Written for UK GDPR and the Data Protection Act 2018.
Who is the controller
The operator of the Sizr platform is the data controller for account data. Where Enterprise customers load their own catalogues and customer records, they are the controller and we act as processor under a data processing agreement.
What we collect
Account data: name, work email, company, job title and optional phone. Subscription data: plan, status, trial dates and usage counts, plus payment references held by our payment provider. Platform data: the quotes you generate and their inputs. Security data: a hashed device identifier, a hashed IP address, browser user agent and timestamps for sign ins, device changes, exports and CRM pushes. We do not store raw IP addresses against your account, and we never see full card details.
Why we use it
To provide the platform and your seat, to enforce the named seat licence and detect credential sharing, to bill your subscription, to keep a security audit trail, and to support you. Our lawful bases are performance of a contract, our legitimate interests in securing the service, and legal obligation for financial records.
Cookies and storage
We use functional storage only: your sign in session and a device identifier used for seat enforcement. There is no advertising tracking on the platform.
Who we share it with
Our infrastructure and database provider, our payment provider, and our email provider, each acting under contract. Where you choose to push a quote to your own CRM, that data goes to your CRM at your instruction. We do not sell personal data.
Where it is held
Platform data is held on UK or EEA infrastructure. Where a sub processor transfers data outside the UK, that transfer relies on adequacy regulations or the International Data Transfer Addendum.
How long we keep it
Account and quote data for the life of your subscription and for twelve months after it ends, unless you ask us to delete it sooner. Security audit entries for twelve months. Financial records for six years, as required for tax purposes.
Your rights
You can ask for a copy of your data, correct it, delete it, restrict or object to processing, and ask for it in a portable format. You can edit most of your details directly in your account. To make a request, or to complain, contact us at privacy@sizr.app. You can also complain to the Information Commissioner's Office at ico.org.uk.
Security
Access to your data is restricted by row level database policies scoped to your account, so a signed in user can only reach their own records. Plan and entitlement changes are written only by trusted server processes, never from the browser. Passwords are hashed by our authentication provider and checked against known breach lists.