Privacy Policy

Last updated: 14 August 2026

1. Who we are

Raven Technical Services Limited is a health and safety consultancy registered in England and Wales (Company No. 17282046). We produce Risk Assessment and Method Statement (RAMS) documents for contractors carrying out structural and architectural steelwork and metalwork site installations.

We are registered as a data controller with the Information Commissioner's Office (ICO) under Tier 1. ICO Reference: ZC177447.

For any privacy-related queries, contact us at the email address registered to your account.

2. What personal data we collect

When you create an account and use this portal, we collect:

  • Account data: your name, company name, and email address
  • Job information: site addresses, client/principal contractor names, scope of works, planned start dates, number of operatives, and any additional site-specific information you provide
  • Uploaded files: project drawings (DWG, DXF), ZIP packs, PDFs, specifications, photographs and other documents you upload — these are processed to extract job details, and the text extracted from them is retained against your job so that other tools can use it without you having to upload the same files again
  • Company logo: if uploaded via your account settings
  • Payment records: amounts charged, discount codes used, and referral credit history (payment card details are handled exclusively by Stripe and are never seen or stored by us)
  • Reviews: if you submit a review through the client portal, your name, company name, and review text are stored
  • Invoicing data: your business and billing details (including VAT number, UTR and bank details if you choose to enter them), your customers’ names and contact details, and the invoices you raise
  • Timesheet data: the names of people who work for you, the hours they worked, their rates of pay where you enter them, and the original photograph, note or email a timesheet came from — the original is kept as the record behind the figures in case one is ever queried
  • Messaging data (if you use the messaging add-on): the mobile numbers and names of the people you put on the plan, the content of messages they send in to log hours, and a record of the reminders we sent and whether the provider accepted them
  • Records about the people who work for you: where you choose to keep them, a person’s job title, home address, date they started, National Insurance number, UTR, bank account details, and the name and telephone number of an emergency contact or next of kin. None of this is required to use the service — it is there because it is what a subcontractor is asked for, and keeping it in one place beats keeping it in a drawer. It is used only to show it back to you and to fill in documents you raise.
  • Details a person enters about themselves: where you send someone a personal link, whatever they fill in on that page. The link identifies one person and one company. It can be withdrawn by you at any time, after which it stops working.
  • Sign-off by someone without an account: where a timesheet or invoice is sent out to be signed, the name typed by whoever signed it, the signature they drew, and the date and time. This is usually a supervisor or agent of the firm you are billing rather than anyone with an account here. The link identifies one document.
  • Hours sent in by email: where you use an email-in address, the address a message was sent from, its subject and body, and any attachment — kept as the record behind the figures in the same way a photographed sheet is.
  • Signatures: if you upload an image of a signature, that image and the name printed beneath it, together with a copy attached to each timesheet it is used to sign and the date and time of signing

Information about other people. The invoicing and timesheet tools mean you may upload information about people who are not our clients — your workers and your customers. For that information you are the data controller and we act as a processor on your instructions only. We use it solely to provide the service to you. We do not sell it, we do not use it to market to those people, and we do not use it for any purpose of our own. It is your responsibility to have a lawful basis for uploading it and to tell those people how it is used.

Information about people who did not give it to you directly. Some of what the system can hold is about people who are neither our client nor yours — an emergency contact, a next of kin, a supervisor who signs a sheet off. You remain the controller of it. Before you record someone’s next of kin you should have asked the person whose contact it is; before you record a National Insurance number or bank details you should be doing so for a purpose you can point to, such as paying them or meeting a CIS duty. We do not look at any of it, and it is used for nothing but showing it back to you.

Mobile numbers in particular. Where you add someone to a messaging plan you are confirming you are entitled to message them on that number. Messages we send on your behalf are service messages about recording working time — we do not market to those numbers, and we do not use them for any purpose beyond delivering the service you have asked for.

3. Legal basis for processing

We process your personal data on the following grounds under UK GDPR:

  • Contract performance — to provide the RAMS document service you have requested
  • Legal obligation — to retain records as required by health and safety and financial legislation
  • Legitimate interests — to operate and improve the portal and communicate with you about your account

The above concerns data where we are the controller — principally your own account and the services you buy. For information you upload about your workers and customers we are a processor, and the legal basis for processing it is a matter for you as the controller.

4. How we use your data

We use your data solely to:

  • Generate and deliver your RAMS documents
  • Communicate with you about submitted jobs, account matters, and pricing notices
  • Send a minimum 14 days' advance notice of any rate changes
  • Maintain billing records as required by law
  • Send reminders to log hours, and record the hours sent back, where you have switched the messaging add-on on
  • Send a timesheet or invoice to whoever you nominate to sign it off, and record their answer

We do not sell your data to third parties. We do not use your data for marketing without your explicit consent.

