Legal

Privacy policy

Estimark is operated by Flavoureak UK LTD T/A Estimark (company number 16410737), whose registered office is 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, registered in England and Wales. This policy explains what personal data we hold, why, and what you can do about it. It covers the Estimark application, the marketing site and our mobile apps.

Last updated 10 August 2026

Who is the data controller

For your own account (the person who signs up, their name, work email, role, and our billing records) Flavoureak UK LTD T/A Estimark is the data controller. Our privacy policy governs that relationship.

For the data you put into Estimark about other people (your staff, your workers and subcontractors, your clients, and the residents and tenants of properties you maintain) you are the data controller and we are your processor. You decide what goes in and how long it stays; we process it on your documented instructions in order to provide the service. Our data processing agreement governs that relationship, and it is the written contract UK GDPR Article 28(3) requires.

These are two different roles over two different sets of people. Read the privacy policy for what we do with your account; read the data processing agreement for what we do with the personal data you enter about everybody else.

Our data processing agreement sets out the Article 28 terms on which we process personal data on your behalf. It forms part of your subscription terms and is accepted in the application, where the version, the exact text and the time of acceptance are recorded. A copy is available at any time from Settings, and we will provide a counter-signed copy on request to privacy@estimark.co.uk. The sub-processor table below is the same table that agreement uses.

What we collect

We collect only what the service needs to work:

  • Account data: name, work email, company name, role, and a hashed password. Passwords are stored as bcrypt hashes and are never recoverable, by us or anyone else.
  • Billing data: your plan, subscription status and payment method reference. Card details are handled by Stripe and never reach our servers.
  • Content you create: clients, jobs, quotes, invoices, timesheets, photographs, documents and any other records you enter. This is the data you are the controller of.
  • Location data: when an operative scans a site QR code to clock in, or takes a site photograph, we record where it happened. This is used to confirm attendance and to evidence site records. It is captured only at the moment of the scan or photograph, never continuously, and never in the background.
  • Technical data: IP address, browser and device type, and pages visited, used for security, rate limiting and diagnosing faults. Your IP address and browser are also recorded against a cookie choice, an electronic signature and a sign-in session, so that each can be evidenced later.
  • Calls to our sales and support line. Every call is recorded and transcribed, and we tell you so at the start of the call before you say anything. We keep recordings for twelve months and then delete the audio and the transcript together; the fact that a call happened, and the number it came from, is kept as an ordinary business record. Voicemail becomes a support ticket so that a message left out of hours is answered rather than missed. If you would rather not be recorded, say so and we will take the details another way, or write to us at privacy@estimark.co.uk.
  • Email we have sent you, and whether it was opened: when we email you about your account — an invoice, a quote, a payment reminder — we record that it was sent, to which address, and the subject. Those emails carry a single invisible image, and when your mail program loads it we record that you opened the message once, the first time. We do this so that a question about an invoice can be answered accurately, and so we do not chase somebody who never received something. We do not record what you clicked inside the message, we do not build a profile from it, and it is never used for advertising. If you would rather not be counted, most mail programs can be set to stop loading remote images, and the email itself is unaffected.
  • Special category and criminal records data, where you put it in. The HR, health and safety and housing features are designed to hold sickness absence, accident and injury records, right-to-work and passport documents, criminal records certificates, and, in the housing modules, notes about a resident’s health or vulnerability, including a child’s. You are the controller of all of it and you need your own lawful basis under Articles 9 and 10 to hold it.

Why we are allowed to hold it

Account, billing and content data are processed to perform our contract with you. Technical and security data are processed under our legitimate interest in keeping the service available and secure, and in preventing abuse. Where we rely on consent, as we do for optional analytics cookies, you can withdraw it at any time without affecting the service.

A record of the account email we have sent you, and whether it was opened, is kept under our legitimate interest in administering your account accurately: if you ask us whether an invoice reached you, we can answer instead of guessing. These are service messages about your own account rather than marketing, so we do not ask for consent to send them, and you can object to the open recording at any time by writing to privacy@estimark.co.uk.

