Privacy • UK GDPR / EU GDPR
Privacy & Cookies
How Fire Door App handles your data. This Privacy Notice explains how we ("Fire Door App", "us") process personal data — including workspace accounts, inspection data, Stripe billing, and support.
In most cases we provide the platform and act as a data processor for your workspace. Your organisation controls the data it enters into Fire Door App. This page is a high-level overview — not legal advice. Your own organisation remains responsible for its compliance obligations.
1. Who this notice covers
Fire Door App is a multi-tenant platform used by fire door contractors, FM teams, and housing providers. Each workspace holds its own data. This notice covers everyone who interacts with the platform — workspace owners, team members, and end users.
Who we are — data controller
For the data we control (your account, billing, marketing, and service logs — see the roles below), the data controller is:
- Legal entity: FireDoorApp Ltd
- Company number: 16988496 (registered in England & Wales)
- ICO registration: ZC097815 (registered with the UK Information Commissioner's Office)
- Privacy contact: privacy@firedoorapp.co.uk
For the personal data inside a customer's workspace (inspections, doors, client contacts), the customer is the controller and we act as their processor — see the roles below.
Workspace owners
Usually the data controller for inspections, doors, and client records in their workspace
Platform provider
We act as processor for most in-app data; controller for our own account, billing, and service logs
End users
Team members using the app, portal users, and client contacts named on inspections, quotes, and invoices
Resident contacts
If you have questions about inspections at your building, contact the organisation that commissioned the work first
Workspace isolation
Separate tenants per customer
- Isolated tenants per customer
- Separate client data per workspace
- Role-based user access
- Audit and activity logs
- Data not mixed between customers
Privacy overview
Three areas at a glance
- Control: workspace-level control + tenant isolation
- Records: inspections, doors, documents, portal activity
- Billing: Stripe billing + audit/security logs
2. Data we process and why we use it
The platform stores different kinds of personal data depending on how your organisation uses it. We use that data for a small number of clear purposes, each with a defined legal basis.
Why we use this data — legal bases
We rely on a small number of straightforward legal bases under UK GDPR / EU GDPR.
Contract
Providing the Fire Door App service
- Creating and administering workspaces, user accounts, and subscriptions
- Storing and presenting inspections, doors, remedials, RAMs, quotes, and invoices
- Sending essential service emails: invites, password resets, and important notices
Legitimate interests
Security, reliability, and improvement
- Maintaining security: logging login events, door tag scans, and error reports
- Generating anonymised analytics to understand feature usage and improve workflows
- Responding to support requests and operating admin health dashboards
Legal obligations
Billing, tax, and compliance
- Maintaining billing and invoice records for tax and accounting purposes
- Recording plan choices, Stripe subscription status, and payment outcomes
Consent
Optional updates and marketing
- Optional product updates sent only with appropriate consent or soft opt-in
- You can opt out at any time
- Workspace owners remain responsible for their own use of exported contact details
How long we keep data
We keep personal data only as long as we need it for the purposes above, then delete or anonymise it. Where we act as processor for a workspace, the customer's own retention choices apply; the periods below are our defaults.
| Data | How long we keep it |
|---|---|
| Account & workspace | For the life of the workspace. You can delete your account or workspace from within the app at any time — scheduled with a ~30-day grace window, or immediately. Separately, after your subscription ends you can export for ~30 days, then remaining data is deleted (~90 days). In all cases residual copies then clear from encrypted database backups within ~7 days, and deleted files are permanently removed from object storage within ~30 days. |
| Inspection & operational records | Held in the workspace and controlled by the customer; kept for the life of the workspace and deleted with it (as above), unless the customer deletes them sooner. |
| Billing, invoice & tax | 6 years — to meet UK tax and accounting requirements. |
| Support correspondence | Up to 24 months after your request is resolved. |
| Security & login events | 6 months — login and authentication security events, kept so we can investigate account-security issues. (Your account's "last login" time is kept for the life of the account.) |
| Service & admin logs | 6 months for service/admin activity; email delivery logs 90 days. |
| Marketing analytics | 90 days for anonymous page statistics, then deleted. |
We may keep specific records longer where the law requires it, or to establish, exercise, or defend legal claims.
3. Cookies, storage, and data location
Fire Door App uses a small number of technical cookies and storage mechanisms to keep you signed in, remember your workspace, and support offline-friendly workflows on site.
