Privacy Policy
Last updated: 1 April 2026 ยท Effective for all WireWrite UK accounts
This privacy policy explains how Phase Logic Ltd ("we", "us", "our") collects, uses, stores, and protects your personal information when you use WireWrite ("the Service"). We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
The data controller for information collected through the Service is:
Phase Logic Ltd
Contact: Support form
2. Information We Collect
2.1 Information you provide
- Account information — your name, email address, and password (or Google profile if using OAuth).
- Professional information — your Competent Person Scheme registration details (NICEIC, NAPIT, ELECSA, STROMA, BESCA), JIB grade, or other UK electrical qualifications.
- Certificate data — client names, addresses, phone numbers, job details, test results, and signatures you enter when creating certificates.
- Company information — company name, address, phone number, Companies House registration number, and logo (for company accounts).
- Payment information — billing details are collected and processed by Stripe; we do not store card numbers.
2.2 Information collected automatically
- Usage data — pages visited, features used, and session duration (via Google Analytics).
- Device information — browser type, operating system, screen resolution, and IP address.
- Cookies — authentication tokens and session cookies necessary for the Service to function.
2.3 Google OAuth data
If you sign in with Google, we access your email address and basic profile information (name and profile photo) via Google OAuth. We do not access your Google contacts, calendars, files, emails, or any other Google services data.
3. How We Use Your Information
We use your personal information for the following purposes:
- Providing the Service — creating your account, generating certificates, and processing payments.
- Authentication — verifying your identity and maintaining your session.
- Communication — sending certificate emails to your clients, account notifications, trial reminders, and support correspondence.
- Legal compliance — retaining certificates as required by UK electrical regulations.
- Service improvement — analysing anonymised usage patterns to improve features and performance.
We do not use your data to serve advertisements, build advertising profiles, sell to third parties, or train machine learning models.
4. Legal Basis for Processing
We process your personal data on the following legal bases under UK GDPR Article 6:
- Contract (Article 6(1)(b)) — processing necessary to provide the Service you have signed up for.
- Legitimate interest (Article 6(1)(f)) — improving the Service, preventing fraud, and ensuring security.
- Legal obligation (Article 6(1)(c)) — retaining certificate records as required by law.
- Consent (Article 6(1)(a)) — where you have opted in to receive marketing communications (you may withdraw consent at any time).
5. Data Sharing
We share your data only with the following service providers, each of whom processes data on our behalf:
- Supabase (database & authentication) — stores your account and certificate data securely in cloud infrastructure.
- Stripe (payment processing) — receives your email and billing details to process subscription payments.
- Vercel (hosting) — serves the application; receives standard web request data (IP address, user agent).
- Google Analytics — receives anonymised usage data to help us understand how the Service is used.
- Certificate recipients — when you email a certificate to a client, they receive the certificate data you created.
We do not sell, rent, or trade your personal information to any third parties.
6. International Data Transfers
Phase Logic Ltd is based in New Zealand. Your data may be transferred to and processed in countries outside the United Kingdom, including New Zealand, the United States (where our cloud infrastructure providers operate), and Singapore (where our database is hosted).
New Zealand has been granted an adequacy decision by the UK government, meaning your data receives an equivalent level of protection when transferred there. For transfers to other countries, we rely on standard contractual clauses and the security measures implemented by our service providers.
7. Data Retention
- Issued certificates — retained for a minimum of 7 years from the date of issue, as required by UK electrical regulations and BS 7671.
- Draft certificates — retained for 90 days from last modification, then permanently deleted.
- Account data — retained while your account is active. Upon account deletion, all personal data is permanently removed within 30 days.
- Usage analytics — anonymised data is retained for up to 26 months.
8. Data Security
We implement appropriate technical and organisational measures to protect your data:
- All data is encrypted in transit (TLS/HTTPS) and at rest.
- Account data and certificates are stored in Supabase-managed PostgreSQL databases with row-level security.
- Access to production systems is restricted to authorised personnel only.
- Two-factor authentication (2FA) is available and recommended for all user accounts.
- Payment data is handled entirely by Stripe (PCI DSS compliant) and is never stored on our servers.
- Digital signatures are stored as encrypted data associated with your account.
9. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right of access — you can request a copy of the personal data we hold about you.
- Right to rectification — you can update your personal information at any time through your account settings.
- Right to erasure — you can request deletion of your account and all associated personal data (the "right to be forgotten").
- Right to data portability — you can download your certificates as PDF files at any time from your dashboard.
- Right to object — you can object to processing based on legitimate interest.
- Right to restrict processing — you can ask us to restrict how we use your data while a dispute is resolved.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.
- Right to lodge a complaint — you have the right to lodge a complaint with the ICO if you believe your data has been mishandled.
To exercise any of these rights, contact us via our support form. We will respond within 30 days as required by UK GDPR.
10. Cookies
WireWrite uses only essential cookies required for the Service to function:
- Authentication cookies — to keep you signed in during your session.
- Preference cookies — to remember your settings.
We also use Google Analytics, which sets its own cookies to collect anonymised usage data. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
11. Children's Privacy
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.
12. Google API Services
WireWrite's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only use Google user data for authentication and do not use it for advertising, profiling, or any purpose unrelated to the Service.
13. Supervisory Authority
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
14. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated by email or through a notice on the Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
15. Governing Law
This privacy policy is governed by the laws of England and Wales. See also our Terms of Service for the full terms covering use of WireWrite.