Who else sees it

We do not sell personal data, and we do not share it for advertising. The table below is generated from the service’s own configuration rather than maintained by hand, so it lists every third party the software actually contacts and cannot quietly fall behind what the software does.

"Always" means every customer on every deployment. "Only if you accept analytics" means the script is not fetched at all until you agree, so with no decision or a refusal nothing reaches that provider. "When enabled by us" means a feature or credential we control, and the register says where that stands today. "Only if you connect it" means nothing is sent until you authorise the connection yourself.

WhoWhat they do for usWhat they receiveWhereWhen
Amazon Web Services (AWS): Lightsail compute, block storage and snapshotsHosts the entire application: the PostgreSQL database, the Redis cache and queue, and the local upload volume that holds every file customers upload.All personal data in the service, without exception, because this is where the database and the uploaded files physically sit.United Kingdom, in AWS eu-west-2a (London).Always
Amazon Web Services (AWS): Bedrock, running Anthropic Claude modelsGenerates estimates, analyses tender and specification documents, drafts planning and tender text, and answers in-product help questions.Whatever appears in the material submitted for analysis, plus specific fields the product adds to the prompt: the name of the signed-in user, the customer's company name, site addresses, tender buyer names, and, when a document is priced against the customer's own labour rates, team member names and their pay rates.The client is pinned to eu-west-2 (London), but the model identifiers are EU cross-region inference profiles (`eu.anthropic.claude-…`), so a request may be served from any AWS EU region rather than from London. Processing takes place in the EEA rather than only in the UK. The EEA is covered by UK adequacy regulations, so no transfer mechanism is required for the EEA leg. Retention and training are governed by the AWS service terms rather than by a setting of ours, and we are confirming those terms in writing.Always
Amazon Web Services (AWS): Simple Email Service (SES)Sends every outbound email: verification and password-reset links, quotes, invoices, receipts, reminders and progress reports. Also receives inbound mail to our published addresses, which becomes an enquiry ticket.Recipient name and email address, company name, the body of the message, and any attachment, which for a quote or invoice contains client names, addresses and amounts, and for a RAMS or progress report can contain site and worker detail.United Kingdom, on the eu-west-2 (London) SMTP and receiving endpoints.Always
Amazon Web Services (AWS): S3Holds off-site copies of the nightly database backup, the raw inbound mail written by SES receiving, and user profile photographs.The backup copy contains the whole database. Inbound mail contains whatever the sender wrote. Profile photographs are images of the customer's own staff.eu-west-2 (London) for backups and for the profile-photograph bucket. A leftover default in our configuration still names an Asia-Pacific region; nothing uses it, and we are removing it.Always
CloudflareAuthoritative DNS for our domains, and the email-routing API that creates and forwards partner mailboxes. Cloudflare is configured DNS-only: it does not proxy application traffic, so it does not see request or response bodies.DNS query metadata. For the email-routing API only: partner email addresses and the personal addresses those are forwarded to.Global anycast network. Cloudflare is US-headquartered and its network is global. Transfers rest on Cloudflare's own UK Addendum to the EU standard contractual clauses, and we are confirming that the signed addendum is on file for our account.Always
Let's Encrypt (Internet Security Research Group)Issues and renews the TLS certificates that encrypt traffic to the service.Domain names and one operational email address of ours. No customer personal data.United States. Listed for completeness rather than because a transfer arises: what it receives is a domain name and one operational address of ours, and no personal data of yours reaches it. A certificate authority that is in the path of every request is worth naming even when it sees nothing.Always
postcodes.ioConverts a UK postcode to coordinates so sites appear on the map.Postcodes of client sites and properties. A postcode on its own is not always personal data, but a residential postcode taken from a tenant's repair record is.United Kingdom.Always
Open-MeteoSite weather for the site diary and for weather-related delay records. This is the default provider and it needs no API key, so it is active on every deployment.Latitude and longitude of a job site.Continental Europe. We have not yet established the operating entity or its exact hosting, and we are doing that rather than guessing at it here.Always
