Legal

Privacy policy

Last updated . We change this date by hand, when the document actually changes.

Stathia holds the sort of information that matters: who worked on your site, what they were trained to do, what they signed, and what you're owed. This page says what we do with it, who else touches it, how long we keep it, and what you can make us do about it.

It's written to be read. If anything here is unclear, ask us and we'll answer it plainly rather than sending you back to the paragraph.

1. Who we are

Stathia Ltd, company number 14590630, registered in England & Wales ("Stathia", "we", "us") is the data controller for the personal data described in this policy. Our registered office is in Northamptonshire, UK, and the full registered address is on the Companies House public register and available from us on request.

Data protection questions, requests and complaints: privacy@stathia.com. A person reads that inbox, not a ticketing robot.

We are registered with the Information Commissioner's Office, registration number ZC209215.

Two different relationships run through this policy, and it matters which one you're in:

  • When you deal with us directly — you sign up, email us, book a demo, subscribe — we are the controller of that data.
  • When your employer puts your records into Stathia — your CSCS card, your timesheets, your right-to-work check — your employer is the controller and we are their processor. We act on their instructions. If you want your records changed or removed, start with them; if they're not answering, come to us anyway and we'll help.

2. What we collect

  • Account data — name, work email, company, job role, the password hash (never the password), and a record of when you signed in and from what kind of device.
  • Company and project data — projects, work packages, RAMS, COSHH assessments, permits, lift plans, ITPs, inspections, checksheets, observations, incidents, briefings and toolbox talks, plus the approvals and signatures attached to them.
  • People data your employer records — competence and CSCS cards, training, health assessments, timesheets, payroll and payslips, CIS status, and right-to-work evidence.
  • Files — documents, drawings, specifications, site photographs and certificates you upload.
  • Commercial data — payment applications, certificates, retention, variations, early warnings and compensation events.
  • Billing data — your subscription, plan and invoice history. Card details go to Stripe and never reach our systems.
  • Technical data — IP address and request logs generated by serving the site, and aggregate, cookieless page counts on the public marketing pages only.

We don't buy personal data, we don't enrich it from third-party databases, and we don't track you across other websites.

3. Why we’re allowed to use it

  • Contract — running the account your company pays for: authentication, the product itself, support, invoicing.
  • Legitimate interests — keeping the service secure, preventing abuse, fixing faults, and improving the product. We've weighed these against your interests, and none of them involve profiling you or selling anything about you.
  • Legal obligation — tax, accounting and company-law record-keeping.
  • Consent — the voice assistant, which does nothing until you open it and use your microphone, and any marketing email, which you can stop in one click.

Right-to-work evidence and occupational-health records are special-category or otherwise sensitive data. Your employer collects those under employment-law obligations; we hold them on their behalf, encrypt them at rest, and restrict them to the roles that genuinely need them.

4. What happens when you use the AI

Stathia's AI drafts safety and quality documents from what you give it. That means text leaves our servers and goes to our AI provider, and you deserve the exact shape of that.

  • What is sent — the scope, specification, drawing text and document content you attach to that specific draft, plus the prompt describing the document you want.
  • Who it goes to — Anthropic, in the United States, using the Claude model family. This is the one point in the product where content is processed outside the UK.
  • What comes back — the draft, which is saved into your account as your document, for you to check, edit and approve. Every generated document carries a notice that a competent person must review it before it's relied on.
  • What we never do — we don't use your data to train AI models, we don't allow our provider to train on it, and we don't pool one customer's documents into another customer's drafts.
  • Your choice — the AI is a feature, not the plumbing. Every module works without it. If you'd rather nothing left the UK, don't use the drafter, and tell us so we can note it on your account.

The optional voice assistant works the same way: your speech goes to ElevenLabs to be transcribed and answered, and nothing from it is written into your account.

5. Who else touches your data

These are every third party that processes data on our behalf. The list is compiled from the codebase rather than from memory, and it changes here before it changes in production.

WhoWhat they doWhere
VercelRuns the application itself — every page and API request is served by Vercel’s compute.London, United Kingdom (region lhr1)
Vercel BlobStores the files you upload — documents, site photographs, certificates and right-to-work evidence.London, United Kingdom (private store “stathia-private”, region lhr1)
NeonHosts the PostgreSQL database that holds your projects, people, records and approvals.AWS London, United Kingdom (eu-west-2)
AnthropicThe AI model that drafts RAMS, COSHH assessments, permits, lift plans, briefings, toolbox talks and ITPs. It receives the scope, specification and drawing text you give it for that document, and returns the draft.United States
ResendSends transactional email — invitations, password resets, expiry alerts and notifications. Never marketing lists.United States and European Union
StripeTakes subscription payments and runs the billing portal. Card details go to Stripe directly and never touch Stathia’s systems.United States, European Union and United Kingdom
ElevenLabsonly if you use itPowers the optional voice assistant. If you talk to it, your speech is sent to ElevenLabs to be transcribed and answered. If you never open it, it receives nothing.United States
Vercel AnalyticsCounts page views on the public marketing pages. Cookieless and aggregated — it does not identify you and is not used inside the signed-in product.European Union and United States

Where a provider processes data outside the UK, the transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or by UK adequacy where it applies. We don't sell data, we don't share it with advertisers, and no other Stathia customer can see yours.

