Legal
Privacy policy
This notice explains how Samuel James, trading as Monolith Compliance (“we”, “us”, “our”), collects, uses, stores, and shares personal data when you use Beacon and our websites. It is written for real people — not for lawyers only.
1. Who we are
The data controller for Beacon and the Monolith Compliance websites is Samuel James, a sole trader trading as Monolith Compliance (the Beacon product and related services).
Privacy contact: [email protected]
A postal address for data-protection correspondence is available on request via that email.
Websites and services covered:
- Marketing site: www.monolithcompliance.co.uk
- Beacon app: beacon.monolithcompliance.co.uk (Field and Console)
If you create an organisation in Beacon, your organisation may also decide how site and compliance records are used inside the service (for example, who on your team can see which sites). In that sense your organisation may act as an independent controller of those operational records, while we provide the platform. This notice still explains what we do as the service provider.
2. What this notice covers
This notice applies when you:
- visit our marketing website;
- create a Beacon account or accept a team invite;
- use Beacon Field (including offline) or Beacon Console;
- issue or download reports and certificates;
- send product feedback; or
- email us.
Beacon is aimed at businesses and competent persons carrying out emergency lighting testing and related record-keeping in the UK. It helps you record work and issue supporting paperwork. Duty-holders remain responsible for fire-safety compliance. Beacon is not certified or endorsed by BSI.
3. What we collect
3.1 Account and identity
- Name, email address, and password (password is stored hashed by our auth provider — we do not see it in plain text).
- Optional multi-factor authentication (MFA) enrolment details when you enable an authenticator app (for example a TOTP factor id and verification status held by our auth provider).
- Organisation membership and role (for example owner, manager, technician, viewer).
- Email confirmation and password-reset activity.
- When you accept this privacy notice at sign-up (version and time, recorded with your account metadata).
3.2 Organisation and site records you enter
Depending on how you use Beacon, this may include:
- organisation name and branding (for example logo and report details);
- site details (addresses, client/responsible-person information, system setup, test switches, design duration);
- fitting / asset register data (site IDs, locations, modes, floors, and related fields);
- test sessions and results (monthly function and annual duration, notes, pass/fail outcomes);
- open defects and related notes;
- photos and images you attach (for example evidence on findings);
- competent-person / sign-off details and signature images;
- issued document payloads and history (test reports, visit periodic inspection reports, site periodic certificates), including unique references and lock timestamps;
- team invites (invited email and role);
- audit / activity records of significant changes in Console where the product records them.
Some of this may include personal data about people other than you (for example a client contact, building manager, or signatory). You must only enter that information where you have a lawful reason to do so.
3.3 Feedback and support
- Messages you send via in-app feedback or email (including category, message text, organisation name, role, app version, page path, and browser user agent when submitted through the app).
3.4 Technical and usage data
- Basic server and security logs from our hosting providers (for example IP address, timestamps, request metadata) needed to run and protect the service.
- Local preferences on your device (for example theme), and offline/sync state held in browser storage.
- On the marketing site only, if you accept analytics cookies: Google Analytics 4 usage data such as pages viewed, referrer, approximate location derived from IP, device/browser type, and a random client identifier.
We do not run advertising pixels or sell analytics profiles. Google Analytics is used only to understand how the marketing site is used, and only after you accept. You can reject analytics or change your mind later via Cookies.
4. How we use data and lawful bases
Under UK GDPR we need a lawful basis for each use. In practice:
| Purpose | Examples | Lawful basis |
|---|---|---|
| Provide the service | Accounts, sync, sites, tests, documents, team access | Contract (Art. 6(1)(b)) — to deliver Beacon to you |
| Secure the service | Auth, abuse prevention, backups, incident response | Legitimate interests (Art. 6(1)(f)) — keeping systems safe |
| Communicate about your account | Email confirmation, password reset, important service notices | Contract / legitimate interests |
| Open beta improvement | In-app feedback you choose to send; fixing bugs | Legitimate interests — improving a free beta product you use |
| Legal obligations | Responding to lawful requests; keeping necessary records | Legal obligation (Art. 6(1)(c)) where it applies |
| Marketing-site analytics | Google Analytics 4 on www.monolithcompliance.co.uk (pages viewed, device/browser, approximate location) | Consent (Art. 6(1)(a)) — and PECR consent for analytics cookies. Optional; the site works if you reject. |
We do not use your site or test data to train public AI models, and we do not sell personal data. We do not send marketing emails unless you have clearly asked for them (or another lawful basis applies, which we will describe if we introduce marketing).