5. Third-party processors

We use the following third-party services to operate the portal:

  • Stripe — payment processing. Card details are entered directly into Stripe's secure interface and are never transmitted to or stored by Raven Technical Services Limited. Stripe's privacy policy applies to payment data.
  • Messaging providers (Plivo and/or Twilio) — used to carry reminders and replies where the messaging add-on is switched on. The recipient's mobile number and the content of the message pass through the provider in order to be delivered, and are subject to that provider's own data handling policy.
  • Email providers — outgoing email (documents sent for sign-off, reminders, account messages) and the mailbox that receives hours sent in are carried by our email provider, and the contents pass through it in order to be delivered or collected.
  • Meta Platforms (WhatsApp) — where WhatsApp is the chosen channel, messages are delivered over the WhatsApp Business Platform and Meta's own terms and privacy policy apply to that delivery. Meta receives the recipient's number and message content as a necessary part of carrying the message.
  • Anthropic (Claude API) — used to extract job details from uploaded files. File contents are sent to Anthropic's API for processing and are subject to Anthropic's data handling policy. Files are not retained by Anthropic after processing.

6. Sharing a document with another account

If the firm you invoice also uses this portal, the two accounts can be linked by exchanging a code, and a document can then be passed from one to the other rather than both of you typing it out. This only ever happens because someone chose it: a link is made by one account offering its code and the other entering it, and a document crosses only when it is deliberately sent.

What crosses is the document and what is on the face of it — the figures, the dates, the lines, the hours behind it and who worked them, and your business details as they appear on the paperwork. Nothing else in your account crosses: not your other clients, not your rates, not your bank or tax details unless they are printed on the document itself, and not the personal records you keep about the people who work for you. The receiving account becomes a controller of what it has been sent, in the same way it would be if you had emailed them a PDF.

A link can be broken by either side at any time. Breaking it stops anything further being passed; it does not reach into the other account and remove documents already sent, any more than withdrawing an email would.

7. Data retention

Job records and associated RAMS documents are retained for a minimum of 7 years to comply with statutory record-keeping requirements relevant to health and safety documentation. Account data is retained for as long as your account is active. You may request deletion of your account and associated data at any time by contacting us — subject to our legal obligation to retain billing and job records.

Uploaded files (drawings, specifications, ZIPs, photographs, timesheet images) are stored against the job or timesheet they were submitted for, together with the text extracted from them. They are kept so that the record behind a document remains available if a figure is ever queried, and so that other tools can reuse the same upload. You can delete them at any time from the job or timesheet they belong to.

Invoices, timesheets and their supporting records are retained for 6 years from the end of the relevant tax year, reflecting HMRC record-keeping expectations for financial and CIS records. You may export your invoice and timesheet history at any time, and may ask us to delete it — though you may have your own legal duty to keep those records, which deleting them here does not discharge.

Messages sent in to log hours are kept as part of the timesheet they contributed to and follow the same 6-year retention. Mobile numbers on a messaging plan are kept until the person is removed from the plan or the account is closed. Anyone receiving reminders can stop them at any time by replying STOP, which stops messages to that person immediately and without needing an account; their previously logged hours are not affected.

A signature image is kept until you remove it. Copies attached to signed timesheets are kept with those timesheets, because removing them would alter a record of what was signed off; those copies are deleted when the timesheet is.

Records you keep about the people who work for you — including National Insurance numbers, UTRs, addresses, bank details and emergency contacts — are kept until you remove that person’s record or close the account. They are not kept on any schedule of ours: nothing here decides that a leaver’s details should be held for a period, because that judgement is yours to make. If you no longer need them, remove them.

A name and signature captured when somebody signs a document off are kept with that document, for the same period as the document, because removing them would alter the record of what was signed. A personal link, whether for someone filling in their own details or for someone signing a document, stops working as soon as it is withdrawn or the record it points at is deleted.

Information about your workers and customers is deleted when you delete the record it belongs to, or on request. Where you close your account we will delete or return it rather than keep it.

8. Your rights under UK GDPR

You have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erasure (right to be forgotten), subject to legal retention obligations
  • Restrict or object to processing
  • Data portability — receive your data in a structured, machine-readable format

To exercise any of these rights, contact us via the email address registered to your account. You also have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk.

9. Security

Passwords are stored as irreversible cryptographic hashes. All access to the portal requires authentication. Connections are encrypted in transit. We take reasonable technical and organisational measures to protect your data against unauthorised access, loss, or disclosure.

10. Changes to this policy

We may update this Privacy Policy from time to time. Continued use of the portal after notification of material changes constitutes acceptance of the updated policy.