Google Analytics 4Product and marketing analytics. It runs inside the signed-in application as well as on the marketing site, each with its own banner. The tag is loaded directly; there is no tag manager container in front of it, so nothing else can be injected through one.IP address, device and browser, pages visited, and a Google analytics identifier, for the customer's own staff while they use the product.United States and global. Transfer to the United States under the UK extension to the EU-US Data Privacy Framework, on which Google LLC is certified, with Google's UK Addendum as the fallback. No transfer happens at all unless you accept analytics: the script is not fetched until then, and withdrawing removes it and expires the cookies it set.Only if you accept analytics
Companies HouseCompany lookup during sign-up and when adding a client or subcontractor, so registered details do not have to be typed.The company number or name searched for. The response includes officers' names and partial dates of birth, which we then hold.United Kingdom.Always
StripeSubscription billing, and card payments taken from the customer's own clients.Company name, billing contact email, billing address, VAT number, plan and subscription state. Card details are captured by Stripe in the customer's browser and never reach our servers.Ireland and the United States. Transfer to the United States under Stripe's data processing agreement and its UK Addendum. Stripe is a separate controller of the card data it holds, not our sub-processor for that data.When enabled by us
TwilioSMS reminders for appointments and a small number of internal alerts.Mobile telephone number and the text of the message.United States. Transfer to the United States under Twilio's data protection addendum and its UK Addendum. We are confirming the signed addendum is on file for our account.When enabled by us
GoCardlessBacs Direct Debit mandates and collections.Payer name, email address, bank mandate details and payment amounts.United Kingdom and Ireland.When enabled by us
CSCS Smart CheckVerifies that a worker's construction skills card is genuine and current.Card number and the cardholder's date of birth.United Kingdom.When enabled by us
SentryApplication error and performance monitoring.Error stack traces and transaction names. It is configured with `send_default_pii=False`, so request bodies, headers and user identifiers are not sent. Personal data can still reach it incidentally inside an exception message.United States or Germany depending on the account region, which is not determinable from this repository. No DSN is configured in any file here, so on the evidence available Sentry is not currently receiving anything. If the US region is in use, transfer rests on Sentry's data processing addendum and its UK Addendum. No error monitoring is configured in this repository, so on the evidence available nothing is being transferred.When enabled by us
HM Revenue & Customs (CIS verification)Verifies a subcontractor's CIS status and deduction rate.Subcontractor name, Unique Taxpayer Reference and National Insurance number.United Kingdom.Only if you connect it
Xero, QuickBooks (Intuit), FreshBooks or SagePushes invoices and contacts into the accounting system the customer chooses.Client and subcontractor names, email addresses, addresses, invoice detail.Xero: global. Intuit and FreshBooks: United States. Sage: United Kingdom and EU. Connecting one of these is the customer's own act and the destination is the customer's own account with that provider. Where the provider is outside the UK the transfer rests on that provider's terms with the customer, not on ours.Only if you connect it
HubSpot or PipedriveTwo-way sync of contacts and deals with the CRM the customer chooses.Contact names, email addresses, telephone numbers and deal notes.HubSpot: United States. Pipedrive: European Union. As for the accounting providers above.Only if you connect it
Google Drive or Microsoft OneDriveCopies documents to the cloud storage account the customer chooses.Whatever is in the documents copied, which can be anything the customer holds.United States and global. As for the accounting providers above.Only if you connect it
Google or Microsoft single sign-onSigns a user in with their existing work account.Email address, name and the provider's account identifier.United States and global. As for the accounting providers above.Only if you connect it
Browser push services (Apple, Google, Mozilla)Delivers web push notifications to a device that has subscribed.A push subscription endpoint and the title and body of the notification.Decided by the recipient's own browser vendor, so not determinable in advance. No VAPID keys are configured in this repository, so this path is currently inert. A potential transfer to the United States. The notification body is the only content that travels, and we are settling what may appear in one before this is switched on.When enabled by us

Recipients that are not our sub-processors

Two recipients receive personal data as controllers in their own right rather than on our instructions, so they are not sub-processors and we have not treated them as such. Where the product sends data to one of them, you need your own lawful basis for that disclosure.

