Privacy Policy
This notice explains how Bloor Engineering Ltd ("we", "us") handles personal data when you use RAMSReady at ramsready.co.uk.
Last updated: 9 October 2026.
1. Who is the data controller?
Bloor Engineering Ltd, registered in England and Wales (company number 14230472), registered office 11 Pennine Way, Swadlincote, Derbyshire DE11 9EX. RAMSReady is one of our trading names and is not a separate company, so Bloor Engineering Ltd is the data controller for everything in this notice. Privacy queries: george@bloorengineering.com.
2. What we collect
- Account data: email address, password hash, plan, sign-in timestamps.
- Usage data: which pages you visit, which features you use, what you submit to our forms.
- Payment data: processed by Stripe. We never see or store full card numbers. We hold your customer ID, last-4, transaction history, and billing email.
- Content data: the prompts and inputs you submit, the AI-generated outputs returned, and any documents you upload. Used to deliver the service and improve quality. We do not sell, share or rent this content.
- Diagnostics: IP address, user-agent, error logs, retained 30 to 90 days for security and debugging.
3. Why we collect it (lawful basis)
- Performance of a contract: running the service you signed up for.
- Legitimate interest: security, fraud prevention, product improvement, transactional email.
- Consent: for marketing email, where you have explicitly opted in. You can withdraw at any time.
- Legal obligation: retaining transaction records for HMRC under the Finance Act and Companies Act.
4. Every company that handles your data
RAMSReady is a trading name of Bloor Engineering Ltd, not a separate company, so Bloor Engineering Ltd is the controller and the companies below are our processors. This is the complete list. Your inputs are sent to Anthropic and Google to generate your documents. Both are used under paid API terms that do not permit them to train their models on the content you send.
| Company | What it does for us | Where | Basis for any transfer outside the UK |
|---|---|---|---|
| Anthropic PBC | Generates your documents (Claude models) | United States | UK Extension to the EU–US Data Privacy Framework, or the standard contractual clauses in that provider’s processing terms |
| Google LLC / Google Ireland Ltd | Generates parts of your documents (Gemini models) | United States and EEA | UK Extension to the EU–US Data Privacy Framework, or the standard contractual clauses in that provider’s processing terms |
| Hetzner Online GmbH | Stores your account and the documents you create | Helsinki, Finland | EEA — UK adequacy, no further safeguard needed |
| Vercel Inc. | Serves the website; aggregate page analytics | United States | UK Extension to the EU–US Data Privacy Framework, or the standard contractual clauses in that provider’s processing terms |
| Stripe Payments Europe Ltd | Card payments and subscriptions | Ireland, with Stripe Inc. in the United States | EEA — UK adequacy, no further safeguard needed; SCCs for the US element |
| Plus Five Five, Inc. (Resend) | Sends service email, such as your receipt and document links | United States | UK Extension to the EU–US Data Privacy Framework, or the standard contractual clauses in that provider’s processing terms |
| Apple Distribution International Ltd | In-app purchases made through the App Store | Ireland, with Apple Inc. in the United States | EEA — UK adequacy, no further safeguard needed; SCCs for the US element |
| Microsoft Ireland Operations Ltd | Hosts the mailbox we reply to you from, so any email you send us is stored there | EEA | EEA — UK adequacy, no further safeguard needed |
We also run our own analytics (BEAKON) on Bloor Engineering infrastructure rather than sending your behaviour to a third-party tracker.
If this list changes. We keep it current and we update this page before a change takes effect, so this page is always the authoritative list. That includes changing which company generates your documents. Any provider we add must be under a written data processing agreement carrying UK GDPR Article 28 terms, must be barred from training on your content, and must meet the transfer safeguards above. Where a change materially affects how your data is handled we tell account holders before it happens.
We may also disclose data where the law requires it (a court order, an HMRC notice, an ICO request) or to protect our rights or another person’s safety. We do not sell, rent or share your data for anyone else’s marketing.
5. How long we keep it
- Account records: while your account is active and for 6 years after closure for HMRC compliance.
- Generated documents and uploaded content: while your account is active, plus 30 days after deletion. You can request earlier erasure at any time.
- Anonymised analytics: indefinitely.
6. Where data is stored
Your account and the records you create are held on servers operated by Hetzner Online GmbH in Helsinki, Finland. The website itself is served by Vercel. Finland is in the European Economic Area, which the United Kingdom has found to provide an adequate level of protection, so no additional transfer safeguards are needed for data held there.
Some processors are in the United States, including Vercel and Anthropic. Stripe is in Ireland. Transfers to the United States rely on the UK Extension to the EU-US Data Privacy Framework or on the standard contractual clauses in each provider's data processing terms.
7. How we protect it
- All traffic between you and the website is encrypted with TLS (HTTPS). The site is served over HTTPS only.
- The connection between the application and the database is also encrypted with TLS 1.3, and the application verifies the database server’s certificate, so the link cannot be silently intercepted.
- Passwords are stored as hashes, never in a form we or anyone else can read back.
- We never receive or store full card numbers. Card details go directly to Stripe.
- The application reaches the database through a dedicated account limited to the specific tables it needs, rather than an administrative account.
- Each customer’s records are separated by account, and a request can only read records belonging to the signed-in account.
- Our own staff and contracted technical support can reach production systems where that is necessary to run or repair the service. That access is limited to the people who need it and is subject to confidentiality obligations.
If a breach happens that is likely to risk your rights, we notify the ICO within 72 hours of becoming aware of it, as section 67 of the Data Protection Act 2018 requires, and we tell you without undue delay where the risk to you is high. If we are acting as a processor for an organisation such as a local authority, we report to that organisation under whatever shorter deadline the contract sets.
8. Your rights
Under UK GDPR and the Data Protection Act 2018 you can ask us to:
- Confirm what data we hold about you (subject access).
- Correct anything that's wrong.
- Delete your data (the right to erasure), subject to legal retention obligations.
- Restrict or object to processing.
- Receive a copy of your data in a portable format.
- Withdraw consent for any purpose where consent was the lawful basis.
To exercise any of these, email george@bloorengineering.com. We aim to respond within 30 days.
9. Complaints
If you think we have handled your data badly, you can complain to the UK Information Commissioner’s Office at ico.org.uk/concerns, but we’d much rather hear from you first so we can fix it.
10. Cookies
See our separate Cookies notice for the cookies and similar technologies we use.
11. Changes to this notice
We may update this notice from time to time. Material changes will be highlighted on the site. The "last updated" date at the top reflects the current version.