Legal

Privacy Policy

How we collect, use, and protect your personal data when you use the DoorTrace platform.

Last updated: September 2026Version 1.2

1. Introduction

DoorTrace ("we", "our", or "us") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our fire door inspection and compliance management platform.

DoorTrace is operated by DoorTRACE Holdings Ltd, a company registered in England and Wales. We act as a data processor on behalf of Facilities Management companies (our clients) who are the data controllers for the personal data processed through our platform. We are the data controller for account and billing contact details, login and security records, and the accounts and documents of engineers who hold their own DoorTRACE login and work for more than one company.

This policy applies to all users of our platform, including FM company administrators, engineers, building managers, and anyone who interacts with our services.

2. Data We Collect

We collect and process the following categories of personal data:

Account Information

When you create an account or are added as a user, we collect your name, email address, phone number, job title, and professional qualifications (for engineers).

Inspection Data

When conducting fire door inspections, we collect location data (GPS coordinates), photographs of doors and defects, inspection notes, timestamps, and digital signatures.

Building Information

We collect building addresses, floor plans, door locations, and details about Responsible Persons as required by fire safety regulations.

Technical Data

We automatically collect device information, IP addresses, browser type, operating system, and usage data to ensure platform security and improve our services.

Crash and Performance Data

When you use our mobile app, we collect anonymous crash reports, performance traces, and device diagnostics to identify and fix technical issues. This data is processed by our error monitoring service (see Section 5) and is not linked to your account identity.

Communication Data

If you contact us, we keep records of correspondence including emails, support tickets, and enquiry form submissions.

3. How We Use Your Data

We use your personal data for the following purposes:

Service Delivery

To provide our fire door inspection and compliance management platform, including processing inspections, generating reports, and maintaining audit trails required by UK fire safety regulations.

Legal Compliance

To help our clients meet their obligations under the Fire Safety (England) Regulations 2022, Building Safety Act 2022, and other applicable legislation. The Golden Thread requirements mandate that we maintain comprehensive digital records.

Communication

To send you service-related notifications, including inspection reminders, compliance alerts, and important updates about your account.

Platform Improvement

To analyse usage patterns, identify issues, and improve our platform's functionality and user experience.

Security

To detect, prevent, and respond to security incidents, fraud, or other malicious activity.

5. Data Sharing

We share your personal data with the following categories of recipients:

FM Companies (Data Controllers)

The Facilities Management company that employs you or manages your building has access to relevant inspection and compliance data.

Building Clients

Building managers and Responsible Persons can access compliance reports and inspection data for their buildings.

Service Providers

We use three trusted service providers: Cloudflare (hosting, database, photos and files, and our website), Resend (email delivery, United States) and Sentry (error monitoring, European Union). These providers act as data processors on our behalf and are contractually bound to protect your data. Our invoicing software holds our own billing records and does not process inspection data.

Regulatory Authorities

We may disclose data to fire safety authorities, local councils, or other regulatory bodies when required by law or in response to valid legal requests.

Professional Advisors

We may share data with our lawyers, accountants, and insurers where necessary for legal, accounting, or insurance purposes.

We never sell your personal data to third parties.

6. Data Retention

We retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, and contractual requirements.

Inspection Records

Fire door inspection records are kept for as long as the customer's account is open. When a customer leaves, a copy of their records is sent to them and, on the customer's instruction under their agreement with us, a locked archive copy is kept for 7 years so the records can be retrieved if they are ever needed again. The customer may ask us to delete the archive earlier. Fire safety legislation expects that inspection records are kept and available; the exact period is for each customer to decide.

Account Data

User account information is kept for the duration of the customer's account and then as part of the customer's archived records for 7 years, unless the customer asks for earlier deletion.

Audit Logs

Platform audit logs cannot be edited or deleted through the Platform, so historical records keep their integrity. They are kept for the duration of the customer's account and then as part of the 7-year archive, and are deleted with it.

Communication Records

Support and enquiry records are retained for 3 years after the last communication.

When data is no longer required, we securely delete or anonymise it in accordance with our data retention policies.

7. Your Rights

Under UK data protection law, you have the following rights:

Right of Access

You can request a copy of the personal data we hold about you.

Right to Rectification

You can request that we correct any inaccurate or incomplete personal data.

Right to Erasure

You can request deletion of your personal data. Where your data forms part of a customer's inspection records, deletion is subject to that customer's instructions to us, because the customer is the data controller for those records.

Right to Restrict Processing

You can request that we limit how we use your data in certain circumstances.

Right to Data Portability

You can request your data in a structured, commonly used, machine-readable format.

Right to Object

You can object to processing based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that significantly affect you.

To exercise any of these rights, please contact us at privacy@doortrace.co.uk.

8. Data Security

We implement robust technical and organisational measures to protect your personal data:

Encryption

All connections to the Platform are encrypted in transit (HTTPS).

Authentication

Passwords are stored only in hashed form, access tokens expire after a short time, and multi-factor authentication is available.

Separation and Access Controls

Each customer's data is separated from every other customer's, and every request is checked against the account it belongs to. Access depends on role: engineers, company logins and Client Portal users each see only what their role allows.

Audit Log

Important actions, including deletions and password-protected changes, require the user's password and are recorded in an audit log that cannot be edited through the Platform.

Infrastructure Security

The Platform is hosted on Cloudflare's network, with protection against denial-of-service attacks and a web application firewall. The database can be restored to an earlier point in time if data is lost or damaged, and errors are monitored so that faults are found and fixed quickly.

Staff Access

Access to live data by DoorTRACE staff is limited to what is needed to provide, support or protect the Platform.

Incident Response

If a personal data breach affects a customer's records, we tell that customer without undue delay and within 48 hours of becoming aware of it.

9. International Data Transfers

DoorTrace stores inspection records, photographs and files on Cloudflare's global network. Our email delivery provider, Resend, processes email in the United States, and our error monitoring provider, Sentry, in the European Union.

Where personal data is transferred outside the UK, we use a safeguard recognised under UK data protection law, such as:

UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses.

You can contact us for more information about the specific safeguards we use for international data transfers.

10. Cookies and Tracking

Our platform uses cookies and similar technologies to ensure proper functionality, enhance security, and improve your experience.

Essential Cookies

Required for the platform to function correctly, including authentication tokens and security cookies. These cannot be disabled.

Analytics Cookies

Help us understand how users interact with our platform so we can improve it. You can opt out of analytics cookies through your browser settings or our cookie preferences.

Preference Cookies

Remember your settings and preferences to provide a more personalised experience.

We do not use advertising cookies or share cookie data with third-party advertisers. For more details, see our Cookie Policy.

11. Children's Privacy

DoorTrace is a business-to-business platform intended for use by adult professionals in the fire safety and facilities management industries. We do not knowingly collect personal data from children under the age of 16.

If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information promptly. If you believe we may have collected data from a child, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or industry standards. When we make material changes, we will:

Notify you via email or through a prominent notice on our platform at least 30 days before the changes take effect, update the "Last Updated" date at the top of this policy, and where required by law, seek your consent to the changes.

We encourage you to review this policy periodically to stay informed about how we protect your data.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, or if you wish to exercise your rights, please contact us:

Data Protection Officer

Email: privacy@doortrace.co.uk Telephone: 0800 310 1300

Postal Address

DoorTRACE Holdings Ltd 8 Niche Place Brook Road Redhill RH1 6DL United Kingdom

Information Commissioner's Office

If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Website: ico.org.uk Telephone: 0303 123 1113