1. Who We Are
NOETA is an AI-native construction compliance service that prepares SSIP and CHAS accreditation documentation for UK construction businesses. The service is operated by:
- Legal name: NOETA LTD
- Company number: 17258957
- Registered address: 118 Hows Building, 2-4 Westfield Avenue, London, E20 1NA, United Kingdom
- ICO registration: ZC165149
- Contact email: contact@noeta.uk
- Website: noeta.uk
NOETA LTD acts as the Data Controller for personal data collected through this website and application portal. For data processed on your behalf as part of delivering the accreditation service, NOETA LTD also acts as Data Processor.
2. What Personal Data We Collect
We collect the following categories of data when you create an account, complete an intake form, or upload documents through the NOETA application:
2.1 Account and Contact Data
- Email address (used solely for magic-link authentication — no password is ever stored)
- Company name, trading name, and registered address
- Name and job title of the responsible person for health and safety
2.2 Compliance and Business Data
- Details of your company's trade, employee count, and declared activities
- Health and safety policies, risk assessments, method statements, and related documents you upload
- Insurance certificate details (insurer, policy number, coverage amounts, expiry dates)
- RIDDOR incident data and workforce consultation arrangements
- Named individuals (directors, H&S advisors, responsible persons) as declared in your intake
2.3 Application Activity Data
- Records of your accreditation applications, readiness scores, and gap reports
- Assessor feedback you paste into the platform for re-analysis
- Timestamps of key actions (application created, documents uploaded, pack downloaded)
2.4 Third-Party Portal Credentials (Optional)
Where you have an existing CHAS Veriforce portal account and ask us to submit your application on your behalf, we collect:
- Your CHAS portal username
- Your CHAS portal password
Passwords are encrypted using AES-256-GCM with an isolated server-side key before being written to the database. The plaintext password is never stored on disk and is only decrypted at the point of submission to deliver the contracted service. You may decline to provide these credentials, in which case we will deliver a submission-ready pack for you to upload yourself.
We do not collect or store payment card details. Payments are processed directly by Stripe — see Section 4.4.
3. Lawful Basis for Processing
We process your personal data under the following lawful bases as defined in Article 6 of the UK General Data Protection Regulation (UK GDPR):
3.1 Contract Performance — Article 6(1)(b)
The primary basis for processing is to perform the contract between you and NOETA LTD. This covers:
- Receiving and analysing the documents you upload
- Generating your gap report and readiness score
- Preparing draft compliance documents on your behalf
- Assembling and delivering your submission-ready accreditation pack
- Processing assessor feedback to support resubmission
- Submitting your application to the CHAS Veriforce portal on your behalf, where you have asked us to do so and provided your portal credentials
3.2 Legitimate Interests — Article 6(1)(f)
We process certain data on the basis of our legitimate interests, having balanced these against your rights and interests:
- Maintaining platform security: audit logs and rate-limiting data to prevent abuse and unauthorised access
- Improving service quality: anonymised and aggregated analysis of gap report outcomes to refine our assessment logic — no identifiable personal data is used for this purpose
- Operational continuity: retaining records to support renewal reminders and accreditation tracking
3.3 Legal Obligation — Article 6(1)(c)
We retain invoicing and transaction records to comply with UK tax and financial record-keeping obligations.
4. Third-Party Data Processors
NOETA LTD uses the following sub-processors to operate the platform. All are engaged under written Data Processing Agreements and are bound by equivalent data protection obligations:
4.1 Supabase, Inc.
Supabase provides the platform's authentication, database, and file storage infrastructure. Your documents and application data are stored on servers located in the West Europe (Netherlands) region. Supabase's standard Data Processing Agreement applies. No data is stored outside the European Economic Area.
4.2 Anthropic, PBC
Anthropic's Claude API is used to extract information from the documents you upload and to analyse your evidence against SSIP accreditation criteria. Document content is transmitted to Anthropic's API solely for this processing purpose. Under Anthropic's standard API terms and the applicable Data Processing Agreement, content submitted via the API is not used to train Anthropic's models. Anthropic is based in the United States; processing occurs under Standard Contractual Clauses as the appropriate safeguard.
