LP LiftPlan Studio

RMT Solutions Ltd

Privacy Notice

LiftPlan Studio — version 1.1, effective 2026-09-17

SHA-256 6c2450b59a40ff4c19f5d45fecac1d58d14d321a4f2c8aa1d4d357e0a215893b

This is the privacy notice referred to in clause 16.1 of the LiftPlan Studio Software Licence Agreement. It explains what personal data RMT Solutions Ltd holds about the people who use LiftPlan Studio, why we hold it, how long we keep it, who else sees it, and what you can require us to do about it.

It is written to be read rather than to be complied with. Where something is unusual — and one thing here is — it says so plainly instead of hiding it in a list.

The short version

Your lift plans never reach us. They are held in your browser, on your device. We hold no copy, we cannot read them, and we cannot recover them if you lose them.

We hold what an account needs: a name, an email address, what you have bought, and a record of sign-ins. The sign-in record includes IP addresses, and section 3.3 says exactly why.

We use no analytics, no advertising and no tracking. There is one cookie and it holds your session.

We never see your card details. Stripe takes the payment on its own pages.

1. Who we are

1.1RMT Solutions Ltd, company number 08338653, whose registered office is at 6 Carr Green, Lowton, Warrington, England, WA3 1EQ, is the controller of the personal data described in this notice. VAT registration number GB 126050355. We are registered with the Information Commissioner as a data controller under reference ZC250006, and our entry is on the public register of fee payers at ico.org.uk/register.

1.2Write to us at ricky@rmtsolutions.co.uk, or at the registered office above. Anything in this notice — a question, a request under section 10, or a complaint — goes to that address.

1.3Being on that register means the data protection fee has been paid and the Commissioner knows who we are. It is not an approval, a certification or an endorsement of anything in this notice, and it should not be read as one.

1.4We are not required to appoint a Data Protection Officer and have not appointed one. That is not a gap: the requirement in Article 37 of the UK GDPR applies to public authorities and to organisations whose core activity is large-scale monitoring or large-scale processing of special category data, and none of those describes us.

2. What this notice covers, and what it does not

2.1It covers the personal data we hold about the named individuals who hold Seats on a LiftPlan Studio account, about anybody who signs in to one, and about anybody who writes to us about one.

2.2It does not cover the contents of your Lift Plans. Those are held in the storage of the browser on the device you use them on. They are not sent to us, we hold no copy of them, and we cannot read them. Where a Lift Plan contains personal data — the name of an operator, a slinger, a supervisor or an Appointed Person — you are the controller of that data and we do not process it. Clause 16.2 of the agreement says the same thing.

2.3There are two exceptions to clause 2.2, and both are in your hands. The first is the optional drafting assistance in section 8. The second is where you send us a document so that we can help with a support request, in which case we use it for that request and nothing else.

2.4Where you are an employer and the Seat holder is your employee, you will have your own obligations to that person about the data in this notice. We are not in a position to discharge those for you.

3. What we hold

This is the whole list. If something is not in it, we do not hold it.

3.1The account record: the Seat holder's name and email address; what has been bought and which modules are enabled; the subscription status and the date the current period ends; the number of Seats; whether the account is on a trial; the Stripe customer identifier; and the branding you set for your own documents, which is your company name, your logo and a colour.

3.2The acceptance record. Each time somebody accepts the Software Licence Agreement we record the version accepted, a SHA-256 digest of the exact wording that was on the screen, the date and time, the IP address it came from, the country that address resolves to, the first 300 characters of the browser's user agent string, and the name given. The record is added to and never replaced, because overwriting it would destroy the only evidence that an earlier version was agreed.

3.3The sign-in record. For each sign-in we record the date and time by our server's clock, an internal session identifier, the IP address the request came from, the two-letter country code our host derives from that address, the first 300 characters of the user agent string, and a ten-character fragment of a SHA-256 of that string which we call a device mark.

(a)Why we hold it: a LiftPlan Studio licence is sold to one business for a stated number of Seats. Nothing in a password stops a licence being passed around, and this record does not stop it either. It makes it visible — an account signed in to from eleven browsers across three countries in a month is either a customer who has outgrown one Seat or a licence being shared, and both of those are conversations we would rather have than not have.

(b)What the device mark is not: it is not an identifier for a person or for a machine. Two people using the same model of laptop with the same browser version produce the same mark, and one person who updates their browser produces a new one. It undercounts browsers and can never overcount them. It is read as "at least this many browsers" and never as "this many people".

(c)What it deliberately cannot become: the record holds the 60 most recent sign-ins and no more, and it deletes itself 180 days after the last one (section 5). It is built to answer whether an account is being shared now, and built so that it cannot answer where somebody was three years ago.