Technical cookies — strictly necessary
| Cookie / key | Purpose | Duration |
|---|---|---|
FIRE_DOOR_SUITEPHP session cookie |
Keeps you signed in across requests for your current session. Required for the service to function. | Session (up to ~24 hours) |
firedoor_tenant |
Remembers which workspace you are currently working in so the correct data is loaded on each request. | ~30 days (cleared on sign-out) |
firedoor_tenant_scope |
Stores the scope of your current workspace session to apply correct role-based access controls. | ~30 days (cleared on sign-out) |
firedoor_tenant_sig |
A signed token that protects tenant selection and prevents cross-tenant access. Required for security. | ~30 days (cleared on sign-out) |
firedoor_cache_version |
Versions your device's offline caches for the current workspace login. Used when you choose "Clear offline cache" in Settings to invalidate stale cached data on your device. | ~12 months |
fd_consent_v1 |
Remembers your cookie choice (whether you accepted or declined optional analytics) so we don't ask again on every visit. | ~12 months |
firedoor_register_email |
Briefly carries the email you typed on the sign-up page so the registration form can pre-fill it. | 15 minutes |
mkt_eo_vid |
An anonymous token used to limit how many example-output sample PDFs a visitor can download (abuse prevention). Marketing site only. | ~12 months |
These cookies are used only to provide the service. They are not used for third-party advertising or cross-site tracking.
Analytics — optional
If you opt in, we may use Google Analytics 4 to understand site usage — for example, which pages are visited and how long people spend on the marketing site. This helps us improve the site and onboarding experience.
- Analytics cookies are optional and are not loaded until you choose "Accept analytics".
- You can change your preference at any time via Cookie settings in the footer.
- We do not use Google Analytics for cross-site advertising or to build advertising profiles.
If you opt in and you arrived from a Google ad, we also store a Google Ads click identifier so we can measure which ad led to a signup (offline conversion measurement):
_fd_gclid— the Google Ads click id (gclid) from your ad click, kept in your browser's local storage for up to 90 days. It is only stored after you accept analytics, is never stored if you decline, and is cleared if you withdraw consent. If you complete a signup it is recorded against your account so the conversion can be reported to Google Ads.
Anonymous page statistics — first-party, no cookies
We keep anonymous page statistics for the marketing site, the public demo, and the signup / sign-in flow — which pages are visited, approximate time on page, scroll depth, and aggregate funnel drop-off. Statistics are never tied to your name, email, IP, or browser fingerprint on our server.
Two small values are stored locally in your browser to make the statistics useful (e.g. so we can tell that a visit to /contact and a follow-up visit to /pricing came from the same browser, without learning who you are):
_fd_v— a random 32-character anonymous identifier, regenerated every 60 days. We never receive your name, email or IP alongside this token. If you complete a workspace signup, the token is recorded against the resulting account so we know which marketing visit led to the signup; it is not shared with any third party._fd_attrib— a copy of any utm_source / utm_medium / utm_campaign values from the URL you originally arrived on, kept for up to 90 days so cross-page attribution works.
Both values are first-party, kept entirely in your browser's local storage, and can be cleared at any time by clearing this site's storage in your browser settings. We don't set tracking cookies for this purpose, and the values are not used for cross-site advertising.
- No IP address, User-Agent, or browser fingerprint is stored on our server.
- Server-side records are retained for 90 days, then deleted.
- Lawful basis: legitimate interests (UK GDPR Art 6(1)(f)). We have completed a Legitimate Interests Assessment (LIA) for this activity. Email privacy@firedoorapp.co.uk for a copy of the signed LIA or our DPA — we'll send it back within 24 hours.
Local storage & offline queues
Where enabled, Fire Door App can queue inspection data offline on your device so it can be synced when connectivity returns.
- Offline queues are stored in browser storage (such as IndexedDB or localStorage) and are tied to your device and browser profile.
- Offline queues and cached pages are scoped to your workspace and user account within this browser profile.
- Queued data is submitted back to the workspace as part of your normal use of the app, or can be removed using "Clear offline cache" in Settings — this clears cached pages and any offline drafts for your current workspace login on this device.
Even with scoping, anyone with access to your device and browser profile may be able to view cached copies. Protect devices accordingly — OS login protection and disk encryption where appropriate.
Hosting & data location
Fire Door App is designed for UK/EU teams and typically stores data in EU regions.
