1. Data controller
The data controller for the personal data described in this policy is Quinnsite Ltd (trading as Quinnsite), a company registered in England and Wales under company number 17325930, with its registered office at 27 Old Gloucester Street, London WC1N 3AX, United Kingdom. Our entry on the public register can be verified at Companies House.
As an organisation that processes personal data, we are registered with the UK Information Commissioner's Office (ICO). Our registration can be verified on the ICO's public register at ico.org.uk, and our registration reference is available on request.
The Service is operated by Quinnsite Ltd and hosted on Netlify (Netlify, Inc., 44 Montgomery Street, Suite 300, San Francisco, CA 94104, United States; see Section 7).
2. Scope
This policy covers all personal data we collect when you:
- Visit any page on quinnsite.co.uk;
- Use any of the Quinnsite calculators or knowledge-base pages;
- Generate, export, download or share a PDF report using our tools;
- Interact with the click-through disclaimer modal or any acknowledgement we record;
- Contact us by email or any future contact form.
It does not cover websites we link to. Once you click through to a third-party site, that site's privacy policy applies.
3. What we collect
Quinnsite is designed to collect as little personal data as possible. You can use the calculators and knowledge base without an account: the tools are calculation engines and your SuDS designs stay on your device. If you choose to create an account (needed only to hold a subscription and to upload a company logo for report branding), we process the limited account and billing data described in Section 3.4. We never store your drainage designs on our servers: only your account, subscription and (for Pro) your company logo.
3.1 Data stored on your device
| What | Storage | Why | Personal? |
|---|---|---|---|
Disclaimer acknowledgement (catchment_ack_v1) | localStorage | Records that you have read and accepted the Terms and the professional-use disclaimer, so we do not re-prompt you on every page. | No. Contains only a timestamp, a Terms version string and your browser's user-agent string. |
Session identifier (suds_session_id_v1) | sessionStorage | A randomly-generated UUID v4 that ties together calculation events within a single browser session, so the audit trail of a PDF report is coherent. | No. Randomly generated; not linked to you outside the session. |
Calculation IO-log (suds_iolog_v1) | localStorage (rolling buffer of last 50 events) | Allows you to export the inputs/outputs/methodology version applied for evidential and quality-assurance purposes. See Section 4 on lawful basis. | Potentially, if you choose to enter your name, project reference or any identifying string into a calculator input field, that string is stored locally. We do not require you to enter such information. |
This data lives in your browser. It does not leave your device unless you actively choose to export, share or transmit a PDF report.
3.2 Data we receive at the server
The Service is hosted on Netlify. When your browser fetches a page, Netlify automatically receives standard server-log information:
- Your IP address;
- The page you requested and the timestamp;
- Your browser's user-agent string;
- The referring page (if any).
This is standard web-server behaviour. We use Netlify's default log retention. For aggregate usage analytics we use Netlify Web Analytics, which is measured server-side from these logs: it sets no cookies, records no personal identifiers, and performs no cross-site tracking or advertising profiling. We do not use Google Analytics or any tracking pixel.
Our hosting provider, Netlify, acts as a data processor on our behalf and processes hosting, request and aggregate-analytics data under its Data Processing Addendum, which is aligned with the UK GDPR and incorporates the UK International Data Transfer Addendum for any transfer of data outside the UK.
3.3 Phase 2 server-side endpoints (planned)
We are preparing two Netlify Functions endpoints (/api/ack-log and /api/iolog) that will, when enabled, record:
- The fact that an acknowledgement was made (Terms version + disclaimer version + acknowledgement timestamp + session UUID + server-derived IP);
- The methodology version applied to each calculation event.
These endpoints are not yet live. When they go live we will update this policy and the disclaimer modal accordingly, and re-prompt for acknowledgement.
3.4 Accounts & billing (when you create an account)
When you sign up we collect your email address and, unless you sign in with Google or Microsoft, a password which is stored only in hashed form (we never see it). You may optionally provide your name, company, job role and sector. If you subscribe, we hold your subscription status (plan, status and renewal date) and a payment-processor customer reference. If you are a Pro subscriber and upload a company logo for report branding, that image is stored in our private cloud storage so it is available across your devices.
We never upload your SuDS projects, calculations or designs; those remain on your device (Section 3.1). Card and payment details are handled entirely by our payment processor, Stripe, and are never seen or stored by us. The processors involved in accounts and billing are listed in Section 6, and the lawful bases in Section 4.
