Privacy Policy
Last updated 10 September 2026
This policy explains what we do with personal data. It covers two things that are deliberately kept separate: this website, which anyone can read, and the Construction Suite application, which customers log into.
Who we are
Construction Suite is a trading name of Xzist Digital Ltd, a company registered in England and Wales (number TODO — Companies House number), whose registered office is TODO — registered office line 1, TODO — town, TODO — postcode.
For the personal data described in this policy, Xzist Digital Ltd is the data controller, except where we say otherwise in the section on customer content below. Our ICO registration number is TODO — ICO registration number, or delete this line.
For anything in this policy, write to hello@xzistgroup.com.
Before publishing — confirm the registered name, company number and office in lib/legal.ts. The repository currently says both “a trading name of Xzist Digital Ltd” (on the guide pages) and “Construction Suite Ltd” (in the footer). Only one can be the controller. Confirm whether a Data Protection Officer has been appointed — if one has, their contact details must appear here; most SMEs are not required to appoint one.
This website
You can read every page of this site, including all 305 document guides, without giving us anything. There is one place where you can choose to give us your details, and it is described immediately below; nothing else on the site asks you for anything.
Registering your interest
Construction Suite is not yet open to new accounts. Our register your interest form asks for your email address, and optionally your name, your company name and your phone number. We use them for one thing: to let you know when the product is ready, and to answer you if you write back.
- Lawful basis: consent (UK GDPR Article 6(1)(a)). You give it by submitting the form, and the Privacy and Electronic Communications Regulations require it before we send you marketing email.
- What we will not do: we do not pass your details to anyone else, we do not add you to any other list, and we do not use the phone number for sales calls.
- How long we keep it: until you ask us to remove you, or until the product opens and you decide not to take an account — whichever comes first. Every email we send carries a way to tell us to stop.
- Withdrawing: email hello@xzistgroup.com and we will delete the record. It takes one line and no explanation.
The list is held in our own database, and the email telling you we are ready is sent through Resend. Both appear in the table further down.
If — and only if — you accept analytics cookies, Google Analytics collects information about your visit on our behalf: the pages you view, roughly how long you spend, how you arrived, your approximate location from your IP address, your device and browser, and whether you click through to sign up. Google assigns your browser an identifier so repeat visits are recognised. We use this to decide what to write and what to fix.
- Lawful basis: consent (UK GDPR Article 6(1)(a)). Consent is also what the Privacy and Electronic Communications Regulations require before the cookies are set.
- Recipient: Google LLC, as our analytics provider.
- If you refuse or ignore the banner: no cookies are set, no data is collected and nothing is sent to Google.
Our cookie policy lists each cookie, what it does and how long it lasts, and lets you change your mind at any time.
The site is hosted by Vercel, which processes server logs — including IP addresses — in order to serve pages and defend against attack. This happens for every visitor because it is how the site functions at all; our lawful basis is legitimate interests (Article 6(1)(f)), being the interest in keeping the site available and secure.
The Construction Suite application
This section is about app.construction-suite.com, which is a separate service you need an account to use.
Your account, where we are the controller
When you sign up we collect your name, your company name, your email address and your phone number, and we store a hashed version of your password. We use these to create and run your account, to identify you when you log in, to send you service-related email such as team invitations and password resets, and to take payment.
The phone number is there so we can reach you about your own account — a problem with your data, a question we cannot answer by email, or help getting started. We do not use it for marketing and we do not pass it to anyone else. If you opened your account before we asked for one, the application will ask you for it, and you are free to close that request every time it appears.
- Lawful basis: performance of a contract (Article 6(1)(b)) for running your account and taking payment; legal obligation (Article 6(1)(c)) for keeping accounting records; legitimate interests (Article 6(1)(f)) for contacting you by phone about your account, being the interest in supporting a customer who is paying for the service.
