PRIVACY POLICY
Last Updated: 1 May 2026 ICO Registration Number: ZC107930
1. Introduction
This Privacy Policy explains how Mark Dodson T/A We Sweep ("We Sweep", "we", "us", "our") collects, uses, stores, and protects personal data in connection with the We Sweep SaaS platform (the "Platform").
We Sweep operates exclusively within the United Kingdom and is committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This Privacy Policy forms part of the Agreement, as defined in the Master Terms of Service.
2. Data Protection Contact
We Sweep has designated a data protection contact responsible for overseeing compliance with data protection law:
Mark Dodson Email: management@we-sweep.co.uk Address: Lower Moorlands, Sherburn‑in‑Elmet, LS25 6DN
You may contact us at any time regarding your personal data or to exercise your rights under data protection law.
3. Roles Under Data Protection Law
We Sweep acts in different capacities depending on the type of data processed:
- 3.1 Business User Data — We Sweep as Controller: We Sweep is the Data Controller for personal data relating to Business Users, including account information, billing details, usage logs, and security data. We determine the purposes and means of processing this data.
- 3.2 Customer Data — We Sweep as Processor: For personal data relating to your Customers (homeowners), We Sweep acts as a Data Processor and processes such data solely on your documented instructions. This is governed by the Data Processing Agreement (DPA).
4. Categories of Personal Data We Process
4.1 Business User Data (Controller Role)
- Identity & Contact Data: name, business name, email address, phone number.
- Billing & Financial Data: Stripe account details, transaction metadata.
- Technical & Log Data: IP address, device identifiers, browser type, timestamps, authentication logs.
- Support & Communication Data: messages, support tickets, and correspondence.
4.2 Customer Data (Processor Role)
Processed on behalf of Business Users:
- Contact Data: name, address, email, phone number.
- Service Data: appliance details, chimney type, service history.
- Inspection Records: photos, safety notes, digital certificates.
- Authentication Data: magic link tokens.
5. Lawful Bases for Processing (Controller Role)
We Sweep processes Business User Data under the following lawful bases:
| Purpose | Lawful Basis |
|---|---|
| Account creation and management | Contract (Art. 6(1)(b)) |
| Payment processing | Contract (Art. 6(1)(b)) |
| Security, fraud prevention, logging | Legitimate Interests (Art. 6(1)(f)) |
| Service communications (transactional) | Legitimate Interests (Art. 6(1)(f)) |
| Platform monitoring and rate limiting | Legitimate Interests (Art. 6(1)(f)) |
| Legal compliance (e.g., tax records) | Legal Obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment to ensure our interests do not override your rights and freedoms. A copy is available on request.
Customer Data is processed under the lawful basis determined by the Business User (Controller).
6. How We Use Personal Data
We use personal data to:
- Provide and maintain the Platform.
- Authenticate users via magic links.
- Process payments through Stripe.
- Generate and store safety certificates.
- Synchronise bookings with Google Calendar (where connected by the Business User).
- Provide customer support.
- Monitor system performance and security.
- Send transactional notifications (booking confirmations, reminders, status updates).
- Comply with legal obligations.
We do not sell personal data or use it for advertising or marketing.
7. Third‑Party Providers and Sub‑Processors
We use trusted third‑party providers to deliver the Platform. A full list is maintained in Annex B of the DPA. Current providers include:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and infrastructure | EU/UK/USA |
| Vercel | Frontend hosting | Global |
| Stripe | Payment processing | UK/USA |
| Postmark | Transactional email | USA |
| Google Maps | Address lookup and routing | Global |
| Google Calendar | Calendar synchronisation | Global |
All providers are bound by data processing agreements and maintain appropriate security certifications. Further details are available in the DPA.
7A. Google API Data — Use, Storage, and Disclosure
WeSweep's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we access: When a Business User connects their Google Calendar, we access calendar event data (event times, titles) solely for booking conflict detection, and we create, update, and delete calendar events to synchronise bookings.
What we store: We store only an encrypted OAuth refresh token (to maintain the connection) and Google Calendar event identifiers (to track which bookings are synced). We do not store, copy, or cache any other Google Calendar content.
Sharing, transfer, and disclosure: We do not share, transfer, or disclose Google user data to any third party. Google Calendar data is not used for advertising, analytics, profiling, or any purpose other than the calendar synchronisation features described above. Google user data is not provided to any artificial intelligence or machine learning model.
Revocation: Users can disconnect their Google Calendar at any time from the Integrations page, which immediately deletes the stored refresh token and all event link records.
