Privacy policy
How Fail List Ltd uses personal data. Last updated 5 September 2026. We follow UK GDPR.
Who is the controller
Fail List Ltd is the controller for account data on faillist.co.uk. Contact hello@faillist.co.uk.
If you are an employee using an organisation account, your employer is usually the controller for site photos and job records they store in Fail List. We process that content on their instructions as a processor.
What we collect
- Name, email and password (hashed) when you create an account.
- Organisation name, company letterhead and logo if you add them.
- Role and membership inside an organisation.
- Content your organisation uploads later: drawings, asset records, photos, quotes and job evidence.
- Technical logs needed to run and secure the service.
Why we use it
To provide the account, keep you signed in, host your organisation’s records, and improve reliability. The legal bases are contract (providing the service you asked for) and legitimate interests (keeping the service secure).
Where it is stored
We use processors to run the service. We do not sell personal data.
- Neon — PostgreSQL in London (AWS eu-west-2).
- Vercel — hosts the web application.
- Cloudflare — DNS for faillist.co.uk.
Some of those providers may process data outside the UK. Where they do, we rely on an appropriate safeguard such as the UK International Data Transfer Agreement or UK Addendum to the EU SCCs.
How long we keep it
Account data is kept while the organisation uses Fail List. You can ask us to close an account. We may retain a copy for a short period where we must, for example to deal with a dispute or a legal request.
Your rights
You can ask for access, correction, deletion, restriction, or a copy of your data. You can complain to the Information Commissioner’s Office at ico.org.uk.
Cookies
See the cookie policy.