QScope

Legal

Privacy policy

Last updated 9 August 2026

QScope Team·4 min read

This policy explains what personal data QScope handles, why, and what rights you have. It covers UK GDPR and the Data Protection Act 2018.

Data controller for account data: Reltic BIM Ltd
Office 676, 60 Tottenham Court Road, London, W1T 2EW, England
Contact: help@qscope.co.uk
Reltic BIM Ltd is registered with the Information Commissioner's Office, registration number ZC211376.

1. Two different roles, and why the distinction matters

QScope handles two kinds of personal data and our legal role is different for each.

Your account data: we are the controller

Your name, work email, password hash, practice name, plan, sign-in times and billing records. We decide how this is used, so we are the controller.

Your project data: we are the processor

Project records contain personal data about other people: client contacts, subcontractor contacts, site personnel, names on certificates and in correspondence, and anyone appearing in site photographs. You decide what goes in and why, so you are the controller and we act as your processor. We handle that data only on your instructions, which are given by your use of the service and by these terms.

This means you are responsible for having a lawful basis for the personal data you put into QScope, and for telling those people how their data is used, where that is required.

2. What we collect and why

  • Account and login so you can sign in and so the audit trail can record who did what. Lawful basis: performance of our contract with you.
  • Billing records so we can take payment and meet accounting obligations. Lawful basis: contract, and legal obligation for tax records.
  • Audit trail recording which user changed which figure and when. This is a deliberate feature: certificates carry legal weight and traceability is expected of professional practice. Lawful basis: legitimate interests, in providing a professionally credible record.
  • Support correspondence when you contact us. Lawful basis: legitimate interests, in answering you.
  • Server logs including IP address, kept for security and fault diagnosis. Lawful basis: legitimate interests, in keeping the service secure.

We do not sell personal data, we do not use your account or project data for advertising, and we do not use your project data to train machine learning models.

3. Cookies

QScope uses a session cookie to keep you signed in and a token to protect against cross-site request forgery, both strictly necessary for the service to work. The public site also sets one preference cookie that remembers the currency you choose, so prices show in your market on your next visit; it holds no personal data and does no tracking.

On the public marketing site we also use Google Analytics 4 and Google Ads to measure visits and the performance of our advertising. These may set analytics and advertising cookies. They are off by default: we use Google Consent Mode, and no such cookie is set unless you accept it in the banner shown on your first visit. If you reject, only the strictly necessary cookies above are used. You can change your choice at any time by clearing the cookies and site data for this site in your browser. Google processes this data as described in the Google privacy policy at policies.google.com/privacy.

4. Who else processes your data

We use a small number of sub-processors. Each is bound by contract to protect the data and to use it only for the service it provides:

  • Hostinger – hosting and database storage.
  • Stripe – subscription payments. Card details are entered on Stripe's own pages. QScope never sees or stores a card number.
  • Google – outbound email for invitations, guest access links and notifications, where email is enabled on the account.
  • Backblaze – off-site backup storage in the European Economic Area (EU Central region, Amsterdam). A nightly copy of project data is sent there by the server itself, so that a project can be recovered if the hosting account is lost. The key the QScope server uses can upload and list backup files. It cannot read them, cannot delete them, and cannot change the rule that deletes them after 30 days.

We will tell you before adding a sub-processor that handles project data.

5. Where data is held

Project data and account records are stored on servers in the United Kingdom or the European Economic Area. Where a sub-processor transfers data outside the UK, that transfer relies on UK adequacy regulations or on the International Data Transfer Addendum to the EU standard contractual clauses.

Backups, as at 9 August 2026. The nightly backup also includes account data: your name, work email, password hash, practice name, plan, billing records, sign-in history, the activity log of actions taken in your projects, and the technical records used to protect sign-in (failed attempts and password-reset requests). This is kept so that the whole service, not only your project files, can be restored after a failure. The nightly backup of project data is sent by the server to Backblaze, in the European Economic Area (EU Central region, Amsterdam).

6. How long we keep it

  • Project data: for as long as your account is active. After cancellation it stays available for export for 60 days. We then delete the account and its project data within a further 30 days, so no later than 90 days after the subscription ended. Backup copies expire over the following 30 days in the ordinary course.
  • Account data: for as long as your account is active, then up to 12 months.
  • Billing and tax records: six years, as required by HMRC.
  • Audit trail: for the life of the project record. It is deliberately not editable, because a record that can be quietly changed is worthless as evidence.

Backups. Deleting a project removes it from the live service immediately. Backup copies persist for a further 30 days and are then overwritten in the ordinary course. We do not delete a single record from a backup, because a backup that can be edited is not a backup; we delete it by letting it expire.

7. Security

  • All traffic is encrypted in transit over HTTPS.
  • Passwords are stored as salted hashes, never in a readable form. We cannot see your password.
  • Each practice's project files are stored in a separate area, keyed to the account.
  • Guest links give access only to the single project they were issued for, at the permission level you choose, and can be revoked at any time.

QScope staff can access project data where it is necessary to provide support, to diagnose a fault, or to recover a project at your request. Access is limited to what the task requires. We do not access project data for any other purpose.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to people's rights, we will notify you without undue delay and report it to the Information Commissioner's Office where required.

8. Your rights

Where we are the controller, you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. You can also withdraw consent where we relied on it.

Where we act as your processor, we will help you answer a request from someone whose data is in your project, and we will not respond to such a request ourselves.

Write to help@qscope.co.uk. We will respond within one month.

If a person's data is in a project you control, send their request to the practice that holds the project, not to us. If you receive such a request and need our help to answer it, contact us and we will assist.

You can complain to the Information Commissioner's Office at ico.org.uk. We would rather you came to us first so we can put things right.

9. Changes

If we make a material change to this policy we will tell you by email before it takes effect.

Keep reading

Related