4. Lawful basis
Our lawful bases under Article 6 UK GDPR are:
- Legitimate interests (Article 6(1)(f)): for storing the disclaimer acknowledgement and the calculation IO-log. The legitimate interests are: (a) operating an evidentially-defensible engineering tool whose outputs can be traced to a methodology version; (b) demonstrating that users have read and accepted the professional-use disclaimer before relying on outputs. We have balanced this against your rights and consider the impact minimal because the data is stored locally on your device and is not used for advertising or profiling.
- Legal obligation (Article 6(1)(c)): where retention is necessary to demonstrate compliance with our duty of care or in response to a regulatory enquiry.
- Consent (Article 6(1)(a)): where you actively click through the disclaimer modal. You can withdraw consent at any time by clearing your browser storage (see Section 10).
- Contract (Article 6(1)(b)): for creating and operating your account, authenticating you, and managing any subscription you take out. This processing is necessary to provide the service you have asked for.
- Consent (Article 6(1)(a)): for sending you marketing or product-update emails, only where you have ticked the separate, unticked-by-default marketing box at sign-up. This is distinct from accepting our Terms. You can withdraw it at any time via the unsubscribe link in any such email or in your account settings.
5. Retention
On-device data: until you clear your browser storage, or until the underlying schema version is bumped, whichever is sooner. The IO-log is a rolling buffer of the last 50 events; older events are evicted automatically.
Netlify server logs: per Netlify's standard retention policy (currently approximately 30 days for access logs; see Netlify's privacy policy for the current period).
Phase 2 server-side logs (once live): retained for 7 years, aligning with the expected limitation period for engineering professional-indemnity claims in England and Wales.
Account data: retained for as long as your account is active. If you delete your account (see Section 9) we delete your profile, login and stored company logo.
Billing & invoice records: we and our payment processor, Stripe, are required by UK tax and accounting law to retain invoice and payment records for approximately six years. Deleting your account therefore does not erase those financial records, which are held for the duration of that legal obligation.
7. International transfers
Netlify is a US-based provider with a UK GDPR-aligned Data Processing Addendum incorporating the EU Standard Contractual Clauses and the UK Addendum. Google and Cloudflare may also process data in the United States or other countries outside the United Kingdom. Where this happens, transfers are made under appropriate safeguards (SCCs + UK Addendum).
For accounts and billing: your Supabase account data is held in the London / EU region, so it is not transferred outside the UK/EU for ordinary account operations. Stripe, Resend and Cloudflare Turnstile may process limited data (such as your email or IP address) in the United States or elsewhere; where they do, transfers are covered by the Standard Contractual Clauses and the UK International Data Transfer Addendum (IDTA).
8. Security
The Service is served exclusively over HTTPS. We use Netlify's automatic TLS provisioning. Local-storage data on your device is protected by your browser's same-origin policy and the security boundaries of your operating system.
Account security. Account data in Supabase is protected by row-level security so that you can only access your own records; all traffic is encrypted in transit (HTTPS/TLS); payment card data is handled solely by Stripe under PCI-DSS; and our secret keys are held server-side only and are never exposed to the browser.
If a security incident occurred that affected personal data, we would notify the Information Commissioner's Office (ICO) within 72 hours where required by Article 33 UK GDPR, and would notify affected individuals directly where required by Article 34.
9. Your rights
Under UK GDPR you have the following rights in relation to personal data we hold about you:
- Right of access (Article 15): request a copy of your personal data.
- Right to rectification (Article 16): request correction of inaccurate data.
- Right to erasure (Article 17): the "right to be forgotten", subject to limited exceptions. If you have an account, you can exercise this directly using the Delete account action in your account settings, which cancels any subscription and deletes your login, profile and stored company logo. As noted in Section 5, invoice and payment records are retained for the legally-required period.
- Right to restrict processing (Article 18).
- Right to data portability (Article 20): for on-device data, this is implemented by the "Export session log" function in the IO-log helper.
- Right to object (Article 21): to processing based on legitimate interests.
- Right to withdraw consent (Article 7(3)).
- Right to lodge a complaint with the ICO (see Section 13).
To exercise any of these rights, contact us at the address in Section 13. We will respond within one calendar month.
11. Children
The Service is aimed at professional engineers, planners, contractors, architects, developers and local-authority staff. It is not directed at children under 13. We do not knowingly collect personal data from children. If you become aware that a child has provided personal data to us, please contact us so we can remove it.
12. Changes to this policy
We will publish any material change here, update the "Effective date" and the disclaimer-version string in the click-through modal, and re-prompt you for acknowledgement on your next visit.
13. Contact & complaints
Privacy queries, data-subject requests and complaints can be sent to: hello@quinnsite.co.uk.
If we cannot resolve your complaint, you have the right to complain to the Information Commissioner's Office:
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF