How we collect, use and protect your personal data.
Last updated: 26 August 2026 (previous version: 19 July 2026)
FireCheckr is operated by Factor Technologies Ltd, a company registered in England and Wales (company number 16929514) with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("FireCheckr", "we", "us" or "our").
This notice explains how we collect, use and protect personal data when you visit firecheckr.co.uk (the "Website") or use the FireCheckr fire risk assessment platform, including our web application and our mobile app for iOS and Android (the "App") (together, the "Service"). We are committed to handling personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Factor Technologies Ltd is the controller of the personal data described in this notice, except where stated otherwise in sections 4 and 5.
If you have any questions about this notice or how we handle personal data, you can contact us:
We are registered with the Information Commissioner's Office (ICO) under registration reference ZC202301.
UK GDPR requires us to have a lawful basis for each way we use personal data. The table below sets out our purposes and the corresponding lawful bases.
| Purpose | Lawful basis |
|---|---|
| Responding to enquiries and demo requests | Legitimate interests — responding to people who contact us and promoting our Service to prospective clients |
| Creating and administering client accounts and providing the Service | Performance of a contract with you or your organisation |
| Billing and managing subscriptions | Performance of a contract; legal obligation (accounting and tax records) |
| Providing customer support | Performance of a contract; legitimate interests |
| Securing, maintaining and improving the Website and Service | Legitimate interests — keeping our systems secure and making our product better |
| Collecting crash and error diagnostics from the App | Legitimate interests — detecting, diagnosing and fixing faults in the App |
| App usage analytics | Legitimate interests — understanding how the App is used so we can maintain and improve it; you can object at any time (see sections 5 and 11) |
| Sending marketing communications about FireCheckr | Consent, or the "soft opt-in" for existing clients under UK e-privacy rules; you can opt out at any time |
| Analytics and non-essential cookies on the Website | Consent (see section 6) |
| Complying with legal obligations and establishing or defending legal claims | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms and concluded they are not overridden. You can ask us for more information about this assessment, and you have the right to object (see section 11).
When our clients create fire risk assessments using the Service, the content they upload, enter or capture — including photos, voice recordings and text captured on site with the App (see section 5) — may include personal data (for example, names of responsible persons, duty holders, site contacts or occupants). For that content, our client is the controller and Factor Technologies Ltd acts as a processor, handling the data only on the client's instructions under our data processing agreement. There is one limited exception: as described in section 5, our App usage analytics can capture short snippets of on-screen text from an assessment, and we process those snippets for our own product-improvement purposes, acting as controller for them, with PostHog as our processor. If your personal data appears in a fire risk assessment created by one of our clients, please direct any privacy questions or rights requests to that organisation in the first instance — we will assist them in responding.
When you carry out an assessment with the App you may take photos, record voice notes and dictation, and type findings on site. This is client content: your organisation is the controller (see section 4). The App uses your camera and microphone only when you choose to, and you can manage those permissions in your device settings at any time.
Microsoft Azure processes assessment content as our sub-processor: voice recordings are converted to text (Azure Speech/Whisper transcription), photos and documents are read for text and structure (Azure Document Intelligence), and typed or transcribed text is used to help draft assessment content (Azure OpenAI). Microsoft does not use this content to train its AI models, and neither do we. AI output is a draft that the assessor reviews and confirms. The App shows you a notice about this processing on first use, and we keep a record of your acknowledgement.
Crash reports and error diagnostics (device model, operating system version, app version and error details) are sent to Sentry, our error-monitoring provider, so we can find and fix problems.
We use PostHog to record the screens you view, the features you use, the in-app screen path (which may contain record references such as an assessment ID) and the visible text of items you tap — on assessment screens this can include material from the assessment itself, such as a finding title, client name or premises address, which we process for our own product-improvement purposes as controller (see section 4). Form inputs are never captured, session recording is switched off, and nothing is stored on your device for analytics. Events are linked to your user ID and your organisation's ID. We rely on our legitimate interests in maintaining and improving the App. You can object at any time by emailing support@firecheckr.co.uk; we will stop collecting usage analytics about you unless we have compelling legitimate grounds to continue.
To request deletion of your account or of data collected through the App, contact support@firecheckr.co.uk. Where your data forms part of your organisation's assessments, your organisation is the controller and we may need to refer your request to it (see sections 4 and 11).
We aim to store and process personal data in the United Kingdom or the European Economic Area. Our PostHog analytics and Sentry crash reporting are hosted in the European Union. Some of our other service providers, including Google and Microsoft, may process personal data in the United States or other countries outside the UK. Where that happens, we make sure an equivalent level of protection applies, for example through a UK adequacy decision (including the UK Extension to the EU–US Data Privacy Framework), the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. You can contact us for more information about the safeguards in place.
When personal data is no longer needed, we securely delete or anonymise it.
We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and limiting access to personal data to those who need it. No system can be guaranteed 100% secure, but we review our measures regularly and will notify you and the ICO of any personal data breach where the law requires us to.
Under UK GDPR you have the right to:
To exercise any of these rights, contact us using the details in section 1, or email support@firecheckr.co.uk for requests relating to the App (see section 5). We will respond within one month. These rights are free to exercise, though we may ask you to verify your identity first.
If you are unhappy with how we have handled your personal data, please contact us first so we can try to put things right. You also have the right to complain to the UK's supervisory authority:
Information Commissioner's OfficeWe may update this notice from time to time. We will post any changes on this page and update the "Last updated" date above. If the changes are significant, we will take reasonable steps to bring them to your attention, for example by email or a notice on the Website or in the App.