Privacy

    Privacy Notice

    How we collect, use and protect your personal data.

    Back to Home

    Last updated: 26 August 2026 (previous version: 19 July 2026)

    FireCheckr is operated by Factor Technologies Ltd, a company registered in England and Wales (company number 16929514) with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("FireCheckr", "we", "us" or "our").

    This notice explains how we collect, use and protect personal data when you visit firecheckr.co.uk (the "Website") or use the FireCheckr fire risk assessment platform, including our web application and our mobile app for iOS and Android (the "App") (together, the "Service"). We are committed to handling personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

    1. Who we are and how to contact us

    Factor Technologies Ltd is the controller of the personal data described in this notice, except where stated otherwise in sections 4 and 5.

    If you have any questions about this notice or how we handle personal data, you can contact us:

    • By email: privacy@firecheckr.co.uk
    • By post: Factor Technologies Ltd, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ

    We are registered with the Information Commissioner's Office (ICO) under registration reference ZC202301.

    2. The personal data we collect

    If you visit our Website

    • Enquiry and demo request details — your name, email address, phone number, organisation, job role and anything you include in your message when you contact us or request a demo.
    • Booking details — when you book a call with us through the appointment scheduler embedded on our Website, your name, email address and chosen appointment time are collected via Google Calendar's appointment scheduling service.
    • Technical and usage data — your IP address, browser type and version, device information, and how you navigate the Website, collected through cookies and similar technologies (see section 6).
    • Attribution data — if you arrive at the Website from an advert or campaign link, we store the campaign identifiers (such as a Google click ID or UTM tags) and the referring site in your browser for up to 30 days, so we know which campaign brought you to us if you go on to book a call (see section 6).

    If you become a FireCheckr client

    • Account data — your name, work email address, password, job role and organisation details when an account is created for you.
    • Billing data — billing contact details and transaction records relating to your subscription.
    • Service usage data — information about how you use the Service, such as features accessed, assessments created and log data, which we use to operate, secure and improve the platform.
    • Support communications — the contents of emails, calls or messages when you contact our support team.
    • App data — if you use the App, the additional data described in section 5.

    3. How and why we use personal data

    UK GDPR requires us to have a lawful basis for each way we use personal data. The table below sets out our purposes and the corresponding lawful bases.

    PurposeLawful basis
    Responding to enquiries and demo requestsLegitimate interests — responding to people who contact us and promoting our Service to prospective clients
    Creating and administering client accounts and providing the ServicePerformance of a contract with you or your organisation
    Billing and managing subscriptionsPerformance of a contract; legal obligation (accounting and tax records)
    Providing customer supportPerformance of a contract; legitimate interests
    Securing, maintaining and improving the Website and ServiceLegitimate interests — keeping our systems secure and making our product better
    Collecting crash and error diagnostics from the AppLegitimate interests — detecting, diagnosing and fixing faults in the App
    App usage analyticsLegitimate interests — understanding how the App is used so we can maintain and improve it; you can object at any time (see sections 5 and 11)
    Sending marketing communications about FireCheckrConsent, or the "soft opt-in" for existing clients under UK e-privacy rules; you can opt out at any time
    Analytics and non-essential cookies on the WebsiteConsent (see section 6)
    Complying with legal obligations and establishing or defending legal claimsLegal obligation; legitimate interests

    Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms and concluded they are not overridden. You can ask us for more information about this assessment, and you have the right to object (see section 11).

    4. Data in fire risk assessments (client content)

    When our clients create fire risk assessments using the Service, the content they upload, enter or capture — including photos, voice recordings and text captured on site with the App (see section 5) — may include personal data (for example, names of responsible persons, duty holders, site contacts or occupants). For that content, our client is the controller and Factor Technologies Ltd acts as a processor, handling the data only on the client's instructions under our data processing agreement. There is one limited exception: as described in section 5, our App usage analytics can capture short snippets of on-screen text from an assessment, and we process those snippets for our own product-improvement purposes, acting as controller for them, with PostHog as our processor. If your personal data appears in a fire risk assessment created by one of our clients, please direct any privacy questions or rights requests to that organisation in the first instance — we will assist them in responding.

    5. The FireCheckr mobile app

    Assessments

    When you carry out an assessment with the App you may take photos, record voice notes and dictation, and type findings on site. This is client content: your organisation is the controller (see section 4). The App uses your camera and microphone only when you choose to, and you can manage those permissions in your device settings at any time.

    AI features

    Microsoft Azure processes assessment content as our sub-processor: voice recordings are converted to text (Azure Speech/Whisper transcription), photos and documents are read for text and structure (Azure Document Intelligence), and typed or transcribed text is used to help draft assessment content (Azure OpenAI). Microsoft does not use this content to train its AI models, and neither do we. AI output is a draft that the assessor reviews and confirms. The App shows you a notice about this processing on first use, and we keep a record of your acknowledgement.

    Crash diagnostics

    Crash reports and error diagnostics (device model, operating system version, app version and error details) are sent to Sentry, our error-monitoring provider, so we can find and fix problems.

    Usage analytics

    We use PostHog to record the screens you view, the features you use, the in-app screen path (which may contain record references such as an assessment ID) and the visible text of items you tap — on assessment screens this can include material from the assessment itself, such as a finding title, client name or premises address, which we process for our own product-improvement purposes as controller (see section 4). Form inputs are never captured, session recording is switched off, and nothing is stored on your device for analytics. Events are linked to your user ID and your organisation's ID. We rely on our legitimate interests in maintaining and improving the App. You can object at any time by emailing support@firecheckr.co.uk; we will stop collecting usage analytics about you unless we have compelling legitimate grounds to continue.

