Privacy Policy
Last updated: 28 July 2026
1. Who we are
CCP-M ("we", "us") operates the Construction Competency Passport for Mechanical Services platform ("the Service") at competenceid.com. We are the data controller for the personal data we process about individual workers ("Workers") and employer administrators ("Employers") who use the Service. Contact: privacy@competenceid.com.
2. What we store
- Account details: name, work email, employer, job role, national insurance number (optional).
- Competence records: skills cards, training certificates, CPD, qualifications, expiry dates.
- Evidence files: card scans, certificates, photos of physical qualifications, PDFs.
- Assessment results: knowledge assessment scores, behaviour reviews and their evidence.
- Project records: assignments, verified experience, employer verifications.
- Operational metadata: audit logs of consequential actions, timestamps, IP address at sign-in.
3. Lawful bases (UK GDPR Article 6)
- Contract — providing your CCP-M account and delivering the Service you have signed up for.
- Legal obligation — retaining competence and verification records to help duty holders meet Building Safety Act 2022 and CDM 2015 obligations (the "golden thread").
- Legitimate interests — securing the Service, preventing fraud, product analytics, and (for Employers) demonstrating workforce competence to their clients and regulators.
- Consent — for optional marketing about product updates, and for the employer–worker link described below.
4. The employer–worker link
Workers own their passport for life. When a Worker joins an Employer's workspace they consent to that Employer viewing their competence records for the duration of the link. Consent is revocable at any time from the Worker's profile.
When consent is revoked, the Employer retains an immutable snapshot of records that duty-holder law requires them to keep (verified experience, behaviour reviews already submitted, exports produced). New records are no longer visible to the former Employer.
5. Data retention — archived, not destroyed
Competence-relevant records are archived, not destroyed, when an account is closed or an employer link ends. This is necessary because Employers, Principal Contractors and duty holders must be able to reproduce the golden thread of competence for the lifetime of a building.
- Account profile: retained for 7 years after account closure.
- Verified experience, behaviour assessments, verifications: retained for the life of the record plus at least 15 years, to align with typical building limitation periods.
- Support communications: 24 months.
- Marketing consents: until you withdraw them.
Records marked immutable by CCP-M (behaviour assessments, verifications, project completions, stored scores with weights version) cannot be edited or deleted — only superseded. This is a design requirement of the golden thread.
6. Subprocessors
We use the following processors under contract. Adding or changing a subprocessor is announced 30 days in advance where practicable.
- Supabase — application database, authentication, file storage (EU region).
- Stripe — subscription billing and payments.
- Resend — transactional email delivery (expiry alerts, verification notices, billing).
- OpenAI — optional AI features (OCR of uploaded certificates, gap analysis, question generation). Uploaded content is transmitted to OpenAI only when a user initiates one of these features. AI outputs never determine competence outcomes on their own.
7. International transfers
Personal data is stored in the EU (Supabase EU region) by default. Where a subprocessor above processes data outside the UK/EEA, we rely on the UK International Data Transfer Addendum or Standard Contractual Clauses.
8. Security
Passwords are hashed. Row-Level Security enforces that Workers can only read/write their own records, Employers can only read linked Workers while consent is active, and Principal Contractors get read-only project aggregates. File access is signed. All consequential actions are audit-logged.
9. Your rights
Under UK GDPR you have the right to:
- Access your personal data (Worker: your passport is your access portal).
- Rectify inaccurate data — for immutable records, request supersession.
- Erase data, subject to the retention obligations above.
- Restrict or object to processing based on legitimate interests.
- Data portability — export your passport as PDF/CSV at any time.
- Withdraw marketing consent — one-click in email footers and in Notification settings.
- Lodge a complaint with the Information Commissioner's Office (ico.org.uk).
To exercise a right, email privacy@competenceid.com.
10. Cookies
We use a small number of strictly-necessary cookies for authentication and session management. We do not use advertising cookies. If we add product analytics we will show a cookie notice and require consent before non-essential cookies are set.
11. Changes
Material changes to this policy are announced by email to account holders at least 30 days in advance. The "Last updated" date at the top of this page reflects the current version.