Privacy
Privacy Policy
Last updated: 21 September 2026
1. Who we are
Beacon is an NDT inspection reporting PWA for professional and organisational use. It is operated by the service provider contactable at siowenson@hotmail.com. This policy explains how personal data and inspection-related information are handled when you use Beacon.
The Terms of Service cover use of the product more generally.
2. Who is responsible for the data
For account details we collect to run Beacon (such as your sign-in identity and workspace membership), we act as a controller under UK GDPR.
Inspection content belongs to the customer organisation. That organisation is typically the controller of client names, site details, findings, photos, drawings, and report text it puts into Beacon. We process that content as a processor to provide the Service — hosting, sync, PDF export, and related features. Organisations remain responsible for the confidentiality of client data they enter and for telling their own clients how that data is used.
3. What we collect
Account and workspace data
- Sign-in identifiers from Google sign-in or a Firebase email sign-in link (typically name, email address, and a unique user ID).
- Workspace membership, roles (owner, admin, member), invites, and related audit-style activity such as who invited whom.
- Profile and company settings you choose to save (for example workspace name and report branding).
Inspection and media content
- Client, site, and asset names; equipment; inspection findings; report text; templates; and similar records you enter.
- Photos, drawings, markups, and other files attached to reports.
- Report metadata used for sync, PDF generation, and authenticity checks (including hashes and inspector/timestamp details).
Technical and usage data
- Device and browser storage used by the offline-first app (IndexedDB / Dexie and localStorage).
- A small authentication cookie used to know you are signed in for routing.
- In production, Firebase Analytics may record basic product-usage events. Beacon does not run a third-party advertising network.
4. How we use information
We use information to:
- create and authenticate accounts, and operate company workspaces;
- store, sync, and display inspection records and media across devices;
- generate PDF reports and register authenticity metadata for QR verification;
- send or complete sign-in and invite flows;
- maintain, debug, and improve the Service, including understanding feature use;
- protect the Service, enforce the Terms, and meet legal obligations.
We do not sell your personal data. We do not use inspection content to train unrelated public models or to serve ads.
5. Legal bases (UK GDPR)
Where we are the controller, we typically rely on:
- Contract — to provide the account and Service you asked for;
- Legitimate interests — to keep the Service secure, understand usage, and improve it, where those interests are not overridden by your rights;
- Legal obligation — where we must keep or disclose information by law.
Where we process inspection content for a customer organisation, that organisation is responsible for its own legal basis (typically its contracts and professional duties). We process that content on its instructions to run Beacon.
6. Device and offline storage
Beacon is offline-first. Inspection data, photos, drawings, and report information may remain on the device in IndexedDB and localStorage until they sync to Firebase when the device is online. A copy can exist on the device even after cloud sync.
Anyone with access to the unlocked device or browser profile may be able to see that local copy. You should use device passcodes, OS updates, and your organisation's security controls. Clearing site data, resetting the device, or losing it before sync can mean data is gone from that device.
9. Public verify page
When a PDF is exported, Beacon may register a verification record and print a QR code linking to /verify/{reportId}. That page is a public authenticity and integrity check against registered report metadata (hash and related fields such as report ID, inspector name, and timestamp). It is not a full open photo gallery.
Anyone with the link can see the limited metadata shown on that page. Photo and drawing files are not published there. The check confirms whether registered export metadata still matches — not that the inspection itself was accurate.
10. International transfers
Beacon uses Google Firebase. Some processing may take place in the United Kingdom or European regions (for example Cloud Functions configured in europe-west2), but Google may also process data in other countries where it operates.
Where UK GDPR requires a safeguard for transfers outside the UK, we rely on Google's contractual terms and transfer mechanisms for Firebase. You can read Google's privacy and infrastructure documentation for more detail.
11. Retention
We keep account and workspace data for as long as the account or workspace is needed to provide the Service, plus a limited period in backups. Inspection content is kept until the organisation deletes it or the workspace is closed, subject to those backups and any legal retention we cannot avoid.
Copies on a device last until they are synced away, overwritten, or cleared by the user or organisation. Public verification records remain available while they are registered, so a printed QR code can still be checked.
Workspace owners can ask us to delete an account or workspace by emailing the contact address below. We will complete deletion requests as far as the Service and the law allow.
12. Security
We use reasonable technical and organisational measures, including Firebase authentication, access control by workspace role, and encrypted transport. No method of storage or transmission is completely secure. We cannot guarantee absolute security, especially for data sitting on a field device.
You should protect devices, sign-out on shared browsers, and only invite people who are allowed to see your organisation's inspection records.
13. Children
Beacon is not directed at children and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.
14. Your rights (UK GDPR)
Where UK GDPR applies to personal data we control, you may ask us to:
- access the personal data we hold about you;
- correct inaccurate personal data;
- delete personal data in certain circumstances;
- restrict or object to certain processing;
- receive a portable copy of personal data you provided, where applicable.
Email siowenson@hotmail.com. We may need to confirm your identity. If your request is about inspection content held for an organisation, we may need to involve that organisation, because they are usually the controller of that content.
You can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to address your concern first.
15. Changes to this policy
We may update this policy as Beacon develops. The "Last updated" date at the top will change when we do. Continued use after an update means you accept the revised policy. Material changes will be reflected on this page.
16. Contact
Privacy questions, rights requests, and data-deletion requests: siowenson@hotmail.com.