Privacy notice

Last updated 14 August 2026 · version 2026-08-14

What personal data UnitOps holds, which of it we decide about and which of it you do, who it is shared with, and how long it is kept.

This notice explains what personal data UnitOps holds, who decides what happens to it, who else sees it and how long it is kept. It covers the software at this address only.

1. Start here: which half applies to you

UnitOps holds two kinds of personal data, and our responsibilities are different for each. Almost every question about this notice is answered by working out which one you are asking about.

Data about our own customers — we are the controller
The people who sign up for UnitOps, run a company account, and deal with us about billing and support. We decide what is collected and why, so we are responsible for it. Sections 2 to 4 cover this.
Data your company puts into UnitOps — we are the processor
Your clients' contacts, your crew's records, who worked which job. Your company decides what goes in and what it is for; we hold it and act on your instructions. You are the controller and we are your processor. Section 5 covers this, and section 11 sets out the terms we process it on.

If you are an employee or contractor of a business that uses UnitOps — if somebody gave you a login to book kit or record your certifications — your employer decides what is held about you and why. Ask them first: they can see, correct and delete your record, and we cannot do any of that without their instruction. If you cannot get an answer from them, contact us and we will pass it on.

2. What we hold about our own customers

Name, work email address, job title, and the company you signed up for
To create and run the account, and to reach you about it.
A hashed password, and a two-factor secret and recovery codes if you turn it on
To let you sign in and to keep other people out. Passwords are stored hashed and cannot be read back.
Sign-in records: date, time, outcome, IP address, browser
Security. Shown to your own administrators so they can spot an account being attacked.
An audit trail of significant actions taken in the app, with IP address and browser
So your company can see who changed what, and so we can investigate abuse.
Company details for billing, invoices raised to you, and payment status
To take payment and to meet our own tax and accounting obligations.
Support correspondence, and a record of email we have sent you
To answer you, and to prove what was sent and when.
Preferences: language, theme, notification settings
So the app looks and behaves the way you set it, on any device.

We do not build profiles, we do not make automated decisions that have a legal or similarly significant effect on anyone, and we do not use your data or your customers' data to train machine learning models.

  • Contract. Running the account, taking payment, and providing support — we cannot do any of it without the data above.
  • Legitimate interests. Keeping the service secure, preventing abuse, investigating faults, and understanding in aggregate how the software is used so we can improve it. We have weighed these against your interests and limited what is collected accordingly.
    This is also the basis for the anonymous, cookieless count of visits to the public pages described in the cookie notice — it stores nothing on your device and cannot follow you anywhere, and the interest is knowing whether the page that sells the software works. You can object to it; a tracker blocker also stops it outright.
  • Legal obligation. Keeping accounting records, and responding to lawful requests.
  • Consent. The analytics cookies on the public pages, and nothing else. They are not set until you say yes, refusing costs you no part of the service, and you can change your mind at any time from the cookie notice. If we ever want consent for anything further — marketing email, say — we will ask for that separately and on the same terms.

4. Who else sees it

We do not sell personal data and we do not share it for advertising. It is shared only with:

  • Our hosting provider, which runs the servers UnitOps and its database sit on. The country is stated at the foot of this page.
  • Microsoft, when UnitOps sends email — invitations, password resets, notifications, and documents you email to a client. Outbound mail is sent through Microsoft 365.
  • Google, for visits to the public pages only — the sales page, the sign-in page and the legal pages. No page inside the application is measured, so Google is never given anything from your records. Two levels apply: every visit is counted anonymously with no cookie and nothing stored on the device, and, if the visitor agrees, cookies are set so that a visit can be recognised across several pages. IP addresses are truncated. The cookie notice sets out both in full and carries the control for changing your mind.
  • A payment provider, once card payment is switched on. It is not switched on today, and no card details pass through UnitOps.
  • Our professional advisers — accountants, lawyers — where they need it.
  • Authorities, where we are required by law to disclose something. We will tell you unless we are prohibited from doing so.
  • A buyer, if the business is sold, under the same protections as this notice.

Where personal data leaves the UK, we rely on the UK's adequacy regulations or on the International Data Transfer Agreement or Addendum, as applicable. Google Analytics is processed in the United States; refusing the analytics cookies stops anything being stored about you, and a tracker blocker stops the transfer altogether.

Your company's records are never given to any of them beyond what the service requires. Hosting holds them because the database is there. Microsoft carries the email you choose to send. Google is given nothing from inside UnitOps at all — it only sees visits to pages a stranger could already read.

5. The data your company puts in

This is the bulk of what UnitOps holds, and it is yours rather than ours. Depending on which modules you use it can include:

  • Your clients: company details, contact names, email addresses, phone numbers, addresses, credit terms, and documents you upload against them.
  • Your staff and crew: names, contact details, job titles, skills, certifications and their expiry dates, availability and leave, and which jobs they were assigned to.
  • Your operations: bookings, venues, equipment allocations, PAT test results and who carried them out, repairs, and the notes anybody typed against any of it.
  • Your paperwork: estimates, invoices, payments, and any document you have shared with a client by link.

We hold it, keep it separated from every other company's, and act on your instructions. We do not use it for our own purposes. Section 11 is the detail.

