Privacy Policy
How Recast collects, uses, and protects your personal data — effective 26 March 2026
| Data Controller | Recast · Sven Gillet |
| ICO Registration | ZC111581 |
| Contact | [email protected] |
| Effective date | 26 March 2026 |
| Version | 1.1 |
This Privacy Policy explains how Recast ("we", "us", "our") collects, uses, stores, and protects personal data when you use our platform at recastplatform.co.uk. We are committed to protecting your privacy and handling your data transparently and in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Please read this policy carefully. By using the Recast platform you acknowledge that you have read and understood this policy.
Who We Are
Recast is a live intelligence platform for demolition activity and reclaimed construction materials across the United Kingdom. The platform is operated by Sven Gillet, trading as Recast, registered with the Information Commissioner's Office (ICO) under registration number ZC111581. Contact: [email protected]
For all data protection enquiries, please contact us at: [email protected]
What Personal Data We Collect
2.1 — Data You Provide Directly
When you register for an account, we collect: your email address, full name, organisation, and profession. When you submit a project through the submission portal, we collect the information you enter across all five tabs of the submission form, including contact details for the project. When you contact us by email, we retain the contents of your correspondence.
2.2 — Data We Collect Automatically
When you use the platform, we may collect: your IP address, browser type and version, the pages you visit, the time and date of your visit, and how you interact with the platform. We use Plausible Analytics, a privacy-respecting analytics service that does not use cookies and does not collect personally identifiable information.
2.3 — Data We Collect From Third Parties
We collect publicly available planning application data from Local Planning Authority (LPA) portals, planning.data.gov.uk, and planit.org.uk. This data relates to demolition projects and does not ordinarily contain personal data about private individuals.
2.4 — Data We Do Not Collect
We do not collect: special category data, financial or payment data (the platform is currently free), or data about children. If you are under 16, please do not register for an account.
How We Use Your Personal Data
| Purpose | Data Used | Legal Basis (UK GDPR) |
|---|---|---|
| Provide and operate the platform | Email, name, organisation, usage data | Contract (Art. 6(1)(b)) |
| Create and manage your account | Email, name, password (hashed), preferences | Contract (Art. 6(1)(b)) |
| Send material watch alerts | Email, alert preferences, location | Contract (Art. 6(1)(b)) |
| Send newsletter | Email, name | Consent (Art. 6(1)(a)) — withdraw at any time |
| Process project submissions | All submission form data, contact details | Contract & Legitimate Interest (Art. 6(1)(b)(f)) |
| Account security & verification | Email, IP address, tokens | Legitimate Interest (Art. 6(1)(f)) |
| Prevent fraud and abuse | IP address, usage data, failed login records | Legitimate Interest (Art. 6(1)(f)) |
| Comply with legal obligations | All data as required | Legal Obligation (Art. 6(1)(c)) |
| Platform analytics (anonymised) | Anonymised usage data only | Legitimate Interest (Art. 6(1)(f)) — no personal data |
| AI-assisted data processing | Project and material data — personal data pseudonymised | Legitimate Interest (Art. 6(1)(f)) — see Section 08 |
How Long We Keep Your Data
| Data Category | Retention Period | End of Retention Action |
|---|---|---|
| Registered user account data | Until deletion + 30 days | Personal data purged. Submitted project records anonymised. |
| Email (newsletter subscribers) | Until unsubscribe + 7 days | Deleted from email provider list. |
| Project submission data (public) | Indefinitely — permanent demolition atlas | Anonymised if submitter deletes account. Archived on project completion. |
| Private contact data (Tab 4) | 3 years from submission or until project archived | Deleted from contacts_private table. Logged in audit trail. |
| IP addresses | Pseudonymised after 30 days · deleted at 12 months | Pseudonymised by scheduled job. Deleted at 12 months. |
| Correspondence (emails to Recast) | 3 years | Deleted from email provider. |
| Audit log records | 7 years minimum | Immutable. Cannot be deleted by any role. |
| Authentication tokens | 1 hour (reset) · 48 hours (verify) | Auto-purged on expiry. |
Who We Share Your Data With
We do not sell your personal data to any third party. We do not share your personal data with advertisers.
5.1 — Service Providers
| Provider | Service | Data Shared | Location |
|---|---|---|---|
| Supabase | Database hosting | Account and project data | EU (Ireland) — GDPR compliant |
| Vercel | Website hosting | None (static files only) | Global CDN — no personal data |
| Cloudflare | DNS, email routing, security | IP addresses (standard web traffic) | Global — DPA in place |
| SendGrid / Postmark | Transactional email | Email address, email content | EU/UK DPA in place |
| Plausible Analytics | Website analytics | Anonymised, aggregated data only | EU (Germany) — no cookies |
| Anthropic (Claude API) | AI-assisted classification | Project and material data only — personal data excluded | EU/UK DPA in place |
5.2 — Legal Requirements
We may disclose personal data if required to do so by law or a court order. We will always seek to limit such disclosure to the minimum necessary.
5.3 — Business Transfer
If Recast is acquired or merged, your personal data may be transferred as part of that transaction. You will be notified in advance.
Your Rights Under UK GDPR
To exercise any of these rights, contact [email protected]. We will respond within one calendar month.
| Right | What It Means for Recast Users |
|---|---|
| Access (Art. 15) | Request a copy of all personal data we hold about you. |
| Rectification (Art. 16) | Ask us to correct inaccurate data. Update most profile data via your dashboard. |
| Erasure (Art. 17) | Delete your account at any time without our approval. Personal data purged within 30 days. Submitted project records anonymised rather than deleted. |
| Restrict Processing (Art. 18) | Ask us to pause processing in certain circumstances. |
| Data Portability (Art. 20) | Request your account data in machine-readable format (JSON). |
| Object (Art. 21) | Object to processing based on legitimate interests. |
| Automated Decision-Making (Art. 22) | We use AI to classify project data. No automated decisions with significant legal effects are made about you personally. Request human review of any decision that affects you. |
| Withdraw Consent | Withdraw newsletter consent at any time by clicking unsubscribe in any email. |
If you are not satisfied with our response, you have the right to lodge a complaint with the ICO at ico.org.uk or by calling 0303 123 1113. ICO registration number: ZC111581.
Cookies
Recast uses a minimal number of cookies. For full details please see our Cookie Policy. We will always ask for your consent before setting any non-essential cookies. Essential cookies (login session, CSRF protection, consent preference) are set without requiring consent.
AI-Assisted Data Processing
Recast uses artificial intelligence to assist with the classification, enrichment, and processing of demolition project and material data. We are transparent about this use.
What AI Is Used For
- Classifying demolition project records ingested from planning portals.
- Enriching project records with supplementary data from public sources.
- Detecting duplicate records across multiple data sources.
- Generating material watch alert notifications matched to your preferences.
- Drafting the weekly newsletter (subject to human editorial review before dispatch).
What AI Is Not Used For
- Making automated decisions with legal or significant effects about you personally.
- Processing your private contact details, account password, or any special category data.
- Assigning the Verified trust tier to any project record — this always requires human review.
Personal Data Safeguards
All personal data is pseudonymised or excluded before being passed to any AI processing service. Contact data is never transmitted to third-party AI APIs. A machine-readable AI transparency disclosure is available at /api/v1/transparency/ai-processing.
Data Security
- All data transmitted between your browser and our platform is encrypted using TLS 1.3.
- All data stored in our database is encrypted at rest using AES-256 encryption.
- Passwords are stored as one-way cryptographic hashes (bcrypt) and are never transmitted in plain text.
- Private contact data is subject to additional application-layer encryption, accessible only to authorised administrators.
- Access to personal data is restricted to authorised personnel with role-based access controls.
- All access to sensitive data is logged in an immutable audit trail retained for a minimum of seven years.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and notify affected individuals without undue delay.
International Data Transfers
Your personal data is primarily stored in the European Union (Ireland) on Supabase infrastructure. Where data is transferred outside the UK or EU, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs), in compliance with UK GDPR Chapter V. We do not transfer private contact data or account passwords outside the Recast infrastructure boundary.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email and update the effective date above. The current version is always available at recastplatform.co.uk/privacy.