Privacy Policy

Your documents are yours.
Full stop.

This policy explains what data we collect, how we handle your engineering documents, and what rights you have over your information. Last updated: 24 July 2026.

Controller

Who we are.

SpecSense is a product of KU Automation Engineering Ltd, a company incorporated in England and Wales.

KU Automation Engineering Ltd

Company number: SC808510

Registered address: 14 Rowett Southway, Bucksburn, Aberdeen, United Kingdom

Privacy contact: contact@specsense.ai

For the purposes of UK GDPR and the Data Protection Act 2018, KU Automation Engineering Ltd is the data controller for personal data processed through the SpecSense platform.

Data collected

What we collect.

We collect the minimum data needed to deliver the service. Here is what that means in practice.

Account data

Collected when you create an account or your organisation provisions access for you.

  • Full name
  • Work email address
  • Employer organisation name
  • Job title / role
  • Password hash (never stored in plaintext)

Uploaded engineering documents

Documents you upload for review. See the document-handling section below for full details on storage, access, and deletion.

  • P&IDs, isometrics, datasheets, HAZOP registers, and other deliverables
  • Document metadata (filename, upload timestamp, project assignment)
  • Review outputs generated against each document

Usage telemetry

How you interact with the platform. Used to improve the service and detect issues.

  • Findings viewed and actioned
  • Export and download events
  • Review completion timestamps
  • Audit log entries (actor, action, timestamp)

Billing data

Payment processing is handled by Stripe. We do not store card numbers or bank details.

  • Subscription tier and billing cycle
  • Invoice records (for UK tax compliance)
  • Stripe customer ID (reference only — card data stays with Stripe)
Document handling

How we handle your engineering documents.

This is the section your procurement and infosec teams care about most. We keep it direct.

Encrypted at rest and in transit.

All uploaded documents are encrypted at rest using AES-256 and in transit using TLS 1.3. No exceptions, no legacy paths.

EU-region hosting by default.

Documents are stored in Frankfurt (eu-central-1) by default. UAE-region hosting is available on the Enterprise tier and is elected in your contract. We do not replicate data across regions without your consent.

Never used to train AI models.

Your documents are processed to deliver the review you requested. They are never used to train, fine-tune, retrain, or otherwise improve any AI model — ours or a third party's. This is a contractual commitment, not marketing language.

Deletion after 90 days.

Uploaded documents are deleted from active storage 90 days after review completion. Cryptographic audit hashes (not the document contents) are retained for 7 years to meet engineering audit trail requirements. You can request earlier deletion at any time.

Access is limited and logged.

Document access is restricted to: (i) the uploading team and project members you designate; (ii) Chartered Engineer reviewers assigned to that project; (iii) SpecSense engineering staff for incident response purposes only (every access is logged with actor, timestamp, and stated reason). No one else.

Sub-processors.

We use the following third-party processors to deliver the service. We contractually require each to meet our data-protection standards.

ProcessorPurposeData location / notes
OpenAILLM inference for candidate finding generationEU endpoint; zero-retention API agreement in place
SupabaseDatabase and authenticationEU-hosted (Frankfurt); data does not leave the EU
VercelEdge compute and platform hostingEU edge nodes; SCCs in place for any non-EU data path
StripePayment processing and billingEU entity; PCI-DSS Level 1 certified
ResendTransactional email (review notifications, receipts)EU endpoint used; no document content included in emails

We will give 30 days' notice of any material change to sub-processors for customers on active contracts.

Retention

How long we keep data.

Uploaded engineering documents

Deleted from active storage 90 days after review completion. Deletable on request at any time.

Audit trail hashes

Retained for 7 years. These are cryptographic hashes, not document content — they prove a review was completed without storing the document.

Account data

Retained for 6 years after account cancellation to meet UK tax and accounting record obligations (Companies Act 2006 / HMRC). Deleted after that period.

Usage telemetry

Aggregated and anonymised after 24 months. Raw telemetry deleted after 24 months.

Billing records

Retained for 7 years per UK HMRC statutory requirements. Card data is never stored by us.

Your rights

Your rights under UK GDPR and the Data Protection Act 2018.

You can exercise any of the following rights by contacting contact@specsense.ai. We respond within one calendar month.

Right of access

Request a copy of the personal data we hold about you.

Right to rectification

Ask us to correct inaccurate or incomplete personal data.

Right to erasure

Request deletion of your personal data ("right to be forgotten"), subject to our legal retention obligations.

Right to portability

Receive your personal data in a structured, machine-readable format.

Right to restriction

Ask us to restrict processing of your personal data in certain circumstances.

Right to object

Object to processing based on legitimate interests or for direct marketing purposes.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. We would prefer you contact us first.

International transfers

International data transfers.

SpecSense defaults to EU-region infrastructure (Frankfurt, eu-central-1). Where any processing involves a transfer outside the UK or EEA, we rely on UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs), as applicable.

Enterprise customers can elect UAE data residency. Data processed under UAE residency is handled in compliance with DIFC Data Protection Law No. 5 of 2020, and appropriate transfer safeguards are documented in your Enterprise agreement.

We do not transfer your data to jurisdictions without an adequacy decision or appropriate safeguards in place.

Cookies.

We use two categories of cookies: strictly necessary cookies (the service cannot function without them — authentication sessions, CSRF tokens) and analytics cookies (aggregated, anonymised usage data; no PII is recorded or linked to individuals).

We do not use advertising cookies, tracking pixels, or third-party behavioural profiling of any kind.

You can opt out of analytics cookies at any time via the cookie preference centre /privacy#cookies or by contacting us. Strictly necessary cookies cannot be disabled without breaking the application.

Security

Security in summary.

We implement technical and organisational measures appropriate to the risk: AES-256 encryption at rest, TLS 1.3 in transit, role-based access control, per-tenant isolation, and a formal incident-response process. SOC 2 Type I audit is in progress.

Full detail — including our compliance roadmap, sub-processor list, and breach notification commitments — is on our Security page.

Changes to this policy.

We will give at least 30 days' notice of any material change to this policy via email to the account holder and a banner on the platform. Continued use after the effective date constitutes acceptance. Non-material changes (corrections, clarifications) take effect immediately.

Archived versions of this policy are available on request.

Contact

Privacy contacts.

Privacy requests

Subject access requests, erasure requests, objections, and general privacy enquiries.

contact@specsense.ai

Data Protection Officer

Escalation, formal notices, and DPA compliance correspondence.

contact@specsense.ai

DPO: KU Automation Engineering Ltd Data Protection Team

Questions about your data?

We respond to privacy requests within one calendar month.