1. Who we are
Subchecked ApS ("Subchecked", "we", "us") operates the Subchecked platform — a compliance management service that helps UK main contractors verify the credentials of their subcontractors before they start on site.
For the purposes of UK data protection law, Subchecked ApS is the data controller for personal data collected through this website, the Subchecked app, and the subcontractor onboarding flow.
Our registered office is in Denmark. All personal data is stored and processed in the United Kingdom (Google Cloud region europe-west2, London).
2. What personal data we collect
2.1 Builders (main contractors)
When you create a Subchecked account as a builder, we collect:
- Full name, company name, company type (sole trader or limited company)
- Companies House registration number (limited companies)
- Email address, phone number
- Company logo (optional — uploaded by you)
- Project details: project name, address, start and end dates, project tier
- Payment information: we use Stripe to process payments. We do not store card numbers or full payment instrument details. We retain Stripe customer and payment intent identifiers for billing history.
- HMRC Government Gateway OAuth2 tokens — used to run CIS subcontractor verification on your behalf. Tokens are stored in Google Secret Manager and are never returned to your browser. You can disconnect your Government Gateway account at any time from account settings.
2.2 Subcontractors
Subchecked collects subcontractor data in two ways: through the one-time onboarding flow (where the builder has invited you via a link) and, if you register an account, through your Subchecked profile and credential vault.
Via onboarding (all subcontractors):
- Name, mobile number, email address, trade type
- CSCS card details: name, registration number, expiry date, card level, trade description; front-face photo of the card; and a card-in-hand photo (a photo of you holding the card in front of you for identity possession purposes). This card-in-hand photo is not processed by any automated facial recognition system. It is reviewed manually by the builder as a visual check.
- Right to Work documents: either a passport or Biometric Residence Permit photograph (OCR-read fields: document number, date of birth, expiry) or a Home Office Share Code and date of birth
- Asbestos R3 Awareness certificate: awarding body, certificate number, issue date, certificate photograph
- Public Liability insurance certificate: insurer name, policy number, indemnity limit, expiry date, insurer contact email, certificate photograph
- Employers' Liability insurance (limited company subcontractors only): same fields as PL
- Gas Safe licence number (gas trade subcontractors only)
- Electrical competency scheme and registration number (electrical trade subcontractors only)
- Letter of Authority (LoA): a PDF recording your consent for Subchecked and your contractor to contact your insurer. The LoA captures your IP address, device identifier, and timestamp at the point of signing as part of the eIDAS Simple Electronic Signature record.
- UTR (Unique Taxpayer Reference) and National Insurance number (for HMRC CIS verification — limited company subcontractors provide Company UTR and Companies House CRN)
If you register a Subchecked account (Free or Pro plan):
- All data from the onboarding flow above
- Account credentials (email address and password via Firebase Authentication, or Google Sign-In)
- Notification preferences
- Pro plan: a persistent credential vault storing the above documents and their verification status; subscription billing data via Stripe
2.3 Credential share recipients (unregistered third parties)
If a Pro plan subcontractor uses the credential sharing feature, they may share a read-only link to their verified credentials with a prospective contractor. The recipient accesses the link after verifying a one-time passcode sent to them. We log the access event (timestamp, IP address) and notify the sharing subcontractor. We do not create an account for the recipient and we do not retain their contact details beyond what was entered by the sharing subcontractor.
2.4 Homeowners
Homeowners are not users of the Subchecked platform. You receive a Homeowner Compliance Pack (a PDF document) at the end of a project, prepared by your builder. We do not collect or store any personal data about homeowners. The PDF does not require you to visit our website or create an account.
2.5 Website visitors and contact form
- Contact form submissions: name, company name, email address, phone number (optional), and message content
- Website analytics: pages visited, session duration, and referral source, via Google Analytics 4. Only set after you accept analytics cookies (see section 8). If you are logged in to a Subchecked account, this activity is linked to your Firebase account ID so we can understand how registered users use the product.
