Last updated: 14 August 2026
Raven Technical Services Limited is a health and safety consultancy registered in England and Wales (Company No. 17282046). We produce Risk Assessment and Method Statement (RAMS) documents for contractors carrying out structural and architectural steelwork and metalwork site installations.
We are registered as a data controller with the Information Commissioner's Office (ICO) under Tier 1. ICO Reference: ZC177447.
For any privacy-related queries, contact us at the email address registered to your account.
When you create an account and use this portal, we collect:
Information about other people. The invoicing and timesheet tools mean you may upload information about people who are not our clients — your workers and your customers. For that information you are the data controller and we act as a processor on your instructions only. We use it solely to provide the service to you. We do not sell it, we do not use it to market to those people, and we do not use it for any purpose of our own. It is your responsibility to have a lawful basis for uploading it and to tell those people how it is used.
Information about people who did not give it to you directly. Some of what the system can hold is about people who are neither our client nor yours — an emergency contact, a next of kin, a supervisor who signs a sheet off. You remain the controller of it. Before you record someone’s next of kin you should have asked the person whose contact it is; before you record a National Insurance number or bank details you should be doing so for a purpose you can point to, such as paying them or meeting a CIS duty. We do not look at any of it, and it is used for nothing but showing it back to you.
Mobile numbers in particular. Where you add someone to a messaging plan you are confirming you are entitled to message them on that number. Messages we send on your behalf are service messages about recording working time — we do not market to those numbers, and we do not use them for any purpose beyond delivering the service you have asked for.
We process your personal data on the following grounds under UK GDPR:
The above concerns data where we are the controller — principally your own account and the services you buy. For information you upload about your workers and customers we are a processor, and the legal basis for processing it is a matter for you as the controller.
We use your data solely to:
We do not sell your data to third parties. We do not use your data for marketing without your explicit consent.
We use the following third-party services to operate the portal:
If the firm you invoice also uses this portal, the two accounts can be linked by exchanging a code, and a document can then be passed from one to the other rather than both of you typing it out. This only ever happens because someone chose it: a link is made by one account offering its code and the other entering it, and a document crosses only when it is deliberately sent.
What crosses is the document and what is on the face of it — the figures, the dates, the lines, the hours behind it and who worked them, and your business details as they appear on the paperwork. Nothing else in your account crosses: not your other clients, not your rates, not your bank or tax details unless they are printed on the document itself, and not the personal records you keep about the people who work for you. The receiving account becomes a controller of what it has been sent, in the same way it would be if you had emailed them a PDF.
A link can be broken by either side at any time. Breaking it stops anything further being passed; it does not reach into the other account and remove documents already sent, any more than withdrawing an email would.
Job records and associated RAMS documents are retained for a minimum of 7 years to comply with statutory record-keeping requirements relevant to health and safety documentation. Account data is retained for as long as your account is active. You may request deletion of your account and associated data at any time by contacting us — subject to our legal obligation to retain billing and job records.
Uploaded files (drawings, specifications, ZIPs, photographs, timesheet images) are stored against the job or timesheet they were submitted for, together with the text extracted from them. They are kept so that the record behind a document remains available if a figure is ever queried, and so that other tools can reuse the same upload. You can delete them at any time from the job or timesheet they belong to.
Invoices, timesheets and their supporting records are retained for 6 years from the end of the relevant tax year, reflecting HMRC record-keeping expectations for financial and CIS records. You may export your invoice and timesheet history at any time, and may ask us to delete it — though you may have your own legal duty to keep those records, which deleting them here does not discharge.
Messages sent in to log hours are kept as part of the timesheet they contributed to and follow the same 6-year retention. Mobile numbers on a messaging plan are kept until the person is removed from the plan or the account is closed. Anyone receiving reminders can stop them at any time by replying STOP, which stops messages to that person immediately and without needing an account; their previously logged hours are not affected.
A signature image is kept until you remove it. Copies attached to signed timesheets are kept with those timesheets, because removing them would alter a record of what was signed off; those copies are deleted when the timesheet is.
Records you keep about the people who work for you — including National Insurance numbers, UTRs, addresses, bank details and emergency contacts — are kept until you remove that person’s record or close the account. They are not kept on any schedule of ours: nothing here decides that a leaver’s details should be held for a period, because that judgement is yours to make. If you no longer need them, remove them.
A name and signature captured when somebody signs a document off are kept with that document, for the same period as the document, because removing them would alter the record of what was signed. A personal link, whether for someone filling in their own details or for someone signing a document, stops working as soon as it is withdrawn or the record it points at is deleted.
Information about your workers and customers is deleted when you delete the record it belongs to, or on request. Where you close your account we will delete or return it rather than keep it.
You have the right to:
To exercise any of these rights, contact us via the email address registered to your account. You also have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk.
Passwords are stored as irreversible cryptographic hashes. All access to the portal requires authentication. Connections are encrypted in transit. We take reasonable technical and organisational measures to protect your data against unauthorised access, loss, or disclosure.
We may update this Privacy Policy from time to time. Continued use of the portal after notification of material changes constitutes acceptance of the updated policy.