PRIVACY POLICY

Last Updated: 1 May 2026 ICO Registration Number: ZC107930


1. Introduction

This Privacy Policy explains how Mark Dodson T/A We Sweep ("We Sweep", "we", "us", "our") collects, uses, stores, and protects personal data in connection with the We Sweep SaaS platform (the "Platform").

We Sweep operates exclusively within the United Kingdom and is committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This Privacy Policy forms part of the Agreement, as defined in the Master Terms of Service.

2. Data Protection Contact

We Sweep has designated a data protection contact responsible for overseeing compliance with data protection law:

Mark Dodson Email: management@we-sweep.co.uk Address: Lower Moorlands, Sherburn‑in‑Elmet, LS25 6DN

You may contact us at any time regarding your personal data or to exercise your rights under data protection law.

3. Roles Under Data Protection Law

We Sweep acts in different capacities depending on the type of data processed:

  • 3.1 Business User Data — We Sweep as Controller: We Sweep is the Data Controller for personal data relating to Business Users, including account information, billing details, usage logs, and security data. We determine the purposes and means of processing this data.
  • 3.2 Customer Data — We Sweep as Processor: For personal data relating to your Customers (homeowners), We Sweep acts as a Data Processor and processes such data solely on your documented instructions. This is governed by the Data Processing Agreement (DPA).

4. Categories of Personal Data We Process

4.1 Business User Data (Controller Role)

  • Identity & Contact Data: name, business name, email address, phone number.
  • Billing & Financial Data: Stripe account details, transaction metadata.
  • Technical & Log Data: IP address, device identifiers, browser type, timestamps, authentication logs.
  • Support & Communication Data: messages, support tickets, and correspondence.

4.2 Customer Data (Processor Role)

Processed on behalf of Business Users:

  • Contact Data: name, address, email, phone number.
  • Service Data: appliance details, chimney type, service history.
  • Inspection Records: photos, safety notes, digital certificates.
  • Authentication Data: magic link tokens.

5. Lawful Bases for Processing (Controller Role)

We Sweep processes Business User Data under the following lawful bases:

PurposeLawful Basis
Account creation and managementContract (Art. 6(1)(b))
Payment processingContract (Art. 6(1)(b))
Security, fraud prevention, loggingLegitimate Interests (Art. 6(1)(f))
Service communications (transactional)Legitimate Interests (Art. 6(1)(f))
Platform monitoring and rate limitingLegitimate Interests (Art. 6(1)(f))
Legal compliance (e.g., tax records)Legal Obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment to ensure our interests do not override your rights and freedoms. A copy is available on request.

Customer Data is processed under the lawful basis determined by the Business User (Controller).

6. How We Use Personal Data

We use personal data to:

  • Provide and maintain the Platform.
  • Authenticate users via magic links.
  • Process payments through Stripe.
  • Generate and store safety certificates.
  • Synchronise bookings with Google Calendar (where connected by the Business User).
  • Provide customer support.
  • Monitor system performance and security.
  • Send transactional notifications (booking confirmations, reminders, status updates).
  • Comply with legal obligations.

We do not sell personal data or use it for advertising or marketing.

7. Third‑Party Providers and Sub‑Processors

We use trusted third‑party providers to deliver the Platform. A full list is maintained in Annex B of the DPA. Current providers include:

ProviderPurposeLocation
SupabaseDatabase and infrastructureEU/UK/USA
VercelFrontend hostingGlobal
StripePayment processingUK/USA
PostmarkTransactional emailUSA
Google MapsAddress lookup and routingGlobal
Google CalendarCalendar synchronisationGlobal

All providers are bound by data processing agreements and maintain appropriate security certifications. Further details are available in the DPA.

7A. Google API Data — Use, Storage, and Disclosure

WeSweep's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What we access: When a Business User connects their Google Calendar, we access calendar event data (event times, titles) solely for booking conflict detection, and we create, update, and delete calendar events to synchronise bookings.

What we store: We store only an encrypted OAuth refresh token (to maintain the connection) and Google Calendar event identifiers (to track which bookings are synced). We do not store, copy, or cache any other Google Calendar content.

Sharing, transfer, and disclosure: We do not share, transfer, or disclose Google user data to any third party. Google Calendar data is not used for advertising, analytics, profiling, or any purpose other than the calendar synchronisation features described above. Google user data is not provided to any artificial intelligence or machine learning model.

