Legal
Privacy Policy
Last updated 28 July 2026
This Privacy Policy explains how Simtec Consult Ltd handles personal data when you visit or use SIMTRACA.
1. Who we are
Simtec Consult Ltd is a private company limited by shares, registered in England and Wales under company number 13710785. Our registered office is Illtud House, Station Road, Llantwit Major, Vale of Glamorgan, Wales, CF61 1ST.
For account administration, billing, service communications, and operation of our own business, we act as a data controller.
For personal data that a customer organisation enters into Waste Transfer Notes or other operational records, we usually act as that organisation's data processor. The customer organisation determines why and how that data is used.
Questions about privacy can be sent to [email protected].
2. Personal data we collect
Depending on how you use the service, we may collect:
Account and identity data
- name, business email address, profile image, and authentication details;
- organisation membership and role;
- passkey, two-factor authentication, session, device, IP address, and security event data; and
- email verification, invitation, and password reset records.
We do not store plain-text passwords.
Organisation and billing data
- organisation name, company number, address, subscription plan, usage, and billing status;
- Stripe customer and subscription references; and
- communications with our support or feedback channels.
Stripe processes card and payment details. We do not receive or store complete card numbers.
Waste operations data
Customer organisations may provide:
- receiving site, permit, licence, exemption, and contact details;
- producer, broker, carrier, and receiver details;
- Waste Transfer Note and digital receipt data;
- carrier registration and Environment Agency lookup results;
- names and signatures associated with waste receipt;
- delivery photographs and file metadata;
- DEFRA API codes, submission responses, Waste Tracking IDs, warnings, and errors; and
- audit history showing who created, changed, completed, or submitted a record.
Technical data
We process logs and diagnostics needed to secure, operate, and troubleshoot the service. This may include timestamps, request details, browser type, device information, IP address, and error data.
Website storage
We use essential session cookies and limited functional storage. See our Cookie Policy.
3. How we receive personal data
We receive personal data:
- directly from you when you register, use the service, contact us, or upload content;
- from your organisation and its Org Admins when they invite or manage members;
- from public Environment Agency registers when a carrier is checked;
- from DEFRA when the service submits or updates a digital receipt;
- from Stripe about subscription and payment status; and
- automatically through essential session and security technologies.
4. How and why we use personal data
Where we act as controller, our purposes and usual UK GDPR lawful bases are:
| Purpose | Usual lawful basis |
|---|---|
| Create and manage accounts, subscriptions, and requested services | Contract |
| Authenticate users and protect accounts and systems | Contract and legitimate interests |
| Process billing and maintain financial records | Contract and legal obligation |
| Send service, security, and administrative communications | Contract and legitimate interests |
| Provide support and respond to feedback | Contract and legitimate interests |
| Monitor reliability, prevent misuse, and improve the service | Legitimate interests |
| Establish, exercise, or defend legal claims | Legitimate interests |
| Meet tax, accounting, regulatory, and legal duties | Legal obligation |
Our legitimate interests include operating a secure and effective B2B software service, preventing fraud, understanding service performance, and improving customer support. We balance those interests against the rights of affected people.
Where we process operational records for a customer organisation, that organisation decides the lawful basis. Please contact that organisation if you want to exercise rights relating to information it controls.
We do not use personal data for automated decision-making that produces legal or similarly significant effects.
5. Who we share data with
We share personal data only where needed with:
- authorised members of the relevant customer organisation;
- DEFRA Digital Waste Tracking when an authorised user submits or updates a receipt;
- the Environment Agency when carrier data is checked against its public service;
- cloud hosting, managed database, object storage, email, monitoring, and support providers;
- Stripe for subscriptions, payment processing, and billing portal services;
- professional advisers, insurers, auditors, and prospective business purchasers under confidentiality obligations; and
- courts, regulators, law enforcement, or public authorities where required by law.
Our service providers may process data only under contract and for the services they provide to us.
6. International transfers
Some service providers may process personal data outside the United Kingdom.
Where UK personal data is transferred to a country without UK adequacy regulations, we use an appropriate safeguard such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism. We also assess supplementary protections where required.
You may contact us for more information about the safeguards used for a particular transfer.
7. How long we keep data
We retain personal data only for as long as reasonably needed for the purpose for which it was collected, including legal, accounting, regulatory, security, and dispute-resolution requirements.
Our current approach is:
- account and organisation records are kept while the account or customer relationship is active;
- subscription and transaction records are normally kept for at least six years after the relevant financial year where UK tax or accounting law requires it;
- operational Customer Data is kept for the subscription term and a limited period after termination so the customer can retrieve it;
- authentication, security, and diagnostic logs are kept for a shorter period proportionate to security and troubleshooting needs; and
- backups expire through scheduled rotation and are not retained indefinitely.
Customer organisations may need to retain waste records for periods set by environmental or duty-of-care law. They are responsible for deciding and meeting those retention requirements.
8. Security
We use technical and organisational measures designed to protect personal data, including:
- encrypted network connections;
- password hashing and support for passkeys and two-factor authentication;
- organisation-based access controls;
- server-side handling of DEFRA credentials and API calls;
- controlled access to production systems;
- backups, audit records, and change controls; and
- supplier due diligence and contractual safeguards.
No service can guarantee absolute security. If you believe personal data or an account has been compromised, contact us promptly at [email protected].
9. Your rights
Under UK data protection law, you may have rights to:
- access your personal data;
- correct inaccurate or incomplete data;
- request erasure;
- restrict processing;
- object to processing based on legitimate interests;
- receive certain data in a portable format; and
- withdraw consent where processing relies on consent.
These rights are not absolute and may depend on the circumstances.
To exercise a right concerning account or billing data controlled by us, email [email protected]. To exercise a right concerning a Waste Transfer Note or another customer's operational record, contact the customer organisation first. We will assist that organisation where required by our Data Processing Agreement.
We may ask for information needed to verify identity. We normally respond within one month, subject to the extensions permitted by law.
10. Complaints
Please contact us first so we can try to resolve your concern.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority:
- Website: ico.org.uk
- Telephone: 0303 123 1113
11. Business contacts and communications
We may send service messages needed to operate your account, such as verification, security, invitation, billing, and material product-change notices. These are not marketing messages.
If we introduce optional marketing communications, we will provide an appropriate choice and an unsubscribe method.
12. Changes to this policy
We may update this policy to reflect changes to the service, suppliers, or law. We will publish the new version here and update the date above. We will give reasonable notice of material changes where appropriate.
13. Contact
Data protection enquiries:
Simtec Consult Ltd
Illtud House, Station Road, Llantwit Major, Vale of Glamorgan, Wales, CF61 1ST
[email protected]