PRIVACY NOTICE

Your information.
Clearly accounted for.

What we collect, why we use it, who receives it and the choices available to you.

Please read this policy with our Subscription Agreement.

If anything is unclear or your organisation needs contractual commitments beyond this policy, contact us before subscribing.

1. Who we are and how to contact us

John Lambert, a sole trader trading as Maintain CMMS, is the controller for personal information used to operate our business, website, accounts, billing, security and direct enquiries. Contact: hello@maintaincmms.com, 209A Plumstead High Street, Greenwich, London, SE18 1HE, England.

For information placed in a customer workspace, the customer organisation is normally the controller and Maintain CMMS acts as its processor. Workspace users should normally direct rights requests about maintenance records to their organisation; we will assist that organisation under the Data Processing Schedule.

2. Who this notice covers

This notice covers website visitors, prospective customers, account owners, Authorised Users, invited users, suppliers, support contacts and people who submit an enquiry or public maintenance request. The service is for business use and is not directed at children.

3. Information we collect

Depending on the interaction, we may collect identity and business contact details; organisation, role and permission information; account and authentication records; subscription, transaction and billing references; enquiries and support correspondence; security, audit, device and connection records; and product usage events.

Customer workspaces may contain asset, work-order, inspection, signature, photograph, supplier and personnel information selected by the customer. We do not receive complete payment-card details from Stripe. We do not intentionally request special-category or criminal-offence data for ordinary service use.

4. Where information comes from

Information may come directly from you, your employer or customer organisation, an administrator inviting you, public request forms, your use of the service, security logs, Stripe payment events and service providers helping us operate the platform. If another organisation controls the information, it is responsible for giving the appropriate privacy information.

5. Purposes and lawful bases

We use personal information to create and administer accounts, supply and support the service, process subscriptions, communicate service information, secure the platform, prevent misuse, keep audit and financial records, answer enquiries and improve reliability.

Our usual lawful bases are performance of a contract or steps requested before a contract; compliance with legal obligations; and legitimate interests in operating, securing, supporting and improving a B2B service, preventing fraud and communicating with business contacts. Where consent is required—for example for a particular non-essential communication—we will request it and it may be withdrawn.

6. Customer-controlled workspace data

When we act as processor, we use workspace personal data only on the customer’s documented instructions to host, organise, retrieve, transmit, secure, back up, support, export and delete it, unless law requires otherwise. The Subscription Agreement’s Data Processing Schedule sets out the subject matter, duration, categories, confidentiality, security, sub-processing, assistance, incident, audit and end-of-contract terms.

7. Recipients and service providers

Information may be available to authorised people in the relevant customer organisation and to providers supporting hosting, private file storage, email delivery, authentication, security, support and payment processing. Providers receive only what is reasonably needed and are subject to contractual or independent legal duties appropriate to their role.

We may disclose information to professional advisers, insurers, regulators, courts, law enforcement or a purchaser of the business where lawful and necessary. We do not sell personal information.

8. International transfers

Some providers may process information outside the UK. Where UK law treats this as a restricted transfer, we will use an applicable adequacy regulation, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard, together with a risk assessment where required. Customers may request further information about material safeguards.

9. Retention

We keep information only for as long as needed for the relevant purpose, account, contract, security investigation or legal obligation. Criteria include the subscription lifecycle, customer instructions, dispute and limitation periods, tax/accounting duties, security needs and protected backup cycles.

At the end of a customer service, return and deletion are handled under the Data Processing Schedule. Suppression information may be retained to honour opt-outs, and limited audit or financial records may be retained where law or legitimate claims require it.

10. Security

Measures are selected according to risk and include encrypted transport, protected password storage, secure sessions, role-based access, tenant separation, private file controls, audit events, bounded uploads, backups and incident handling. No online service can promise absolute security. Users must protect credentials and promptly report suspected compromise.

11. Your rights

Depending on the circumstances, UK data-protection law may give you rights to be informed, access information, correct it, erase it, restrict or object to processing, receive portable information and withdraw consent. Rights are not absolute and we may need to verify identity.

Email hello@maintaincmms.com. If your request concerns a customer workspace, identify the customer organisation so it can be handled with the controller.

12. Complaints

Please contact us first so we can investigate. You may also complain to the UK Information Commissioner’s Office at ico.org.uk. If you are elsewhere, you may have a right to contact your local supervisory authority.

13. Marketing and communications

Operational messages about accounts, security, billing and service changes are not marketing. Any direct marketing will follow applicable consent, soft-opt-in and business-contact rules. You can opt out of marketing without losing necessary service communications.

14. Automated decisions and profiling

Maintain CMMS Flows automate customer-configured maintenance administration. We do not use personal information to make solely automated decisions producing legal or similarly significant effects about individuals. Customers remain responsible for how they configure and review their own workflows.

15. Changes to this notice

We will update this notice when processing materially changes and will bring significant changes to affected users where required. The date above identifies the current public version.

QUESTIONS ABOUT THIS POLICY?

Ask before you rely on it.

hello@maintaincmms.com →

READY TO GET MAINTENANCE UNDER CONTROL?

Choose your plan. Create your workspace. Start today.

Pick the functionality level you need, create or sign in to your account, accept the terms and complete secure checkout. Your paid features unlock automatically.
Choose a plan & sign up →Try free firstNo per-user fees · No per-asset fees · Secure Stripe checkout