  • Structural warranty providers (Premier Guarantee, Build-Zone, LABC, NHBC): EstiWarranty submits a project for a structural warranty quotation.
  • Google (AdSense, on EstiJob only): Contextual advertising on the public EstiJob site, and an advertising controller in its own right rather than our processor. It loads only if a visitor accepts advertising cookies, and only where a publisher ID is configured. None is configured today, so EstiJob currently makes no request to Google whatever a visitor chooses.

Where it is stored, and what leaves the UK

Your data is hosted in the United Kingdom, in Amazon Web Services' London region, and backups, of the database and of the files you upload alike, are held in the United Kingdom too. Some processing happens outside the UK and we would rather name it than average it out. Our AI features run on Amazon Bedrock using EU inference, so a request issued from London may be served from another Amazon European region; the EEA is covered by UK adequacy regulations, so no additional safeguard is needed for that. Analytics, card payments and SMS involve transfers to the United States under those providers' own approved transfer terms. If you connect an accounting system, a CRM or a cloud drive of your own, data goes to your account with that provider wherever it is. Every recipient and its location is listed in the sub-processor table.

How long we keep it

While your account is active we keep your data so the service works, and you control how long the records inside it live. You can set your own retention periods for most record types, from 30 days to ten years, and for timesheets, attendance records and audit entries you can choose anonymisation instead of deletion, which keeps the hours, the attendance and the sequence of events and removes the person, including the clock-in coordinates. For record types where removing every identifier would leave nothing meaningful, the product deletes and tells you so rather than performing a rename and calling it anonymisation. Where you set no period, records are kept until you delete them or close the account. Some records have their own fixed period: a data export you request is deleted after seven days, and a recorded screening video is deleted after 183 days. One record is ours rather than yours, so we set its period rather than you: the security log that records failed sign-ins, password and two-factor changes and administrator sign-ins, together with the IP address and browser each came from. Most of the addresses in it belong to people who are not customers, because an attempt to guess somebody's password is recorded against whoever made it. Those entries are deleted after 180 days. The one exception is the receipt an account erasure leaves behind, which records how many rows and files were deleted and names nobody; it is kept, because it is the only durable evidence that the erasure was carried out. After you cancel, your data is kept for 90 days and then erased, and the export stays available for the whole of that window. Two kinds of record are not yours or ours to delete on a timer, because the law fixes a minimum period for them, and the product enforces those minimums over both your own retention settings and a request to close the account. Financial and tax records are kept for at least 6 years (invoices, credit notes, payments received and recorded, expense claims and the receipts attached to them, and CIS returns and deductions) because of the VAT Regulations 1995 reg 31(1), which requires records of supplies made and received to be preserved for six years, and the Finance Act 1998 sch 18 para 21, which requires company tax records to be kept for six years. The period runs six years from the date of the record itself. Stated plainly because it is not quite the statutory clock: the instruments run from the end of the VAT period or accounting period the record falls in, which is later, and the product does not hold your accounting period. Accident records are kept for at least 3 years (accident and incident reports, including the RIDDOR particulars recorded on them) because of RIDDOR 2013 reg 12(2), which requires a record of a reportable incident to be kept for at least three years from the date on which it was made, and the Social Security (Claims and Payments) Regulations 1979 reg 25(3), which requires accident book entries to be kept for three years from the date of the last entry. The period runs three years from the date the record was made. That is what reg 12(2) says, and it is not always the date of the accident. A retention period you set shorter than one of those is refused when you set it, naming the rule; a record still inside one of those periods is not removed by a retention sweep, and an account closure that would remove one is held until the period has run, with the rule that held it recorded. Apart from those two, we apply no blanket period of our own to your business records, because deleting a customer's records on a timer we chose would be worse than keeping them.

