Skip to main content

Privacy Policy & Data Protection Notice

Version 1.0 Effective Date: 3 March 2026

1. Who We Are

1.1 This Privacy Policy applies to the fire risk assessment documentation platform, Fire Record, operated by ElevateCore ("we", "us", or "our").

1.2 For the purposes of UK GDPR, we act as:

  • Data Controller for account and registration information relating to Users of the Software.
  • Data Processor for personal data entered into the Software by Users in the course of carrying out fire risk assessments.

1.3 Contact details for data protection matters:

Compliance Officer
compliance@elevatecore.io

2. Definitions

2.1 Software — The fire risk assessment documentation platform operated by us.

2.2 User — Any individual or organisation using the Software.

2.3 Assessment Data — Any data entered into the Software by Users relating to fire risk assessments, including building information, responsible persons, client information, and associated documentation.

2.4 Personal Data — Any information relating to an identified or identifiable individual.

3. Types of Data We Collect

3.1 Account Information

  • Name
  • Email address
  • Telephone number (optional)
  • Login credentials
  • Account identifiers
  • Billing information

3.2 Assessment Data

  • Client names
  • Client contact details
  • Responsible person details
  • Building addresses and building information
  • Fire safety observations and notes
  • Photographs or documents uploaded during assessments
  • Compliance records relating to fire safety management

3.3 Technical Data

  • IP address
  • Device information
  • Browser type
  • System logs
  • Usage analytics
  • Security monitoring data

4. How We Collect Data

4.1 Personal data may be collected through:

  • User registration
  • Account management
  • Data entered into assessments
  • Customer support interactions
  • System logs and technical monitoring

4.2 Some information may be collected automatically through the operation of the Software for security and performance purposes.

5. Purposes of Processing

Personal data is processed for the following purposes:

  1. Creating and managing user accounts
  2. Providing access to and operating the Software
  3. Enabling Users to generate fire risk assessment documentation
  4. Storing and managing compliance records and assessment reports
  5. Providing technical support and service communications
  6. Maintaining system security and preventing misuse
  7. Improving the Software and developing new features
  8. Complying with legal or regulatory obligations

We do not sell personal data to third parties.

6. Legal Basis for Processing

We process personal data only where a lawful basis exists under Article 6 UK GDPR, including:

  • Contractual necessity — Processing necessary to provide the Software and fulfil contractual obligations.
  • Legitimate interests — Maintaining system security, improving the Software, and operating our services.
  • Legal obligations — Complying with applicable laws, including record-keeping obligations relating to fire safety documentation.
  • Consent — Where Users voluntarily provide optional information or consent to receive communications.

Users may opt out of non-essential communications at any time.

7. User Responsibility for Client Data

Users may upload or input personal data relating to their clients, building occupants, or responsible persons.

In relation to such information:

  • The User acts as Data Controller
  • We act as Data Processor

Users are responsible for ensuring they have lawful authority to collect and process personal data they enter into the Software.

8. Data Retention

The Software is designed for the storage of fire risk assessment documentation and compliance records.

Data may therefore be retained to allow Users to:

  • Access historical assessments
  • Maintain compliance records
  • Retain documentation required for regulatory or professional purposes

Where an account is closed, we may delete or anonymise personal data within a reasonable time unless retention is required:

  • To comply with legal obligations
  • To resolve disputes
  • To enforce contractual rights
  • For legitimate system integrity or security purposes

9. Data Security

We implement appropriate technical and organisational security measures designed to protect personal data.

Measures may include:

  • Encrypted communications (HTTPS)
  • Secure cloud infrastructure
  • Access control systems
  • Authentication protections
  • Restricted internal access
  • Monitoring and logging systems

However, no internet-based service can guarantee absolute security.

10. Third-Party Service Providers

We may use trusted third-party service providers to operate the Software, including:

  • Cloud hosting providers
  • Payment processors
  • Authentication services
  • System monitoring tools
  • Scheduling services (Cal.com — used for demo bookings on our marketing website)

These providers may process personal data on our behalf and must implement appropriate data protection safeguards.

11. International Data Transfers

Where personal data is transferred outside the United Kingdom or European Economic Area, we ensure appropriate safeguards are implemented, including recognised legal transfer mechanisms where required.

12. Data Subject Rights

Individuals have the following rights under UK GDPR:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing

Requests may be submitted to:

13. Data Breaches

In the event of a personal data breach affecting personal data stored within the Software, we will:

  1. Investigate the incident promptly
  2. Take appropriate remedial actions
  3. Notify affected parties where required by law

14. Use of Anonymised Data

We may use anonymised or aggregated data derived from system usage or assessment information for the purpose of improving the Software, analysing performance, and developing new features. Such data will not identify individuals.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Updated versions will be published within the Software or on our website. Continued use of the Software after updates constitutes acceptance of the revised policy.

16. Contact

For questions or requests relating to data protection:

Compliance Officer
compliance@elevatecore.io