Privacy Policy
Version 1.2 · 23 July 2026

1. Introduction

This policy explains how Crut3D Methods Ltd ("we", "our", "the Company") collects, uses, retains and protects personal data in connection with its website, professional communications, commercial relationships and BIM and construction-methods services. It applies to processing governed by the UK GDPR, the Data Protection Act 2018 as amended, including by the Data (Use and Access) Act 2025, and, where applicable, the European Union General Data Protection Regulation (EU GDPR, Regulation (EU) 2016/679).

The English version is the reference version if there is any inconsistency in interpretation, without limiting rights granted by applicable law.

2. Data Controller

Crut3D Methods Ltd

Company No. 17337190 (registered in England & Wales)

Registered office: 9 Goldington Road, Bedford, MK40 3JY, United Kingdom

Privacy contact: contact@crut3dmethods.co.uk

Website: crut3dmethods.co.uk

Registered with the Information Commissioner's Office under reference ZC205948.

The Company is not required to appoint a Data Protection Officer at the date of this policy. Requests are handled by the person responsible for the Company.

3. Data Collected and Sources

Depending on your relationship with us, we may process the following categories of personal data:

  • Identity and contact details: name, job title, organisation, business address, email address and telephone number.

  • Enquiries and communications: contact-form content, emails, messages, meeting notes, correspondence history, voicemail and call logs.

  • Commercial and contractual information: quotations, proposals, purchase orders, contracts, instructions, invoices, payments, bank details where necessary, and information used to manage the client relationship.

  • Project information: documents and communications relating to BIM, construction methods, buildability and coordination projects, names and contact details appearing in project records, access permissions and collaboration records.

  • Telephone data: calling or called number, call date, time and duration, and, where recording is enabled, audio, transcription, translation, summary and related notes.

  • Website technical data: IP address, date and time, requested page or resource, browser, device type, approximate country, transferred data, response time, and error or security logs generated by the Hostinger infrastructure.

We obtain this data directly from you or, depending on the context, from your employer, client, project partners, a professional referral, publicly available professional sources such as company websites or LinkedIn, and the technical systems used to provide our services.

Sensitive data. We do not ask for special-category personal data, criminal-conviction data or payment-card details through the website. Please do not send this type of information through the contact form or by email unless there is a clearly established need and prior agreement.

Required information. Fields marked as mandatory are needed to answer your enquiry or prepare a contractual relationship. Without them, we may be unable to reply or provide the requested service.

4. Purposes and Lawful Bases
  • Answering enquiries and preparing a service. Lawful basis: pre-contractual steps where you contact us on your own behalf; legitimate interests where you act for an organisation.

  • Delivering and managing our services, projects and contracts. Lawful basis: performance of a contract; legitimate interests in processing the contact details and instructions of representatives, collaborators and partners of a client organisation.

  • Preparing quotations, invoices, accounts and filings. Lawful basis: performance of a contract and compliance with legal, tax and accounting obligations.

  • Operating, securing and troubleshooting the website and systems. Lawful basis: legitimate interests in protecting our services, preventing abuse, resolving incidents and maintaining proportionate audit records.

  • Measuring website audience through the analytics tool built into our website platform. Lawful basis: your consent, given through the cookie banner.

  • Managing calls, voicemail and, where enabled, recordings and transcriptions. Lawful basis: performance of a contract and legitimate interests in following instructions, service quality, continuity of communications and dispute prevention; consent only where required by applicable law.

  • Establishing, exercising or defending legal claims. Lawful basis: legitimate interests and, where relevant, compliance with a legal obligation.

Our legitimate interests are operating a B2B business, answering professional enquiries, securing our systems, delivering projects properly, maintaining proportionate evidence and protecting the rights of the Company and its clients. We assess these interests against your rights and freedoms.

5. Cookies, Analytics and Technical Logs

Strictly necessary cookies. Some cookies are essential for the website to function and to record your cookie preferences. They are set without consent because the website cannot operate properly without them.

Analytics cookies. Our website uses the analytics tool built into the Hostinger Website Builder platform to measure audience. It records aggregated information such as sessions, unique visitors, approximate country and device type, so that we can understand overall use of the site and improve its content. These cookies are only set after you give your consent through the cookie banner. They are never used for advertising, profiling or automated decision-making.

International transfer. Data collected through this analytics tool may be processed outside the United Kingdom, including in the United States, where the service provider is established. Such transfers are covered by appropriate safeguards as described in section 8.

Withdrawing your consent. You may accept, refuse or change your cookie choices at any time through the cookie preferences banner accessible from every page of the website. Refusing analytics cookies has no effect on your access to the site or its content.

No advertising tools. As at the date of this policy, Google Analytics 4, advertising pixels and marketing-profiling tools are not enabled on the website.

Technical logs. The hosting service automatically generates access, request and error logs, independently of cookies. These may contain an IP address, timestamp, browser or device information, approximate country and requested resource. They are used for security, troubleshooting and website availability, on the basis of our legitimate interests.

