Back to Home

Privacy Policy

Last updated: 8 December 2025

1. Introduction

RAMS Builder ("we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our Risk Assessment Method Statement (RAMS) building service.

We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data Controller

RAMS Builder, operated by Ictus Flow, is the data controller responsible for your personal data.

3. Information We Collect

We collect the following types of information:

Account Information

  • Email address
  • Full name
  • Company name
  • Contractor type (main contractor/subcontractor)
  • Password (securely hashed)

RAMS Document Data

  • Project information (titles, addresses, descriptions)
  • Client and contractor details
  • Risk assessments and method statements
  • CDM (Construction Design and Management) information

Technical Data

  • IP address
  • Browser type and version
  • Device information
  • Usage data and analytics

Payment Information

  • Payment history (amounts, dates, status)
  • Subscription tier
  • Note: Card details are processed securely by Stripe and never stored by us

4. Legal Basis for Processing

We process your data based on:

  • Contract: Processing necessary to provide our RAMS building service
  • Legitimate Interest: To improve our service and prevent fraud
  • Consent: For marketing communications (where you have opted in)
  • Legal Obligation: To comply with UK laws and regulations

5. How We Use Your Information

We use your information to:

  • Provide and maintain the RAMS Builder service
  • Process payments and manage subscriptions
  • Generate AI-powered RAMS content
  • Send service-related communications
  • Improve our service and develop new features
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

6. Data Sharing

We share data with the following third parties:

ServicePurposeData Shared
SupabaseDatabase hosting and authenticationAll account and document data
StripePayment processingEmail, payment details
Anthropic (Claude AI)AI content generationProject details for RAMS generation

We do not sell your personal data to third parties.

7. Data Retention

We retain your data for as long as your account is active. After account deletion:

  • Account data is deleted immediately
  • RAMS documents and associated data are deleted immediately
  • Payment records may be retained for up to 7 years for legal/tax purposes
  • Anonymized analytics data may be retained indefinitely

8. Your Rights (GDPR)

Under UK GDPR, you have the following rights:

Right of Access (Article 15)

Request a copy of all personal data we hold about you.

Right to Rectification (Article 16)

Request correction of inaccurate or incomplete data.

Right to Erasure (Article 17)

Request deletion of your personal data ("right to be forgotten").

Right to Data Portability (Article 20)

Receive your data in a machine-readable format (JSON).

Right to Object (Article 21)

Object to processing of your data for certain purposes.

To exercise these rights, visit your Account Settings page or contact us directly.

9. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit (HTTPS/TLS)
  • Encryption at rest for database storage
  • Row Level Security (RLS) to isolate user data
  • Regular security audits and updates
  • Access controls and authentication
  • Secure password hashing

10. International Transfers

Your data may be processed in countries outside the UK. We ensure appropriate safeguards are in place, including Standard Contractual Clauses or adequacy decisions where applicable.

11. Children's Privacy

RAMS Builder is not intended for use by individuals under 18 years of age. We do not knowingly collect data from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice on our website.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:

Email: privacy@ramsbuilder.com
Address: RAMS Builder, Ictus Flow Ltd

14. Supervisory Authority

You have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Website: ico.org.uk
Phone: 0303 123 1113