Last updated: 8/26/2026
1. Who We Are & Scope
Hydro Compliance provides a cloud platform for planning and recording water treatment and compliance activities. This policy explains how we handle personal data when you use m.hydrocompliance.uk, our mobile interfaces, and related services. We act as a data controller for account and platform operations data, and as a processor for Customer Data your organisation stores in the Service.
2. Data We Process
- Account & profile: name, email, role, company association, preferences.
- Company & workspace: company name, settings, module subscriptions, logos.
- Operational records: clients, buildings, work orders, job sheets, photos, signatures, assessments, notifications.
- Device & usage: IP address, browser/device info, logs, analytics events, push tokens (e.g., OneSignal IDs/FCM tokens).
- Billing: subscription details and invoices processed by our payment provider (we do not store full card data).
3. Purposes & Legal Bases (UK GDPR)
- Provide and maintain the Service (contract).
- Security, fraud prevention, diagnostics, and service quality (legitimate interests).
- Usage analytics to improve features and performance (legitimate interests).
- Operational notifications and push messages (legitimate interests; consent where required by local law).
- Legal compliance and responding to lawful requests (legal obligation).
- Marketing communications (consent; you can opt out any time).
4. Sharing & International Transfers
We use vetted subprocessors to host and operate the platform (e.g., cloud infrastructure, file storage, email, push notifications, and payments). Examples include hosting providers, OneSignal/FCM for push, and Stripe for billing. Some providers may be outside the UK/EEA; where applicable we use Standard Contractual Clauses or equivalent safeguards.
5. Retention
- Account data: kept for your subscription term and a reasonable period after closure (typically up to 12 months) unless you request earlier deletion.
- Operational records: retained while your organisation maintains them; company admins control deletion/export inside the app.
- Logs and diagnostics: typically up to 12 months; backups may persist for a limited cycle.
6. Security
We apply technical and organisational measures appropriate to risk, including access controls, encryption in transit, audit logging, and least‑privilege principles. No system is perfectly secure; please notify us promptly of any suspected issues via the in‑app Support page.
7. Your Rights
- Access, rectification, erasure, restriction, portability, and objection (subject to legal limits).
- Where processing is based on consent, you may withdraw it at any time.
- You may raise concerns with the UK Information Commissioner’s Office (ICO) or your local authority.
To exercise rights, contact us via the in‑app Support page or our website contact options. For workspace data, please contact your company admin first.
8. Changes
We may update this policy from time to time. Material changes will be communicated in the app; continued use indicates acceptance.