Legal

Privacy Policy

Last updated: June 2026

This Privacy Policy explains how CDM Marketing Ltd (“we”, “us”, “our”), trading as AsbestoPlan, collects and processes your personal data when you use our website and application (the “Service”). We are the “controller” of your personal data under the UK GDPR and the Data Protection Act 2018.

Product usage analytics: we record limited first-party analytics events on our own systems — for example pricing page views, signup started, project created and export completed — to understand product usage, improve onboarding, measure conversion and detect errors. These are not advertising cookies and do not track you across other websites. We do not record drawing contents, uploaded file names, client names or site details in analytics events.

1. Who we are

  • Controller: CDM Marketing Ltd, trading as AsbestoPlan
  • Company registration number: 14010841 (registered in England & Wales)
  • Registered address: 34 Clarence Street, Southend-on-Sea, England, SS1 1BD
  • ICO registration number: ZB580027
  • Data protection contact: adam@cdmmarketing.co.uk

2. The personal data we collect

  • Account data: name, email address and authentication metadata (e.g. login timestamps).
  • Project data: content you create in the editor — drawings, notes and any client or site details you choose to enter.
  • Billing data: subscription status, plan and the Stripe customer/ subscription identifiers. Card details are entered directly with Stripe and are never stored on our servers.
  • Communications: demo bookings, contact-form messages and support correspondence.
  • Technical data: limited operational logs (e.g. error reports) needed to keep the Service secure and reliable.
  • Product usage analytics: limited first-party events (e.g. pricing page views, signup started, project created, export completed) to understand product usage, improve onboarding, detect errors and measure conversion. We do not record drawing contents, file names, client names or site details in these events.

Product usage analytics

We record limited first-party analytics events on our own systems — for example pricing page views, signup started, project created and export completed — to understand product usage, improve onboarding, measure conversion and detect errors. These events are not advertising cookies and do not track you across other websites. We do not record drawing contents, uploaded file names, client names or site details in analytics events.

3. How we use your data and our lawful bases

Under the UK GDPR we rely on the following lawful bases (Article 6):

  • Performance of a contract: creating and operating your account, providing the editor, processing your subscription and providing support.
  • Legitimate interests: securing the Service, preventing fraud and abuse, keeping operational logs, recording limited product usage analytics (see section 2), and improving the product. We balance these against your rights.
  • Legal obligation: keeping records required by tax, accounting and other applicable laws.
  • Consent: where we ask for it (for example, optional marketing emails or any non-essential cookies). You can withdraw consent at any time.

4. Cookies

We use only strictly necessary cookies required to keep you signed in and to operate the Service securely. We do not use advertising or third-party tracking cookies. See our Cookie Policy for details.

5. Who we share your data with

We do not sell your personal data. We share it only with the service providers (“processors”) needed to run the Service, under contracts that require them to protect it:

  • Supabase — database, authentication and file storage hosting.
  • Stripe — payment processing and subscription management.
  • Resend — sending transactional emails (confirmations, password resets, notifications).
  • Vercel — application hosting and content delivery.
  • Microsoft Clarity — behavioural analytics (session replay / heatmaps), loaded only if you accept analytics cookies.

See our sub-processor list for the current register, including what each provider processes and where. We may also disclose data where required by law or to protect our legal rights.

6. International transfers

Some of our processors (such as Stripe and Resend) may process data outside the UK, including in the United States. Where data is transferred outside the UK, we rely on appropriate safeguards — such as UK adequacy regulations, the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. We keep these safeguards under review as our processors update their infrastructure.

7. How long we keep your data

  • Account & project data: for as long as your account is active.
  • After deletion:when you delete your account, your profile, projects and associated data are removed from our systems. Backups are overwritten on our provider’s normal cycle, up to 30 days.
  • Billing records: retained for 6 years to meet UK tax and accounting obligations.

8. How we protect your data

Data is stored on encrypted infrastructure. Project data is private to your account and protected by row-level security. Access to production systems is restricted, and payment card data is handled entirely by Stripe (a PCI-DSS Level 1 provider).

9. Your rights

Under the UK GDPR you have the right to:

  • access a copy of your personal data;
  • have inaccurate data corrected;
  • have your data erased (“right to be forgotten”);
  • restrict or object to certain processing;
  • data portability (receive your data in a machine-readable format);
  • withdraw consent where processing is based on consent.

You can exercise the rights of access, portability and erasure yourself at any time from your Account & privacy page — download a structured JSON copy of your data (profile, projects, billing, team memberships, storage file list, and more) or delete your account. For any other request, email adam@cdmmarketing.co.uk and we will respond within one month.

10. Complaints

If you are unhappy with how we handle your data, please contact us first. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.

11. Children

The Service is intended for use by businesses and professionals and is not directed at children under 18. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy from time to time. We will update the “last updated” date above and, where changes are significant, notify you by email or in the app.

13. Contact

For any privacy question or request, contact adam@cdmmarketing.co.uk.