3. How we use your data
We use personal data only for the specific purposes for which it was collected:
| Purpose | Data used |
|---|---|
| Deliver the compliance verification service — running OCR on uploaded documents, storing verification results, generating the Compliance Pack PDF | All subcontractor compliance documents |
| HMRC CIS verification — submitting UTR / NI / CRN to HMRC's API on the builder's behalf and recording the deduction status and verification number | UTR, NI number, CRN, HMRC OAuth tokens |
| Insurance Letter of Authority — generating the LoA PDF, storing it, and providing the pre-populated mailto: link for the subcontractor to send to their insurer | Insurance policy details, subcontractor name, contractor name, eIDAS signature metadata |
| Sending onboarding links and reminders — dispatching the unique link by email | Subcontractor email address |
| Builder account management — profile setup, project creation, billing, notifications | Builder account and payment data |
| Subcontractor account management — vault, Pro plan subscription, sharing features | Subcontractor profile and credential data |
| Responding to contact form enquiries | Name, email, message |
| Website and product analytics — understanding how visitors and registered users navigate the site and product, to improve it | Pages visited, session data, and (for logged-in users) Firebase account ID |
| Complying with legal obligations — responding to subject access requests, data erasure requests, and audit requirements | As required per request |
We do not use your personal data for direct marketing without your explicit consent. We do not sell personal data to third parties.
4. Legal basis for processing (UK GDPR)
All processing of personal data by Subchecked is conducted under one or more of the following lawful bases under Article 6 of the UK GDPR:
| Processing activity | Legal basis | Reference |
|---|---|---|
| Builder account, project, and billing management | Art. 6(1)(b) — performance of a contract | Subchecked Terms of Service |
| CSCS card verification, Asbestos R3 check, Gas Safe/electrical registration check | Art. 6(1)(f) — legitimate interests of the builder (legal duty of care on construction sites under Health & Safety at Work Act 1974) | Legitimate Interests Assessment available on request |
| Right to Work check | Art. 6(1)(c) — compliance with a legal obligation (Immigration, Asylum and Nationality Act 2006; Immigration Act 2014 and 2016) | UK Home Office guidance |
| HMRC CIS verification | Art. 6(1)(c) — compliance with a legal obligation (Finance Act 2004, CIS regulations) | HMRC CIS guidance |
| Insurance Letter of Authority and verification | Art. 6(1)(f) — legitimate interests (builder's obligation to verify adequate insurance under common law duty of care; Employers' Liability (Compulsory Insurance) Act 1969 for EL) | — |
| Subcontractor account and credential vault (registered users) | Art. 6(1)(b) — performance of a contract (Subchecked Terms of Service accepted on registration) | — |
| Contact form processing | Art. 6(1)(f) — legitimate interests (responding to a genuine business enquiry) | — |
| Website analytics | Art. 6(1)(a) — consent (cookie banner) | — |
Note on Right to Work documents. Photographs of passports and Biometric Residence Permits are stored securely and used only to support the Right to Work check. Document photo files are stored in object-locked (WORM) Cloud Storage buckets and cannot be deleted or overwritten after upload. The Home Office's statutory excuse guidance requires employers to retain evidence of checks performed.
5. Third parties and sub-processors
We share personal data only with the third parties necessary to deliver the service. All sub-processors are contractually bound to process data only on our instructions and to maintain appropriate security measures.
| Sub-processor | Purpose | Data location |
|---|---|---|
| Google Cloud (Firebase, Cloud SQL, Cloud Storage, Secret Manager) | Database, authentication, file storage, secrets management | UK — europe-west2 (London) |
| Stripe | Payment processing for project payments and Pro plan subscriptions | EU/US (Stripe DPA applies; SCCs in place) |
| Anthropic (Claude Vision) | OCR extraction from insurance certificates and Asbestos R3 certificates | US (API call; document images sent for processing; Anthropic API terms apply) |
| Microsoft Azure (Azure Document Intelligence) | OCR extraction from CSCS cards, passports, and Biometric Residence Permits | US (API call; document images sent for processing; Azure Data Protection terms apply) |
| Resend | Transactional email delivery (onboarding links, notifications, compliance packs) | EU/US (Resend DPA applies) |
| HMRC (Government Gateway) | CIS subcontractor verification API — receives UTR/NI/CRN; returns deduction status and verification number | UK government infrastructure |
| Google Analytics (Google Ireland Limited) | Website and product usage analytics. Only activated after you accept cookies via the cookie banner — not loaded at all otherwise. | EU/US (Google's EU-U.S. Data Privacy Framework certification and UK IDTA apply) |
5.1 International transfers
Two of our OCR sub-processors (Anthropic and Azure) process document images in the United States. These transfers are made under the UK International Data Transfer Agreement (IDTA) or equivalent safeguards. Document images are transmitted over TLS and are not retained by these providers beyond the duration of the API call, in accordance with their data processing terms.
All other personal data — including all structured records, account data, document files, and audit logs — remains in the United Kingdom (Google Cloud europe-west2).
