Ribbonmark
Home Privacy Terms DPA
Legal

Privacy policy

Last updated 22 July 2026 · Ribbonmark is a product of Hili Limited

On this page 1. Who we are 2. Our two roles 3. Data we handle 4. How we use data 5. Sharing & sub-processors 6. International transfers 7. Residency & security 8. Retention 9. Your rights 10. Cookies 11. Changes 12. Contact

This policy explains how Hili Limited ("Ribbonmark", "we", "us") collects, uses, shares and protects personal data when you use the Ribbonmark website and application (the "Service"). It is written to meet our obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It should be read alongside our Terms of service and, for customers on whose behalf we process personal data, our Data processing addendum.

1. Who we are

Hili Limited (company number 17323707), registered in England & Wales
Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Contact: info@ribbonmark.co.uk

We are registered with the UK Information Commissioner's Office (ICO) as a data controller, registration number ZC193433. We have not appointed a statutory Data Protection Officer (not required at our size); privacy queries are handled by our team via the contact details above.

2. Controller and processor — our two roles

Ribbonmark is a business-to-business service, and our role under data protection law depends on the data:

  • When you are our customer (an installer, inspection firm or dutyholder organisation) and you upload building, doorset, inspection and evidence data into the Service, you are the data controller for that data and we act as your data processor, handling it on your instructions under our customer agreement and our Data processing addendum.
  • We act as a controller in our own right for the data we need to run our business — for example the account and identity details of the individuals who log in, billing information, and communications with you.

Where we are a processor, the controller's own privacy notice governs how the underlying data subjects' information is used; this policy describes our handling of it as processor.

3. The personal data we handle

CategoryExamplesOur role
Account & identity dataName, work email, employer/organisation, job role, authentication identifiersController
Field-captured recordsBuilding and doorset details, location references, inspection checklists, measurements, product selections, recommendationsProcessor (for our customer)
Evidence mediaPhotographs taken on site — with embedded metadata such as time and approximate location — which may incidentally include images of peopleProcessor (for our customer)
Certificates & handover packsGenerated documents that may name the operative and signatoryProcessor (for our customer)
Usage & technical dataDevice information, app and server logs, IP address, timestampsController
Billing dataCompany billing details processed via our payment providerController

We do not seek to collect special category data. Where an evidence photograph incidentally captures an identifiable person, our customer (as controller) is responsible for the lawful basis of that capture; we process such images only to provide the Service.

4. How and why we use personal data (and our lawful bases)

  • To provide the Service — authenticate users, capture and sync field data, generate certificates and handover packs. Lawful basis: performance of a contract; and, for the underlying records, our customer's instructions as processor.
  • To secure and maintain the Service — monitoring, logging, preventing abuse, backups and diagnostics. Lawful basis: legitimate interests (keeping the Service safe and reliable).
  • To understand and improve the Service — privacy-preserving product analytics that record which features are used, tied only to pseudonymous account identifiers, never to your field records or evidence media. Lawful basis: legitimate interests (understanding usage to maintain and improve the Service).
  • To communicate with you — service messages, support, and (where permitted) product updates. Lawful basis: legitimate interests, or consent where required.
  • To tell you about our products — where you have opted in, or where we rely on legitimate interests to contact people at businesses in our sector about services relevant to their work, we may send marketing about Ribbonmark. You can opt out at any time using the link in any message or by emailing info@ribbonmark.co.uk, and we will stop.
  • To take payment and keep records — billing and statutory record-keeping. Lawful basis: contract and legal obligation.
  • To comply with the law — responding to lawful requests and meeting our legal duties. Lawful basis: legal obligation.