(d)What it does not contain: nothing about what anybody did inside the application. No lift plan, no calculation, no document, no page view.

3.4The Seats currently held. The same fields as clause 3.3, for the sessions currently holding a Seat, capped at the number of Seats bought. The account screen in the application shows the date, the country and the device mark only; it does not show the IP address or the user agent string.

3.5Sign-in attempt counters: a count of recent attempts against an email address, and a count of recent attempts from a network address. They exist to slow down somebody guessing passwords.

3.6Correspondence: whatever you send us when you write to us, and our reply.

3.7We never hold card or bank details, at any point, in any form. Section 6.2 explains how payment works without them.

3.8We hold no special category data as defined by Article 9 of the UK GDPR, and we do not ask for any. Nothing in the application invites health, biometric or any other Article 9 data, and it should not be entered into one.

4. Why we hold it, and the lawful basis

4.1The account record and the Seats held (clauses 3.1 and 3.4): Article 6(1)(b) of the UK GDPR, performance of the contract. Without a name, an email address and a record of what was bought there is no account to sign in to.

4.2The acceptance record (clause 3.2): Article 6(1)(b), and Article 6(1)(f), our legitimate interest in being able to show which version of the agreement was accepted, by whom, and when. The digest is the whole point of it: a record saying somebody accepted "version 1.0" is worth very little three revisions later, and a record carrying the digest of the exact wording ties an acceptance to a text.

4.3The sign-in record (clause 3.3): Article 6(1)(f), our legitimate interest in knowing whether a licence sold to one business is in use by more than one, and in noticing an account that has been compromised. We have weighed that interest against your rights and concluded it is proportionate because the record is capped at 60 entries, expires after 180 days, holds nothing about what anybody did in the application, is seen only by us and by the owner of the account it belongs to, and is shown in the application without the address or the user agent. Our assessment is available on request, and you may object under section 10.

4.4The attempt counters (clause 3.5): Article 6(1)(f), our legitimate interest in the security of our customers' accounts.

4.5Invoices, VAT records and the accounting records behind them: Article 6(1)(c), compliance with a legal obligation, under the Companies Act 2006 and the Value Added Tax Act 1994.

4.6Correspondence (clause 3.6): Article 6(1)(b) where it concerns your subscription, and otherwise Article 6(1)(f), our legitimate interest in answering people who write to us.

4.7We do not rely on consent for anything in section 3, because none of it is optional to the service. The one thing we do rely on your decision for is drafting assistance, which is off until you switch it on (section 8).

4.8We do not use any of it for marketing, profiling, audience building, lead scoring or advertising, and we do not use it to train any model. If we ever want to email you about anything other than your own account, your account's security, or a change to this notice or the agreement, we will ask you first.

5. How long we keep it

5.1The sign-in record: the 60 most recent sign-ins, and the record as a whole removes itself 180 days after the last sign-in written to it. Older entries are dropped as newer ones arrive. This is a limit built into the store rather than a policy somebody has to remember to apply.

5.2The attempt counters: one hour.

5.3The session cookie: up to 30 days, and less where the subscription ends sooner. Signing out clears it.

5.4The account record and the acceptance record: while the account exists, and for six years after the end of the last Subscription Period. Six years is the limitation period for a contract claim under the Limitation Act 1980 and the period for which accounting records must be kept, and we keep the acceptance record for exactly as long as somebody could still be arguing about what was agreed.

5.5Correspondence: three years, unless it concerns something still live, in which case until that is finished and then three years.

5.6Where you ask us to delete an account before those periods end, we will, except for what section 4.5 obliges us to keep. We will tell you what we have kept and why.

6. Who else sees it

Four companies, each doing one job. That is the whole list.

6.1Vercel Inc — hosting. It serves the application and the public pages and runs the server functions behind them, and it keeps short-lived operational logs which include IP addresses.

6.2Stripe Payments Europe, Ltd — payments and subscriptions. When you buy or change a subscription you enter your card details on Stripe's own pages. Those details never pass through our software and we never hold them. We send Stripe your name and email address so that the invoice is addressed correctly, and Stripe tells us the subscription status and a customer identifier.

6.3Upstash, Inc — the database the account record, the acceptance record and the sign-in record are held in.

6.4Anthropic PBC — only where you have switched drafting assistance on, and only what section 8 describes.

6.5We use no analytics, no advertising network, no tag manager, no session recorder, no customer data platform and no marketing automation. Nothing about you is sold, rented, or shared with anybody for their own purposes, and nothing about you follows you to another website.

6.6We may disclose personal data where the law or a regulator requires it, and to our professional advisers, auditors or insurers where it is necessary for them to advise us.