8. International Data Transfers
Some of our third‑party providers process data outside the United Kingdom. Where personal data is transferred outside the UK, We Sweep ensures appropriate safeguards are in place, including:
- UK Addendum to the EU Standard Contractual Clauses.
- The UK–US Data Bridge (where applicable).
- Adequacy regulations issued by the UK Government.
We have conducted transfer risk assessments for each international transfer. Details are available on request.
9. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected:
| Data Category | Retention Period | Basis |
|---|---|---|
| Business User account data | Duration of the Agreement | Contract |
| Customer Data | Tenant lifetime + 60 days post‑termination | Contractual necessity |
| Financial transaction data | 7 years | HMRC legal obligation |
| Platform audit logs | 2 years | Legitimate interests / Legal obligation |
| Security logs | 12 months | Legitimate interests |
| API usage logs | 90 days | Legitimate interests |
| Magic link tokens | 15 minutes (session) / 1 hour (auth) | Security necessity |
| Rate limit records | 24 hours | Legitimate interests |
| Data exports | 7 days (files), 24 hours (download links) | Data portability |
When a Business User terminates their account, all associated data (including Customer Data) is retained for 60 days to allow for reactivation or data export, then permanently deleted via automated processes.
10. Cookies
We Sweep uses a small number of cookies, all of which are strictly necessary for the operation of the Platform. We do not use any analytics, advertising, or tracking cookies.
| Cookie | Purpose | Duration |
|---|---|---|
sb-* | Supabase authentication session | Session |
wesweep_admin_last_activity | 2FA inactivity timeout (admin panel) | Session |
wesweep_platform_last_activity | 2FA inactivity timeout (platform admin) | Session |
wesweep_impersonation_auth | Impersonation session security (HttpOnly) | Session |
wesweep_impersonation | Impersonation display banner | Session |
Because all cookies are strictly necessary for the provision of the service, consent is not required under the Privacy and Electronic Communications Regulations 2003 (PECR), Regulation 6.
For full details, see our Cookie Policy.
11. Security Measures
We Sweep implements technical and organisational measures (TOMs) including:
- Encryption in transit (TLS 1.2+) and at rest (AES‑256).
- Multi‑factor authentication for all administrative access.
- Role‑based access controls and principle of least privilege.
- Schema‑per‑tenant database isolation.
- Continuous monitoring, logging, and regular encrypted backups.
- Confidentiality obligations for all personnel with data access.
- Secure development lifecycle and vulnerability scanning.
12. Your Rights (Business Users)
As a Data Controller for Business User Data, We Sweep upholds your rights under the UK GDPR:
- Right of Access (Art. 15) — obtain a copy of your personal data.
- Right to Rectification (Art. 16) — correct inaccurate or incomplete data.
- Right to Erasure (Art. 17) — request deletion of your data.
- Right to Restriction (Art. 18) — restrict processing in certain circumstances.
- Right to Data Portability (Art. 20) — receive your data in a structured format.
- Right to Object (Art. 21) — object to processing based on legitimate interests.
To exercise any of these rights, contact: management@we-sweep.co.uk
We will respond to your request within one calendar month. This may be extended by two further months for complex requests, in which case we will inform you within the first month.
13. Customer Rights (Homeowners)
For Customer Data, We Sweep acts as a Processor. Homeowners must direct their data rights requests to the relevant Business User (the Controller). We Sweep will assist Controllers in fulfilling such requests in accordance with the DPA, including through our data export and erasure tools.
14. Automated Decision‑Making
We Sweep does not use automated decision‑making or profiling that produces legal or similarly significant effects on individuals. Rate limiting and security monitoring are automated but do not constitute automated individual decision‑making under Art. 22 of the UK GDPR.
15. Children's Data
The Platform is not intended for individuals under 18. We do not knowingly collect children's data. If we become aware that we have collected data from a child, we will delete it promptly.
16. Business Transfers
If We Sweep is involved in a merger, acquisition, or sale of assets, personal data may be transferred. We will provide at least 30 days' notice and ensure the successor entity is bound by equivalent data protection obligations.
17. Complaints
If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would appreciate the opportunity to address your concerns before you contact the ICO. Please contact us at management@we-sweep.co.uk in the first instance.
18. Changes to This Policy
We may update this Privacy Policy to reflect legal, technical, or operational changes. Material changes will be notified via email or dashboard notification. The "Last Updated" date at the top of this page indicates when the Policy was last revised.