggest actions. These features are governed: they are advisory, a person reviews and approves anything that matters, and every AI action is logged. We do not sell your data, and we do not use the operational data in your account to train our own AI models. Where a feature relies on a third-party AI service, we use it through that provider's business API, under terms that do not permit the provider to train its models on your content.
6. Who we share data with
We share personal data with service providers who help us run PropSec, each under a contract that requires them to protect it and use it only on our instructions. These are Vercel (hosting and file storage), Neon (database), Clerk (authentication and sign-in), Resend (transactional email), Pusher (realtime updates), Sentry (error monitoring) and Anthropic (AI processing). We will tell you before we add a sub-processor that handles your operational data. We may also disclose data where the law requires it.
7. International transfers
Some of our providers process data outside the UK or the EEA. Where they do, we rely on an approved safeguard, such as UK or EU adequacy regulations, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses, so your data keeps an equivalent level of protection. Platform data itself is hosted in the United Kingdom (London). The UK holds an EU adequacy decision, so EU and EEA customer data can lawfully be held here.
8. How long we keep it
We keep personal data only as long as we need it for the purposes above, or as the law requires. Enquiries and demo requests are kept for 12 months after our last contact, then deleted. Account and sign-in records are kept for the life of your organisation's agreement plus 12 months. Operational data in the platform is kept for as long as your organisation's agreement is in place and then deleted or returned in line with that agreement. Records we must keep by law, such as accounting records, are kept for the period the law sets.
9. Your rights
Under UK and EU data protection law you have the right to access your personal data, to have it corrected or erased, to restrict or object to certain processing, and to data portability. To exercise any of these, emailinfo@propsec.co.uk. If the data sits in your organisation's PropSec account, we will pass your request to that organisation as the controller.
10. How to complain
If you are unhappy with how we have handled your personal data, please tell us first atinfo@propsec.co.uk. We will acknowledge your complaint within 30 days and work to resolve it without undue delay. You also have the right to complain to a data protection regulator: in the UK, the Information Commissioner's Office (ico.org.uk); in the EU or EEA, your local supervisory authority. We would welcome the chance to put things right first.
11. Cookies
This website does not use tracking or advertising cookies. We use your browser's local storage only to remember small preferences, such as whether you have dismissed a notice. Because we set no non-essential cookies, you will not see a consent banner here.
12. Changes to this policy
We may update this policy from time to time. The date at the top shows when it last changed.
13. Contact
Questions about this policy or your data: info@propsec.co.uk.