Open beta: Beacon is free while we test with real sites. Features and retention practices may evolve; material changes will be reflected in an updated notice (see section 13).
5. On-device and offline storage
Beacon Field is designed to work when signal is poor or missing. That means visit and site data may be stored on your phone, tablet, or computer (for example in browser storage / IndexedDB) until it can sync to our cloud service.
- Anyone with access to that device may be able to access locally stored Beacon data.
- Clearing site data, uninstalling the app, or using a shared device can affect what remains locally.
- Syncing sends applicable records to our cloud so your organisation can use Console and recover work across devices according to product rules and permissions.
7. International transfers
Beacon’s primary application database, authentication, and file storage are hosted with Supabase in AWS eu-west-1 (Ireland), inside the European Economic Area. The app and marketing site are delivered via Cloudflare. Provider infrastructure (including support tooling and email) may still involve processing outside the United Kingdom. If you accept analytics cookies, Google Analytics also involves processing by Google, including in the United States. Where personal data is transferred internationally, we rely on appropriate safeguards recognised under UK data protection law (for example the UK International Data Transfer Agreement / Addendum, an adequacy regulation, or the UK Extension to the EU-US Data Privacy Framework), as offered by our providers’ terms and configurations.
8. How long we keep data
Current automated practice for Beacon’s open beta:
- Active organisation data — while the organisation uses Beacon.
- Soft-deleted sites and related records — recoverable for about 90 days, then permanently removed by automated jobs (including associated file objects where applicable).
- Organisation closure — owners can schedule closure in Console; after about a 14-day grace period we permanently delete the organisation’s cloud data, stored files under that organisation, and member sign-in accounts (except any Monolith staff accounts). You can cancel during the grace period. Export your data first if you need to keep compliance records.
- Customer activity / audit logs — about 24 months, then removed.
- Staff / platform audit logs — about 24 months.
- Product telemetry (performance samples and heartbeats) — about 90 days.
- In-app feedback — about 24 months (copies in email inboxes are outside automated deletion).
- Platform logical backups — weekly encrypted copies of database content to Cloudflare R2, kept about 56 days. These do not include photo/signature binary files. After erasure, residual copies may remain until those backups expire.
- On-device offline data — until synced, cleared, or removed with browser/app data. Closing a cloud account does not wipe phones or laptops you control.
- Marketing-site analytics (Google Analytics, only if you accepted cookies) — analytics cookies last up to about 6 months. Event data in our Google Analytics property is kept for the retention period we set there (we use the shortest period Google offers, currently 2 months), then removed from that property.
Issued reports and certificates are kept as locked snapshots while the organisation exists, for audit integrity. Download what you need before requesting erasure. If you need a written retention schedule for procurement, email us and we will confirm the current practice.
9. Security
We take appropriate technical and organisational measures for a cloud SaaS product of this type, including:
- encrypted transport (HTTPS);
- authentication and access control (including organisation roles and database access rules);
- hashed passwords via our auth provider;
- optional multi-factor authentication (TOTP authenticator apps) that you can enable in Settings — once enrolled, a second factor is required at sign-in;
- separation of customer organisations in the application data model;
- private storage for photos and signatures;
- automated retention and erasure jobs;
- weekly logical database backups to Cloudflare R2 for disaster recovery (founding beta; not a full photo archive);
- Monolith staff access only through a locked-down Staff Ops path that is audited (staff do not “log in as you”).
No method of transmission or storage is perfectly secure. You can help by using a strong unique password, enabling MFA where available, protecting devices that hold offline Field data, and inviting only people who should access your organisation.
