Privacy Policy
Last updated: 15 July 2026
1. Who we are
FillSizer is operated by EDSN Ltd, a company registered in England and Wales (Company No. 14709199), registered office at 13 Freeland Park, Wareham Road, Poole, Dorset, United Kingdom, BH16 6FA.
For data protection purposes, EDSN Ltd is the data controller. You can contact us at [email protected].
2. What data we collect
We collect and process the following categories of data:
| Category | Examples | Source |
|---|
| Account data | Name, email address | You provide this at sign-up (via Clerk) |
| Project data | PDF floorplans, cable schedules, equipment lists, route drawings, sizing calculations, export files | You upload or create this within the app |
| Billing data | Subscription status, payment history (card details are held by Stripe, never by us) | You provide this when purchasing a plan |
| Technical data | IP address, browser type, request logs, error reports | Collected automatically |
| Audit data | Significant actions performed in your organisation (who did what, when) | Collected automatically |
| Feedback | Bug reports, feature requests, questions and optional screenshots you submit | You provide this via the feedback form |
| Terms acceptance records | Which version of the Terms of Service you accepted, and when (at sign-up and when starting a purchase) | Recorded automatically when you accept |
3. How we use your data
We use your data for the following purposes:
- Providing the service - storing your projects, running containment sizing calculations, and generating exports.
- Account management - authenticating your identity, managing your organisation, and sending service emails about your account (for example a trial expiry warning, a payment problem notice, or a reminder before a scheduled account deletion).
- Billing - processing subscriptions and payments through Stripe.
- Security and integrity - detecting and preventing misuse, maintaining audit trails, preventing repeat use of the free trial (see section 6), and keeping a record of your acceptance of our terms.
- Improving the service - investigating errors reported automatically by the app and bug reports you send us.
- Communication - responding to your feedback and support requests.
4. Legal basis
Under UK GDPR, we process your data on the following legal bases:
- Contract performance (Art. 6(1)(b)) - account, project and billing data are necessary to provide the FillSizer service.
- Legitimate interest (Art. 6(1)(f)) - security logging, audit trails, error monitoring, repeat-trial prevention and terms-acceptance records help us maintain a reliable, safe and fairly operated service.
4A. Prospective customers (direct marketing)
Separately from the service itself, we send occasional short, professional introduction emails about FillSizer to named individuals in relevant engineering roles (mechanical and electrical building services) at UK limited companies and LLPs. We do not send marketing to sole traders or unincorporated partnerships, and we do not use personal email addresses.
- What we hold: name, job title, company, work email address, the public source the details came from, and our correspondence history with you. Nothing else.
- Where it comes from: publicly available professional sources such as company websites, Companies House records, professional directories and LinkedIn profiles (in some cases the address is derived from a company's published email address format).
- Legal basis: legitimate interests (Art. 6(1)(f)), supported by a documented Legitimate Interests Assessment, available on request. Business-to-business email to corporate subscribers is conducted in accordance with the Privacy and Electronic Communications Regulations (PECR).
- Limits we apply: at most three short emails, then we stop permanently. Contacts who do not reply are deleted within 6 months of the last email. Opt-outs are kept on a permanent suppression list (email address and date only) so we never contact you again.
- Your right to object: under Art. 21(2)-(3) UK GDPR you have an absolute right to object to direct marketing. Reply to any of our emails or write to [email protected] and we will stop immediately - no reason needed.
5. Error monitoring (Sentry)
We use Sentry to tell us when the app breaks, so we can fix it. Here is exactly what that involves:
- What is sent: when an error occurs, a report is sent containing the technical details of the error (stack trace), your browser and operating system type, and the page where the error happened. So that we can help you if the error affected your work, the report is associated with your account identifier and email address.
- Session Replay is disabled. Sentry offers a feature that records a video-like replay of what a user sees on screen. We do not use it: no screen recording or session replay of any kind takes place.
- Performance tracing: a small sample (10%) of requests carries timing information so we can find slow pages. This is performance metadata, not content.
- Server-side reports are configured not to include personal data by default.
- Purpose and legal basis: keeping the service working (legitimate interest, Art. 6(1)(f)).
- Retention: error reports expire automatically under Sentry's standard retention schedule; we do not keep them indefinitely.
6. What happens when you delete your account
You can request deletion of your account and all its data at any time from your account settings. The process works like this:
- 30-day grace period. Deletion takes effect 30 days after you request it. During that period the account is locked against new work, but you can still view your account status, download a full copy of your data, and cancel the deletion request. We send a reminder email before the deletion becomes final.
