Privacy Policy
Last updated 8 June 2026 · Version 2026-06-07-v2
Who controls your data
Your Building (the business centre that gave you access) is the data controller — it decides what personal data is collected and why. ECET Studios Ltd is the data processor: we run the software on your Building's behalf, on its instructions, under a written contract that meets the requirements of Article 28 UK GDPR. We don't use your data for our own purposes.
Your Building's name, registered address, and Data Protection Officer or contact (where appointed) are shown inside the app at Profile → Contact us. Direct privacy questions to your Building first.
The law this follows
This notice is written to the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 (Royal Assent 19 June 2025; the main data-protection changes took effect 5 February 2026). The Act amends — it does not replace — UK GDPR, the DPA 2018 and the PECR cookie rules, which all remain in force.
What we collect
Account data — your name, email address, password (stored only as a salted hash), your role, job title, an optional profile photo, and the company within the Building you belong to.
Booking data— each room booking you make or that's made for you: start and end time, room, who created it, any notes, and a cancellation reason if given.
Access events — each sign-in / sign-out at the building, with timestamp, method (entry card, QR, or kiosk) and the credential used. We do not capture photos, fingerprints, face scans or GPS location — only the fact and time of entry.
Visitor data — if you host a visitor: their name, expected arrival, your reason for the visit, and their arrival sign-in.
Activity & account records — in-app notifications addressed to you, hours adjustments affecting your free monthly hours, and a security audit log of key actions (who did what, and when).
Billing & financial records— where your Building bills your company, the records needed to do so: the company's rent or fee, hours used and extra hours, invoices and their status, and the billing contact. For an individual or sole-trader account billed in your own name, these are your personal financial data. ECET only stores and presents these figures — your Building sets the amounts and is responsible for them.
No special-category data. We don't collect health, biometric, racial, political, religious or similar sensitive data, and we don't build a marketing profile or use third-party advertising trackers.
Why we use it (lawful basis)
UK GDPR now has seven lawful bases (the 2025 Act added a narrow "recognised legitimate interests" basis for things like crime prevention and emergencies, which does not cover ordinary room booking or access logging). Your Building relies on:
- Contract (Art 6(1)(b)) — bookings, access and account administration needed to provide the service you signed up for.
- Legitimate interests (Art 6(1)(f)) — building security, knowing who is on the premises, fraud prevention, audit logging and accurate usage records, weighed against your rights in a documented assessment. For staff attendance your Building does not rely on consent, because the employer–worker relationship makes consent difficult to give freely.
- Legal obligation (Art 6(1)(c)) — tax and accounting records (kept around 6 years under Making Tax Digital), and responding to lawful requests.
- Consent (Art 6(1)(a)) — only where it genuinely applies, such as push notifications. You can withdraw consent at any time in the app.
Who we share it with
Your Building's staff — administrators see the data their role allows. Visibility is enforced in the database, not just hidden in the screen.
Our sub-processors — the vendors we rely on to run the platform. Each is bound by a data-processing agreement:
- Supabase— database & authentication. Your data is stored in the EU (Ireland). supabase.com/legal/dpa
- Vercel — application hosting (US). vercel.com/legal/dpa
- Resend — transactional email, e.g. invites and booking confirmations (US). Processes only your name and email. resend.com/legal/dpa
We don't sell your data, don't share it with advertising networks, and don't use it to train AI models.
International transfers
Your data is stored primarily in the EU (Ireland), which has UK adequacy — so no extra transfer safeguard is needed for that storage. Where a US sub-processor is involved (Vercel, Resend), transfers are covered by an appropriate Article 46 safeguard — the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses — and, where the vendor is certified, the UK Extension to the EU–US Data Privacy Framework. A transfer risk assessment supports these. Copies are available from your Building on request.
How long we keep it
- Active account data: for as long as you have an account.
- Access logs: your Building sets the retention period (default 7 years, adjustable down to a 12-month minimum), aligned with accounting and dispute-resolution needs.
- Booking, billing and tax records (including invoices): around 6–7 years, the UK accounting and HMRC Making Tax Digital retention minimum.
- Closed-account data: removed or anonymised within 30 days of closure, unless one of the categories above requires us to keep it.
Your rights (UK GDPR)
- Access (Art 15) — get a copy of your data. The app has a one-click export at Profile → Your data. A subject access request must normally be answered within one month (extendable by up to two months for complex requests); if your Building needs to clarify your request, that clock can pause until you reply.
- Rectification (Art 16) — fix wrong details in the app or via your Building.
- Erasure(Art 17) — ask your Building to delete data we're not legally required to keep. (A self-service erasure button is on our roadmap; today it's a quick manual request.)
- Portability (Art 20) — the same one-click export gives your data in a machine-readable format.
- Restriction / objection (Art 18, 21) — pause or object to certain processing.
- Withdraw consent — for anything based on consent, in one step.
- Complain — to your Building first (see the Complaints page), then to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.
Cookies & storage
We use only essential session cookies and the settings you choose (like your theme) — no tracking or advertising cookies, so there's no consent banner to click through. The full breakdown is on the Cookies & storage page.
Security
We use industry-standard practices: encryption in transit and at rest; row-level security on every database query, so one company can never read another's data — enforced by the database itself, not just the screen. Passwords are hashed with bcrypt; we never see them. Access to production systems is restricted and audited.
Changes
If we change this policy in a way that materially affects how your data is used, we'll ask you to review and re-accept it the next time you sign in. The current version is shown at the top.
Prospective customers & postal marketing
If you run a business centre, we may write to you by post about ECET. For that we act as a data controller and rely on legitimate interests(Article 6(1)(f) UK GDPR) — postal B2B marketing doesn't require prior consent under PECR. The details we use (your building's trading address, and directors' names from the Companies House public register or your own website) are used only to write to you, are never sold or shared, and are deleted when no longer needed.
Don't want to hear from us? Email hello@ecetapp.com and we'll add you to our permanent suppression list — you won't hear from us again. If you enquire through this site, we use what you send us solely to reply to you.
Contact
ECET (processor) data-protection contact: privacy@ecetagency.co.uk. For your Building's own privacy contact (the controller), see Profile → Contact us.
See also the Terms of Service, Cookies, the Data Processing Agreement and the Complaints page.