Certifications and availability can amount to special category data. A certificate that lapses because somebody was on sick leave, or an availability note explaining why, is health data. Decide what your company records there, and keep it to what you actually need — that decision is yours, not ours, and it is your legal exposure if it goes too far.

6. Cookies

One essential cookie, no analytics, no advertising, and nothing that follows anybody between sites. The detail, including what else the browser stores and why you are not asked to consent, is in the cookie notice.

7. How long it is kept

  • Your records, while you are a customer: until you delete them. UnitOps does not delete your data on a schedule — what you put in stays until somebody in your company removes it, so how long you keep a client's details is your retention decision to make and to apply.
  • After an account closes or lapses: at least 30 days, and we may delete it after 90. Export what you need before then. Ask us to delete it sooner and we will, unless we have to keep something.
  • Sign-in and audit records: kept while the account is live, because that is what makes them useful to your administrators.
  • Invoices and accounting records: six years, because tax law says so.
  • Support email: as long as it is useful, and not more than three years after the account closes.
  • Backups: a deleted record can survive in a backup for a short period after deletion, and is deleted when that backup rotates.

8. How it is protected

  • Traffic to and from UnitOps is encrypted in transit.
  • Passwords are stored as bcrypt hashes and are never recoverable; nobody at Sweet Pea Software can read one.
  • Two-factor authentication is available on every account. Require it of your administrators.
  • Every query in the application is scoped to one company, so one customer's data is not reachable from another's session.
  • Sign-in attempts and significant changes are logged with IP address and browser, and shown to your own administrators.
  • Support staff can enter a customer's account to diagnose a fault. That is deliberately limited: it is time-limited, it cannot be used to change a password or reach billing, every action taken is recorded against the operator rather than the person whose account it is, and it is visible in your audit trail. It happens for support reasons, and we will normally have asked you first.
  • Documents shared with a client by link are protected by a signed URL rather than a login, so treat those links as confidential and revoke one if it goes astray.

No system is perfect. If we suffer a breach that is likely to result in a risk to people's rights, we will notify the ICO within 72 hours where required, and tell you without undue delay so that you can meet your own obligations as controller.

9. Your rights

Where we are the controller — the data in section 2 — you can ask us to:

  • give you a copy of what we hold about you, and where it came from;
  • correct it if it is wrong;
  • delete it, where we do not have to keep it;
  • restrict or object to what we do with it;
  • give you a portable copy of what you gave us;
  • stop relying on consent, where consent is what we relied on.

Email the address at the foot of this page. We will answer within one month. We will not charge you unless a request is repetitive or excessive.

Where the data is your employer's rather than ours — section 5 — send the request to them. If it reaches us instead, we will pass it on and help them answer it, but we will not act on it ourselves.

You can complain to the Information Commissioner's Office at ico.org.uk, on 0303 123 1113. We would rather you came to us first so we can put it right.

10. Who to contact

Sweet Pea Software is the controller for the data in section 2. Our details, including the address for data protection questions, are at the foot of this page. We have not appointed a data protection officer — we are not required to — and questions go to the same address as everything else.

11. The terms we process your data on

This section is the data processing agreement between us for the purposes of Article 28 of the UK GDPR, and forms part of the terms of use. In it, you are the controller and we are the processor.

  • Subject matter and duration. Providing UnitOps to you, for as long as your account exists, plus the retention period in section 7.
  • Nature and purpose. Storing, organising, retrieving, displaying, transmitting and deleting the records described in section 5, so that the software works.
  • Categories of data and data subjects. As described in section 5: your staff, your clients and their contacts, and anybody named in a booking or a document.
  • Our instructions. We process it only on your documented instructions, which include your use of the software's features, unless the law requires otherwise — in which case we will tell you first, unless the law forbids that.
  • Confidentiality. Anybody with access is under a duty of confidence.
  • Security. The measures in section 8, kept appropriate to the risk.
  • Sub-processors. You give general authorisation for the sub-processors in section 4. We will give you notice before adding or replacing one, and you may object on reasonable data protection grounds — if we cannot resolve it, you may cancel without penalty. Each is bound by obligations no weaker than these.
  • Helping you. We will assist with data subject requests, with breach notification, and with impact assessments, so far as is reasonable and given the information available to us.
  • Deletion and return. On termination we will delete your data within the period in section 7, or return it to you if you ask before then. Export is available from inside the app while your account is reachable.
  • Audit. We will make available the information reasonably needed to show we are meeting these obligations, and will contribute to an audit or inspection at your reasonable cost and on reasonable notice.

12. Children

UnitOps is business software and is not directed at children. Do not give a login to anyone under 16. If your company records details of a young worker in a staff record, that is your decision as controller and your responsibility to justify.

13. Changes to this notice

We update this notice when what we do changes. The date at the top of this page is when it last changed, and material changes are notified the same way as changes to the terms — by email to your company's administrators and by a notice inside the app.


Who you are dealing with

Trading name
Sweet Pea Software
Registered name
[registered company name]
Company number
[company number]
Registered office
[registered office address]
VAT
Not VAT registered. No VAT is charged on our invoices.
Hosting
[country the hosting is in]
Governing law
England and Wales
Contact
support@sweetpeasoftware.com