4.3 Upstash, Inc.
Upstash provides Redis-based rate limiting to protect the platform against abuse. Upstash processes request metadata (IP-derived identifiers and timestamps) only — no personal data from your application or documents is transmitted to Upstash. Our rate-limiting database is hosted in the EU-West-1 (Ireland) region.
4.4 Stripe Payments Europe Ltd
Stripe processes payment transactions on our behalf. When you make a payment, your card details are entered directly into Stripe's hosted checkout — they never touch NOETA's servers. Stripe receives your email address, billing name, and transaction amount as part of normal payment processing. Stripe's data processing is governed by their own Privacy Policy and applicable Data Processing Agreement. Stripe is based in Ireland; processing occurs within the European Economic Area.
4.5 Google Workspace (Email Delivery)
Google Workspace is used to send authentication emails (magic links) and transactional service emails (status updates, renewal reminders). Email content includes your registered email address and the body of the message. Emails are sent from noreply@noeta.uk through Google's SMTP infrastructure. Google's data handling is governed by Google Workspace's standard terms and Data Processing Agreement.
4.6 Google Ireland Limited (Advertising Measurement — Cookieless)
We use Google Ads conversion measurement to understand whether visitors who arrive from a Google advertisement go on to purchase. This measurement is operated in a strictly cookielessconfiguration: Google's tag is initialised with Consent Mode v2 and every storage category (advertising, analytics, functionality, personalisation) is set to denied. As a result, the Google tag does not place advertising or analytics cookies on your device, does not read existing identifiers, and does not build a profile of you across sites.
When a purchase completes, a single event is transmitted to Google containing the purchase value, currency, and a payment-processor transaction reference (to prevent double-counting). No personal information about you, no account or session identifier, and no device-storage identifier is included. Google receives the event and the standard request metadata that any HTTP request carries (IP address, browser user agent, page URL). Google Click ID parameters present in the URL are read but not stored.
The lawful basis for this processing is our legitimate interest in measuring the effectiveness of our marketing spend (UK GDPR Article 6(1)(f)). Because no information is stored on or accessed from your device, this processing is outside the scope of PECR consent requirements. You can prevent this processing entirely by using your browser's ad-blocker, by enabling tracking protection, or by adjusting your Google account ad personalisation settings at myadcenter.google.com.
Google Ireland Limited is the data controller for the data it receives, processing under its own privacy policy. Where data is transferred outside the UK / EEA, Google relies on Standard Contractual Clauses as the appropriate safeguard.
4.7 Vercel Inc. (Hosting and Cookieless Web Analytics)
Vercel hosts the noeta.uk website and edge infrastructure. In addition, we use Vercel Web Analytics to understand how many people visit the site, which pages they read, and which marketing channels send traffic. Vercel Web Analytics is cookieless by design: it does not place any cookies on your device, does not assign a persistent identifier, and does not track you across sessions or other websites.
For aggregate visitor counting, Vercel hashes your IP address combined with the page URL into a short-lived, non-reversible identifier that resets daily. The hash exists only to count unique visitors within a single day; no individual is identified. Information collected is limited to: page URL, referrer, device class (desktop / mobile / tablet), country / region, and the hashed identifier described above. No purchase data, account data, or document content is sent to Vercel Web Analytics.
The lawful basis is our legitimate interest in understanding aggregate site usage to improve the service and measure marketing effectiveness (UK GDPR Article 6(1)(f)). Because no information is stored on or accessed from your device, this processing is outside the scope of PECR consent requirements. Vercel Inc. is based in the United States; processing occurs under Standard Contractual Clauses.
We do not share your data with CHAS, SSIP, or any accreditation body except where you explicitly direct us to act on your behalf as part of service delivery.