6. Data retention
| Data category | Retention period |
|---|---|
| Builder account data | Until account deletion request is completed |
| Subcontractor account data | Until account deletion request is completed (self-serve with 24-hour cancellation window, or via support request) |
| Subcontractor compliance documents (CSCS photos, RTW documents, Asbestos certificates, insurance certificates, LoA PDFs, verification screenshots) | Stored in object-locked (WORM) storage; retained for the life of the project plus 6 years (in line with Limitation Act 1980 for construction contract disputes). These files cannot be deleted from storage once uploaded — this is an intentional technical and legal control to protect the evidential integrity of the compliance record. |
| Case and project records (Cloud SQL) | Projects moved to trash are recoverable for 30 days, then permanently deleted. Case records associated with a deleted project are also deleted, subject to the WORM document exception above. |
| Onboarding link tokens | 30-day TTL from creation; expired tokens cannot be used and are purged on deletion |
| HMRC Government Gateway tokens | Stored in Google Secret Manager; deleted on builder account deletion or on explicit disconnection from account settings |
| Credential share links | 7-day TTL; access log retained for 12 months |
| Contact form submissions | Deleted after 12 months if no ongoing business relationship |
| Billing records | 7 years (VAT and financial record-keeping obligation) |
| Website analytics data (Google Analytics) | Retained per the retention period configured in our Google Analytics property (event-level data, up to 14 months) |
7. Your rights under UK GDPR
You have the following rights regarding your personal data. To exercise any of these rights, email privacy@subchecked.co.uk. We will respond within one calendar month.
7.1 Right of access (Subject Access Request)
You may request a copy of the personal data we hold about you. Registered users can initiate a self-serve data export from Account Settings — the export is delivered by email within 24 hours. For unregistered subcontractors, submit a request to privacy@subchecked.co.uk.
7.2 Right to rectification
If any data we hold about you is inaccurate, you may request correction. For compliance document fields (such as OCR-extracted data you reviewed during onboarding), corrections are already captured in the audit log at the time of submission.
7.3 Right to erasure
Registered users can delete their account from Account Settings. Account deletion removes structured personal data (name, email, contact details, payment data) from Cloud SQL and deactivates the Firebase Auth account. Please be aware that document files in WORM object-locked storage buckets cannot be deleted — these are retained as a legal compliance record. We will confirm exactly what has been deleted and what remains when you submit an erasure request.
7.4 Right to restriction
You may request that we restrict processing of your data in certain circumstances (for example, while a rectification request is being resolved).
7.5 Right to data portability
Where processing is based on contract or consent and carried out by automated means, you may request your data in a structured, machine-readable format. The self-serve export from Account Settings delivers your data in JSON and PDF formats.
7.6 Right to object
Where processing is based on legitimate interests (Article 6(1)(f)), you have the right to object. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
7.7 Automated decision-making
Subchecked does not make any automated decisions that produce legal or similarly significant effects about you. Compliance check results (Green / Amber / Red status) are information presented to the builder to support their own judgement — they do not constitute automated decisions by Subchecked.
7.8 Right to lodge a complaint
If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk or 0303 123 1113.
8. Cookies
This website uses cookies in two categories:
- Strictly necessary cookies — required for the service to function (authentication session tokens, CSRF protection). These are not subject to consent.
- Analytics cookies — set by Google Analytics 4 to help us understand how the site and product are used, and improve them. Google Analytics does not run and no analytics cookie is set until you click "Accept" on the cookie banner shown on your first visit.
If you are logged in to a Subchecked account when you accept analytics cookies, your Google Analytics activity is linked to your Firebase account ID so we can understand how registered users use the product. This data is not shared outside Subchecked and Google, our analytics sub-processor (see section 5).
We do not use advertising or tracking cookies. We do not share cookie data with advertisers.
You can change or withdraw your cookie choice at any time using the "Cookie settings" tab shown in the bottom-left corner of any page, which reopens the banner. You do not need to clear your browser's cookies to do this.
9. Contact us and Data Protection
For any privacy-related questions, data subject requests, or to request our Legitimate Interests Assessment, contact us at:
- Email: privacy@subchecked.co.uk
- Post: Subchecked ApS, Data Protection, Fjordglimt 12, 7100 Vejle, Denmark
- UK Representative (Art. 27 UK GDPR): Adam Barnes, Beech Place, St Albans, AL3 5LQ, United Kingdom
We will appoint a Data Protection Officer (DPO) before processing any special category data. At the current stage of the product, we do not process special category data as defined by Article 9 of the UK GDPR. The card-in-hand photograph is not biometric data — no automated biometric processing is performed on this image.
This Privacy Policy may be updated periodically. Material changes will be notified to registered users by email and will be reflected in the "Last updated" date at the top of this page.