    Deleting your data

    To request deletion of your account or of data collected through the App, contact support@firecheckr.co.uk. Where your data forms part of your organisation's assessments, your organisation is the controller and we may need to refer your request to it (see sections 4 and 11).

    6. Cookies and analytics

    We use cookies and similar technologies (including browser local storage) on the Website and in the Service:

    TypeWhat it doesProvider
    EssentialRequired for the Website and Service to function, for example keeping you logged in and protecting against fraud. These do not require consent.FireCheckr
    AnalyticsGoogle Analytics helps us understand how visitors use the Website (pages visited, time on site, approximate location) so we can improve it.Google
    AdvertisingGoogle Ads conversion tracking tells us when a visit or booking resulted from one of our adverts, so we can measure whether our advertising works.Google
    Product analyticsPostHog helps us understand how visitors interact with the Website (pages visited, clicks, navigation flows) and may record anonymised session replays with all form inputs masked, so we can improve usability. Hosted in the EU.PostHog
    AttributionA first-touch attribution script stores campaign identifiers (Google click ID, UTM tags) and the referring site in your browser's local storage for up to 30 days, so we can link a later booking back to the campaign that brought you here.FireCheckr

    Analytics, advertising and attribution technologies are only used with your consent, which you can give or withdraw at any time through the cookie banner on the Website. You can also control cookies through your browser settings, including deleting cookies and local storage that have already been set. Blocking essential cookies may affect how the Website and Service work.

    The App does not use cookies and stores nothing on your device for analytics. The technologies it uses are described in section 5, together with how to object to usage analytics.

    For more about how Google uses data collected through these services, see how Google uses information from sites that use its services.

    7. Who we share personal data with

    We do not sell personal data. We share it only with:

    • Service providers acting on our behalf, such as cloud hosting, email, payment processing and customer support providers, under contracts that require them to protect the data and use it only on our instructions;
    • Microsoft, whose Azure services provide the AI transcription, document analysis and drafting features described in section 5, acting as our sub-processor for client content;
    • Sentry, which provides crash and error monitoring for the App and the Service, as described in section 5;
    • Google, which provides our website analytics (Google Analytics), advertising measurement (Google Ads) and appointment booking (Google Calendar appointment scheduling), as described in sections 2 and 6;
    • PostHog, which provides our product analytics and session replay, hosted in the European Union;
    • Professional advisers such as accountants, auditors, insurers and lawyers, where necessary;
    • Authorities and regulators where we are required to do so by law; and
    • A buyer or successor in the event of a sale, merger or reorganisation of our business, subject to appropriate safeguards.

    Any third party with whom we share personal data — including the analytics, diagnostics and AI providers named above — is required to provide the same or equal protection of that data as set out in this notice.

    8. International transfers

    We aim to store and process personal data in the United Kingdom or the European Economic Area. Our PostHog analytics and Sentry crash reporting are hosted in the European Union. Some of our other service providers, including Google and Microsoft, may process personal data in the United States or other countries outside the UK. Where that happens, we make sure an equivalent level of protection applies, for example through a UK adequacy decision (including the UK Extension to the EU–US Data Privacy Framework), the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. You can contact us for more information about the safeguards in place.

    9. How long we keep personal data

    • Enquiry and demo request data — kept while we handle your enquiry and for up to 2 years afterwards, in case you return to us.
    • Client account data — kept for the duration of the client relationship and deleted or anonymised within 12 months of the account closing, unless we need to keep it longer for a legal reason.
    • Billing and accounting records — kept for 6 years after the end of the relevant financial year, as required by UK law.
    • Client content (fire risk assessments) — including photos, recordings and text captured with the App: retained and deleted in accordance with our clients' instructions and our data processing agreement.
    • Crash and error diagnostics — retained in Sentry for [●] days and then deleted automatically.
    • App usage analytics — retained for [●].

    When personal data is no longer needed, we securely delete or anonymise it.

    10. How we protect personal data

    We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and limiting access to personal data to those who need it. No system can be guaranteed 100% secure, but we review our measures regularly and will notify you and the ICO of any personal data breach where the law requires us to.

    11. Your rights

    Under UK GDPR you have the right to:

    • Access — request a copy of the personal data we hold about you;
    • Rectification — ask us to correct inaccurate or incomplete data;
    • Erasure — ask us to delete your data in certain circumstances;
    • Restriction — ask us to limit how we use your data in certain circumstances;
    • Data portability — receive the data you provided to us in a machine-readable format;
    • Object — object to processing based on legitimate interests (including App usage analytics and crash diagnostics), and to direct marketing at any time; and
    • Withdraw consent — where we rely on consent (for example, analytics cookies or marketing), withdraw it at any time without affecting the lawfulness of processing before withdrawal.

    To exercise any of these rights, contact us using the details in section 1, or email support@firecheckr.co.uk for requests relating to the App (see section 5). We will respond within one month. These rights are free to exercise, though we may ask you to verify your identity first.

    12. Complaints

    If you are unhappy with how we have handled your personal data, please contact us first so we can try to put things right. You also have the right to complain to the UK's supervisory authority:

    Information Commissioner's Office
    Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
    Helpline: 0303 123 1113
    www.ico.org.uk

    13. Changes to this notice

    We may update this notice from time to time. We will post any changes on this page and update the "Last updated" date above. If the changes are significant, we will take reasonable steps to bring them to your attention, for example by email or a notice on the Website or in the App.