Privacy policy
SysteMate builds and runs bespoke business systems for small businesses in the United Kingdom. This policy explains what data those systems hold, who else touches it, and how to get it out or have it deleted.
It is written for two audiences: the businesses who use SysteMate, and their own customers whose details end up in it. Contact for anything below: admin@systemate.uk.
Who controls what
When a business uses SysteMate, that business is the data controller for the information it puts in — its customers, their addresses, the work done for them. SysteMate is the processor: we hold and process that information on their instructions and do not use it for anything else.
For the account information of the businesses themselves — who signed up, billing, support correspondence — SysteMate is the controller.
What a system holds
| Account | Name, work email address, a hashed password, and which business the account belongs to. Passwords are stored hashed and cannot be read by us. |
|---|---|
| The business's own records | Its customers and their contact details, site addresses, jobs, bookings, on-site reports, quotes and invoices — whatever that business's system is configured to record. |
| Files | Photographs taken on site, receipts, and signatures captured on screen. |
| Activity | A record of changes to a job — who moved it, when — so the history of a piece of work can be reconstructed. |
| Session | A cookie that keeps you signed in. There is no advertising, analytics or third-party tracking on the application. |
We do not sell data, we do not share it with advertisers, and we do not use one business's data to do anything for another.
Google Calendar
A business can optionally connect a Google Calendar so that bookings made in SysteMate appear in the calendar its staff already use. This is off unless it is switched on and explicitly authorised by someone at that business.
What we ask for, and what we do not
We request the calendar.events scope only. That permits
creating and updating events. We deliberately do not request the
full calendar scope, which would allow reading and altering everything in
a person's diary.
- We create and update events that correspond to bookings made in SysteMate.
- We store the identifier of an event we created, so a changed booking updates the right event rather than adding a second one.
- We do not read, copy, index or store the contents of any other event in the calendar.
- We do not use Google data for advertising, and we do not sell it.
- We do not use Google user data to train generalised artificial-intelligence or machine-learning models.
- No human at SysteMate reads Google calendar data, except where you have asked us to help with a specific problem, where the law requires it, or to investigate abuse or a security incident.
Disconnecting
A connected calendar can be disconnected at any time from within SysteMate's settings, which deletes the stored authorisation. Access can also be revoked directly from your Google account permissions. Events already created remain in the calendar, because they are the business's own bookings — delete them in Google Calendar if they are not wanted.
Who else processes the data
SysteMate is built on a small number of established providers. Each is used for one job and nothing more.
| Vercel | Runs the application. Configured to execute in the London region. |
|---|---|
| Neon | The database. Hosted in London (eu-west-2). |
| Cloudflare R2 | Stores photographs, receipts and signatures. |
| Anthropic | Used only by the optional "paste a message" feature. When a user pastes a message — typically a job sent by a subcontractor — that text is sent to Anthropic's API to be read into a draft job, which the user then confirms. Most messages are handled by SysteMate's own rules and never leave our systems. Anthropic does not use this content to train its models. |
| Resend | Delivers email, where a business has email sending switched on. It sees the recipient address and the message. |
| Only where a calendar has been connected, as described above. |
Where it is kept, and for how long
Data is stored in the United Kingdom and the European Economic Area. Some providers above are United States companies and may process data outside the UK under the safeguards their agreements provide.
A business's records are kept for as long as it is a SysteMate customer. When an agreement ends, we provide a full export in an open format and then delete the system, including backups, within 90 days. A business can ask for individual records to be deleted at any time — we act on the instruction of the business, not of its individual customers, which is what being a processor means.
Security
- Traffic is encrypted in transit. Passwords are stored hashed.
- Every query is scoped to one business, so one client's system cannot reach another's.
- Files are served through an access check, not from a public bucket.
- Documents shared with a customer — a report or an invoice — use an unguessable single-purpose link that can be revoked, and expose only that one document.
Your rights
Under UK data protection law you may ask for a copy of your personal data, ask for it to be corrected or deleted, or object to how it is used. If your details are in a SysteMate system because you are a customer of one of the businesses that uses it, ask that business first — it is their record. If you cannot reach them, contact us and we will help.
Write to admin@systemate.uk. You also have the right to complain to the Information Commissioner's Office.
Changes
If this policy changes materially we will tell the businesses using SysteMate directly rather than relying on them to notice. The date at the top always reflects the current version.
