Trust centre

Data protection

How BuildPilot approaches customer-controlled data, UK data-protection obligations, subprocessors and practical account rights.

Last updated: 13 August 2026

Roles and responsibilities

BuildPilot generally acts as controller for account, billing, security, direct support and service-administration data. For personal data a business customer places into its private workspace and asks BuildPilot to process on its behalf, the customer will normally be controller and BuildPilot will normally act as processor. Our Data Processing Agreement applies where Article 28 processor terms are required.

Customer-controlled information

Customers remain responsible for ensuring they have a lawful basis to upload and use personal data, tender documents, contact details, marketing lists and other information within the platform, and for giving their own data subjects any notices required by law.

Data minimisation

Only information reasonably required for the relevant workflow should be uploaded. Special-category personal data, criminal-offence data and unnecessary identity documents should not be uploaded unless the customer has confirmed a lawful need and appropriate safeguards.

Rights requests

Logged-in users can use the Privacy & data centre to download core account data or submit access, correction, erasure, restriction, objection and portability requests. Requests can also be emailed to admin@buildpilotai.co.uk. We may need to verify identity, protect other people's information and apply legal exceptions. We aim to respond without undue delay and normally within one month.

Retention framework

Active account and workspace records are retained while needed to provide the service. After closure, operational data is queued for deletion or anonymisation after a limited recovery/security period unless longer retention is required for billing, tax, fraud prevention, legal claims, incident investigation or another lawful purpose. Backups may persist for a limited rotation period after primary deletion. We periodically review whether stored information is still necessary.

Subprocessors and transfers

Our current provider categories are maintained on the Subprocessors page. Where use of a provider involves a restricted international transfer under UK data-protection law, BuildPilot must have an appropriate transfer mechanism or lawful exception in place.

Security incidents

Suspected personal-data incidents are investigated, contained where possible and assessed against applicable notification duties. Where BuildPilot acts as processor, affected controller customers will be informed without undue delay when required.

ICO registration

BuildPilot's operator is responsible for completing the ICO data-protection fee self-assessment and registering/paying where the statutory fee applies. Payment of the fee does not replace the wider UK GDPR obligations described here.

Retention and incident response

Our retention schedule explains how long categories of information are normally kept and how deletion is handled. Our incident-response overview explains the process for recording, assessing and, where legally required, reporting personal-data breaches.