6.7Some of those providers process data outside the United Kingdom. Where they do, the transfer relies on the safeguards permitted by Article 46 of the UK GDPR — in practice the International Data Transfer Agreement, or the UK Addendum to the European Commission's standard contractual clauses — under each provider's own data processing terms. We will tell you which applies to which provider if you ask.

7. Cookies, and what is stored on your device

7.1There is one cookie. It is called lps_session, it holds a signed token identifying your session and nothing else, and it is set HttpOnly, Secure and SameSite=Lax with a lifetime of up to 30 days. It cannot be read by any script, on our pages or anybody else's.

7.2It is strictly necessary for a service you have asked for, which is why there is no cookie banner: regulation 6(4) of the Privacy and Electronic Communications Regulations 2003 exempts a cookie of that kind from the consent requirement. There is nothing else to consent to, because there is nothing else.

7.3The application also stores your Lift Plans, your equipment records and your settings in the browser's own storage on your device. That is not a cookie, it is never transmitted, and no part of it reaches us. It is also why clearing your browser data deletes your work and why we cannot get it back for you — keep your own exports.

8. Drafting assistance

8.1The application includes optional drafting assistance which proposes wording for written fields. It is off until you switch it on, and the application tells you what it sends before it sends it.

8.2Where it is on, the text of the field being drafted and the facts of the job are sent to Anthropic PBC for processing and a suggestion comes back. The facts of the job may include a client's site details, and may include the names of people on it, because that is what a lift plan is made of.

8.3The request does not carry your name, your email address, or any identifier for your account. It carries the text and nothing that says who sent it.

8.4Whether that is acceptable for a given job is your decision and, where the site is your client's, your client's. Where it is not acceptable, leave the assistance off; everything in the application works without it.

8.5No output of a language model is used in, or permitted to affect, any calculation. Every figure in a Lift Plan comes from the calculation engine. The assistance proposes words and never produces or alters a number.

9. Automated decisions

9.1We make no decision about anybody by automated means that produces a legal effect or anything similarly significant, and we do not profile anybody.

9.2The sign-in record is deliberately not scored. It reports three plain counts and a date — browsers, addresses, countries — and leaves the judgement to the person reading the screen. A single number saying an account "looks shared" would be wrong often enough to turn a conversation into an accusation built on an artefact of the arithmetic, so there is no such number.

9.3The attempt counters in clause 3.5 delay a sign-in attempt. They decide nothing about a person and nothing about an account.

10. Your rights

10.1Under the UK GDPR you have the right to:

(a)be told what we hold about you and be given a copy of it (Article 15);

(b)have anything inaccurate corrected, and anything incomplete completed (Article 16);

(c)have it erased where one of the grounds in Article 17 applies (Article 17);

(d)have our use of it restricted while a dispute about its accuracy or our grounds is resolved (Article 18);

(e)receive the data you gave us in a structured, commonly used, machine-readable form, and have it sent directly to another controller where that is technically feasible (Article 20);

(f)object to anything we do on the basis of legitimate interests, which means the sign-in record in clause 3.3 and the attempt counters in clause 3.5 (Article 21); and

(g)not be subject to a decision based solely on automated processing (Article 22), which as section 9 explains does not arise here.

10.2To exercise any of them, email ricky@rmtsolutions.co.uk. We will respond within one month. Where a request is complex or there are several of them the law allows us up to two further months, and we will tell you inside the first month if we are taking them and why.

10.3We may need to satisfy ourselves that you are who you say you are before we hand over a copy of an account's data. We will do that by asking something only the account holder could answer. We will not ask you to send us a passport, a driving licence or any other identity document, and you should not send us one.

10.4There is no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse it, and will explain which and why.

10.5Where you object under clause 10.1(f) to the sign-in record, we will stop unless we can show compelling legitimate grounds that override your interests. Objecting does not end your subscription and does not affect your use of the application.

11. Complaints

11.1If you think we have got something wrong, tell us first at ricky@rmtsolutions.co.uk. It is the fastest way to have it put right and we would rather hear it.

11.2You may complain to the Information Commissioner's Office at any time, and you do not have to come to us first. Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Telephone 0303 123 1113. ico.org.uk.

11.3Complaining to the Commissioner does not affect any other remedy you have, including a claim in court under Article 82 of the UK GDPR.

12. Changes to this notice

12.1This notice is published at liftplanstudio.com/privacy with a version number, an effective date and a SHA-256 digest of its exact wording, so that a version can be identified rather than described. The digest is generated from the text, not typed in beside it.

12.2Where a change materially affects how we use personal data we already hold, we will tell the account holder by email before it takes effect.

12.3Earlier versions are available on request.

12.4A change to this notice is not a change to the Software Licence Agreement. This notice tells you what we do; the agreement is what you agreed. Clause 17 of the agreement governs changes to that.