Privacy Policy

This notice explains how Bloor Engineering Ltd ("we", "us") handles personal data when you use RAMSReady at ramsready.co.uk.

Last updated: 9 October 2026.

1. Who is the data controller?

Bloor Engineering Ltd, registered in England and Wales (company number 14230472), registered office 11 Pennine Way, Swadlincote, Derbyshire DE11 9EX. RAMSReady is one of our trading names and is not a separate company, so Bloor Engineering Ltd is the data controller for everything in this notice. Privacy queries: george@bloorengineering.com.

2. What we collect

3. Why we collect it (lawful basis)

4. Every company that handles your data

RAMSReady is a trading name of Bloor Engineering Ltd, not a separate company, so Bloor Engineering Ltd is the controller and the companies below are our processors. This is the complete list. Your inputs are sent to Anthropic and Google to generate your documents. Both are used under paid API terms that do not permit them to train their models on the content you send.

CompanyWhat it does for usWhereBasis for any transfer outside the UK
Anthropic PBCGenerates your documents (Claude models)United StatesUK Extension to the EU–US Data Privacy Framework, or the standard contractual clauses in that provider’s processing terms
Google LLC / Google Ireland LtdGenerates parts of your documents (Gemini models)United States and EEAUK Extension to the EU–US Data Privacy Framework, or the standard contractual clauses in that provider’s processing terms
Hetzner Online GmbHStores your account and the documents you createHelsinki, FinlandEEA — UK adequacy, no further safeguard needed
Vercel Inc.Serves the website; aggregate page analyticsUnited StatesUK Extension to the EU–US Data Privacy Framework, or the standard contractual clauses in that provider’s processing terms
Stripe Payments Europe LtdCard payments and subscriptionsIreland, with Stripe Inc. in the United StatesEEA — UK adequacy, no further safeguard needed; SCCs for the US element
Plus Five Five, Inc. (Resend)Sends service email, such as your receipt and document linksUnited StatesUK Extension to the EU–US Data Privacy Framework, or the standard contractual clauses in that provider’s processing terms
Apple Distribution International LtdIn-app purchases made through the App StoreIreland, with Apple Inc. in the United StatesEEA — UK adequacy, no further safeguard needed; SCCs for the US element
Microsoft Ireland Operations LtdHosts the mailbox we reply to you from, so any email you send us is stored thereEEAEEA — UK adequacy, no further safeguard needed

We also run our own analytics (BEAKON) on Bloor Engineering infrastructure rather than sending your behaviour to a third-party tracker.

If this list changes. We keep it current and we update this page before a change takes effect, so this page is always the authoritative list. That includes changing which company generates your documents. Any provider we add must be under a written data processing agreement carrying UK GDPR Article 28 terms, must be barred from training on your content, and must meet the transfer safeguards above. Where a change materially affects how your data is handled we tell account holders before it happens.

We may also disclose data where the law requires it (a court order, an HMRC notice, an ICO request) or to protect our rights or another person’s safety. We do not sell, rent or share your data for anyone else’s marketing.

5. How long we keep it

6. Where data is stored

Your account and the records you create are held on servers operated by Hetzner Online GmbH in Helsinki, Finland. The website itself is served by Vercel. Finland is in the European Economic Area, which the United Kingdom has found to provide an adequate level of protection, so no additional transfer safeguards are needed for data held there.

Some processors are in the United States, including Vercel and Anthropic. Stripe is in Ireland. Transfers to the United States rely on the UK Extension to the EU-US Data Privacy Framework or on the standard contractual clauses in each provider's data processing terms.

7. How we protect it

If a breach happens that is likely to risk your rights, we notify the ICO within 72 hours of becoming aware of it, as section 67 of the Data Protection Act 2018 requires, and we tell you without undue delay where the risk to you is high. If we are acting as a processor for an organisation such as a local authority, we report to that organisation under whatever shorter deadline the contract sets.

8. Your rights

Under UK GDPR and the Data Protection Act 2018 you can ask us to:

To exercise any of these, email george@bloorengineering.com. We aim to respond within 30 days.

9. Complaints

If you think we have handled your data badly, you can complain to the UK Information Commissioner’s Office at ico.org.uk/concerns, but we’d much rather hear from you first so we can fix it.

10. Cookies

See our separate Cookies notice for the cookies and similar technologies we use.

11. Changes to this notice

We may update this notice from time to time. Material changes will be highlighted on the site. The "last updated" date at the top reflects the current version.