- Full erasure. After the grace period, your organisation and all its data are permanently deleted: projects, floorplans, schedules, calculations, exports, uploaded and generated files, audit logs, feedback records and billing records. Any active subscriptions are cancelled, and we ask Clerk (our sign-in provider) to delete your login identity.
- What remains, and why. Three minimal records survive the erasure:
- A deletion log entry containing only our internal organisation identifier and the deletion timestamp (accountability).
- For up to 90 days, your sign-in provider's user identifier, so that a leftover login session cannot silently recreate the deleted account.
- For up to 90 days, a one-way cryptographic hash (SHA-256) of your email address, kept solely to detect repeat free trials. If you sign up again with the same email address within that period, you can use the service and pay for a plan, but you will not receive a second free trial. We do not store your email address itself in this record, and we use the hash for no other purpose. It is deleted automatically when the 90 days expire.
- If a subscription cancellation with Stripe fails at the moment of erasure, we keep a retry record containing only our internal organisation identifier and the Stripe customer reference until the cancellation is confirmed, so you are never billed after deletion.
7. Third-party processors
We use the following third-party services to operate FillSizer. Each processes data on our behalf under appropriate contractual safeguards:
| Service | Purpose | Data processed |
|---|
| Clerk | Authentication and user management | Name, email, login sessions |
| DigitalOcean | Application hosting and managed database | All application data (encrypted at rest) |
| Cloudflare | DNS, traffic protection and file storage (R2) | Uploaded files, request metadata |
| Stripe (when paid subscriptions are enabled) | Subscription billing and payments | Name, email, payment details (card data is held by Stripe only) |
| Google Workspace | Email (support and correspondence; feedback you submit in the app is also emailed to our support inbox) | The content of emails and feedback you send us |
| Sentry | Error monitoring (see section 5) | Error reports, stack traces, browser info, account identifier and email of the affected user |
We do not use any analytics or advertising tracking service.
8. Data retention
- Account and project data - retained for the lifetime of your account, and deleted through the process described in section 6 when you request deletion.
- Post-deletion records - as described in section 6: the sign-in identifier and email hash are kept at most 90 days and purged automatically; the minimal deletion log and any pending billing-cancellation retry record are kept for accountability.
- Error reports - expire under Sentry's standard retention schedule.
- Server request logs - kept for a limited period by our hosting provider for security and troubleshooting.
9. Your rights
Under UK GDPR, you have the following rights regarding your personal data:
- Access - request a copy of all data we hold about you.
- Rectification - request correction of inaccurate data.
- Erasure - request deletion of your account and all associated data (see section 6).
- Data portability - download your data yourself, at any time, from your account settings. The export is a ZIP file containing your account, project, billing, feedback and audit records in structured, machine-readable formats, together with your uploaded floorplan PDFs and generated export files.
- Restriction - request that we limit processing of your data in certain circumstances.
- Objection - object to processing based on legitimate interest.
To exercise any of these rights, contact us at [email protected]. You can also export your data or request account deletion directly from your account settings within the app.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
10. Cookies and local browser storage
FillSizer uses only what is strictly necessary to sign you in and make the app work. Under PECR, strictly necessary storage does not require consent, which is why you will not see a cookie banner:
- Authentication cookies set by Clerk, our sign-in provider, to keep you signed in securely.
- Local browser storage used for app functionality only: your interface preferences (for example table column widths and zoom level), dismissed hint messages, a random identifier used to prevent duplicate votes in the anonymous feature poll, and a short-lived note of a plan you chose on the pricing page so the purchase can continue after you sign in.
We do not use advertising, analytics or cross-site tracking cookies of any kind.
11. Data security
We take appropriate technical and organisational measures to protect your data, including:
- Encryption in transit (TLS/HTTPS on all connections).
- Encryption at rest (managed database and object storage encryption).
- Organisation-scoped access control - your data is isolated from other organisations.
- Audit logging of significant actions.
- Regular security reviews of the application.
12. International transfers
Some of our third-party processors may process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses or adequacy decisions) in compliance with UK GDPR.
13. Changes to this policy
We may update this privacy policy from time to time. Material changes will be communicated via the app or email. The "last updated" date at the top of this page indicates when this policy was last revised.
14. Contact
For any questions about this privacy policy or your personal data, contact:
EDSN Ltd (registered in England and Wales, Company No. 14709199)
13 Freeland Park, Wareham Road
Poole, Dorset, BH16 6FA
United Kingdom
[email protected]