Privacy Policy
Version 1.2 · Last updated 10 October 2026
1. Who we are
Science of Compliance (the app and the website at app.scienceofcompliance.co.uk) is provided by LCS Project Solutions Ltd, trading as Science of Compliance (“we”, “us”). LCS Project Solutions Ltd is registered in England and Wales, company number 14527954, with its registered office at 33 Corsair Drive, Dibden, Southampton, Hampshire, SO45 5UF. Contact us at support@scienceofcompliance.co.uk. LCS Project Solutions Ltd is registered with the Information Commissioner’s Office, registration number ZC269075.
For any privacy question or request, email support@scienceofcompliance.co.uk.
2. Who this policy covers
- Consultancies that hold a company account, and their administrators and consultants who use the app and website.
- People invited to join a company account.
- People whose details appear in reports, such as site managers, contractors, operatives and client contacts.
- Visitors to our website.
3. Our role
We are the controller of account information (names, email addresses, roles and company details) and of the records we need to run, secure and support the service.
For the content of reports (inspection findings, photos, recordings, transcripts and actions), the consultancy that holds the company account is the controller and we act as its processor. We only use that content to provide the service to the consultancy, under the data processing terms in our Terms of Use. If your details appear in a report, please contact the consultancy that prepared it first; we will help them respond.
4. What we collect
- Account details: your name, email address, password (stored only in encrypted, hashed form), role, the company you belong to and the date you accepted our terms.
- Company details: company name, company logo, client and site names.
- Report content: site and contractor details, names of people on site who are recorded in the report, inspection ratings and comments, actions, incident numbers and short incident comments, photos and captions, transcripts of recordings, and the Word reports produced.
- Audio recordings: recordings are made and kept on the consultant’s phone. They are uploaded to our server only so that they can be transcribed, and are deleted from our server once transcription is complete. We do not store recordings in the cloud.
- Activity and security records: sign-in records, and an audit log of who created, changed or issued each report and when.
- Technical information: our hosting providers keep standard server logs, which include IP addresses, for security and fault-finding.
- Billing details: the company’s billing name, address, email, VAT number if given, subscription and invoice history. Card details are entered directly with our payment provider, Stripe, and we never see or store them.
- Messages you send us: if you email us, we keep the correspondence.
We do not use advertising, we do not use analytics or tracking cookies, and we do not sell personal information.
5. How we use it and our lawful basis
| What we do | Lawful basis (UK GDPR) |
|---|---|
| Create and run accounts, let administrators invite and manage staff, and send invitation and password-reset emails. | Contract with the consultancy, and our legitimate interest in providing the service to its staff. |
| Store, edit and share reports, produce Word reports and keep them in the company’s cloud. | Processing on the consultancy’s instructions (the consultancy relies on its own lawful basis). |
| Transcribe recordings and prepare AI draft reports for the consultant to review. | Processing on the consultancy’s instructions. |
| Keep the audit log, protect accounts and investigate misuse or faults. | Legitimate interests in keeping the service and its records secure and reliable. |
| Respond to messages and support requests. | Legitimate interests, or contract where it relates to the service. |
| Take subscription payments and send invoices. | Contract with the consultancy. |
| Meet legal, tax and regulatory duties. | Legal obligation. |
6. AI transcription and drafting
Recordings and transcripts are sent to OpenAI so that recordings can be transcribed and a draft report prepared. OpenAI does not use data sent through its API to train its models, and may keep it for up to 30 days for abuse monitoring before deleting it.
AI drafts are a starting point only. The consultant reviews, edits and approves every report, and only an administrator can issue it. No decisions with legal or similarly significant effects are made about anyone by automated means.
7. Who we share information with
Within a company account, report content can be seen by that company’s administrators and consultants. Reports are shared outside the company only when the consultancy chooses to send them.
We use the following service providers (sub-processors) to run the service. Each is bound by a data processing agreement.
| Provider | What it does | Where the data is held |
|---|---|---|
| Supabase | Database, file storage (reports, photos, logos), sign-in and account emails. | London, United Kingdom |
| Render | Runs our application server, which transcribes recordings and builds Word reports. | Frankfurt, Germany (EU) |
| OpenAI | Transcription of recordings and preparation of AI draft reports. | United States |
| Resend | Sends account emails, such as invitations, email confirmations and password resets. | United States |
| Stripe | Takes subscription payments and produces invoices. Stripe does not receive report content. | United States and other countries |
| Apple | Distributes the iPhone app through the App Store and TestFlight. Apple does not receive report content from us. | United States and other countries |
We will update this list before adding or replacing a sub-processor that handles report content, and tell company administrators by email.
We may also disclose information where the law requires it, or to protect the rights, property or safety of our users or others.
8. International transfers
Our database and files are held in London and our application server runs in Frankfurt, Germany, which the UK recognises as providing adequate protection. Some of our providers are based in, or may access data from, the United States. Where personal information is transferred outside the UK, we rely on the UK’s adequacy regulations, the UK Extension to the EU–US Data Privacy Framework where the provider is certified, or the UK International Data Transfer Agreement or Addendum.
9. How long we keep information
- Accounts: while the account is open. When a user deletes their account in the app, their sign-in details are deleted straight away. Reports they prepared stay with their company, because they belong to the consultancy.
- Company data and reports: while the company account is open. When a consultancy closes its account, we delete its data within 90 days, unless the law requires us to keep it for longer.
- Recordings: deleted from our server as soon as transcription is complete. They remain on the consultant’s phone until deleted there.
- Temporary processing results: deleted from our server’s memory within 6 hours.
- Audit log: kept while the company account is open, so that the history of each report can be shown.
- Billing and invoice records: kept for 6 years after the end of the financial year they relate to, to meet tax and accounting duties.
- Backups: deleted on a rolling basis by our database provider.
10. How we protect information
- All connections are encrypted (HTTPS), and data is encrypted at rest by our database provider.
- Access controls in the database make sure each company can only see its own data.
- Only administrators can issue reports, and issued reports are locked.
- An audit log records who created, changed or issued each report.
If a personal data breach affects you, we will tell you, and the Information Commissioner’s Office where required, as the law requires.
11. Your rights
Under UK data protection law you can ask to see the personal information we hold about you, and ask us to correct it, delete it, restrict or object to how we use it, or give it to you in a portable format. Email support@scienceofcompliance.co.uk. We will reply within one month.
If your request is about report content, we may pass it to the consultancy that controls that report, and help them respond.
You can also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put things right first.
12. Cookies and storage
The website uses your browser’s storage only to keep you signed in and remember which company you are working in. It does not use analytics or advertising cookies. The app stores reports, photos and recordings on your phone so that you can work without signal.
13. Children
The service is for business use and is not intended for anyone under 18.
14. Changes to this policy
We will update this page when the way we handle information changes, and tell company administrators by email about significant changes.