5. Data Storage and Security
All documents you upload are stored in a private storage bucket with no public access. Files are never reachable via a guessable or shareable URL. Access is granted exclusively through time-limited signed URLs generated server-side on authenticated request, expiring after 60 seconds.
Database access is governed by row-level security policies that ensure each user can only access their own application records. It is not possible for one user to view another user's documents or gap reports through any application route.
Authentication uses magic-link email only. No passwords are ever created, stored, or transmitted.
6. Data Retention and Deletion
6.1 Retention Period
Application data (including uploaded documents, intake responses, gap reports, and generated documents) is retained for 24 months from the date the application is created. This period covers the standard CHAS certificate validity and the first annual renewal cycle.
After 24 months, application records are anonymised rather than deleted outright. Anonymisation removes all personally identifiable fields. Retained fields are limited to: accreditation scheme, overall readiness status, and completion date — used solely for aggregate service quality analysis.
6.2 Your Right to Delete
You may request deletion of your application data at any time. Within the application portal, you can delete any of your applications, which permanently removes all associated documents and data from storage.
Deletion requests submitted by email are processed within 30 days. Note that deletion prior to the end of the 24-month retention period does not affect anonymised aggregate records already generated, as these contain no personal data.
7. Your Rights Under UK GDPR
Under UK GDPR, you have the following rights:
- Right of access: to request a copy of the personal data we hold about you
- Right to rectification: to request correction of inaccurate or incomplete data
- Right to erasure: to request deletion of your personal data (subject to legal retention requirements)
- Right to restriction: to request that we limit how we process your data
- Right to data portability: to receive your data in a structured, machine-readable format
- Right to object: to object to processing based on legitimate interests
- Right to withdraw consent: where processing is based on consent, to withdraw it at any time without affecting prior lawful processing
To exercise any of these rights, contact us at contact@noeta.uk. We will respond within one calendar month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies and Local Storage
NOETA uses a minimal number of strictly necessary cookies. We do not use advertising cookies, analytics cookies, or any cross-site tracking technologies on this website.
8.1 Strictly Necessary Cookies
- Authentication session cookie: set by Supabase Auth to maintain your logged-in session after you click a magic link. This cookie is essential; the application cannot function without it.
- CSRF / admin cookies: short-lived cookies that protect form submissions and the operator console against forgery. Essential for security.
Your current application step is stored in browser localStorage — not in a cookie — and contains only a job identifier and step number. No personal data or document content is stored client-side.
8.2 Advertising Measurement (Cookieless)
On our public marketing pages we load Google's gtag.js script for conversion measurement of our advertising. The script is initialised in cookieless mode (Google Consent Mode v2, all storage categories denied), so it does not place advertising or analytics cookies on your device and does not read existing identifiers. A single cookieless event is transmitted to Google when a purchase completes; the data sent and your options are described in detail at Section 4.6 above.
8.3 Web Analytics (Cookieless)
We also use Vercel Web Analytics on the marketing pages to count visitors and page views in aggregate. The Vercel Analytics script is cookieless by design — it places no cookies, does not read existing identifiers, and does not track you across sessions. Aggregate visitor counting relies on a daily-rotating one-way hash of your IP address combined with the page URL; no individual is identified. See Section 4.7 above for details.
Because neither advertising measurement nor web analytics stores anything on or accesses anything from your device, no PECR consent banner is shown. If you would prefer neither to run at all, please use a browser-level ad blocker or tracking-protection feature, which will prevent both scripts from loading.
9. Changes to This Policy
We may update this Privacy Policy when our processing activities or legal obligations change. Material changes will be communicated to registered users by email before they take effect. The most recent version is always published at noeta.uk/privacy with the date of last update.
10. Contact
For any questions about this Privacy Policy, to exercise your rights, or to raise a concern:
- Email: contact@noeta.uk
- Website: noeta.uk
- Post: NOETA LTD, 118 Hows Building, 2-4 Westfield Avenue, London, E20 1NA