UK GDPR · public notice

Privacy notice and your rights

Last updated 3 September 2026

Professional review required

This is a working privacy notice and operational template, not legal advice or a guarantee of compliance. A solicitor or qualified UK data-protection professional must confirm the controller identity and contact details, supplier terms, international-transfer mechanisms, retention controls and final wording before customer launch.

1. Who controls your data

The operator of Dorset Trade Signals is the controller for personal data processed in the scanner service. For any privacy or data request, contact us at dorsettradesignals@gmail.com. [Operator legal name and postal address — insert before publication.]

If you are signed in, use Privacy & data controls in your account to submit a request securely. Do not include passwords, payment details or sensitive information about another person in a request.

2. What the service does

The scanner reads selected public planning, tender and building-control registers in Dorset and Hampshire, identifies signals relevant to roofing and building contractors, and lets an authenticated customer review, export, email and track those opportunities. It is a business-information tool: source records and prioritisation must be independently checked before outreach.

3. Data we use, purposes, lawful bases and retention

CategoryData and purposeLawful basisRetention
Account and authenticationAccount identifier and the details needed to sign in (name and email address). Purpose: create and secure an account, authenticate requests and provide support.Contract; legitimate interests in account security.While the account is open; removed after account deletion is confirmed.
Scan and lead-pack dataLookback setting, scan timestamps, public-source results, prioritisation, generated packs and source links. Purpose: run the scanner, show results and provide exports.Contract.Up to 90 days from generation; a customer may delete saved packs sooner.
Customer workflow and rewardsOpportunity outcomes, follow-up dates, notes and reward credits. Purpose: help customers manage opportunities and operate rewards.Contract; legitimate interests in preventing fraud.With the related account while open; deleted on closure or request.
Email deliveryRecipient addresses supplied for a requested pack, delivery status and a recipient count. Recipient lists are not written to the application database.Contract for the requested delivery; legitimate interests in security.Audit metadata retained for up to 12 months.
Business outreachPublicly listed business name, email, the public source URL, sourcing confirmation, drafts, approvals and delivery attempts. Purpose: approval-first outreach with a global opt-out list.Legitimate interests in business-to-business outreach.Until deleted by the customer; opt-out records are kept indefinitely to honour the opt-out.
Security and privacy audit metadataPseudonymous account reference, event type, timestamp and limited counts. Audit events must not contain lead content, tokens or secrets.Legitimate interests in security and accountability.Up to 12 months, then securely deleted.
Public-source informationPlanning approvals, planning signals, public tenders and building-control signals published by public registers.Legitimate interests in providing a business intelligence service.Normally up to 90 days in a generated pack or cached record.

We do not intentionally request special-category data. Please do not put health, racial or ethnic, political, religious, biometric, sexual-life or criminal-offence information into scan notes or lead records.

4. Sources and providers

  • BCP Council public planning approvals and related public planning records.
  • Contracts Finder public tender records.
  • Southampton public building-control records.

Availability, attribution, access rules and the publisher's own privacy notice apply to each source.

5. Business outreach

Outreach is approval-first. Businesses are added manually from a recorded public source URL with a sourcing confirmation, duplicates are blocked, and every message is previewed and confirmed individually before sending. There is no automatic mass emailing. Every email identifies the sender and includes an opt-out instruction, and opt-outs are enforced globally.

6. Your rights

You can request access, correction, deletion, restriction, objection or portability, and you can withdraw consent for alerts at any time. Signed-in customers can submit a request and export or delete their data from Privacy & data controls. You also have the right to complain to the Information Commissioner's Office.

7. Security

Data is account-scoped and protected by row-level security so one customer cannot read another's records. Billing and paid features are enforced server-side. Audit records hold only pseudonymous references, event types, timestamps and status values.