10. Your rights
Under UK GDPR, you may have the right to:
- Access — ask what personal data we hold about you;
- Rectification — correct inaccurate data;
- Erasure — ask us to delete personal data in certain circumstances;
- Restriction — ask us to limit processing in certain circumstances;
- Portability — receive certain data in a usable format;
- Object — object to processing based on legitimate interests;
- Withdraw consent — where processing is based on consent. For marketing-site analytics, use Cookies or the cookie banner (footer link: Cookies) to reject analytics. That stops further Google Analytics cookies and deletes the ones we can from this browser. It does not affect your Beacon account.
Organisation owners can also download an organisation data export and schedule organisation closure from Beacon Console → Settings → Data & privacy. Team members should ask their organisation owner for site-level exports where appropriate.
To exercise these rights, email [email protected] with enough detail for us to verify your identity and find the relevant records. We will respond within the time limits required by law.
If you are a team member in someone else’s organisation, some requests may need to be coordinated with that organisation’s owner/manager (for example site registers that belong to the business).
11. Cookies and similar tech
Marketing site (www.monolithcompliance.co.uk)
UK law (PECR, read with UK GDPR) requires consent before we set non-essential cookies. The marketing site works without analytics cookies. We ask you to accept or reject analytics when you first visit. Both choices are equally available. We do not treat scrolling or continuing to browse as consent.
You can change your choice at any time using the Cookies link in the footer. We store that choice in your browser (local storage) so we can respect it on later visits. That storage is strictly necessary to remember your decision.
| Name | Provider | Purpose | Duration | When set |
|---|---|---|---|---|
Cloudflare security / delivery cookies (names vary, for example __cf_bm) |
Cloudflare | Protect the site and deliver pages (bot and network security) | Typically minutes to hours | Essential — always, as required to operate the site |
monolith-cookie-consent (browser local storage, not a cookie) |
Monolith Compliance | Remember whether you accepted or rejected analytics | Until you clear site data | Essential — when you make a choice |
_ga |
Google Analytics | Distinguish unique visitors on the marketing site | Up to 6 months | Only if you accept analytics |
_ga_GFWP9D7SZL |
Google Analytics | Keep session state for the measurement ID we use | Up to 6 months | Only if you accept analytics |
If you accept, we load Google’s tag (G-GFWP9D7SZL) and send usage data to Google Analytics 4.
We configure it so advertising storage, Google Signals, and ad personalisation stay off. We do not use this
tag for ads on our site. Google may still process the data in accordance with its
privacy policy and
data processing terms.
If you reject, we do not load the Google tag and we do not set analytics cookies. If you later reject after previously accepting, we update consent, stop further analytics cookies, and delete the Google Analytics cookies we can from this browser.
Beacon app (beacon.monolithcompliance.co.uk)
Beacon uses essential local storage and similar technologies that are required to sign you in, keep preferences (for example theme), support offline Field use, and operate as an installable web app. These are necessary for the service you request, not for advertising. No separate cookie consent popup is shown for these essential technologies. The Google Analytics tag described above is for the marketing site only, not the Beacon app.
12. Children
Beacon is a business tool for emergency lighting testing and related professional use. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided personal data, contact us and we will delete it.
13. Changes to this notice
We may update this notice as Beacon grows (especially during open beta). The “Last updated” date at the top will change when we do. For material changes, we will take reasonable steps to notify account holders (for example an in-app or email notice) and, where appropriate, ask you to review the updated notice.
The current version will always be published at https://www.monolithcompliance.co.uk/privacy.html.
14. Contact and complaints
Questions, data requests, or concerns: [email protected]
You also have the right to complain to the UK Information Commissioner’s Office (ICO): https://ico.org.uk/
This notice is intended to meet UK GDPR transparency requirements for Beacon’s current open-beta operations. It is not legal advice to you or your clients. If you need a signed DPA / processor terms for enterprise procurement, contact us and we will confirm what we can offer at your stage of use.