ENGcore

Legal

Privacy Policy

Last updated 27 August 2026.

1. Who we are

ENGcore ("ENGcore", "we", "us") provides a suite of engineering and compliance calculators for UK-based engineering teams, operated from the United Kingdom. For the purpose of UK data protection law, ENGcore is the data controller for the personal data described in this policy.

2. Data we collect

We collect:

  • Account data — email address, name, and organisation membership, collected when you sign in or are invited to an organisation.
  • Usage data — the inputs, calculations and exports you create within a tool, stored against your organisation so your team can find and review past work.
  • Technical data — IP address, browser type, and request logs, collected automatically for security and to keep the service running.

3. How we use it

We use your data to:

  • authenticate you and maintain your session across ENGcore tools;
  • run the calculation you request and store the result against your account;
  • send account-related email, including magic-link sign-in messages;
  • maintain the security and integrity of the service; and
  • meet our own legal and regulatory obligations.

We do not sell personal data, and we do not use your calculation inputs or results to train any model outside the service you asked us to run.

4. Legal basis

We process account and usage data under contract (to provide the service you signed up for) and technical data under legitimate interest (to keep the service secure and functioning). Where we rely on consent — for example, optional product email — you can withdraw it at any time.

5. Who we share it with

We use a small number of processors to run the service: infrastructure hosting, and transactional email delivery for sign-in links. Each processor is bound by a data processing agreement and only receives the data it needs to perform its function. We do not share personal data with third parties for their own marketing purposes.

6. International transfers

Where a processor stores or processes data outside the UK, we rely on that provider's UK-approved transfer mechanism (such as the UK International Data Transfer Addendum) to keep the transfer lawful.

7. Retention

We keep account and usage data for as long as your organisation has an active account, plus a limited period afterwards to meet legal, audit and dispute-handling obligations. You can request earlier deletion under your rights below.

8. Your rights

Under UK GDPR, you have the right to:

  • access the personal data we hold about you;
  • correct inaccurate data;
  • request erasure or restriction of processing;
  • object to processing based on legitimate interest;
  • receive your data in a portable format; and
  • complain to the Information Commissioner's Office (ICO) if you think we've got something wrong.

To exercise any of these rights, contact us using the details in Section 10.

9. Changes to this policy

We'll update the date at the top of this page when this policy changes, and tell affected organisations directly if a change materially reduces your rights.

10. Contact

Questions about this policy or your data: see the Contact page.