This privacy policy explains how Defectly Ltd ("Defectly", "we", "us") collects, uses, shares, and protects your personal data when you visit our website, request early access, use our property defect management platform, or interact with our advertising, and what rights you have over that data.
Who we are
Defectly Ltd is a company registered in England and Wales (company number 16764636) with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018), Defectly Ltd is the controller of the personal data described in this policy, except where this policy says otherwise (see "Advertising and joint controllers" below). You can contact us about anything in this policy at [email protected].
Personal data we collect
Information you give us
Account information: your name, email address, phone number, password, and the organisation you belong to.
Property and defect information: property addresses, defect descriptions, photographs, comments, and related records you or your organisation create on the platform.
Contractor profile information: if you register as a contractor, your business details, trades, service areas, accreditations, portfolio items, and verification documents.
Billing information: your billing contact details and subscription choices. Card payments are processed by Stripe; we do not store full card numbers on our systems.
Communications: messages you send through the platform, support requests, enquiries submitted via our contact form, and emails to addresses such as [email protected] (which are handled in our helpdesk system).
Marketing preferences: whether you have signed up for product updates or early-access news, and your consent choices.
Information we collect automatically
Technical data such as your IP address, browser and device type, operating system, and pages visited.
Analytics and advertising data collected through cookies and similar technologies, but only with your consent - see "Analytics and advertising" below and our cookie policy for full details.
Usage and audit data generated as you use the platform, such as login events and actions taken on defects, which we record to provide the audit-trail functionality that is core to the service.
Error and performance data, collected through our monitoring provider so we can fix faults. We configure this to strip personal data where possible.
Information from other sources
Public register data from Companies House, used to verify businesses and to populate company profiles in our contractor directory - see "Public register data" below.
Sign-in information from Google or Microsoft if you choose to sign in with those accounts (your name and email address).
Interaction data from our advertising partners, such as the fact that you clicked one of our adverts, where you have consented to advertising cookies.
How we use your data and our lawful bases
To provide the platform, manage your account, and process payments - necessary to perform our contract with you.
To send service communications such as defect notifications, verification codes (by email, SMS, voice call, or WhatsApp), and billing emails - necessary to perform our contract with you.
To operate the contractor directory, verification, and review features - our legitimate interests in providing a trustworthy marketplace, balanced against your rights.
To monitor, secure, and improve the platform, including fraud and abuse prevention - our legitimate interests in running a safe, reliable service.
To measure how our website is used and how our advertising performs, and to show you relevant advertising on other platforms - your consent, given through our cookie banner, which you can withdraw at any time.
To send marketing emails about Defectly where you have signed up for them - your consent, which you can withdraw at any time using the unsubscribe link present in every message.
To comply with legal obligations, such as accounting and tax record-keeping.
Analytics and advertising
With your consent, we use the following tools on our website. None of them run, and none of their cookies are set, unless you opt in through our consent banner. You can change your mind at any time - see our cookie policy for how.
Google Analytics 4
Provided by Google Ireland Limited. We use it to understand how visitors use our website - for example which pages are popular and how people found us - and, where linked with Google Ads, to measure advertising performance. Google sets cookies such as _ga and may transfer data to Google LLC in the United States (see "International transfers"). More information is available in Google's privacy policy at policies.google.com/privacy.
Google Ads
Provided by Google Ireland Limited. We use conversion tracking and remarketing so we can measure whether our adverts work and show relevant adverts to people who have visited our site. We send Google "consent mode" signals that reflect the choices you make in our banner, so these features only operate for you if you have consented.
Meta Pixel (Facebook and Instagram)
Provided by Meta Platforms Ireland Limited. The Meta Pixel lets us measure the performance of our Facebook and Instagram advertising and reach people who have shown interest in Defectly. It sets the _fbp and _fbc cookies (each lasting around 90 days). For the data collected through Meta Business Tools and processed for ad targeting and measurement, Defectly and Meta Platforms Ireland are joint controllers under a controller addendum: in essence, we are responsible for telling you about the processing and establishing a lawful basis (your consent), while Meta is responsible for the subsequent processing on its platform and for honouring your rights, which you can exercise against either of us. Meta's privacy policy is at facebook.com/privacy/policy.
LinkedIn Insight Tag
Provided by LinkedIn Ireland Unlimited Company. We use it to measure the performance of LinkedIn advertising aimed at professional audiences such as property developers and agents, and to build audiences of people interested in Defectly. LinkedIn sets cookies described in its cookie table at linkedin.com/legal/l/cookie-table, and its privacy policy is at linkedin.com/legal/privacy-policy.