What you put into the product, where we are the processor
The documents you create will often contain personal data about other people — your employees, subcontractors and site staff. Health and safety paperwork frequently does: training records, competence assessments, health surveillance, accident reports and inductions all name individuals, and some of it is data about health, which UK GDPR treats as a special category.
For that content you are the data controller and we act as your processor. We process it on your instructions in order to provide the service, and we do not use it for our own purposes. You remain responsible for having a lawful basis for holding it and for telling those individuals what you do with it.
Before publishing — this arrangement needs a written data processing agreement to be effective — Article 28 requires the controller-processor relationship to be governed by a contract with specified terms. Confirm one exists and is offered to customers, and that equivalent terms are in place with each sub-processor listed below.
How the AI features work
Some features send content to Anthropic’s API to be processed: improving the wording of answers you have written, identifying gaps in a document, and reading uploaded construction drawings to produce a materials take-off.
This means the text and drawings you submit to those features leave our systems and are processed by Anthropic on our behalf. It only happens when you use one of those features — nothing is sent in the background, and the rest of the product works without it.
Document recommendations are not AI-generated: they come from a fixed rule set based on the role and work activity you select.
Before publishing — state Anthropic’s retention period and confirm the commercial terms that apply to your API usage, including whether submitted content may be used for model training. Customers uploading drawings and health records will ask, and it is a sub-processor disclosure either way.
Where your data goes
Application data — your account and everything you create in the product — is stored in the European Union, in Frankfurt. Transfers from the UK to the EEA are permitted under the UK’s adequacy regulations, so no additional safeguard is needed.
Some of the providers above are in the United States. Transfers there rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it, or otherwise on the International Data Transfer Addendum to the European Commission’s standard contractual clauses.
Before publishing — check each US provider’s current position individually. Certification under the Data Privacy Framework can be withdrawn, and the correct mechanism differs by provider. Name the mechanism actually relied on for each rather than describing both.
How long we keep it
Analytics data collected through this website is retained by Google for the period set on our Analytics property, after which it is deleted automatically.
Account data is kept for as long as you have an account with us. Records we need for accounting and tax are kept for six years after the end of the accounting period they relate to, as UK law requires.
Before publishing — set and state two retention periods: the Google Analytics data-retention setting on the property (the options are 2 or 14 months), and how long customer content is kept after an account closes. The second is a genuine product decision, and a significant one — some CDM and health surveillance records carry statutory retention obligations measured in decades, so deleting promptly on cancellation may leave a customer unable to meet a duty they cannot discharge any other way.
Your rights
Under UK data protection law you have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected;
- ask us to delete it, in some circumstances;
- ask us to restrict how we use it, in some circumstances;
- object to processing we carry out on the basis of legitimate interests;
- receive data you gave us in a portable format, where we hold it on the basis of consent or a contract; and
- withdraw consent at any time, where consent is what we rely on — as it is for analytics cookies. Withdrawing is as easy as giving it, through the cookie settings or the link in the footer. Withdrawing does not affect anything done before you withdrew.
To exercise any of these, email hello@xzistgroup.com. We will respond within one month. There is no charge.
If your data is in a document created by one of our customers, they are the controller and you should contact them. If you contact us instead, we will pass your request on.
Automated decision-making
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, and we do not profile you.
The AI features described above assist you in drafting documents. They do not make decisions about anyone, and what they produce is a suggestion for you to review, accept or discard.
Security
Access to application data is enforced at the database itself, so one organisation’s records cannot be read by another even if the application layer were at fault. Passwords are stored hashed and are never visible to us. Data is encrypted in transit, and at rest by our hosting providers.
If a personal data breach occurs that is likely to result in a risk to people’s rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it, and tell those affected where the risk is high.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority:
ico.org.uk/make-a-complaint · 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Changes to this policy
If we change how we use personal data, we will update this page and change the date at the top. Where the change affects something you consented to, we will ask again rather than rely on the consent you gave for something else.