What happens if you close your account

Your account owner can ask us to delete the account from inside the product. The request is held for 90 days so it can be cancelled, and is then carried out by a scheduled job. That job deletes the files you have uploaded first and the database rows second, in that order on purpose: a row without its file is untidy, but a file without its row is an unkept promise and an unfindable one, because nothing is left to say the file is there. It removes your company record and everything the database links to it, the fifteen tables a foreign key would otherwise have stranded, and the accounts of users who belonged to no other company. It cancels your Stripe subscription and deletes the Stripe customer record. If storage refuses a deletion the whole erasure is abandoned rather than committed, so we never record an account as erased while its files are still in the bucket. Every run produces a report listing what was deleted and what was left, and the report outlives the account it describes. Where the account still holds a record the law requires to be kept (a financial record inside its six years, an accident record inside its three), the closure does not run at all. It is held until the last of those periods has expired, the owner is told which rule held it and until when, and nothing is deleted in the meantime; a partial erasure that left the ledger behind and reported success would be a worse answer than a delay we can explain. Three things we cannot reach, and we would rather name them than let the sentence above imply otherwise. Stripe keeps issued invoices and payment records, as its own legal obligations require. Anything we previously pushed into your own accounting system stays in your ledger, where you are the controller and we have no standing to delete it, though our stored credentials for it are destroyed. Erasure does not reach backups. Backups are taken nightly and cover both the database and the files you have uploaded; they are kept 14 days on the host and 35 days off-site, both enforced automatically rather than by hand. Personal data that has been erased from the live service therefore persists in those backups for at most 36 days after erasure, after which no copy remains. Backups are not searched, edited or restored selectively to honour an erasure: production holds write-only credentials for the backup store and cannot read or delete from it, which is the correct security position and the reason the residual exists. The files you upload (photographs, scanned documents, signed PDFs) are inside that residual and not outside it: an erased photograph or scanned certificate survives in a backup for the same bounded window as an erased database row, and is then gone. The same nightly archive is what allows those files to be restored if the server holding them is lost. That is the reason it is taken. We are telling you the first half as plainly as the second. Finally, a user account that belongs to another company as well as yours is kept, because deleting it would lock somebody out of an account that is nothing to do with you.

Your rights

Under UK GDPR you can ask us for a copy of your data, ask us to correct it, ask us to delete it, object to processing, or ask us to restrict it. In the product you can export your company's data and request deletion of the account. Anything else, such as correcting or erasing one individual's records across the system, restricting processing, or objecting, is handled by us on request rather than by a button, and there is no per-person erasure function yet. Email privacy@estimark.co.uk and we will respond within one month. If we are your processor rather than your controller (that is, if the request is about your employee, client or tenant) we will pass it to you rather than answer it, because it is yours to answer. If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk, though we would rather you came to us first so we can put it right.

Security

Traffic is encrypted in transit with TLS and HTTP Strict Transport Security is enforced. Passwords are stored as bcrypt hashes and are never recoverable, by us or anyone else. Employees' National Insurance numbers and bank details, and the credentials for any system you connect, are encrypted in the database with a key held outside it. Access is role-based, two-factor authentication is available, uploaded files are reachable only through short-lived signed links, and every significant action is written to an audit log you can read. Database backups are taken nightly, verified, and copied off-site encrypted, and the production servers hold write-only credentials for them so a compromise of the application cannot destroy historic backups. Uploaded files are not part of that: the backup covers the database only, so a file you upload exists in one place, and we would rather say so plainly than let a general word about backups be read as covering it. We hold no security certification of any kind: no ISO 27001, no SOC 2, no Cyber Essentials. We would rather tell you that than let a badge imply one. No system is perfectly secure.

If we suffer a personal data breach affecting data we hold as your processor, we will tell you without undue delay and in any event within 24 hours of becoming aware of it, and help you make any report you have to make. Where we are the controller, we will report to the Information Commissioner's Office within 72 hours where the law requires it, and tell the people affected where the law requires that. Those are the timescales we are bound by, and we will not dress them up as a rehearsed procedure: the platform records security events and flags anomalies such as repeated failed sign-ins, but the alerting, the on-call rota and the written incident plan that would make those timescales dependable are being built rather than already in place. Until they are, a breach would be handled by the people who run the service. We would rather you knew that than assumed otherwise.

Changes

If we change this policy materially we will tell account holders by email before the change takes effect. The date at the top always reflects the current version.

Build on a solid foundation.

Run the whole business without an implementation project and without legacy baggage. Every plan starts with 14 days free.

Estimating · Jobs · Invoicing · CIS · H&S · Reactive maintenance