Legal
Privacy Policy
Last updated: 21 May 2026
1. Who we are
RESTEC Roofing Ltd ("RESTEC", "we", "us") is the data controller for personal data collected through this site and through bookings for the RESTEC Academy.
Contact: Training@restecroofing.co.uk.
2. What we collect
- Booking details: buyer name, email, phone, company.
- Attendee details: name, email, phone, disclaimer status.
- Payment metadata from Stripe (we never store card numbers).
- Operational logs (admin actions, payment webhooks) used to investigate issues.
3. How we use your data
- To process your booking and deliver the training course.
- To send you transactional emails (confirmations, reminders, invoices).
- To comply with our legal and accounting obligations.
- With your consent, to send you occasional updates about future training.
4. Lawful basis
Under UK GDPR Article 6 we rely on the following lawful bases:
- Contract (Art. 6(1)(b)) β processing booking, attendee and payment data to deliver the training course you have booked.
- Legal obligation (Art. 6(1)(c)) β retaining invoice and booking records for UK accounting and tax purposes.
- Legitimate interests (Art. 6(1)(f)) β running, securing and improving the service, including operational logs, rate-limiting, and fraud-prevention via Stripe.
- Consent (Art. 6(1)(a)) β loading non-essential cookies (Google Maps, Stripe's fraud iframe) and, if you opt in, sending occasional marketing emails. You can withdraw consent at any time via our cookie settings or unsubscribe link without affecting processing carried out under the other bases above.
5. Sharing & sub-processors
We share your data only with processors that help us run the service. Each is bound by a data-processing agreement and only handles personal data on our instructions:
- Stripe β payment processing (buyer name, email, phone, amount).
- Supabase β database and authentication hosting (all booking and attendee data).
- Google Cloud β application hosting.
- Microsoft 365 (Exchange Online) β transactional email delivery (recipient email and message content).
- Google Maps β map display and address lookup on our locations pages (postcodes, coordinates).
We do not sell your data.
6. International transfers
Some of our processors are based outside the UK / EEA (notably Stripe and Google services in the United States; Microsoft 365 may also process data outside the UK depending on tenant configuration). Where this is the case, transfers are protected by the UK International Data Transfer Agreement or the EU Standard Contractual Clauses incorporated into each processor's terms, together with any supplementary measures we consider appropriate.
7. Retention
- Booking and invoice records β 7 years from the booking date, to meet UK accounting requirements.
- Attendee details and disclaimer records β 7 years, alongside the related booking, for health-and-safety and insurance purposes.
- Stripe webhook payloads and admin audit logs β 12 months, for security and reconciliation.
- Application logs β 30 days, with email addresses masked at write-time.
- Abandoned or expired reservations β marked cancelled after 7 days and purged with the related booking record.
- Marketing-list data β retained until you unsubscribe.
8. Your rights
Under UK GDPR you have the following rights in respect of your personal data:
- Access (Art. 15) β a copy of the personal data we hold about you.
- Rectification (Art. 16) β correction of inaccurate or incomplete data.
- Erasure (Art. 17) β deletion of your data, subject to our legal retention obligations (see Section 7).
- Restriction (Art. 18) β ask us to stop processing while a query is investigated.
- Portability (Art. 20) β receive your data in a machine-readable format.
- Object (Art. 21) β object to processing based on legitimate interests.
- Withdraw consent (Art. 7(3)) β for processing that relies on consent (marketing, non-essential cookies). Withdrawal does not affect prior processing.
To exercise any of these rights, email Training@restecroofing.co.uk. We respond within one calendar month (the statutory maximum), extendable by a further two months for complex requests β we will tell you within the first month if an extension is needed. You can also unsubscribe from marketing emails at any time via our Unsubscribe page, or change your cookie preferences from the Cookie settings link in the footer.
Sign-in links sent to your email expire 30 minutes after issue and are single-use.
If you are not satisfied with how we have handled your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO): ico.org.uk/make-a-complaintΒ· helpline 0303 123 1113.
9. Cookies
We use strictly-necessary cookies for the site to function (authentication, booking-session state) and, with your consent, third-party functional cookies set by Google Maps and Stripe. We do not use advertising, analytics or social-media tracking cookies. Manage your choices at any time via the Cookie settings link in the footer. Full detail in our Cookie Policy.
10. Changes
We may update this policy. The version in force is the one displayed on this page on the date you visit.
