Privacy Policy
Last updated 8 September 2026
This policy explains what personal data Techcopter Ltd ("Techcopter", "we") collects when you use techcopter.co.uk and the Techcopter platform, why we collect it, and what rights you have over it.
It is written to describe what the software actually does. Where we say we do not collect something, that is because there is no code that collects it.
Who we are
Techcopter Ltd (company number 14423500), 2 Frederick Street, Kings Cross, London, WC1X 0ND, United Kingdom, is the data controller for the personal data described in this policy.
For any privacy question, or to exercise the rights set out below, contact privacy@techcopter.co.uk.
What we collect, and why
Each category below is listed with the reason we hold it and the lawful basis we rely on under UK GDPR. We only hold a category if you use the part of the service that needs it — signing in with Google, for example, means we never hold a password for you.
| Data | Why we hold it |
|---|---|
| Account: your name, email address, a hashed password, your role, and whether your email is confirmed | To create and secure your account. Lawful basis: performance of a contract. |
| Google sign-in, if you use it: the permanent account identifier Google issues for you, and the email address on that Google account | To recognise you next time without holding a password for you. We ask Google only for your name, email address and basic profile — never your contacts, files or anything else in your Google account. Lawful basis: performance of a contract. |
| Session: a hashed session token, its expiry, your IP address and browser user-agent | To keep you signed in and to detect abuse. Lawful basis: legitimate interests (securing the service). |
| Enquiries: your name, email, organisation, the subject you chose, your message, plus IP address and user-agent | To answer you and to limit automated abuse of the form. Lawful basis: legitimate interests, and steps toward a contract. |
| Billing account: your PayPal payer ID and the email on your PayPal account, your plan, seat count and billing dates | To provide and bill the subscription you bought. Lawful basis: performance of a contract. |
| Invoice details you give us at checkout: the billing contact's name and email address, the company being invoiced, its billing address, and — where you enter them — a VAT number and a purchase-order reference | To issue an invoice your finance team can accept, and to keep the accounting records the law requires of us. We also record when you accepted these terms. Lawful basis: performance of a contract, and legal obligation for the accounting record. |
| Invitations: the email address of anyone you invite to your workspace, until they accept or the invitation is removed | To let you add colleagues to your workspace. Lawful basis: legitimate interests (running the workspace you asked for). |
| Learning records: modules assigned to you, your progress and completion dates | To deliver training and produce completion evidence for your employer. Lawful basis: performance of a contract. |
What we do not collect
Techcopter runs no analytics, no advertising pixels and no third-party trackers. We do not profile you, we do not build advertising audiences, and we do not sell or share personal data with data brokers. There is no code in the product that does any of these things.
We never see your payment card or bank details. Payments are handled entirely by PayPal, and the only things we receive back from PayPal are a payer identifier, the email on the PayPal account, and the status of the subscription. That is separate from the invoice details you type into our checkout form, which are listed in the table above and which we do hold.
We do not ask for special category data (health, biometrics, political opinions and similar), and you should not send it to us.
Cookies and browser storage
Techcopter sets two cookies, both strictly necessary, and neither of them present until you sign in:
| Cookie | Purpose |
|---|---|
| tc_session | Keeps you signed in. HttpOnly, Secure and SameSite=Lax. Contains a random token — no personal data is stored in the cookie itself. Expires after 30 days, or immediately when you sign out. |
| tc_oauth_state | Set only when you choose to sign in with Google, and only for the ten minutes that takes. HttpOnly, Secure and SameSite=Lax. It holds a random token that lets us check the reply came from the sign-in you started, which is what stops someone else's sign-in being substituted for yours. Deleted as soon as you come back from Google. |
Cookies, continued
Both cookies are strictly necessary to provide a service you asked for, so neither requires consent and we do not show a cookie banner. Browsing the site without signing in sets no cookies at all. If we ever add analytics, we will ask for your consent before it runs, and this policy will change before that code ships.
The signed-in workspace also stores a small amount of data in your browser's local storage — your colour theme, whether the sidebar is collapsed, and whether you have seen the welcome tour. This never leaves your device and is not personal data. Clearing your browser data removes it.
Fonts are served from our own domain. Although they originate from Google Fonts, they are downloaded when the site is built and served by us, so your browser makes no request to Google and your IP address is never disclosed to them.
Who else processes your data
We keep the list of processors short on purpose.
| Processor | What they handle |
|---|---|
| PayPal | Payment and subscription processing. PayPal is a separate controller for the payment itself and applies its own privacy policy. |
| Sign-in, only if you choose it. Google tells us your name, email address and account identifier, and learns that you signed in to Techcopter. Google is a separate controller for your Google account itself and applies its own privacy policy. | |
| GoDaddy | Hosting of the application, database and uploaded files, and the mail account that sends verification and enquiry email. |
| OpenAI | Part identification, and only if you use that step on the conversion page. It receives the name of your file and the names of the parts inside it — never the geometry itself, and never your account, billing or training data. Nothing is sent unless you press the button. |
Where your data is held
Application data and uploaded files are stored on our hosting provider's infrastructure in Singapore. That includes your account, your enquiries and anything you upload.
Singapore is not covered by a UK adequacy decision, so storing your data there is a restricted transfer under UK GDPR. We rely on the UK International Data Transfer Addendum with our hosting provider, together with an assessment of the risks of that transfer, and we keep both under review.
PayPal processes payments internationally and may transfer data outside the UK and EEA under its own safeguards. Where we transfer personal data outside the UK, we rely on the UK International Data Transfer Addendum or an adequacy decision.
How long we keep it
| Data | Retention |
|---|---|
| Account and learning records | Kept while your account is open. Closing it deletes them immediately — you can close it in Settings, in the app, or by writing to us. |
| Sessions | Deleted automatically when they expire, and immediately when you sign out. |
| Abuse-prevention counters (which include IP addresses) | Deleted automatically after 24 hours. |
| Enquiries | 24 months from your last contact with us. |
| Billing records, including the invoice details you gave us at checkout | Kept for at least 6 years, which is what tax and accounting law requires of us. These survive account closure, because the obligation to keep them does. |
| Invitations you have sent | Kept until the invitation is accepted or removed. If you close your account but colleagues remain in the workspace, any invitations still outstanding belong to that workspace and remain with it; if you were the last member, the workspace and its invitations are deleted with your account. |
How we protect it
No system is perfectly secure. If we ever suffer a breach that is likely to result in a risk to your rights, we will notify the ICO within 72 hours and tell you directly where the risk is high.
Passwords are hashed with scrypt and are never stored or logged in a readable form — we cannot see your password, and a database leak would not reveal it.
Session cookies hold a random token; only a SHA-256 hash of that token is stored in our database, so a copy of the database cannot be replayed to sign in as you.
Uploaded model files are stored outside the public web root and can only be reached through an authenticated request.
The site is served over HTTPS and session cookies are marked Secure, so they are never transmitted unencrypted.
Your rights
Under UK GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. You can also withdraw consent where we rely on it.
Write to privacy@techcopter.co.uk. We will respond within one month.
If your employer bought your Techcopter seat, they may be the controller of your learning records. We will tell you if that is the case and point you to them.
If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk.
Children
Techcopter is a professional tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
Changes
If we change this policy materially — for example by adding a processor or a new category of data — we will update the date at the top and, for significant changes, email account holders before the change takes effect.
See also the Privacy Policy and Terms of Service.