Skip to content

Privacy Policy

Last updated 19 August 2026

This policy explains what personal data we collect through subbywise.co.uk and the SubbyWise application, why we collect it, and what you can do about it. We have tried to write it in plain English rather than legal padding.

Who we are

SubbyWise is a UK sole trader business. Our business address is available on request by email. We are the data controller for the personal data described below, and you can reach us at hello@subbywise.co.uk.

What we collect

When you use this website

  • The details you type into a form — your email address, and where you provide them, your name, company, phone number and message.
  • Your IP address at the moment you submit a form, kept purely to stop the forms being abused by bots.

We do not use advertising trackers, and this website sets no cookies of its own. Fonts and other assets are served from our own domain, so browsing the site does not report your visit to a third party.

When you use the SubbyWise application

  • Account details for you and any users you invite — name, email address, role and password (stored only as a secure hash, never in a readable form).
  • The business data you enter: projects, payment applications, invoices, payments, retention, variations and related records.
  • Compliance records you choose to store, which may include operative names, roles, contact details and uploaded certificates.
  • Ordinary technical logs — the time of a request, the page, and the IP address — kept for security and troubleshooting.

Why we use it, and our lawful basis

  • To reply to you and to run your account — performance of a contract, or steps taken at your request before entering one.
  • To tell you when early access opens — your consent, given when you join the waitlist. You can withdraw it at any time by replying to any email or writing to us.
  • To keep the service secure and working — our legitimate interest in protecting the service and its users.
  • To meet legal and accounting obligations — legal obligation.

We do not sell personal data, and we do not share it for anyone else's marketing.

Compliance records and operatives

If you store compliance records, you may be entering personal data about people who work for you — names, roles, contact details and certificates. For that data you are the controller and we are your processor: we hold and process it on your instructions in order to provide the service, and we do not use it for anything else. Please make sure your own staff know their certificates are held in SubbyWise.

A compliance share link is an unlisted URL you create deliberately. Anyone holding the link can see what you chose to include, until it expires or you revoke it — so only send one to people who should have it.

Who we share it with

Only the suppliers needed to run the service, each under a contract that restricts what they may do with it:

  • Our hosting and infrastructure providers, in UK and EU data centres.
  • Our email delivery provider, for messages the service sends you.
  • Professional advisers or authorities where the law requires it.

How long we keep it

  • Waitlist signups — until early access closes, or until you ask us to remove you.
  • Contact enquiries — up to 24 months, so we have the history of a conversation.
  • Account and business data — for as long as your account is open, and normally up to 90 days after it closes so it can be restored if you change your mind. Say the word and we will delete it sooner.
  • Financial records we are legally required to retain — for the period the law requires.

Security

Data is transmitted over HTTPS and stored on managed infrastructure with encrypted backups. Passwords are hashed, never stored in readable form. Uploaded certificates are held in private storage and served only to signed-in users of the company that owns them — they are never on a public URL. Access inside your account is scoped by role: field users cannot see financial data, and an external QS only sees what they need to prepare applications.

No system is perfect. If a breach ever affects your personal data and poses a risk to you, we will tell you and the Information Commissioner's Office without undue delay.

Your rights

Under UK GDPR you have the right to:

  • Ask what personal data we hold about you, and get a copy.
  • Have inaccurate data corrected.
  • Ask us to delete data, where we have no overriding obligation to keep it.
  • Object to, or ask us to restrict, certain processing.
  • Receive data you gave us in a portable format.
  • Withdraw consent at any time, where consent is the basis we rely on.

Email hello@subbywise.co.uk and we will respond within one month. If you are not satisfied you can complain to the Information Commissioner's Office at ico.org.uk.

Changes to this policy

If we change this policy we will update the date at the top, and for anything significant we will tell account holders by email.