Contents

  1. Who we are
  2. What personal data we collect
  3. How we use your data
  4. Legal basis for processing
  5. Third parties we share data with
  6. International transfers
  7. Data retention
  8. Security
  9. Your rights under UK GDPR
  10. Cookies
  11. Children
  12. Changes to this policy
  13. Contact and complaints
Plain English summary: Strucly collects only the data needed to provide our construction management platform. We use Google Firebase for secure storage and authentication, and we never sell your personal data to third parties. You have full rights over your data under UK GDPR.

1. Who we are

Strucly Ltd ("Strucly", "we", "us", "our") is the data controller for personal data processed through the Strucly platform. We are registered in England and Wales.

This Privacy Policy explains what personal data we collect, why we collect it, and how we use, store, and protect it — in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

For data protection enquiries, contact us at hello@strucly.app.

2. What personal data we collect

2.1 Account and identity data

2.2 Business and project data

As you use the platform, you enter business data including job details, risk assessments, COSHH records, employee records, subcontractor details, financial figures (invoices, variations, expenses), and documents. This data may contain personal data about your staff, subcontractors, or clients.

You are the data controller for any personal data about third parties that you upload to Strucly. We process this data as your data processor, strictly on your instructions.

2.3 Usage and technical data

2.4 Communications

If you contact us by email or through any support channel, we collect the content of those communications and any personal data you choose to include.

2.5 Data you do not need to provide

Where fields are marked optional, you have no obligation to provide that data. Providing less data may limit some features.

3. How we use your data

We use personal data for the following purposes:

We do not sell your personal data. We do not use your data for advertising or profiling purposes.

4. Legal basis for processing

Under UK GDPR, we rely on the following legal bases:

Where we process special category data (for example, health and safety incident data that references individuals' medical information), we rely on Article 9(2)(b) — processing necessary for obligations and rights in the field of employment and social security.

5. Third parties we share data with

We share personal data only with the following categories of third-party service providers, each bound by appropriate data protection agreements:

ProviderPurposeData sharedPrivacy info
Google Firebase
(Google LLC / Google Cloud EMEA Ltd)
Authentication, database (Firestore), hosting, cloud functions Account data, all project data stored in Firestore firebase.google.com/support/privacy
Google Vertex AI / Gemini
(Google LLC)
AI-assisted features within the platform Text queries you submit to AI features cloud.google.com
EmailJS Transactional email delivery (e.g. notifications, reports) Recipient email address, email content emailjs.com/legal/privacy-policy
Payment processor
(e.g. Stripe)
Processing subscription payments Billing name, address, payment card details (handled directly by the processor; we do not store card numbers) stripe.com/gb/privacy

We do not share your data with any other third parties unless required to do so by law (for example, in response to a court order or regulatory request), in which case we will notify you where legally permitted to do so.

6. International transfers

Some of our service providers (including Google Firebase and EmailJS) may process data outside the UK and EEA. Where this occurs, we ensure appropriate safeguards are in place, including:

Google Firebase processes data in data centres that may be located in the United States or other regions. Google participates in the EU-US Data Privacy Framework and operates under SCCs for UK transfers. Details are available at privacy.google.com/businesses/gdprservices.

7. Data retention

We retain personal data only as long as necessary for the purposes set out in this policy:

You may request early deletion of your personal data subject to our legal retention obligations — see Section 9 below.

8. Security

We implement appropriate technical and organisational security measures, including:

Despite these measures, no system is entirely secure. If you believe your account or data has been compromised, please contact us immediately at hello@strucly.app.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and notify you without undue delay where required.

9. Your rights under UK GDPR

You have the following rights in respect of your personal data:

Right of access

Request a copy of the personal data we hold about you (Subject Access Request)

Right to rectification

Ask us to correct inaccurate or incomplete personal data

Right to erasure

Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements

Right to restriction

Ask us to restrict processing of your data in certain circumstances

Right to data portability

Receive your data in a structured, machine-readable format and transfer it to another controller

Right to object

Object to processing based on legitimate interests or for direct marketing purposes

Right to withdraw consent

Where processing is based on consent, withdraw it at any time without affecting lawfulness of prior processing

Rights re: automated decisions

Not to be subject to solely automated decisions that produce significant legal or similarly significant effects

To exercise any of these rights, please contact us at hello@strucly.app. We will respond within one month. We may need to verify your identity before processing your request.

There is no charge for exercising your rights, unless a request is manifestly unfounded or excessive.

10. Cookies and local storage

Strucly uses browser localStorage (not traditional cookies) to remember your preferences within the application — for example, your sidebar navigation state and display settings. This data is stored entirely on your device and is not transmitted to us.

Firebase Authentication uses a session token stored in your browser to keep you signed in. This is essential to the operation of the Service and cannot be disabled without preventing sign-in.

We do not currently use tracking or advertising cookies. If we introduce analytics or tracking in the future, we will update this policy and seek your consent where required.

11. Children

The Service is intended for business use by adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data about a child, please contact us immediately and we will delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.

Continued use of the Service after changes take effect constitutes your acknowledgement of the updated policy.

13. Contact and complaints

For any questions or concerns about this policy or our data practices, please contact:

If you are not satisfied with our response, you have the right to lodge a complaint with the UK supervisory authority: