Skip to content
Legal

Privacy Policy

Last updated: June 2026

This Privacy Policy explains how CDM Marketing Ltd (“we”, “us”, “our”), trading as AsbestoPlan, collects and processes your personal data when you use our website and application (the “Service”). We are the “controller” of your personal data under the UK GDPR and the Data Protection Act 2018.

Product usage analytics: we record limited first-party analytics events on our own systems — for example pricing page views, signup started, project created and export completed — to understand product usage, improve onboarding, measure conversion and detect errors. These are not advertising cookies and do not track you across other websites. We do not record drawing contents, uploaded file names, client names or site details in analytics events.

1. Who we are

  • Controller: CDM Marketing Ltd, trading as AsbestoPlan
  • Company registration number: 14010841 (registered in England & Wales)
  • Registered address: 34 Clarence Street, Southend-on-Sea, England, SS1 1BD
  • ICO registration number: ZB580027
  • Data protection contact: support@asbestoplan.co.uk

2. The personal data we collect

  • Account data: name, email address and authentication metadata (e.g. login timestamps).
  • Project data: content you create in the editor — drawings, notes and any client or site details you choose to enter.
  • Billing data: subscription status, plan and the Stripe customer/ subscription identifiers. Card details are entered directly with Stripe and are never stored on our servers.
  • Communications: contact-form messages, earlier demo enquiries and support correspondence.
  • Technical data: limited operational logs (e.g. error reports) needed to keep the Service secure and reliable.
  • Product usage analytics: limited first-party events (e.g. pricing page views, signup started, project created, export completed) to understand product usage, improve onboarding, detect errors and measure conversion. We do not record drawing contents, file names, client names or site details in these events.

Product usage analytics

If you accept analytics, we also attach a broad arrival category (such as search, paid, email or referral) and a public landing-page path to browser product events. We keep this attribution in this tab's session storage for up to 30 minutes. We do not store the referring URL, search query or advertising click identifier in this attribution. Declining analytics disables this attribution; withdrawing consent clears its stored value.

We record limited first-party analytics events on our own systems — for example pricing page views, signup started, project created and export completed — to understand product usage, improve onboarding, measure conversion and detect errors. These events are not advertising cookies and do not track you across other websites. We do not record drawing contents, uploaded file names, client names or site details in analytics events.

3. How we use your data and our lawful bases

Under the UK GDPR we rely on the following lawful bases (Article 6):

  • Performance of a contract: creating and operating your account, providing the editor, processing your subscription and providing support.
  • Legitimate interests: securing the Service, preventing fraud and abuse, keeping operational logs, recording limited product usage analytics (see section 2), and improving the product. We balance these against your rights.
  • Legal obligation: keeping records required by tax, accounting and other applicable laws.
  • Consent: where we ask for it (for example, optional marketing emails or any non-essential cookies). You can withdraw consent at any time.

4. Cookies

We use necessary cookies to keep you signed in and operate the Service securely. If you accept analytics cookies, we also load Microsoft Clarity for session replay and heatmaps. Analytics are optional; we do not use advertising cookies. See our Cookie Policy for details.

5. Who we share your data with

We do not sell your personal data. We share it only with the service providers (“processors”) needed to run the Service, under contracts that require them to protect it:

  • Supabase — database, authentication and file storage hosting.
  • Stripe — payment processing and subscription management.
  • Resend — sending transactional emails (confirmations, password resets, notifications).
  • Vercel — application hosting and content delivery.
  • Microsoft Clarity — behavioural analytics (session replay / heatmaps), loaded only if you accept analytics cookies.

See our sub-processor list for the current register, including what each provider processes and where. We may also disclose data where required by law or to protect our legal rights.

6. International transfers

Some of our processors (such as Stripe and Resend) may process data outside the UK, including in the United States. Where data is transferred outside the UK, we rely on appropriate safeguards — such as UK adequacy regulations, the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. We keep these safeguards under review as our processors update their infrastructure.

7. How long we keep your data

  • Account & project data: for as long as your account is active.
  • After deletion: when you delete your account, your profile, projects and personal project data are removed from the live service. Records that belong to a shared organisation, such as site-assessment photos, can remain with that organisation. Backup copies expire according to the applicable provider retention schedule.
  • Issued revisions: frozen drawing files are retained in private storage while their project exists. Deleting the project or your account removes the associated issued revisions. Your account data export includes revision records and a storage file list; download drawing files separately before deletion.
  • Billing records: retained for 6 years to meet UK tax and accounting obligations.

8. How we protect your data

Data is stored on encrypted infrastructure. Project data is private to your account and protected by row-level security. Access to production systems is restricted, and payment card data is handled entirely by Stripe (a PCI-DSS Level 1 provider).

9. Your rights

Under the UK GDPR you have the right to:

  • access a copy of your personal data;
  • have inaccurate data corrected;
  • have your data erased (“right to be forgotten”);
  • restrict or object to certain processing;
  • data portability (receive your data in a machine-readable format);
  • withdraw consent where processing is based on consent.

You can exercise the rights of access, portability and erasure yourself at any time from your Account & privacy page — download a structured JSON copy of your data (profile, projects, billing, team memberships, storage file list, and more) or delete your account. For any other request, email support@asbestoplan.co.uk and we will respond within one month.

10. Complaints

If you are unhappy with how we handle your data, please contact us first. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.

11. Children

The Service is intended for use by businesses and professionals and is not directed at children under 18. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy from time to time. We will update the “last updated” date above and, where changes are significant, notify you by email or in the app.

13. Contact

For any privacy question or request, contact support@asbestoplan.co.uk.