- Core application and database hosting is provided by reputable infrastructure providers in EU regions.
- File storage (photos and floorplans) may use cloud object storage in an EU region.
- Stripe acts as a separate processor for payments and subscription billing.
- International transfers: some providers may process limited data outside the UK/EEA, including in the United States — for example Stripe (payments), Cloudflare Turnstile (contact-form anti-spam), and Google Analytics if you opt in. Where that happens we rely on appropriate safeguards, such as the UK International Data Transfer Agreement/Addendum or the EU Standard Contractual Clauses. Our EU hosting is covered by the UK's data-adequacy regulations for the EEA.
Subprocessors
Key service providers we rely on to operate Fire Door App. This list is intentionally high-level — procurement can request the current named subprocessor list and locations via the Contact page.
| Category | What they do | Region |
|---|---|---|
| Hosting | Infrastructure providers that host the core application and tenant-isolated databases. | EU |
| File storage | Object storage for uploads such as inspection photos and floorplans. | EU |
| Email delivery | Transactional email (via Amazon SES) for signup verification, invites, and workspace notifications. | EU |
| Payments | Stripe for subscription billing and payment processing. Stripe is a separate data processor subject to its own privacy policy. Card details are handled entirely by Stripe — Fire Door App does not store full card numbers or CVV codes. | Stripe (own DPA) |
| Anti-spam | Cloudflare Turnstile protects our contact form from spam and bots. It processes limited technical data (such as your IP address) to run that check. | US/global (SCCs) |
| Analytics (optional) | Google Analytics 4 — used only if you accept analytics cookies, to measure marketing-site usage. Not loaded without your consent. | US (SCCs) · consent |
Need the named subprocessor list for procurement? Request it via the Contact page. We provide current names and locations on request.
Your rights and how to contact us
If you are in the UK or EU, you generally have the following rights over personal data. For data held inside a workspace, contact your workspace owner or admin in the first instance (they are the controller). For the data we control ourselves — your account, billing, marketing, and portal-account data — contact us directly using the details in "Who we are — data controller".
Access & correction
Ask to see and update personal data held about you. Usually by contacting your workspace owner or admin for data inside the app.
Deletion & retention
Delete your account yourself in the app — team members via Security → Delete my account, owners via Settings → Delete workspace — or, if you've uninstalled, request it at firedoorapp.co.uk/delete-account. We permanently erase your data and keep only what the law requires (billing and tax records, ~6 years, plus a minimal record of the deletion).
Objection & restriction
Object to certain uses of your data (for example direct marketing) or ask us to limit processing in specific situations.
Portability
Receive a copy of your personal data in a portable format where processing is based on consent or contract and is carried out automatically.
Withdraw consent
Where we rely on your consent (such as optional analytics or marketing emails), you can withdraw it at any time — via Cookie settings for analytics, or the unsubscribe link in any marketing email. This does not affect processing carried out before you withdraw.
Complaints
Raise concerns with your local data protection authority if you believe your rights have been infringed. In the UK: the Information Commissioner's Office (ICO).
Contact us
For questions about how the platform itself handles data: via the in-app Support area, or at privacy@firedoorapp.co.uk.
Need to discuss data handling in more detail? We can walk through where data lives in Fire Door App, how Stripe is used for billing, and how to export records for your own retention policies. Best next step: run a test building through your trial and review the resulting records with your compliance lead.
Changes to this notice
We may update this Privacy & Cookies notice from time to time — for example to reflect changes to the service, our sub-processors, or the law. The current version is always on this page, with the "last updated" date shown at the top. For significant changes we will take reasonable steps to bring them to your attention (for example a notice in the app or by email).
Children, vulnerable people & automated decisions
- Children: Fire Door App is a business tool for adults and is not intended for, or directed at, children. Accounts are for users aged 18 or over, and we do not knowingly collect personal data from children as users of the platform.
- Children & vulnerable people in inspection content: inspections and surveys sometimes take place in schools, hospices, hospitals, and care homes. Our customers (as controllers) are responsible for capturing only what the inspection needs and for not including identifiable people — especially children, patients, residents, and other vulnerable individuals — in photos beyond what is necessary, and for following their own safeguarding and data-protection duties (including a DPIA where required). We store the images our customers capture; we do not choose or review their content.
- Automated decisions: we do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.