5. Who we share data with (sub-processors and providers)

We use a small set of carefully chosen providers to run the Service. We do not sell personal data. Our providers, current and planned, are:

ProviderPurposeRegion
Google Cloud PlatformApplication hosting and evidence storageUnited Kingdom (London)
NeonManaged databaseUnited Kingdom (London)
Auth0 (Okta)Identity and loginUnited Kingdom
PostHogProduct-usage analytics (aggregate feature usage; no advertising cookies, no cross-site tracking)European Union (Frankfurt), under the safeguards in section 6
PowerSync (planned — not yet in use)Offline data synchronisation; today the app syncs directly with our own APIEuropean Union
Stripe (planned — only once billing is enabled)Payment processingUnited States, under the safeguards in section 6

An up-to-date list of sub-processors is maintained in Schedule B of our Data processing addendum. We put appropriate contracts in place with each provider. We may also disclose data where required by law, or in connection with a corporate transaction, subject to appropriate safeguards.

6. International transfers

We aim to keep personal data — including evidence media — hosted in the United Kingdom. Where a provider processes data outside the UK, we rely on an appropriate safeguard such as UK adequacy regulations or the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses). Our core records — accounts, field data and evidence media — are hosted in the United Kingdom. Our product-analytics provider (PostHog) processes a limited set of usage events in the European Union; transfers from the UK to the EEA are covered by UK adequacy regulations. Any provider that would process data outside the UK or the EEA (such as Stripe in the United States, once billing is enabled) is covered by the safeguards above before it is used.

7. Data residency & security

Your data, including evidence photos, is hosted in United Kingdom regions. Data is encrypted in transit and at rest, and each organisation's data is isolated at the database level, not merely in application code. We maintain access controls, logging and operational safeguards appropriate to the sensitivity of fire-safety records, and are designing towards ISO 27001 and Cyber Essentials Plus as we mature. No method of storage or transmission is completely secure, but we work to protect your data and to detect and respond to incidents.

8. How long we keep it

Fire-safety records are intended to endure for the life of a building. Where we act as processor, we keep the underlying records for as long as our customer instructs and their agreement remains in force, and we return or delete them on termination in line with that agreement. Account, billing and log data we hold as controller is kept only as long as needed for the purposes above and to meet legal and accounting requirements. Specifically: account and organisation records are kept for the life of your agreement and for 12 months afterwards; server and access logs for 12 months; and billing and accounting records for 6 years, as UK tax law requires.

9. Your rights

Subject to the conditions in data protection law, individuals have the right to: access their data; have inaccurate data corrected; have data erased; restrict or object to processing; data portability; and to withdraw consent where processing is based on consent. Where we act as a processor, please direct requests to the relevant controller (your organisation) in the first instance, and we will assist them in responding.

To make a request to us as controller, contact info@ribbonmark.co.uk; we will respond within one month of receiving your request (extendable where the law allows for complex requests, in which case we will tell you). You also have the right to complain to the ICO (ico.org.uk, helpline 0303 123 1113), though we'd appreciate the chance to resolve any concern first.

10. Cookies

This website uses only cookies and local storage that are strictly necessary for it to function and to remember preferences such as your light/dark theme. We do not use advertising cookies, and this website sets no analytics cookies. The Ribbonmark application uses cookies and similar technologies as needed to keep you signed in and to operate the Service. We use privacy-preserving product analytics within the application to understand which features are used; this operates server-side and does not set advertising or cross-site tracking cookies on your device. If we later introduce analytics that require cookies or your consent, we will update this policy and ask for that consent where required.

11. Changes to this policy

We may update this policy from time to time. We will post the updated version here and change the "last updated" date above; where changes are material we will take reasonable steps to notify you.

12. Contact

Questions about this policy or our handling of data can be sent to info@ribbonmark.co.uk, or by post to Hili Limited at the registered office above.

Ribbonmark

Ribbonmark is a product of Hili Limited, registered in England & Wales, company number 17323707. Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

ProductHow it worksA day on siteSecurityFAQ
Companyinfo@ribbonmark.co.ukPrivacy policyTerms of serviceData processing addendum

© 2026 Hili Limited. All rights reserved.Ribbonmark™ is a trademark of Hili Limited.