CostappReturn to Costapp

LEGAL INFORMATION

Privacy
Notice.

Last updated: 26 August 2026
Your information

This notice explains how Costapp Ltd uses personal information when you visit our website, use Costapp software, join a project, enquire about Costapp People services, seek work or provide services through us.

1. Who is responsible for your information?

Costapp Ltd, registered in England and Wales under company number 15112418, is the controller for personal information used to create and manage accounts, operate and secure the service, provide support and administer subscriptions and billing. Its registered office is 9 Regent Street, Runcorn, England, WA7 1LJ. Contact us at kevin.morley@costapp.co.uk.

For personal information that a customer puts into its project workspace, the customer normally decides why and how it is used and is the controller. Costapp acts as its processor under our Data Processing Agreement. You may therefore need to contact the relevant customer organisation about a project-data request.

Costapp is registered with the Information Commissioner’s Office and pays the applicable data protection fee. Its registration number will be added to this notice once verified against the public register.

2. Information we collect

  • Identity and contact data: name, work email address, organisation, role and project contact details.
  • Account and subscription data: account membership, permissions, plan, trial and subscription status, billing contact, invoices and payment status. Stripe handles full payment-card details; Costapp does not need to store them.
  • Website and trial measurement: pages viewed, video plays, free-trial clicks, registrations, signed-in activity, project creation and paid conversion; referring website host; campaign tags; timestamps; and a one-way pseudonymous visitor key that rotates daily. Costapp does not retain the raw IP address used momentarily to create that key.
  • Project and professional data: project team details, subcontractor contacts, contractual notices, responses, quotations, cost plans, commercial records, comments, correspondence and other information entered by users.
  • Costapp People data: CVs, employment and assignment history, skills, qualifications, references, availability, rates, right-to-work and identity-check information, limited-company or self-employed business details, insurance information, timesheets and engagement records.
  • Files and attachments: documents and other material users choose to upload or issue.
  • Technical and security data: sign-in events, IP address and device or browser information made available by our infrastructure, timestamps, audit activity and email-delivery information.
  • Support and communications: questions, feedback, fault reports and our replies.

Costapp software is not designed for special category data, criminal-offence data or unnecessary personal information. Customers should not upload it unless it is genuinely required, lawful and subject to appropriate safeguards. Costapp People may process limited health, equality-monitoring or criminal-record information where it is relevant to a role and lawful safeguards are in place.

3. Where the information comes from

We receive information directly from you, from your employer or another Costapp customer that invites you or includes you in a project, from authorised project participants, and from documents uploaded to the service. For Costapp People, information may also come from referees, clients, recruitment contacts, public professional profiles, qualification bodies and lawful right-to-work or compliance checks. We also receive limited account information from ChatGPT/OpenAI sign-in and subscription or transaction information from Stripe.

4. How and why we use it

  • To provide accounts, project workspaces, collaboration, document issue, exports, support and subscription services, because this is necessary to perform our contract or take requested pre-contract steps.
  • To measure how people find and use the Costapp website, video, trial and software funnel, assess outreach campaigns and improve the service. We use limited first-party statistical information, daily rotation and one-way pseudonymisation to protect privacy. This supports our legitimate interests in understanding and improving our business service.
  • To consider people for work, make introductions, manage assignments and services, verify suitability and qualifications, administer pay and timesheets, and communicate with clients, candidates, workers, contractors and service providers.
  • To authenticate users, prevent misuse, investigate faults, protect Costapp and improve reliability, based on our legitimate interests in operating secure and effective business services.
  • To administer billing, payroll, tax, pensions, CIS or off-payroll obligations where applicable, maintain business records and comply with legal and regulatory obligations.
  • To communicate service, security and contractual information, based on contract and our legitimate interests.
  • To establish, exercise or defend legal claims and respond to regulators or lawful requests.
  • For optional marketing or non-essential cookies only where consent is required and has been obtained. Costapp does not use advertising cookies or cross-site behavioural tracking.