Revocation: Users can disconnect their Google Calendar at any time from the Integrations page, which immediately deletes the stored refresh token and all event link records.

8. International Data Transfers

Some of our third‑party providers process data outside the United Kingdom. Where personal data is transferred outside the UK, We Sweep ensures appropriate safeguards are in place, including:

  • UK Addendum to the EU Standard Contractual Clauses.
  • The UK–US Data Bridge (where applicable).
  • Adequacy regulations issued by the UK Government.

We have conducted transfer risk assessments for each international transfer. Details are available on request.

9. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected:

Data CategoryRetention PeriodBasis
Business User account dataDuration of the AgreementContract
Customer DataTenant lifetime + 60 days post‑terminationContractual necessity
Financial transaction data7 yearsHMRC legal obligation
Platform audit logs2 yearsLegitimate interests / Legal obligation
Security logs12 monthsLegitimate interests
API usage logs90 daysLegitimate interests
Magic link tokens15 minutes (session) / 1 hour (auth)Security necessity
Rate limit records24 hoursLegitimate interests
Data exports7 days (files), 24 hours (download links)Data portability

When a Business User terminates their account, all associated data (including Customer Data) is retained for 60 days to allow for reactivation or data export, then permanently deleted via automated processes.

10. Cookies

We Sweep uses a small number of cookies, all of which are strictly necessary for the operation of the Platform. We do not use any analytics, advertising, or tracking cookies.

CookiePurposeDuration
sb-*Supabase authentication sessionSession
wesweep_admin_last_activity2FA inactivity timeout (admin panel)Session
wesweep_platform_last_activity2FA inactivity timeout (platform admin)Session
wesweep_impersonation_authImpersonation session security (HttpOnly)Session
wesweep_impersonationImpersonation display bannerSession

Because all cookies are strictly necessary for the provision of the service, consent is not required under the Privacy and Electronic Communications Regulations 2003 (PECR), Regulation 6.

For full details, see our Cookie Policy.

11. Security Measures

We Sweep implements technical and organisational measures (TOMs) including:

  • Encryption in transit (TLS 1.2+) and at rest (AES‑256).
  • Multi‑factor authentication for all administrative access.
  • Role‑based access controls and principle of least privilege.
  • Schema‑per‑tenant database isolation.
  • Continuous monitoring, logging, and regular encrypted backups.
  • Confidentiality obligations for all personnel with data access.
  • Secure development lifecycle and vulnerability scanning.

12. Your Rights (Business Users)

As a Data Controller for Business User Data, We Sweep upholds your rights under the UK GDPR:

  • Right of Access (Art. 15) — obtain a copy of your personal data.
  • Right to Rectification (Art. 16) — correct inaccurate or incomplete data.
  • Right to Erasure (Art. 17) — request deletion of your data.
  • Right to Restriction (Art. 18) — restrict processing in certain circumstances.
  • Right to Data Portability (Art. 20) — receive your data in a structured format.
  • Right to Object (Art. 21) — object to processing based on legitimate interests.

To exercise any of these rights, contact: management@we-sweep.co.uk

We will respond to your request within one calendar month. This may be extended by two further months for complex requests, in which case we will inform you within the first month.

13. Customer Rights (Homeowners)

For Customer Data, We Sweep acts as a Processor. Homeowners must direct their data rights requests to the relevant Business User (the Controller). We Sweep will assist Controllers in fulfilling such requests in accordance with the DPA, including through our data export and erasure tools.

14. Automated Decision‑Making

We Sweep does not use automated decision‑making or profiling that produces legal or similarly significant effects on individuals. Rate limiting and security monitoring are automated but do not constitute automated individual decision‑making under Art. 22 of the UK GDPR.

15. Children's Data

The Platform is not intended for individuals under 18. We do not knowingly collect children's data. If we become aware that we have collected data from a child, we will delete it promptly.

16. Business Transfers

If We Sweep is involved in a merger, acquisition, or sale of assets, personal data may be transferred. We will provide at least 30 days' notice and ensure the successor entity is bound by equivalent data protection obligations.

17. Complaints

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

  • Website: ico.org.uk
  • Telephone: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would appreciate the opportunity to address your concerns before you contact the ICO. Please contact us at management@we-sweep.co.uk in the first instance.

18. Changes to This Policy

We may update this Privacy Policy to reflect legal, technical, or operational changes. Material changes will be notified via email or dashboard notification. The "Last Updated" date at the top of this page indicates when the Policy was last revised.