1. Introduction
Bia Electric Ltd ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at https://bia-electric.com and use our services.
We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Information We Collect
2.1 Information You Provide
- Account information: name, email address, password
- Profile information: company name, accreditations, qualifications
- Contact information: phone number, address (optional)
- Payment information: processed securely by Stripe (we don't store card details)
- Content you create: certificates, quotes, invoices, customer records
2.2 Information Collected Automatically
- Device information: browser type, operating system, device type
- Usage data: pages visited, features used, time spent
- Location data: approximate location based on IP address (city/country level)
- Log data: IP address, access times, referring URLs
2.3 Information from Third Parties
- Google OAuth: if you sign in with Google, we receive your name, email, and profile picture
3. How We Use Your Information
We use your information to:
- Provide and maintain our services
- Process your transactions and manage your account
- Send you service-related communications
- Improve and personalise our services
- Monitor and analyse usage patterns
- Detect and prevent fraud or abuse
- Comply with legal obligations
4. Legal Basis for Processing (GDPR)
We process your data based on:
- Contract: To provide services you've requested
- Legitimate interests: To improve our services and prevent fraud
- Consent: For marketing communications (where applicable)
- Legal obligation: To comply with applicable laws
5. Data Sharing
We share your data with:
- Service providers: hosting (Vercel), database (Neon), payments (Stripe), email (Resend), AI services (Anthropic), error monitoring (Sentry)
- Legal authorities: when required by law or to protect rights
We do not sell your personal data to third parties.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. After account deletion, we may retain certain data for legal compliance or legitimate business purposes for up to 7 years.
Analytics data is aggregated and anonymised after 24 hours.
7. Your Rights (GDPR)
Under UK GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a portable format
- Restriction: Limit how we use your data
- Object: Object to processing based on legitimate interests
- Withdraw consent: Where processing is based on consent
To exercise these rights, contact us at privacy@bia-electric.com.
8. Data Security
We implement appropriate technical and organisational measures to protect your data, including:
- Encryption in transit (HTTPS/TLS)
- Encrypted database connections
- Password hashing (bcrypt)
- Access controls and authentication
- Regular security reviews
9. International Transfers
Your data may be transferred to and processed in countries outside the UK. Our service providers (Vercel, Neon, Stripe, Anthropic) maintain appropriate safeguards including Standard Contractual Clauses where required.
10. Cookies
We use essential cookies for authentication and session management. We also use analytics to understand how our service is used. For more details, see our Cookie Policy.
11. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.
13. Contact Us
For questions about this Privacy Policy or to exercise your data rights:
Data Controller: Bia Electric Ltd
Email: privacy@bia-electric.com
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.