INSCOPE 360 privacy notice
1. Who we are
INSCOPE 360 (also referred to as AIM) is operated by The INS Group Ltd. We are the data controller for the personal data described in this notice, except where section 9 says a client of ours is. You can contact our data-protection lead at privacy@theinsgroup.co.uk. We do not have a statutory Data Protection Officer; the lead performs that role.
2. What INSCOPE 360 is
INSCOPE 360 is a platform that infrastructure programmes use to plan, deliver and record work on sites such as telecoms masts and rooftops: who visits which site, when, what they found, what documents and approvals apply, and what was paid for. It is used by INS staff, by staff of our clients, and by staff of our suppliers and subcontractors.
3. Whose data we hold, and what
| If you are… | We hold |
|---|---|
| A user with a login (INS, client or supplier staff) | Name, work email, phone number, employer, job title, profile photo if you add one; login history (time, method, IP address, browser); the work items, comments, files, approvals and notifications connected to your account; your notification preferences |
| A field engineer or drone pilot (in addition to the above) | Your home postcode and location (used to plan routes from home), qualifications and certificates with expiry dates and the scanned documents, CAA flyer and operator IDs, vehicle description, equipment serial numbers, emergency contact name and number, shift limits, site visit times (arrival and departure), work quality and productivity measures, leave and unavailability, and — where a site requires it — DBS, NPPV or security-clearance status (see section 5) |
| A site contact, access contact or out-of-hours emergency contact | Name, phone number, email and role as recorded against a site, usually supplied by the site owner or our client |
| A landlord, agent or other party to a lease or wayleave | Name, company, address, email, phone, role in the agreement, as taken from the lease documents |
| An external contact at a client, supplier or authority | Name, employer, job title, email, phone, and notes of our dealings with you (for example a record of a phone call about an invoice) |
| An attendee at a design review or a named person on a safety document | Name, organisation, role, phone number, attendance |
| Anyone appearing in site photography or drone imagery | Your image if you were on or near a site when it was surveyed (see section 6) |
We do not hold dates of birth, National Insurance numbers, passport or driving-licence numbers, or bank details as data fields. Uploaded certificate scans may contain some of these; they are visible only to you, your managers and platform administrators.
4. Why we use it, and our lawful basis
| Purpose | Lawful basis (UK GDPR Article 6) |
|---|---|
| Running your account and delivering the platform | Performance of a contract (with you or your employer) |
| Planning and scheduling site work, including routing from engineers' home locations | Legitimate interests: operating a field workforce efficiently |
| Recording site visits, work done, approvals and safety documents | Contract, and legal obligation (health and safety, construction records) |
| Checking qualifications, certificates and clearances before work is assigned | Legal obligation, and legitimate interests: only competent, cleared people attend sites |
| Measuring work quality and productivity | Legitimate interests: managing service delivery. You can ask to see your own figures (section 8) |
| Contacting site, access and emergency contacts | Legitimate interests: safe access to sites |
| Keeping audit trails of who did what | Legal obligation, and legitimate interests: accountability and dispute resolution |
| Sending you operational emails and notifications | Contract. You can turn off non-essential notifications in Settings |
| Security: login history, IP addresses, session records | Legitimate interests: protecting accounts and data |
We do not use your data for marketing, and we do not sell it.
5. Criminal-records and special-category data
Some sites, for example police or utility sites, require DBS, NPPV or security-clearance status. We record that a clearance is held, its level and expiry, and the supporting document. This is processed under the employment condition in Schedule 1 of the Data Protection Act 2018, and our Appropriate Policy Document is available on request. Absence and leave records may reveal health information; we ask that no diagnosis is recorded, and we use these records only to plan work.
6. Photography and imagery
Site surveys produce photographs, panoramas and drone imagery of infrastructure. People are not the subject and we do not identify them, but you may appear incidentally. Imagery is shared with the site owner and, for defect analysis, with our processor SiteSee (section 9). If you believe you appear in imagery and want it removed or blurred, contact us (section 8).
7. How long we keep it
| Data | Kept for |
|---|---|
| Account, work records, safety documents, financial records | 7 years after the record was made or the contract ended, to meet UK tax and construction-records requirements |
| Login history, session records, file-access and audit logs | Currently kept for the life of the platform. We are introducing shorter periods for these operational records and will publish them here when they take effect |
| Notifications, site contacts and external contacts | While the site or relationship is active. These are also covered by the shorter periods described above |
| Certificates and clearances | Until expiry, then with the related work record |
| Records of data-protection requests you make and our responses | Indefinitely, as proof of compliance |
Where we must keep a record but no longer need to know who you are, we replace your identity with a marker rather than delete the record.
8. Your rights
You can ask us to: give you a copy of your data (if you have a login you can download it now at My Profile, then My Data); correct it; erase it; restrict or object to particular uses, including the productivity measures in section 4; and, for data you gave us under contract, receive it in a portable format. Email privacy@theinsgroup.co.uk and we will respond within one month.
You can complain to the Information Commissioner's Office at ico.org.uk or 0303 123 1113. We would rather you told us first.
9. Who we share it with
- Our clients, the owners of the estates and sites you work on: work records, safety documents, site contacts and imagery for their sites. Our client is the controller of the site and contact data it supplies to us.
- Suppliers and subcontractors we engage: only the work assigned to them. Staff names and financial details are not shared across company boundaries.
- Processors acting for us: Microsoft (email, sign-in, calendar, hosting); SiteSee with Amazon Web Services (imagery analysis and its storage); Anthropic (AI reading of documents, only where the estate has opted in); Zoho (project tracking and support tickets, EU); Tailscale (encrypted connectivity for our engineers).
- Google Maps Platform (maps, geocoding and distance calculation, which includes sending engineers' home locations as route origins) and Xero (accounting), which use data under their own terms.
- Regulators, insurers and legal advisers where the law requires.
10. International transfers
Our data is hosted in the UK. Some of the processors named above operate in the United States. Where data leaves the UK we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and we assess the risk of each transfer. Copies of the safeguards are available on request.
Where we have not yet confirmed in writing which region a processor stores data in, we do not send it there. Imagery is not transferred to SiteSee's storage until its region is contractually confirmed.
11. Security
Data is encrypted in transit. Access is by named account with role-based permissions; sign-in attempts are rate-limited and logged; privileged access is audited; and multi-factor authentication is available. If we discover a breach that puts you at risk we will tell you and the Information Commissioner's Office.
12. Cookies
We set only the cookies needed to sign you in and protect forms. No analytics or advertising cookies are set.
13. Changes
We will post each new version here with its date. Material changes to how we use your data will be notified to users in the app.