Where we rely on legitimate interests, we consider the need for the processing, its effect on people and whether there is a less intrusive way to achieve the purpose. Browser Do Not Track and Global Privacy Control signals stop the first-party website-measurement event from being stored.

5. Who we share information with

We share information only where necessary with:

  • authorised people in the customer’s account and project recipients selected by the customer;
  • prospective and current Costapp People clients considering or managing a person for a role or service;
  • payroll, pension, umbrella, background-check, qualification, insurance and professional advisers used for a lawful engagement;
  • OpenAI/ChatGPT Sites and Cloudflare infrastructure used for sign-in, hosting, application delivery, security, database and file storage;
  • Stripe for subscription billing, payments and the billing portal;
  • Resend for transactional email delivery;
  • professional advisers, auditors, insurers and prospective buyers or investors under suitable confidentiality duties; and
  • courts, regulators, law-enforcement bodies or other parties where disclosure is required or permitted by law.

We do not sell personal information.

6. International transfers

Some providers or their support operations may process information outside the United Kingdom. Where UK data protection law requires it, we use an adequacy regulation or approved contractual safeguards, such as the UK International Data Transfer Agreement or UK Addendum, and assess supplementary protections as appropriate. Provider locations can change, so contact us if you need current transfer information for your organisation.

7. How long we keep information

We keep information only for as long as reasonably needed for the purpose collected, including legal, accounting, security and dispute requirements. Our normal criteria are:

  • website and trial measurement events for up to 12 months, after which they are deleted or reduced to non-identifying totals;
  • account and project data while the customer’s agreement is active;
  • after termination, the workspace is placed into controlled read-only access while export or deletion is arranged;
  • unless the customer instructs earlier return or deletion, project data may be retained for up to 12 months to allow export or reinstatement;
  • protected backup copies remain only until securely overwritten in the ordinary backup cycle and are not used routinely;
  • candidate and work-seeker records while an engagement or introduction is active and afterwards for the period reasonably needed to manage repeat opportunities, compliance, complaints and legal claims;
  • financial, payroll, tax, assignment and subscription records for up to seven years;
  • routine support, security and email-delivery records for up to 24 months; and
  • records relevant to a complaint, investigation or legal claim for as long as reasonably necessary to resolve and document it.

Deletion and export are currently administered through a controlled request rather than an automatic account purge. Customers may request export or deletion at any time, and we will confirm the applicable steps and completion. A different retention period may apply where a customer’s order, engagement terms or legal obligation requires it.

8. Security

We use proportionate technical and organisational measures designed to protect information, including authenticated access, role and project permissions, provider-managed encryption in transit, restricted administrative access, security monitoring and incident procedures. No internet service can promise absolute security. Customers must manage their users and recipients carefully and protect their own devices and sign-in access.

9. Your data protection rights

Depending on the circumstances, you may have rights to be informed, access your information, correct it, have it erased, restrict its use, object to processing, receive portable information, and withdraw consent where consent is the basis. These rights can be limited by law and may need to be handled by the customer that controls the project data.

To make a request, email kevin.morley@costapp.co.uk. We may need to verify your identity.

10. Data-protection complaints

You may make a data-protection complaint by emailing kevin.morley@costapp.co.uk with the subject “Data protection complaint”. We will acknowledge the complaint within 30 days, investigate it without undue delay, keep you informed where the investigation remains open and communicate the outcome. We maintain a complaint record and may ask for information needed to verify identity, authority and the relevant facts.

If you remain dissatisfied, you may complain to the Information Commissioner’s Office.

11. Children

Costapp is a business service and is not intended for children or anyone under 18. We do not knowingly offer accounts to children.

12. Changes to this notice

We may update this notice as the service, providers or law changes. The current version and date will remain on this page, and we will give active customers appropriate notice of a material change.