Data processing terms
These terms form part of our terms of service. They cover personal information you (the customer) put into QualTrack, for which you're the controller and QualTrack Ltd (“QualTrack”, “we”) is your processor, as UK data protection law (the UK GDPR and the Data Protection Act 2018) requires.
1. What we process
| Purpose | Providing QualTrack to you: holding records of your operatives' tickets, qualifications and training, working out who is in date, sending reminders and booking notices, producing Passports, exports and reports, showing each operative's site check page to whoever scans their site card, and printing site cards when you order them from us. |
|---|---|
| People | Your operatives, and members of your team who use QualTrack. |
| Information | Names, employee references, job roles, departments, start dates and who they're employed by; optionally email addresses, mobile numbers and photos; tickets, qualifications and training with dates, card numbers and copies of certificates; card checks (how, when and by whom); bookings; the reminders sent; and when each site card was scanned. |
| Sensitive information | None is needed. Don't record health or other special category information unless a ticket itself requires it. |
| How long | For as long as you use QualTrack, then as in section 8. |
2. Your instructions
We only process this information to provide QualTrack as these terms describe, and as you direct through QualTrack and its settings. Those are your documented instructions. If we believe an instruction breaks data protection law, we'll tell you. If the law requires us to process the information otherwise, we'll tell you first unless the law forbids it.
Quote requests to training partners don't include any of this information: only the course, how many people, where and when, and the details of the team member asking. Nor do feature suggestions (“Ideas and updates”): they hold what your team member wrote and who sent it, and we ask them to leave operatives' names out. If one slips in, we take it out when we read it.
3. Confidentiality
Anyone working on QualTrack for us who could access your information is bound to keep it confidential. QualTrack staff can only see operative records while your owner has turned on support access (read-only, at most 72 hours, logged where you can see it).
4. Security
We keep appropriate technical and organisational measures in place, including:
- encryption of information on its way to and from QualTrack, and at rest by our database provider;
- each customer's records kept apart by the database itself, so one customer can never read another's;
- certificates and photos stored privately and shown only through short-lived links, except that an operative's photo is shown on their site check page to whoever scans their site card, which you can switch off for your organisation or replace for one operative at any time;
- roles within your team, so managers only see their own department;
- authenticator-app sign-in for QualTrack staff, and a log of every look and change they make;
- error reports with names, contact details and page contents removed;
- daily backups by our database provider.
5. Sub-processors
You agree to us using these sub-processors. Each is bound by a written contract with data protection obligations no weaker than these. We'll tell account owners at least 30 days before adding or replacing one; if you object on reasonable data protection grounds and we can't resolve it, you can cancel.
| Sub-processor | What for | Where |
|---|---|---|
| Supabase | Database, sign-in and file storage (certificates and photos) | London, UK |
| Vercel | Hosting the app | London, UK (a US company) |
| Resend | Sending alert and sign-in emails | USA |
| Twilio | Sending alert texts, when switched on | USA |
| Stripe | Payments and subscriptions | UK, EU and USA |
| Sentry | Error reports, with names, emails, phone numbers and page contents removed | EU (Germany) |
| Cloudflare | Turnstile, the check at sign-up and sign-in that stops automated sign-ups | Global network |
| CardHero (Lesar UK Ltd) | Printing site cards, only when you order printed cards: the cards as you'd download them | Blackburn, UK |
6. Transfers outside the UK
Where a sub-processor handles information outside the UK, we make sure a safeguard UK law recognises is in place, such as the UK's data bridge with the US, the UK international data transfer agreement, or the UK addendum to the EU standard contractual clauses.
7. Helping you
- People's requests. QualTrack lets you view, correct, export and delete records yourself: an operative's details are corrected on their Passport, exported in the operatives CSV and their Passport, and deleted for good from their Passport, which also removes their name and contact details from the alert history and audit log. If someone asks us directly about records you control, we'll pass the request to you and help you answer it.
- Breaches. If we become aware of a breach affecting your information, we'll tell you without undue delay, and aim to within 48 hours, with what we know and what we're doing about it.
- Assessments. We'll give you reasonable help with data protection impact assessments and with the Information Commissioner's Office, as far as they concern QualTrack.
8. At the end
You can export your records at any time, including while your account is read-only after cancelling. A read-only account is deleted 12 months after it became read-only (your owners are emailed a month before, and choosing a plan keeps it). When your owner asks us to delete the account (in Settings, or by email), we delete your information within 30 days. Either way it goes from backups when those are overwritten, unless the law requires us to keep it.
9. Information and audits
We'll give you the information you reasonably need to show these obligations are met, and answer reasonable questions about our security. Ask at support@qualtrack.co.uk.
Last updated 7 October 2026. Questions: support@qualtrack.co.uk.