6. Calls, Recordings and Transcriptions

We use a business telephony provider for our professional telephone line. The provider may process telephone numbers, call dates, times and durations, call logs, voicemail and technical information needed to provide the service.

Where recording, transcription, translation or AI-assisted summaries are enabled, you are informed at the beginning of the call. You may object to recording by telling the person you are speaking with. Recording can be stopped where sensitive or unnecessary information needs to be discussed.

These functions are used only to follow instructions and commitments, maintain continuity of communications, improve service quality, prepare meeting records and prevent or manage disputes. Access is restricted to people who need it. Automatically generated summaries may contain errors and are checked by a person before any significant use.

7. Sharing, Processors and Recipients

We do not sell or rent personal data. Where necessary, data may be disclosed to the following categories of recipient:

  • Hostinger: website hosting, Website Builder, built-in analytics, technical logs, security and backups.

  • Google Workspace / Gmail: business email and, where used, document-collaboration tools.

  • Business telephony provider: telephony, call logs, voicemail, recordings, transcriptions and summaries where those functions are enabled.

  • Administrative and professional providers: accountant, accounting software, bank, payment provider, insurer, legal advisers, IT support and other providers subject to confidentiality obligations.

  • Clients and project partners: only where sharing is necessary for coordination, safety, service delivery or project requirements.

  • Authorities and public bodies: HMRC, Companies House, courts, regulators or law-enforcement bodies where required or permitted by law.

Where these organisations act as processors, they handle data under our instructions and a data-processing agreement. Some recipients, such as banks, authorities, insurers or professional advisers, may act as independent controllers for their own legal obligations.

8. International Transfers

Our providers may process or make some data accessible from the United Kingdom, the European Economic Area or other countries, including the United States. Before making a restricted transfer, we check that it is covered by an adequacy decision or regulation, or by appropriate safeguards. Depending on the applicable regime, these may include the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses and an assessment of the level of protection. You may request further information about the safeguards used, subject to confidentiality requirements.

9. Data Retention
  • Enquiries and prospects: up to 3 years after the last useful interaction, unless you object or a longer period is needed for a contract or dispute.

  • Client, contract and project records: for the relationship and generally 6 years after it ends, or longer where a contract, claim, insurance requirement or legal obligation requires it.

  • Accounting and tax records: at least 6 years from the end of the relevant company financial year, and longer in the circumstances specified by HMRC.

  • Call logs and voicemail: up to 12 months, unless deleted earlier or needed for a specific matter.

  • Recordings, transcripts and summaries: no more than 6 months within the service, unless a justified copy is retained for a contract or dispute, in which case the retention period for that matter applies.

  • Analytics data and technical logs: for the recent periods made available by our hosting provider, generally up to 30 days for the traffic view; access, error and security logs are retained only for as long as needed for troubleshooting, security and the provider’s obligations.

  • Rights requests and complaints: for as long as needed to handle them and demonstrate our response, generally up to 6 years after closure.

10. Your Rights

Depending on the processing and the applicable lawful basis, you may request access to your data, rectification, erasure, restriction, portability, or object to the processing. You may withdraw consent at any time where processing relies on consent, including for analytics cookies. In particular, you may object to processing based on our legitimate interests for reasons relating to your particular situation.

To exercise your rights, email contact@crut3dmethods.co.uk and describe your request. We may ask for reasonable information to verify your identity. We normally respond within one month, subject to extensions or exemptions permitted by law.

11. Data Protection Complaints

You may complain about how we use your personal data by emailing contact@crut3dmethods.co.uk with "Data Protection Complaint" in the subject line. We acknowledge receipt within 30 days, take appropriate steps to investigate without undue delay, keep you informed where necessary and communicate the outcome without undue delay.

We encourage you to contact us first so that we can try to resolve the issue. You retain the right to complain to the UK Information Commissioner’s Office. Where the EU GDPR applies, you may also complain to the competent authority where you live or work, including the CNIL in France.

12. Automated Decisions, Profiling and Children

We do not make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. Any artificial-intelligence tools used to transcribe or summarise communications are support tools and do not make decisions about you.

Our website and professional services are not directed at children and we do not intentionally seek to collect their data. If information about a child appears in a project document, it must be limited to what is strictly necessary and handled in accordance with the client’s instructions and applicable law.

13. Security

We apply technical and organisational measures proportionate to the risks, including access controls, strong passwords, multi-factor authentication where available, encrypted communications, backups, updates, restricted permissions, contractual confidentiality and incident-management procedures. No system can provide absolute security.

14. Updates

We review this policy when our services, providers or obligations change. Any material new use of personal data will be brought to your attention before implementation where required by law. The version published on the website shows the applicable review date and version number.

This policy must remain aligned with the settings actually enabled in Hostinger, Google Workspace and the business telephony service.

CONTACT@CRUT3DMETHODS.CO.UK

+44 1234 978359

© 2026 Crut3D Methods Ltd. All rights reserved.

Crut3D Methods Ltd · Company No. 17337190 · Registered in England and Wales · 9 Goldington Road, Bedford, MK40 3JY - ICO registration: ZC205948