Skip to content
Security & privacy

Security & Data Privacy

How we protect your enclosure projects, uploads and exports — written for asbestos teams handling site and client information.

Who this page is for

Asbestos contractors, supervisors, document teams and company owners who upload floor plans, site drawings, client names or enclosure layouts and need plain-English answers about how data is handled.

How project data is stored

Project drawings (walls, assets, routes, notes and title-block fields) are stored in a PostgreSQL database hosted by Supabase, scoped to the creating user. Live CAD projects remain with their creator. Business, Team and Company include invitations, roles and company templates. Team and Company also provide workspace export history.

Sharing a drawing preview

Business, Team and Company let you create a read-only snapshot link. Anyone with an active link can view that saved snapshot; the link does not give them editor access. Links expire and can be revoked. Later edits to the project do not change an existing snapshot.

Uploaded drawings, backdrops and exports

Floor-plan backdrops, company branding files and export record copies are stored in private Supabase Storage buckets. Access is checked against account ownership and the permissions for the relevant workspace or shared record. When the app shows a backdrop preview or export history thumbnail, it uses a short-lived signed link that expires automatically (typically one to eight hours depending on the feature).

Private account-based access

Database row-level security enforces owner-based access to projects, exports and billing rows. The application checks your signed-in session on protected routes. We do not operate a shared library of customer drawings.

Payment security

Subscriptions and one-off purchases are processed by Stripe. Card details are entered on Stripe’s hosted Checkout and Customer Portal pages. AsbestoPlan stores Stripe customer and subscription identifiers — not full card numbers.

AI and your files

Your project data, floor-plan uploads and exports are not used to train AI models. The product does not send your drawings to third-party generative AI services for model training. Operational error logs may contain technical metadata (URLs, error messages) but not your drawing content.

Export, deletion and data requests

Signed-in users can download a JSON copy of their account records, including a storage file list, or permanently delete their account from Dashboard → Account & privacy. The JSON download does not contain the drawing files, uploads or images themselves; download those separately before deletion. For other data-protection questions contact support@asbestoplan.co.uk — controller details are in our Privacy Policy.

Security FAQ

Who can see my projects?
Live CAD projects belong to the account that created them. Invited colleagues do not automatically gain access to edit them. Business, Team and Company support read-only snapshot links: anyone you give an active link to can view that snapshot until it expires or you revoke it. Team and Company also provide workspace export history.
Are floor-plan uploads and exports stored securely?
Yes. Floor-plan backdrops, branding files and export record copies sit in private Supabase Storage buckets — not public URLs. Previews and downloads use short-lived signed links that expire automatically.
Does AsbestoPlan use my drawings to train AI models?
No. Your project data, uploads and exports are not fed into AI training models. The editor does not send your floor plans or enclosure layouts to third-party generative AI services for model training.
How are payments handled?
Card payments and subscriptions are processed by Stripe. Card details are entered on Stripe’s hosted checkout and billing portal — AsbestoPlan stores subscription identifiers, not full card numbers.
Can I export or delete my data?
Yes. Signed-in users can download a structured JSON copy of their account records or permanently delete their account from Dashboard → Account & privacy. The JSON export lists stored files but does not include their contents; download drawing files separately before deletion. You can also email support@asbestoplan.co.uk for data-protection requests.
Where is data stored?
Application data is hosted on Supabase (PostgreSQL database and private object storage). Our infrastructure providers process data under contractual safeguards appropriate for UK GDPR.
Is AsbestoPlan compliance-approved?
No. It is a planning and communication tool for enclosure visuals — not legal advice, HSE approval or a substitute for competent professional judgement.

AsbestoPlan is a planning and communication tool for enclosure visuals — not legal advice, HSE approval or compliance certification. See also the Privacy Policy and Disclaimer.