More on where everything physically lives: data residency.

6. How long we keep it

Not "as long as necessary". Here are the actual periods, and why each one is what it is.

WhatHow longWhy
Your account (name, work email, role, sign-in history)While your company’s account is open, then 12 monthsSo an account can be reopened, a leaver’s access questioned, or a dispute answered.
Your company’s records (projects, RAMS, permits, ITPs, inspections, checksheets, competence records)While the account is open. After it closes: 30 days to export, then deleted within 90 daysYou own this data. The window exists so nobody loses a year of evidence to an unpaid invoice.
Audit trail (who approved what, and when)Kept for the life of the account, deleted with itAn approval record with the trail stripped out isn’t evidence any more.
Right-to-work evidence (ID documents, share codes)Encrypted at rest, and deleted 2 years after the person’s engagement ends — or sooner if you askHome Office guidance on retaining right-to-work checks. It is the most sensitive thing in the system and it is treated that way.
Timesheets, payroll and payslips6 years after the end of the tax year they relate toHMRC record-keeping requirements for PAYE and CIS.
Billing records (subscriptions, invoices, payment history)6 years after the end of the financial yearCompanies Act 2006 and HMRC requirements for accounting records.
Support enquiries, contact-form messages and demo requests24 months from your last contact with us, or sooner on requestLong enough to remember the conversation you had; short enough not to hoard it.
AI drafting — what you send and what comes backHeld as the document inside your account, for as long as that account is openThe draft is your record. It is not kept separately by us, and it is not used to train models.
Voice assistant recordings and transcriptsNot stored by Stathia. Handled by ElevenLabs for the duration of the conversationThe assistant answers a question and forgets it. Nothing goes into your account.
Uptime and service checks90 daysEnough history to show a real uptime figure on /status. Contains no personal data.
Platform request logsA short rolling window held by our hosting providerUsed for security and fault-finding only, and never for anything else.
BackupsDeleted data can persist in database backups until they age out of the recovery windowPoint-in-time recovery is what stops a bad afternoon becoming a lost year. Backups are encrypted and access-controlled.

Health-and-safety records carry statutory retention periods of their own — accident and RIDDOR records, health-surveillance records, and the rest. Those obligations sit with your company as the employer. Stathia keeps the records available and exportable so you can meet them; it doesn't discharge them for you.

7. How it’s protected

  • Everything travels over TLS, and the database is encrypted at rest with point-in-time recovery.
  • Right-to-work evidence is separately encrypted, and served through an authenticated, company-scoped route rather than a public file link.
  • Every query is scoped to your company. Access inside your company is scoped again by role — a quantity surveyor and a site operative do not see the same screens.
  • Passwords are hashed, never stored or recoverable. We will never ask you for yours.
  • Access to production is limited to the people who build and run Stathia, and is used to operate the service, not to browse it.

We don't claim certifications we don't hold. Stathia is not ISO 27001 certified today, and where we get to on formal certification, we'll say so on data residency rather than in a badge.

If a breach affects your personal data and is likely to risk your rights, we'll tell the ICO within 72 hours of becoming aware, and tell you without undue delay where the risk to you is high.

8. Your rights

Under UK GDPR you can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct anything that is wrong.
  • Delete it, where we don’t have a legal reason to keep it.
  • Restrict or object to what we’re doing with it.
  • Hand it over in a portable format — and every account admin can already export the company’s entire dataset from Settings, at any time, without asking us.
  • Withdraw consent for anything you consented to, such as the voice assistant or marketing email.

Write to privacy@stathia.com and we'll answer within one month. If your data is in Stathia because your employer put it there, we'll pass the request to them and tell you we've done it.

If we get it wrong, you can complain to the Information Commissioner's Office — ico.org.uk, or 0303 123 1113. We'd rather you came to us first, but it's your right either way.

9. Cookies

Stathia sets a session cookie when you sign in, and a small number of cookies that remember your preferences inside the app. They are strictly necessary — without them you can't stay signed in — so they don't need consent and there's no banner asking for it.

The public marketing pages use aggregate, cookieless analytics. No advertising cookies, no third-party trackers, no pixels.

10. Changes, and how to reach us

When this policy changes materially we'll email account admins and change the date at the top by hand. There is no silent update.

Privacy: privacy@stathia.com. Anything else: support@stathia.com. This policy is governed by the law of England & Wales.

Stathia Ltd, company number 14590630, registered in England & Wales. Terms of service.