Cloudflare Zaraz
We load the tools above through Cloudflare Zaraz, a service provided by Cloudflare, Inc. that runs them at the network edge rather than directly in your browser. This reduces the number of third parties your browser connects to, and it is also how we technically enforce your consent choices: tools assigned to a purpose you have not consented to do not run at all.
Public register data (Companies House)
Our contractor directory includes company information sourced from the public register maintained by Companies House, used under the Open Government Licence v3.0. This may include company names, company numbers, registered office addresses, company status, and the names of company officers as they appear on the public register.
We keep register-sourced information separate from information supplied by the businesses themselves, refresh it periodically from Companies House, and do not publish anything beyond what is already on the public register. If you are an officer of a company shown in our directory and you object to our processing of your personal data, contact us at [email protected] and we will review and respond in line with your rights below. Contains public sector information licensed under the Open Government Licence v3.0.
Who we share data with
We do not sell your personal data. We share it with service providers (processors) who help us run Defectly, under contracts that require them to protect it:
Stripe (payment processing) and Xero (invoicing and accounting).
Postmark (transactional email, including early-access and contact-form messages) and Twilio (SMS, voice, and WhatsApp verification messages).
Cloudflare (hosting, content delivery, security including the Turnstile anti-abuse check, and the Zaraz service described above).
Our helpdesk platform, which processes support conversations sent to addresses such as [email protected].
Sentry (error monitoring).
Google and Microsoft, where you choose to sign in with those services.
Separately from our processors, the advertising partners described above (Google, Meta, LinkedIn) receive data as controllers or joint controllers when you consent to advertising cookies. We may also share data where the law requires it, to enforce our terms, or as part of a business sale or restructuring, in which case we would notify you.
International transfers
We aim to store customer data in the United Kingdom or the European Economic Area. Some of our providers - including Google, Meta, LinkedIn, Cloudflare, Stripe, Twilio, Postmark, and Sentry - may process data in the United States or other countries.
Where personal data leaves the UK, we rely on safeguards recognised under UK law: the UK's adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework, known as the UK-US Data Bridge, for certified US companies such as Google LLC and LinkedIn Corporation), or the UK International Data Transfer Agreement or Addendum and equivalent standard contractual protections. You can check a US company's certification at dataprivacyframework.gov. If you would like more detail about the safeguard applying to a particular transfer, contact us.
How long we keep your data
Account and platform data: kept while your account is active. Defect records and their audit trails are retained while the relevant organisation's account remains active, because a complete history is the core function of the service.
After account closure: we delete or anonymise personal data within a reasonable period, except where we must keep records longer to meet legal obligations (for example billing records, which we keep for six years).
Analytics data: our Google Analytics retention setting limits event-level data, after which it is deleted or aggregated.
Marketing lists: we remove you promptly when you unsubscribe, and we periodically remove inactive contacts.
Support conversations: retained in our helpdesk so we can deal with follow-up questions, then deleted on a rolling basis.
Your rights
Under UK data protection law you have the right to:
Access the personal data we hold about you.
Have inaccurate data corrected.
Have your data erased in certain circumstances.
Restrict or object to our processing in certain circumstances, including any processing based on legitimate interests.
Receive a copy of data you provided to us in a portable format.
Withdraw consent at any time, where consent is our lawful basis - including consent to analytics and advertising cookies, which you can withdraw through the cookie settings link in our website footer.
To exercise any of these rights, email [email protected]. We will respond within one month. For data processed jointly with Meta, you can also exercise your rights directly against Meta. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, although we would welcome the chance to address your concerns first.
Security
All traffic to Defectly is encrypted in transit. We operate access controls, audit logging, and two-factor authentication, and we limit access to personal data to those who need it to operate the service. No system is perfectly secure, but we take the protection of your data seriously and review our measures regularly.
Children
Defectly is a service for adults and businesses and is not intended for use by anyone under 18. We do not knowingly collect personal data from children.
Changes to this policy
We may update this policy from time to time - for example if we add or change the tools described above. If we make material changes we will notify you by email or through the platform before they take effect, and where a change involves new cookies or purposes we will ask for your consent again. The date at the top of this page shows when it was last updated.
Contact us
Questions about this policy or our handling of your data: [email protected], or write to Defectly Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.