Legal
Privacy Policy
Last updated: 8 May 2026
1. Who we are
RESTEC Roofing Ltd ("RESTEC", "we", "us") is the data controller for personal data collected through this site and through bookings for the RESTEC Academy.
Contact: Training@restecroofing.co.uk.
2. What we collect
- Booking details: buyer name, email, phone, company.
- Attendee details: name, email, phone, disclaimer status.
- Payment metadata from Stripe (we never store card numbers).
- Operational logs (admin actions, payment webhooks) used to investigate issues.
3. How we use your data
- To process your booking and deliver the training course.
- To send you transactional emails (confirmations, reminders, invoices).
- To comply with our legal and accounting obligations.
- With your consent, to send you occasional updates about future training.
4. Lawful basis
We rely on the following lawful bases under UK GDPR: performance of a contract (your booking), legitimate interests (running and securing the service), legal obligation (record-keeping), and consent (for marketing communications).
5. Sharing & sub-processors
We share your data only with processors that help us run the service. Each is bound by a data-processing agreement and only handles personal data on our instructions:
- Stripe — payment processing (buyer name, email, phone, amount).
- Supabase — database and authentication hosting (all booking and attendee data).
- Google Cloud — application hosting.
- Microsoft 365 and Resend — transactional email delivery (recipient email and message content).
- Attio — customer-relationship management (buyer and order details, used to follow up on bookings).
- Google Maps — map display and address lookup on our locations pages (postcodes, coordinates).
We do not sell your data.
6. International transfers
Some of our processors are based outside the UK / EEA (notably Stripe, Resend, Attio and Google services in the United States). Where this is the case, transfers are protected by the UK International Data Transfer Agreement or the EU Standard Contractual Clauses incorporated into each processor's terms, together with any supplementary measures we consider appropriate.
7. Retention
- Booking and invoice records — 7 years from the booking date, to meet UK accounting requirements.
- Attendee details and disclaimer records — 7 years, alongside the related booking, for health-and-safety and insurance purposes.
- Stripe webhook payloads and admin audit logs — 12 months, for security and reconciliation.
- Application logs — 30 days, with email addresses masked at write-time.
- Abandoned or expired reservations — marked cancelled after 7 days and purged with the related booking record.
- Marketing-list data — retained until you unsubscribe.
8. Your rights
You have the right to access, correct or delete the personal data we hold about you, to restrict or object to processing, and to data portability. To exercise any of these rights, email Training@restecroofing.co.uk. We aim to respond within 30 days. You can also unsubscribe from marketing emails at any time via our Unsubscribe page or the link in any of our emails.
Sign-in links sent to your email expire 30 minutes after issue and are single-use.
You have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk).
9. Cookies
We use a small number of cookies that are strictly necessary for the site to function (e.g. authentication, payment session). We do not use advertising or third-party tracking cookies.
10. Changes
We may update this policy. The version in force is the one displayed on this page on the date you visit.
